{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-741b991b03fbb5aa", "name": "Stray `console.log` in TS/JS \u2014 Oscar_Server/scripts/lint-inline-scripts.js:170", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Oscar_Server/scripts/lint-inline-scripts.js:170"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d04c4040cb3d4829", "name": "Icon-only button without accessible name \u2014 Oscar_Server/public/js/scenarios.js:4946", "shortDescription": {"text": "Icon-only button without accessible name \u2014 Oscar_Server/public/js/scenarios.js:4946"}, "fullDescription": {"text": "A `<button>` whose only child is a single glyph or symbol needs `title=` or `aria-label=` so screen readers (and tooltips on hover) work.\n\nWhy: P3 in CHECKLIST.md \u2014 icon-only buttons skipped a title.\nRule id: fq.button.no-label"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d50539b252044b06", "name": "TODO/FIXME marker in shipping code \u2014 Oscar_Server/public/js/scenarios.js:1032", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 Oscar_Server/public/js/scenarios.js:1032"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-020884c918b645c9", "name": "Stray `console.log` in TS/JS \u2014 Oscar_Server/public/js/scenarios.js:1147", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Oscar_Server/public/js/scenarios.js:1147"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1e2ae3f4e6cdf3e3", "name": "Stray `console.log` in TS/JS \u2014 Oscar_Server/src/utils/at-rest.js:58", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Oscar_Server/src/utils/at-rest.js:58"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-46bd273d170432f3", "name": "Stray `console.log` in TS/JS \u2014 Oscar_Server/src/db/db.js:319", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Oscar_Server/src/db/db.js:319"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-45da7b5ec00db69e", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/osdmVersion.js:171", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/osdmVersion.js:171"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bb5603673ced7287", "name": "TODO/FIXME marker in shipping code \u2014 Bruno_Collection/library-bruno/fulfillments.js:190", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 Bruno_Collection/library-bruno/fulfillments.js:190"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8e08cd678682e135", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/fulfillments.js:206", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/fulfillments.js:206"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72c3a27635c536e9", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/scenarioParser.js:516", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/scenarioParser.js:516"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e0af670ac7fe5d86", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/expiredFlow.js:464", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/expiredFlow.js:464"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9c67f38692c552fa", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/osdmSchema.js:153", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/osdmSchema.js:153"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-38cbbea5a783614b", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/exchanges.js:307", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/exchanges.js:307"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-53aa76075b7cc746", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/osdmSchemas.js:2385", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/osdmSchemas.js:2385"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7ecaa871356e263c", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/mergeReport.js:263", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/mergeReport.js:263"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-096cd791fb90a44c", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/offers.js:122", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/offers.js:122"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5e1fa29b60fbc808", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/auth.js:192", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/auth.js:192"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cb143a08de7a368b", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/requestedInformation.js:866", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/requestedInformation.js:866"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-311ae10b65d01734", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/partialRefund.js:368", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/partialRefund.js:368"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3be45e5826ee9452", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/envUtils.js:35", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/envUtils.js:35"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-06f9a589d83b3609", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/afterSalesRules.js:164", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/afterSalesRules.js:164"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7ac6e11110c29d77", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/loopback.js:22", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/loopback.js:22"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-93cd3c9344629fd5", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/reportGenerator.js:87", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/reportGenerator.js:87"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9e9113160be67736", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/bookings.js:1120", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/bookings.js:1120"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4765199449420518", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/refunds.js:757", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/refunds.js:757"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-feeb3150dbd4338c", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/model.js:344", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/model.js:344"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-65a34b2cc2a1b2e4", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/passengers.js:107", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/passengers.js:107"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-876deb2c5c826b86", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/placeProbes.js:274", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/placeProbes.js:274"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e0c08e9c9dfe6393", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/displays.js:46", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/displays.js:46"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-edf47cbe8ca0fc17", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/validators.js:80", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/validators.js:80"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5ef4421a7b44ca5d", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/osdmCompliance.js:745", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/osdmCompliance.js:745"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9a1e034446f5fa4a", "name": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/json_validator/ajv.js:2", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/json_validator/ajv.js:2"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-64bb2db5ee874595", "name": "Privileged port 10 in use", "shortDescription": {"text": "Privileged port 10 in use"}, "fullDescription": {"text": "Port 10 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4736f11afa1965a8", "name": "Docker base image is tag-pinned but not digest-pinned: node:22-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-67ddb5907c03f5bc", "name": "Insecure pattern 'new_function_used' in compatibility.json:15", "shortDescription": {"text": "Insecure pattern 'new_function_used' in compatibility.json:15"}, "fullDescription": {"text": "Found a known-risky pattern (new_function_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a2ea4f75f261914a", "name": "Insecure pattern 'direct_innerhtml_assignment' in compatibility.json:672", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in compatibility.json:672"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8465b35660e1a90c", "name": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/compare.html:134", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/compare.html:134"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-be224b545ca7ea19", "name": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/forgot-password.html:129", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/forgot-password.html:129"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-395e3a5f3f12e8b0", "name": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/dashboard.html:348", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/dashboard.html:348"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-949563b35ae7afde", "name": "Insecure pattern 'direct_outerhtml_assignment' in Oscar_Server/public/dashboard.html:748", "shortDescription": {"text": "Insecure pattern 'direct_outerhtml_assignment' in Oscar_Server/public/dashboard.html:748"}, "fullDescription": {"text": "Found a known-risky pattern (direct_outerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cdcf41ae5191b898", "name": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/reset-password.html:131", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/reset-password.html:131"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5be762d043546468", "name": "Insecure pattern 'local_storage_auth_token' in Oscar_Server/public/index.html:209", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in Oscar_Server/public/index.html:209"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4b05d84a6f3c9e00", "name": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/run-detail.html:331", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/run-detail.html:331"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-624917821732e53a", "name": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/verify-email.html:133", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/verify-email.html:133"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f48c7e3b739bc6bd", "name": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/nav.js:177", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/nav.js:177"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e10396efe7c05f44", "name": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/run.html:144", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/run.html:144"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9a86aabeff6e9c0e", "name": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/admin.html:469", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/admin.html:469"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d5442f864cc06229", "name": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/welcome.html:246", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/welcome.html:246"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a0a3ec802352e74d", "name": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/report-builder.html:541", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/report-builder.html:541"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ad9e50f0697e26c7", "name": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/js/scenarios.js:316", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/js/scenarios.js:316"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1615cb74a92e1f95", "name": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/js/findings.js:109", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/js/findings.js:109"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ff116c341b5d7183", "name": "Insecure pattern 'node_child_process' in Oscar_Server/src/worker/runner.js:26", "shortDescription": {"text": "Insecure pattern 'node_child_process' in Oscar_Server/src/worker/runner.js:26"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-717caf98e193e3cd", "name": "Insecure pattern 'new_function_used' in Bruno_Collection/library-bruno/validators.js:33", "shortDescription": {"text": "Insecure pattern 'new_function_used' in Bruno_Collection/library-bruno/validators.js:33"}, "fullDescription": {"text": "Found a known-risky pattern (new_function_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-71dfc163b5ae521e", "name": "Insecure pattern 'new_function_used' in Bruno_Collection/json_validator/ajv.js:2", "shortDescription": {"text": "Insecure pattern 'new_function_used' in Bruno_Collection/json_validator/ajv.js:2"}, "fullDescription": {"text": "Found a known-risky pattern (new_function_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-65aa740cba4a4a73", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6eb37d0775531fdd", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/create-github-app-token@v3 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9e7af4f8ebfcb421", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-324315fc59926125", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-096f9e90022db85e", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f77fc1ddc9ad242c", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0e92f17cd1ad9214", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-af9fb474dc7a6503", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0fb7308b9dc643a3", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d1b928f8f8d158f1", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3f003244c96a70bd", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ec932018dd52049", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-917bb02476171dfe", "name": "Very large file: Oscar_Server/public/js/scenarios.js (6900 lines)", "shortDescription": {"text": "Very large file: Oscar_Server/public/js/scenarios.js (6900 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b0d5410e6c33622e", "name": "Very large file: Oscar_Server/src/api/routes/runs.js (1219 lines)", "shortDescription": {"text": "Very large file: Oscar_Server/src/api/routes/runs.js (1219 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa9c15a8a785d348", "name": "Very large file: Oscar_Server/src/worker/runner.js (1076 lines)", "shortDescription": {"text": "Very large file: Oscar_Server/src/worker/runner.js (1076 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ed1d752c4e8fad98", "name": "Very large file: Bruno_Collection/library-bruno/scenarioParser.js (1555 lines)", "shortDescription": {"text": "Very large file: Bruno_Collection/library-bruno/scenarioParser.js (1555 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ba184d9b38a11e7c", "name": "Very large file: Bruno_Collection/library-bruno/offers.js (1838 lines)", "shortDescription": {"text": "Very large file: Bruno_Collection/library-bruno/offers.js (1838 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-48b0a3cf128f4d15", "name": "Very large file: Bruno_Collection/library-bruno/bookings.js (1121 lines)", "shortDescription": {"text": "Very large file: Bruno_Collection/library-bruno/bookings.js (1121 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 93 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 61 placeholder/mock markers across 5 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c8f8960d0a75107b", "name": "Commented-code block (7 lines) in Oscar_Server/tests/integration/company-routes.test.js:232", "shortDescription": {"text": "Commented-code block (7 lines) in Oscar_Server/tests/integration/company-routes.test.js:232"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4166ecea4d14bab4", "name": "Commented-code block (5 lines) in Oscar_Server/tests/integration/admin-routes.test.js:63", "shortDescription": {"text": "Commented-code block (5 lines) in Oscar_Server/tests/integration/admin-routes.test.js:63"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6e14de5caab6c5dd", "name": "Commented-code block (7 lines) in Oscar_Server/tests/unit/bruno-partialrefund.test.js:235", "shortDescription": {"text": "Commented-code block (7 lines) in Oscar_Server/tests/unit/bruno-partialrefund.test.js:235"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-fa2904bd33c0f32e", "name": "Commented-code block (5 lines) in Oscar_Server/tests/unit/access-token.test.js:75", "shortDescription": {"text": "Commented-code block (5 lines) in Oscar_Server/tests/unit/access-token.test.js:75"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1921891650d243f5", "name": "Commented-code block (6 lines) in Oscar_Server/tests/unit/at-rest.test.js:29", "shortDescription": {"text": "Commented-code block (6 lines) in Oscar_Server/tests/unit/at-rest.test.js:29"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4b7f15eda198f891", "name": "Commented-code block (5 lines) in Oscar_Server/tests/unit/bruno-expiredflow.test.js:33", "shortDescription": {"text": "Commented-code block (5 lines) in Oscar_Server/tests/unit/bruno-expiredflow.test.js:33"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c7f866b8eac8484a", "name": "Commented-code block (7 lines) in Oscar_Server/public/nav.js:24", "shortDescription": {"text": "Commented-code block (7 lines) in Oscar_Server/public/nav.js:24"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-fbad523f5c7d773a", "name": "`fetch()` without try/.catch or AbortSignal \u2014 Oscar_Server/public/nav.js:25", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 Oscar_Server/public/nav.js:25"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c062b7abf8fad7b2", "name": "Commented-code block (5 lines) in Oscar_Server/public/js/scenarios.js:108", "shortDescription": {"text": "Commented-code block (5 lines) in Oscar_Server/public/js/scenarios.js:108"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0371d572c544aacf", "name": "`fetch()` without try/.catch or AbortSignal \u2014 Oscar_Server/public/js/scenarios.js:736", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 Oscar_Server/public/js/scenarios.js:736"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-83607ff8ff43944b", "name": "Commented-code block (5 lines) in Oscar_Server/public/js/findings.js:137", "shortDescription": {"text": "Commented-code block (5 lines) in Oscar_Server/public/js/findings.js:137"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3d5a33a3c5609dd9", "name": "Commented-code block (9 lines) in Oscar_Server/src/server.js:79", "shortDescription": {"text": "Commented-code block (9 lines) in Oscar_Server/src/server.js:79"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-de27ac77ae3aaad8", "name": "`fetch()` without try/.catch or AbortSignal \u2014 Oscar_Server/src/server.js:365", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 Oscar_Server/src/server.js:365"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9b0912c2612055d0", "name": "Commented-code block (9 lines) in Oscar_Server/src/api/middleware/auth.js:42", "shortDescription": {"text": "Commented-code block (9 lines) in Oscar_Server/src/api/middleware/auth.js:42"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-69f034d56ff48548", "name": "Commented-code block (6 lines) in Oscar_Server/src/api/middleware/tenant.js:28", "shortDescription": {"text": "Commented-code block (6 lines) in Oscar_Server/src/api/middleware/tenant.js:28"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9ee763112a862c2c", "name": "Commented-code block (8 lines) in Oscar_Server/src/api/routes/admin.js:36", "shortDescription": {"text": "Commented-code block (8 lines) in Oscar_Server/src/api/routes/admin.js:36"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-dba4b3e494846fbe", "name": "Commented-code block (5 lines) in Oscar_Server/src/api/routes/company-test-framework.js:33", "shortDescription": {"text": "Commented-code block (5 lines) in Oscar_Server/src/api/routes/company-test-framework.js:33"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-15cc5ff74533c80f", "name": "Commented-code block (5 lines) in Oscar_Server/src/api/routes/auth.js:39", "shortDescription": {"text": "Commented-code block (5 lines) in Oscar_Server/src/api/routes/auth.js:39"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2c8c4982985e08f5", "name": "Commented-code block (7 lines) in Oscar_Server/src/api/routes/reports.js:306", "shortDescription": {"text": "Commented-code block (7 lines) in Oscar_Server/src/api/routes/reports.js:306"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f7ef7f604fe943f7", "name": "Commented-code block (5 lines) in Oscar_Server/src/api/routes/me-credentials.js:102", "shortDescription": {"text": "Commented-code block (5 lines) in Oscar_Server/src/api/routes/me-credentials.js:102"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-be5e702d1d8a4cde", "name": "Commented-code block (6 lines) in Oscar_Server/src/api/routes/company.js:217", "shortDescription": {"text": "Commented-code block (6 lines) in Oscar_Server/src/api/routes/company.js:217"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d3ca7d3dfe2d9d64", "name": "Commented-code block (6 lines) in Oscar_Server/src/api/routes/runs.js:69", "shortDescription": {"text": "Commented-code block (6 lines) in Oscar_Server/src/api/routes/runs.js:69"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ab9ccc7e41b61e80", "name": "Commented-code block (7 lines) in Oscar_Server/src/api/routes/company-test-resources.js:33", "shortDescription": {"text": "Commented-code block (7 lines) in Oscar_Server/src/api/routes/company-test-resources.js:33"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bf82d867f6764903", "name": "Commented-code block (5 lines) in Oscar_Server/src/api/helpers/run-access.js:64", "shortDescription": {"text": "Commented-code block (5 lines) in Oscar_Server/src/api/helpers/run-access.js:64"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-09917431e5266827", "name": "Commented-code block (5 lines) in Oscar_Server/src/utils/alertmanagerConfig.js:87", "shortDescription": {"text": "Commented-code block (5 lines) in Oscar_Server/src/utils/alertmanagerConfig.js:87"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-dfb0bcc2bad87cee", "name": "Commented-code block (5 lines) in Oscar_Server/src/utils/metrics.js:88", "shortDescription": {"text": "Commented-code block (5 lines) in Oscar_Server/src/utils/metrics.js:88"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2ae32103c8a5f7c2", "name": "Commented-code block (5 lines) in Oscar_Server/src/worker/access-token.js:69", "shortDescription": {"text": "Commented-code block (5 lines) in Oscar_Server/src/worker/access-token.js:69"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-fcea7960dee75715", "name": "Commented-code block (6 lines) in Oscar_Server/src/worker/runner.js:42", "shortDescription": {"text": "Commented-code block (6 lines) in Oscar_Server/src/worker/runner.js:42"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e1272be5b434819e", "name": "Commented-code block (5 lines) in Oscar_Server/src/services/timetable-discovery.js:237", "shortDescription": {"text": "Commented-code block (5 lines) in Oscar_Server/src/services/timetable-discovery.js:237"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-276214ac7eda0e74", "name": "Commented-code block (7 lines) in Oscar_Server/src/db/db.js:145", "shortDescription": {"text": "Commented-code block (7 lines) in Oscar_Server/src/db/db.js:145"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6376ec85ee9b884b", "name": "Commented-code block (7 lines) in Oscar_Server/src/reports/structureResults.js:97", "shortDescription": {"text": "Commented-code block (7 lines) in Oscar_Server/src/reports/structureResults.js:97"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4ea71615d562d45f", "name": "Commented-code block (6 lines) in Oscar_Server/src/reports/diff.js:32", "shortDescription": {"text": "Commented-code block (6 lines) in Oscar_Server/src/reports/diff.js:32"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f2b883d67fd5627e", "name": "Commented-code block (5 lines) in Oscar_Server/src/reports/contextExtractors.js:37", "shortDescription": {"text": "Commented-code block (5 lines) in Oscar_Server/src/reports/contextExtractors.js:37"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-15a852ce7210492c", "name": "Commented-code block (9 lines) in Bruno_Collection/library-bruno/osdmVersion.js:121", "shortDescription": {"text": "Commented-code block (9 lines) in Bruno_Collection/library-bruno/osdmVersion.js:121"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-17229c1ea1714bf0", "name": "Commented-code block (8 lines) in Bruno_Collection/library-bruno/scenarioParser.js:38", "shortDescription": {"text": "Commented-code block (8 lines) in Bruno_Collection/library-bruno/scenarioParser.js:38"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-73a2e4a86f4102fb", "name": "Commented-code block (23 lines) in Bruno_Collection/library-bruno/expiredFlow.js:176", "shortDescription": {"text": "Commented-code block (23 lines) in Bruno_Collection/library-bruno/expiredFlow.js:176"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9fda6b173d9c8acb", "name": "Commented-code block (5 lines) in Bruno_Collection/library-bruno/osdmSchema.js:115", "shortDescription": {"text": "Commented-code block (5 lines) in Bruno_Collection/library-bruno/osdmSchema.js:115"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-92b2cf389c8d361c", "name": "Commented-code block (8 lines) in Bruno_Collection/library-bruno/exchanges.js:44", "shortDescription": {"text": "Commented-code block (8 lines) in Bruno_Collection/library-bruno/exchanges.js:44"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-98331a867e5ddaaa", "name": "Commented-code block (6 lines) in Bruno_Collection/library-bruno/mergeReport.js:44", "shortDescription": {"text": "Commented-code block (6 lines) in Bruno_Collection/library-bruno/mergeReport.js:44"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-eb897eb20021a11b", "name": "Commented-code block (16 lines) in Bruno_Collection/library-bruno/offers.js:41", "shortDescription": {"text": "Commented-code block (16 lines) in Bruno_Collection/library-bruno/offers.js:41"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-258f24f89ded090e", "name": "Commented-code block (5 lines) in Bruno_Collection/library-bruno/requestedInformation.js:758", "shortDescription": {"text": "Commented-code block (5 lines) in Bruno_Collection/library-bruno/requestedInformation.js:758"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bff4e9d43a48bbd1", "name": "Commented-code block (5 lines) in Bruno_Collection/library-bruno/partialRefund.js:280", "shortDescription": {"text": "Commented-code block (5 lines) in Bruno_Collection/library-bruno/partialRefund.js:280"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-721b7b71c8d9c9f1", "name": "Commented-code block (6 lines) in Bruno_Collection/library-bruno/envUtils.js:14", "shortDescription": {"text": "Commented-code block (6 lines) in Bruno_Collection/library-bruno/envUtils.js:14"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7cebac830fdfdae4", "name": "Commented-code block (6 lines) in Bruno_Collection/library-bruno/loopback.js:34", "shortDescription": {"text": "Commented-code block (6 lines) in Bruno_Collection/library-bruno/loopback.js:34"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4490619d67606d38", "name": "Commented-code block (5 lines) in Bruno_Collection/library-bruno/reportGenerator.js:51", "shortDescription": {"text": "Commented-code block (5 lines) in Bruno_Collection/library-bruno/reportGenerator.js:51"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-15f524c20892e7bb", "name": "Commented-code block (8 lines) in Bruno_Collection/library-bruno/bookings.js:148", "shortDescription": {"text": "Commented-code block (8 lines) in Bruno_Collection/library-bruno/bookings.js:148"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a3b94a6afec05263", "name": "Commented-code block (8 lines) in Bruno_Collection/library-bruno/refunds.js:55", "shortDescription": {"text": "Commented-code block (8 lines) in Bruno_Collection/library-bruno/refunds.js:55"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e39371973f4639f1", "name": "Commented-code block (6 lines) in Bruno_Collection/library-bruno/passengers.js:22", "shortDescription": {"text": "Commented-code block (6 lines) in Bruno_Collection/library-bruno/passengers.js:22"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7cbebd71a8f953eb", "name": "Commented-code block (8 lines) in Bruno_Collection/library-bruno/requestsBuilder.js:25", "shortDescription": {"text": "Commented-code block (8 lines) in Bruno_Collection/library-bruno/requestsBuilder.js:25"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4fc0102891b9ee3f", "name": "Commented-code block (8 lines) in Bruno_Collection/library-bruno/displays.js:83", "shortDescription": {"text": "Commented-code block (8 lines) in Bruno_Collection/library-bruno/displays.js:83"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-42f22b98a5f33839", "name": "Commented-code block (9 lines) in Bruno_Collection/library-bruno/validators.js:258", "shortDescription": {"text": "Commented-code block (9 lines) in Bruno_Collection/library-bruno/validators.js:258"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-56331e3aac77e2e6", "name": "Commented-code block (7 lines) in Bruno_Collection/library-bruno/osdmCompliance.js:60", "shortDescription": {"text": "Commented-code block (7 lines) in Bruno_Collection/library-bruno/osdmCompliance.js:60"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1c2ce67dc5bc6db9", "name": "Commented-code block (8 lines) in Documentation/Test_Coverage/_build_coverage_matrix.py:75", "shortDescription": {"text": "Commented-code block (8 lines) in Documentation/Test_Coverage/_build_coverage_matrix.py:75"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e41d8fa03eaebf74", "name": "Commented-code block (5 lines) in Documentation/Test_Coverage/_build_field_level_coverage.py:227", "shortDescription": {"text": "Commented-code block (5 lines) in Documentation/Test_Coverage/_build_field_level_coverage.py:227"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cc0f9d8e41b33b0e", "name": "11 env vars used in code but missing from .env.example", "shortDescription": {"text": "11 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `ALERTMANAGER_CONFIG_PATH`, `ALERTMANAGER_RELOAD_URL`, `ALERT_RECIPIENTS`, `ALERT_REPEAT_CRITICAL`, `ALERT_REPEAT_WARNING`, `ALLOWED_ORIGINS`, `AUTH_RATE_LIMIT_MAX`, `COMPATIBILITY_FILE` + 3 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nDocumentation/Test_Coverage/_build_coverage_matrix.py:request_files, Documentation/Test_Coverage/_build_field_level_coverage.py:request_files\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4c1cbcc7e6732a66", "name": "Dangling fetch: POST /v1/auth/logout (Oscar_Server/public/nav.js:341)", "shortDescription": {"text": "Dangling fetch: POST /v1/auth/logout (Oscar_Server/public/nav.js:341)"}, "fullDescription": {"text": "`Oscar_Server/public/nav.js:341` calls `POST /v1/auth/logout` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/auth/logout`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7643838e6643fe71", "name": "Dangling fetch: GET /v1/company/test-framework (Oscar_Server/public/js/scenarios.js:324)", "shortDescription": {"text": "Dangling fetch: GET /v1/company/test-framework (Oscar_Server/public/js/scenarios.js:324)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:324` calls `GET /v1/company/test-framework` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company/test-framework`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9f3dd14830e6cc2d", "name": "Dangling fetch: GET /v1/company/test-resources (Oscar_Server/public/js/scenarios.js:325)", "shortDescription": {"text": "Dangling fetch: GET /v1/company/test-resources (Oscar_Server/public/js/scenarios.js:325)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:325` calls `GET /v1/company/test-resources` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company/test-resources`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4bf0cff404c5a593", "name": "Dangling fetch: GET /v1/company (Oscar_Server/public/js/scenarios.js:326)", "shortDescription": {"text": "Dangling fetch: GET /v1/company (Oscar_Server/public/js/scenarios.js:326)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:326` calls `GET /v1/company` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b6a85068dde14f7b", "name": "Dangling fetch: GET /v1/company/datafile (Oscar_Server/public/js/scenarios.js:355)", "shortDescription": {"text": "Dangling fetch: GET /v1/company/datafile (Oscar_Server/public/js/scenarios.js:355)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:355` calls `GET /v1/company/datafile` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company/datafile`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6639c2367bdc17d1", "name": "Dangling fetch: PUT /v1/company/test-framework (Oscar_Server/public/js/scenarios.js:612)", "shortDescription": {"text": "Dangling fetch: PUT /v1/company/test-framework (Oscar_Server/public/js/scenarios.js:612)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:612` calls `PUT /v1/company/test-framework` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company/test-framework`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d005f210320eee71", "name": "Dangling fetch: DELETE /v1/company/datafile (Oscar_Server/public/js/scenarios.js:644)", "shortDescription": {"text": "Dangling fetch: DELETE /v1/company/datafile (Oscar_Server/public/js/scenarios.js:644)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:644` calls `DELETE /v1/company/datafile` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company/datafile`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b5c0373eea33241f", "name": "Dangling fetch: DELETE /v1/company/test-resources/${r.id} (Oscar_Server/public/js/scenarios.js:647)", "shortDescription": {"text": "Dangling fetch: DELETE /v1/company/test-resources/${r.id} (Oscar_Server/public/js/scenarios.js:647)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:647` calls `DELETE /v1/company/test-resources/${r.id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company/test-resources/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a9cd73f3f8dc4616", "name": "Dangling fetch: DELETE /v1/company/test-framework (Oscar_Server/public/js/scenarios.js:650)", "shortDescription": {"text": "Dangling fetch: DELETE /v1/company/test-framework (Oscar_Server/public/js/scenarios.js:650)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:650` calls `DELETE /v1/company/test-framework` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company/test-framework`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4544b0fbb5a429f3", "name": "Dangling fetch: DELETE /v1/company/datafile (Oscar_Server/public/js/scenarios.js:672)", "shortDescription": {"text": "Dangling fetch: DELETE /v1/company/datafile (Oscar_Server/public/js/scenarios.js:672)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:672` calls `DELETE /v1/company/datafile` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company/datafile`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-615a26c0f8755bb7", "name": "Dangling fetch: DELETE /v1/company/test-resources/${r.id} (Oscar_Server/public/js/scenarios.js:675)", "shortDescription": {"text": "Dangling fetch: DELETE /v1/company/test-resources/${r.id} (Oscar_Server/public/js/scenarios.js:675)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:675` calls `DELETE /v1/company/test-resources/${r.id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company/test-resources/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-18c1bc7402b43c89", "name": "Dangling fetch: DELETE /v1/company/test-resources/${resourceId} (Oscar_Server/public/js/scenarios.js:726)", "shortDescription": {"text": "Dangling fetch: DELETE /v1/company/test-resources/${resourceId} (Oscar_Server/public/js/scenarios.js:726)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:726` calls `DELETE /v1/company/test-resources/${resourceId}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company/test-resources/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b0f10765a1b3d08b", "name": "Dangling fetch: PUT /v1/company/datafile/json (Oscar_Server/public/js/scenarios.js:736)", "shortDescription": {"text": "Dangling fetch: PUT /v1/company/datafile/json (Oscar_Server/public/js/scenarios.js:736)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:736` calls `PUT /v1/company/datafile/json` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company/datafile/json`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e206b679fd39b407", "name": "Dangling fetch: DELETE /v1/company/datafile (Oscar_Server/public/js/scenarios.js:785)", "shortDescription": {"text": "Dangling fetch: DELETE /v1/company/datafile (Oscar_Server/public/js/scenarios.js:785)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:785` calls `DELETE /v1/company/datafile` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company/datafile`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f140c30ed842301f", "name": "Dangling fetch: POST /v1/company/datafile (Oscar_Server/public/js/scenarios.js:999)", "shortDescription": {"text": "Dangling fetch: POST /v1/company/datafile (Oscar_Server/public/js/scenarios.js:999)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:999` calls `POST /v1/company/datafile` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company/datafile`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-016af9fa92b8a253", "name": "Dangling fetch: PUT /v1/company/test-framework (Oscar_Server/public/js/scenarios.js:1113)", "shortDescription": {"text": "Dangling fetch: PUT /v1/company/test-framework (Oscar_Server/public/js/scenarios.js:1113)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:1113` calls `PUT /v1/company/test-framework` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company/test-framework`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d23a9d93856587e6", "name": "Dangling fetch: GET /v1/company/test-resources (Oscar_Server/public/js/scenarios.js:1123)", "shortDescription": {"text": "Dangling fetch: GET /v1/company/test-resources (Oscar_Server/public/js/scenarios.js:1123)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:1123` calls `GET /v1/company/test-resources` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company/test-resources`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bebba8a005a03d2a", "name": "Dangling fetch: POST /v1/company/test-resources (Oscar_Server/public/js/scenarios.js:1140)", "shortDescription": {"text": "Dangling fetch: POST /v1/company/test-resources (Oscar_Server/public/js/scenarios.js:1140)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:1140` calls `POST /v1/company/test-resources` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company/test-resources`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1bfd943e8aeb2a07", "name": "Dangling fetch: DELETE /v1/company/datafile (Oscar_Server/public/js/scenarios.js:1158)", "shortDescription": {"text": "Dangling fetch: DELETE /v1/company/datafile (Oscar_Server/public/js/scenarios.js:1158)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:1158` calls `DELETE /v1/company/datafile` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company/datafile`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-268594b2cc892de6", "name": "Dangling fetch: PUT /v1/company/datafile/json (Oscar_Server/public/js/scenarios.js:2896)", "shortDescription": {"text": "Dangling fetch: PUT /v1/company/datafile/json (Oscar_Server/public/js/scenarios.js:2896)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:2896` calls `PUT /v1/company/datafile/json` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company/datafile/json`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e1af1fbba7cb6f32", "name": "Dangling fetch: GET /v1/company/datafile (Oscar_Server/public/js/scenarios.js:2912)", "shortDescription": {"text": "Dangling fetch: GET /v1/company/datafile (Oscar_Server/public/js/scenarios.js:2912)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:2912` calls `GET /v1/company/datafile` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company/datafile`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6d33e158437c3e65", "name": "Dangling fetch: POST /v1/company/test-resources/discover-timetable (Oscar_Server/public/js/scenarios.js:4284)", "shortDescription": {"text": "Dangling fetch: POST /v1/company/test-resources/discover-timetable (Oscar_Server/public/js/scenarios.js:4284)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:4284` calls `POST /v1/company/test-resources/discover-timetable` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company/test-resources/discover-timetable`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-da25e3e52a12e254", "name": "Dangling fetch: DELETE /v1/company/test-resources/${id} (Oscar_Server/public/js/scenarios.js:4753)", "shortDescription": {"text": "Dangling fetch: DELETE /v1/company/test-resources/${id} (Oscar_Server/public/js/scenarios.js:4753)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:4753` calls `DELETE /v1/company/test-resources/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company/test-resources/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-66a267fc65c5b836", "name": "Dangling fetch: GET /v1/company/datafile (Oscar_Server/public/js/scenarios.js:5470)", "shortDescription": {"text": "Dangling fetch: GET /v1/company/datafile (Oscar_Server/public/js/scenarios.js:5470)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:5470` calls `GET /v1/company/datafile` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company/datafile`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-84ae552c777f3df2", "name": "Dangling fetch: PUT /v1/company/datafile/json (Oscar_Server/public/js/scenarios.js:5736)", "shortDescription": {"text": "Dangling fetch: PUT /v1/company/datafile/json (Oscar_Server/public/js/scenarios.js:5736)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:5736` calls `PUT /v1/company/datafile/json` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company/datafile/json`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-38322f96e31c7b14", "name": "Dangling fetch: POST /v1/company/test-resources/reprobe-offers (Oscar_Server/public/js/scenarios.js:6184)", "shortDescription": {"text": "Dangling fetch: POST /v1/company/test-resources/reprobe-offers (Oscar_Server/public/js/scenarios.js:6184)"}, "fullDescription": {"text": "`Oscar_Server/public/js/scenarios.js:6184` calls `POST /v1/company/test-resources/reprobe-offers` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/company/test-resources/reprobe-offers`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7e13c3f2244bf384", "name": "Unused endpoint: GET /json_validator/datafile.schema.json", "shortDescription": {"text": "Unused endpoint: GET /json_validator/datafile.schema.json"}, "fullDescription": {"text": "`Oscar_Server/src/server.js` declares `GET /json_validator/datafile.schema.json` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-777c5acb045bc546", "name": "Unused endpoint: GET /data/:filename", "shortDescription": {"text": "Unused endpoint: GET /data/:filename"}, "fullDescription": {"text": "`Oscar_Server/src/server.js` declares `GET /data/:filename` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-87b2f887faa50a10", "name": "Unused endpoint: POST /v1/runs/:runId/refresh-access-token", "shortDescription": {"text": "Unused endpoint: POST /v1/runs/:runId/refresh-access-token"}, "fullDescription": {"text": "`Oscar_Server/src/server.js` declares `POST /v1/runs/:runId/refresh-access-token` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3d17e43986ccff67", "name": "Unused endpoint: GET /artifacts/:runId/:filename", "shortDescription": {"text": "Unused endpoint: GET /artifacts/:runId/:filename"}, "fullDescription": {"text": "`Oscar_Server/src/server.js` declares `GET /artifacts/:runId/:filename` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8839ee8182dff27d", "name": "Unused endpoint: USE /v1/auth", "shortDescription": {"text": "Unused endpoint: USE /v1/auth"}, "fullDescription": {"text": "`Oscar_Server/src/server.js` declares `USE /v1/auth` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b578af8a81516f0d", "name": "Unused endpoint: USE /v1/me/credentials", "shortDescription": {"text": "Unused endpoint: USE /v1/me/credentials"}, "fullDescription": {"text": "`Oscar_Server/src/server.js` declares `USE /v1/me/credentials` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-315abca8c5ee3d14", "name": "Unused endpoint: USE /v1/company/users", "shortDescription": {"text": "Unused endpoint: USE /v1/company/users"}, "fullDescription": {"text": "`Oscar_Server/src/server.js` declares `USE /v1/company/users` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c7af28756bda791e", "name": "Unused endpoint: USE /v1/company", "shortDescription": {"text": "Unused endpoint: USE /v1/company"}, "fullDescription": {"text": "`Oscar_Server/src/server.js` declares `USE /v1/company` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c6e3207389235c58", "name": "Unused endpoint: USE /v1/runs", "shortDescription": {"text": "Unused endpoint: USE /v1/runs"}, "fullDescription": {"text": "`Oscar_Server/src/server.js` declares `USE /v1/runs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b233a496d1ed0ab5", "name": "Unused endpoint: USE /v1/reports", "shortDescription": {"text": "Unused endpoint: USE /v1/reports"}, "fullDescription": {"text": "`Oscar_Server/src/server.js` declares `USE /v1/reports` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0ce96799aac655", "name": "Unused endpoint: USE /v1/admin", "shortDescription": {"text": "Unused endpoint: USE /v1/admin"}, "fullDescription": {"text": "`Oscar_Server/src/server.js` declares `USE /v1/admin` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3a10a160de68aa02", "name": "Unused endpoint: GET /v1/openapi.json", "shortDescription": {"text": "Unused endpoint: GET /v1/openapi.json"}, "fullDescription": {"text": "`Oscar_Server/src/server.js` declares `GET /v1/openapi.json` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-388a8dd37b6782cb", "name": "Unused endpoint: USE /v1/docs", "shortDescription": {"text": "Unused endpoint: USE /v1/docs"}, "fullDescription": {"text": "`Oscar_Server/src/server.js` declares `USE /v1/docs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-618721b912bad1c2", "name": "Unused endpoint: POST /login", "shortDescription": {"text": "Unused endpoint: POST /login"}, "fullDescription": {"text": "`Oscar_Server/src/api/middleware/validate.js` declares `POST /login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-841e50bf821e4158", "name": "Unused endpoint: GET /users", "shortDescription": {"text": "Unused endpoint: GET /users"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/admin.js` declares `GET /users` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1bca8100a44f7f25", "name": "Unused endpoint: POST /users", "shortDescription": {"text": "Unused endpoint: POST /users"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/admin.js` declares `POST /users` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a2da8d08e12b122c", "name": "Unused endpoint: PATCH /users/:id", "shortDescription": {"text": "Unused endpoint: PATCH /users/:id"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/admin.js` declares `PATCH /users/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fa4e1071fc9bdadb", "name": "Unused endpoint: POST /users/:id/reset-password", "shortDescription": {"text": "Unused endpoint: POST /users/:id/reset-password"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/admin.js` declares `POST /users/:id/reset-password` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-833b8e34e489bb10", "name": "Unused endpoint: POST /users/:id/generate-reset-link", "shortDescription": {"text": "Unused endpoint: POST /users/:id/generate-reset-link"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/admin.js` declares `POST /users/:id/generate-reset-link` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-79406b9fd85263bf", "name": "Unused endpoint: DELETE /users/:id", "shortDescription": {"text": "Unused endpoint: DELETE /users/:id"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/admin.js` declares `DELETE /users/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2a366262a6be358f", "name": "Unused endpoint: GET /activity", "shortDescription": {"text": "Unused endpoint: GET /activity"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/admin.js` declares `GET /activity` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a35ce3e9c9f59e0a", "name": "Unused endpoint: GET /companies", "shortDescription": {"text": "Unused endpoint: GET /companies"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/admin.js` declares `GET /companies` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ec39abb0b24cc5b2", "name": "Unused endpoint: POST /companies", "shortDescription": {"text": "Unused endpoint: POST /companies"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/admin.js` declares `POST /companies` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-799efc4b396984aa", "name": "Unused endpoint: PATCH /companies/:id", "shortDescription": {"text": "Unused endpoint: PATCH /companies/:id"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/admin.js` declares `PATCH /companies/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b4108b6c06c6b5c0", "name": "Unused endpoint: DELETE /companies/:id", "shortDescription": {"text": "Unused endpoint: DELETE /companies/:id"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/admin.js` declares `DELETE /companies/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a6f48e60c30777ab", "name": "Unused endpoint: GET /config", "shortDescription": {"text": "Unused endpoint: GET /config"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/admin.js` declares `GET /config` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4cff4b2e8c2f239b", "name": "Unused endpoint: PATCH /config", "shortDescription": {"text": "Unused endpoint: PATCH /config"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/admin.js` declares `PATCH /config` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-660cc9b103629ed8", "name": "Unused endpoint: POST /alertmanager/apply", "shortDescription": {"text": "Unused endpoint: POST /alertmanager/apply"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/admin.js` declares `POST /alertmanager/apply` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3f93fbf292efc28e", "name": "Unused endpoint: POST /rotate-jwt-secret", "shortDescription": {"text": "Unused endpoint: POST /rotate-jwt-secret"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/admin.js` declares `POST /rotate-jwt-secret` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea016db9a638f359", "name": "Unused endpoint: POST /test-email", "shortDescription": {"text": "Unused endpoint: POST /test-email"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/admin.js` declares `POST /test-email` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4b92445a61b01e81", "name": "Unused endpoint: GET /test-framework", "shortDescription": {"text": "Unused endpoint: GET /test-framework"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/company-test-framework.js` declares `GET /test-framework` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5a05bf952e88c699", "name": "Unused endpoint: PUT /test-framework", "shortDescription": {"text": "Unused endpoint: PUT /test-framework"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/company-test-framework.js` declares `PUT /test-framework` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6b971a208a6475ad", "name": "Unused endpoint: DELETE /test-framework", "shortDescription": {"text": "Unused endpoint: DELETE /test-framework"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/company-test-framework.js` declares `DELETE /test-framework` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-74a694079368f227", "name": "Unused endpoint: USE /login", "shortDescription": {"text": "Unused endpoint: USE /login"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/auth.js` declares `USE /login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0aea1f429e292d45", "name": "Unused endpoint: USE /register", "shortDescription": {"text": "Unused endpoint: USE /register"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/auth.js` declares `USE /register` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c81619fbcb39d276", "name": "Unused endpoint: USE /bootstrap", "shortDescription": {"text": "Unused endpoint: USE /bootstrap"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/auth.js` declares `USE /bootstrap` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0e9f62ffdc857013", "name": "Unused endpoint: GET /register/companies", "shortDescription": {"text": "Unused endpoint: GET /register/companies"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/auth.js` declares `GET /register/companies` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-111e16b3687be06d", "name": "Unused endpoint: POST /register/request", "shortDescription": {"text": "Unused endpoint: POST /register/request"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/auth.js` declares `POST /register/request` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a3446a5f74053792", "name": "Unused endpoint: POST /register/confirm", "shortDescription": {"text": "Unused endpoint: POST /register/confirm"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/auth.js` declares `POST /register/confirm` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cf634f331f1be47c", "name": "Unused endpoint: POST /password-reset/request", "shortDescription": {"text": "Unused endpoint: POST /password-reset/request"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/auth.js` declares `POST /password-reset/request` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bfe9ab88a9863c25", "name": "Unused endpoint: GET /password-reset/check-token", "shortDescription": {"text": "Unused endpoint: GET /password-reset/check-token"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/auth.js` declares `GET /password-reset/check-token` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4c74973257c0143d", "name": "Unused endpoint: POST /password-reset/confirm", "shortDescription": {"text": "Unused endpoint: POST /password-reset/confirm"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/auth.js` declares `POST /password-reset/confirm` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f7748d198147c107", "name": "Unused endpoint: GET /register/check-token", "shortDescription": {"text": "Unused endpoint: GET /register/check-token"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/auth.js` declares `GET /register/check-token` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-662ed1659363a8c1", "name": "Unused endpoint: POST /bootstrap/platform-user", "shortDescription": {"text": "Unused endpoint: POST /bootstrap/platform-user"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/auth.js` declares `POST /bootstrap/platform-user` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd1dc91abf32142d", "name": "Unused endpoint: GET /me", "shortDescription": {"text": "Unused endpoint: GET /me"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/auth.js` declares `GET /me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-99fc36db98c134ce", "name": "Unused endpoint: POST /logout", "shortDescription": {"text": "Unused endpoint: POST /logout"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/auth.js` declares `POST /logout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5eed2447bf4a087f", "name": "Unused endpoint: GET /sso-check", "shortDescription": {"text": "Unused endpoint: GET /sso-check"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/auth.js` declares `GET /sso-check` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5cf10967b5fa0cac", "name": "Unused endpoint: POST /compare", "shortDescription": {"text": "Unused endpoint: POST /compare"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/reports.js` declares `POST /compare` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e8f8fc83db4ff640", "name": "Unused endpoint: GET /comparisons", "shortDescription": {"text": "Unused endpoint: GET /comparisons"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/reports.js` declares `GET /comparisons` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-215dc02c4e24d666", "name": "Unused endpoint: GET /comparisons/:id", "shortDescription": {"text": "Unused endpoint: GET /comparisons/:id"}, "fullDescription": {"text": "`Oscar_Server/src/api/routes/reports.js` declares `GET /comparisons/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/21549"}, "properties": {"repository": "TOP-PHE/UIC_OSCAR-OSdm-Compliance-Automation-Runner", "repoUrl": "https://github.com/TOP-PHE/UIC_OSCAR-OSdm-Compliance-Automation-Runner", "branch": "main"}, "results": [{"ruleId": "scanner-741b991b03fbb5aa", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Oscar_Server/scripts/lint-inline-scripts.js:170"}, "properties": {"repobilityId": "7e22dbe2f4fb7a70", "scanner": "scanner-primary", "fingerprint": "741b991b03fbb5aa", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d04c4040cb3d4829", "level": "note", "message": {"text": "Icon-only button without accessible name \u2014 Oscar_Server/public/js/scenarios.js:4946"}, "properties": {"repobilityId": "b6fee94c22d24868", "scanner": "scanner-primary", "fingerprint": "d04c4040cb3d4829", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.button.no-label"]}}, {"ruleId": "scanner-d50539b252044b06", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 Oscar_Server/public/js/scenarios.js:1032"}, "properties": {"repobilityId": "a14934b54300c351", "scanner": "scanner-primary", "fingerprint": "d50539b252044b06", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-020884c918b645c9", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Oscar_Server/public/js/scenarios.js:1147"}, "properties": {"repobilityId": "196caef314611ba5", "scanner": "scanner-primary", "fingerprint": "020884c918b645c9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-1e2ae3f4e6cdf3e3", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Oscar_Server/src/utils/at-rest.js:58"}, "properties": {"repobilityId": "13d1a51162234830", "scanner": "scanner-primary", "fingerprint": "1e2ae3f4e6cdf3e3", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-46bd273d170432f3", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Oscar_Server/src/db/db.js:319"}, "properties": {"repobilityId": "3cac946217e404de", "scanner": "scanner-primary", "fingerprint": "46bd273d170432f3", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-45da7b5ec00db69e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/osdmVersion.js:171"}, "properties": {"repobilityId": "55d909989e4fd548", "scanner": "scanner-primary", "fingerprint": "45da7b5ec00db69e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-bb5603673ced7287", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 Bruno_Collection/library-bruno/fulfillments.js:190"}, "properties": {"repobilityId": "78a856085413f2e3", "scanner": "scanner-primary", "fingerprint": "bb5603673ced7287", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-8e08cd678682e135", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/fulfillments.js:206"}, "properties": {"repobilityId": "bb963647a68744fd", "scanner": "scanner-primary", "fingerprint": "8e08cd678682e135", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-72c3a27635c536e9", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/scenarioParser.js:516"}, "properties": {"repobilityId": "008e62f919d2eb59", "scanner": "scanner-primary", "fingerprint": "72c3a27635c536e9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e0af670ac7fe5d86", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/expiredFlow.js:464"}, "properties": {"repobilityId": "f557fc1f66bd1a93", "scanner": "scanner-primary", "fingerprint": "e0af670ac7fe5d86", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9c67f38692c552fa", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/osdmSchema.js:153"}, "properties": {"repobilityId": "73d700669542f942", "scanner": "scanner-primary", "fingerprint": "9c67f38692c552fa", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-38cbbea5a783614b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/exchanges.js:307"}, "properties": {"repobilityId": "51bf01f3c63dce9e", "scanner": "scanner-primary", "fingerprint": "38cbbea5a783614b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-53aa76075b7cc746", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/osdmSchemas.js:2385"}, "properties": {"repobilityId": "3796ee25aaa3090a", "scanner": "scanner-primary", "fingerprint": "53aa76075b7cc746", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7ecaa871356e263c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/mergeReport.js:263"}, "properties": {"repobilityId": "558ff69e5f18cf2c", "scanner": "scanner-primary", "fingerprint": "7ecaa871356e263c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-096cd791fb90a44c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/offers.js:122"}, "properties": {"repobilityId": "9c9eabc60e292dcd", "scanner": "scanner-primary", "fingerprint": "096cd791fb90a44c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5e1fa29b60fbc808", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/auth.js:192"}, "properties": {"repobilityId": "ea074c78d9ef4251", "scanner": "scanner-primary", "fingerprint": "5e1fa29b60fbc808", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-cb143a08de7a368b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/requestedInformation.js:866"}, "properties": {"repobilityId": "0dbe53eb0abd23e5", "scanner": "scanner-primary", "fingerprint": "cb143a08de7a368b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-311ae10b65d01734", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/partialRefund.js:368"}, "properties": {"repobilityId": "48077d771b19ebfb", "scanner": "scanner-primary", "fingerprint": "311ae10b65d01734", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3be45e5826ee9452", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/envUtils.js:35"}, "properties": {"repobilityId": "e511e5f542752391", "scanner": "scanner-primary", "fingerprint": "3be45e5826ee9452", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-06f9a589d83b3609", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/afterSalesRules.js:164"}, "properties": {"repobilityId": "c71a6419c24d6b40", "scanner": "scanner-primary", "fingerprint": "06f9a589d83b3609", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7ac6e11110c29d77", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/loopback.js:22"}, "properties": {"repobilityId": "e5f438f89b2fa335", "scanner": "scanner-primary", "fingerprint": "7ac6e11110c29d77", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-93cd3c9344629fd5", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/reportGenerator.js:87"}, "properties": {"repobilityId": "434e14d15191e1ff", "scanner": "scanner-primary", "fingerprint": "93cd3c9344629fd5", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9e9113160be67736", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/bookings.js:1120"}, "properties": {"repobilityId": "ade1d62d98990ae7", "scanner": "scanner-primary", "fingerprint": "9e9113160be67736", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4765199449420518", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/refunds.js:757"}, "properties": {"repobilityId": "31db405dd1ffbcfa", "scanner": "scanner-primary", "fingerprint": "4765199449420518", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-feeb3150dbd4338c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/model.js:344"}, "properties": {"repobilityId": "6a023d0b0bde01a7", "scanner": "scanner-primary", "fingerprint": "feeb3150dbd4338c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-65a34b2cc2a1b2e4", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/passengers.js:107"}, "properties": {"repobilityId": "458d6c3773a7c31e", "scanner": "scanner-primary", "fingerprint": "65a34b2cc2a1b2e4", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-876deb2c5c826b86", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/placeProbes.js:274"}, "properties": {"repobilityId": "747b59acca16ce49", "scanner": "scanner-primary", "fingerprint": "876deb2c5c826b86", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e0c08e9c9dfe6393", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/displays.js:46"}, "properties": {"repobilityId": "4f958c42828af4bc", "scanner": "scanner-primary", "fingerprint": "e0c08e9c9dfe6393", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-edf47cbe8ca0fc17", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/validators.js:80"}, "properties": {"repobilityId": "fe0888da2f4a2d87", "scanner": "scanner-primary", "fingerprint": "edf47cbe8ca0fc17", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5ef4421a7b44ca5d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/library-bruno/osdmCompliance.js:745"}, "properties": {"repobilityId": "9b76d7f3c705b042", "scanner": "scanner-primary", "fingerprint": "5ef4421a7b44ca5d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9a1e034446f5fa4a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 Bruno_Collection/json_validator/ajv.js:2"}, "properties": {"repobilityId": "8bb25db7152f4212", "scanner": "scanner-primary", "fingerprint": "9a1e034446f5fa4a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-64bb2db5ee874595", "level": "warning", "message": {"text": "Privileged port 10 in use"}, "properties": {"repobilityId": "735372d6b5594915", "scanner": "scanner-primary", "fingerprint": "64bb2db5ee874595", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Bruno_Collection/02-Common Requests/Post Offer-Req param chk.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4736f11afa1965a8", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-slim"}, "properties": {"repobilityId": "b1d7f7b73a8cbae6", "scanner": "scanner-primary", "fingerprint": "4736f11afa1965a8", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Oscar_Server/Dockerfile"}, "region": {"startLine": 11}}}]}, {"ruleId": "scanner-4736f11afa1965a8", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-slim"}, "properties": {"repobilityId": "f81701fe77bb7cb8", "scanner": "scanner-primary", "fingerprint": "4736f11afa1965a8", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Oscar_Server/Dockerfile"}, "region": {"startLine": 39}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-67ddb5907c03f5bc", "level": "error", "message": {"text": "Insecure pattern 'new_function_used' in compatibility.json:15"}, "properties": {"repobilityId": "8475391a940d792e", "scanner": "scanner-primary", "fingerprint": "67ddb5907c03f5bc", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "new_function_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "compatibility.json"}, "region": {"startLine": 15}}}]}, {"ruleId": "scanner-a2ea4f75f261914a", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in compatibility.json:672"}, "properties": {"repobilityId": "26599bac86f96c88", "scanner": "scanner-primary", "fingerprint": "a2ea4f75f261914a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "compatibility.json"}, "region": {"startLine": 672}}}]}, {"ruleId": "scanner-8465b35660e1a90c", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/compare.html:134"}, "properties": {"repobilityId": "057a48e176bd9759", "scanner": "scanner-primary", "fingerprint": "8465b35660e1a90c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Oscar_Server/public/compare.html"}, "region": {"startLine": 134}}}]}, {"ruleId": "scanner-be224b545ca7ea19", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/forgot-password.html:129"}, "properties": {"repobilityId": "46ce2791b7fd22ef", "scanner": "scanner-primary", "fingerprint": "be224b545ca7ea19", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Oscar_Server/public/forgot-password.html"}, "region": {"startLine": 129}}}]}, {"ruleId": "scanner-395e3a5f3f12e8b0", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/dashboard.html:348"}, "properties": {"repobilityId": "2f65528a6c73dbbd", "scanner": "scanner-primary", "fingerprint": "395e3a5f3f12e8b0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Oscar_Server/public/dashboard.html"}, "region": {"startLine": 348}}}]}, {"ruleId": "scanner-949563b35ae7afde", "level": "warning", "message": {"text": "Insecure pattern 'direct_outerhtml_assignment' in Oscar_Server/public/dashboard.html:748"}, "properties": {"repobilityId": "57cb8e8b1fec7669", "scanner": "scanner-primary", "fingerprint": "949563b35ae7afde", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_outerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Oscar_Server/public/dashboard.html"}, "region": {"startLine": 748}}}]}, {"ruleId": "scanner-cdcf41ae5191b898", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/reset-password.html:131"}, "properties": {"repobilityId": "af7ac7433d662c05", "scanner": "scanner-primary", "fingerprint": "cdcf41ae5191b898", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Oscar_Server/public/reset-password.html"}, "region": {"startLine": 131}}}]}, {"ruleId": "scanner-5be762d043546468", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in Oscar_Server/public/index.html:209"}, "properties": {"repobilityId": "c717d520e03a3746", "scanner": "scanner-primary", "fingerprint": "5be762d043546468", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Oscar_Server/public/index.html"}, "region": {"startLine": 209}}}]}, {"ruleId": "scanner-4b05d84a6f3c9e00", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/run-detail.html:331"}, "properties": {"repobilityId": "23b29658d858d884", "scanner": "scanner-primary", "fingerprint": "4b05d84a6f3c9e00", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Oscar_Server/public/run-detail.html"}, "region": {"startLine": 331}}}]}, {"ruleId": "scanner-624917821732e53a", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/verify-email.html:133"}, "properties": {"repobilityId": "56dd12f641a8f5af", "scanner": "scanner-primary", "fingerprint": "624917821732e53a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Oscar_Server/public/verify-email.html"}, "region": {"startLine": 133}}}]}, {"ruleId": "scanner-f48c7e3b739bc6bd", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/nav.js:177"}, "properties": {"repobilityId": "87b796ce2f6db7bc", "scanner": "scanner-primary", "fingerprint": "f48c7e3b739bc6bd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Oscar_Server/public/nav.js"}, "region": {"startLine": 177}}}]}, {"ruleId": "scanner-e10396efe7c05f44", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/run.html:144"}, "properties": {"repobilityId": "565241d21ec5268f", "scanner": "scanner-primary", "fingerprint": "e10396efe7c05f44", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Oscar_Server/public/run.html"}, "region": {"startLine": 144}}}]}, {"ruleId": "scanner-9a86aabeff6e9c0e", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/admin.html:469"}, "properties": {"repobilityId": "71e60d8472d5f2e6", "scanner": "scanner-primary", "fingerprint": "9a86aabeff6e9c0e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Oscar_Server/public/admin.html"}, "region": {"startLine": 469}}}]}, {"ruleId": "scanner-d5442f864cc06229", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/welcome.html:246"}, "properties": {"repobilityId": "349afd787a0aa283", "scanner": "scanner-primary", "fingerprint": "d5442f864cc06229", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Oscar_Server/public/welcome.html"}, "region": {"startLine": 246}}}]}, {"ruleId": "scanner-a0a3ec802352e74d", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/report-builder.html:541"}, "properties": {"repobilityId": "3fdbb0afce9c45bc", "scanner": "scanner-primary", "fingerprint": "a0a3ec802352e74d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Oscar_Server/public/report-builder.html"}, "region": {"startLine": 541}}}]}, {"ruleId": "scanner-ad9e50f0697e26c7", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/js/scenarios.js:316"}, "properties": {"repobilityId": "73ea1c852786fcd9", "scanner": "scanner-primary", "fingerprint": "ad9e50f0697e26c7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Oscar_Server/public/js/scenarios.js"}, "region": {"startLine": 316}}}]}, {"ruleId": "scanner-1615cb74a92e1f95", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in Oscar_Server/public/js/findings.js:109"}, "properties": {"repobilityId": "6f4cf0930aa66236", "scanner": "scanner-primary", "fingerprint": "1615cb74a92e1f95", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Oscar_Server/public/js/findings.js"}, "region": {"startLine": 109}}}]}, {"ruleId": "scanner-ff116c341b5d7183", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in Oscar_Server/src/worker/runner.js:26"}, "properties": {"repobilityId": "73fb1e72a32ab4d3", "scanner": "scanner-primary", "fingerprint": "ff116c341b5d7183", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Oscar_Server/src/worker/runner.js"}, "region": {"startLine": 26}}}]}, {"ruleId": "scanner-717caf98e193e3cd", "level": "error", "message": {"text": "Insecure pattern 'new_function_used' in Bruno_Collection/library-bruno/validators.js:33"}, "properties": {"repobilityId": "140d485eaceb098d", "scanner": "scanner-primary", "fingerprint": "717caf98e193e3cd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "new_function_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Bruno_Collection/library-bruno/validators.js"}, "region": {"startLine": 33}}}]}, {"ruleId": "scanner-71dfc163b5ae521e", "level": "error", "message": {"text": "Insecure pattern 'new_function_used' in Bruno_Collection/json_validator/ajv.js:2"}, "properties": {"repobilityId": "86c560a26dc4314c", "scanner": "scanner-primary", "fingerprint": "71dfc163b5ae521e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "new_function_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Bruno_Collection/json_validator/ajv.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-65aa740cba4a4a73", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "f72e4b498f09201b", "scanner": "scanner-primary", "fingerprint": "65aa740cba4a4a73", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/codeql.yml"}, "region": {"startLine": 52}}}]}, {"ruleId": "scanner-65aa740cba4a4a73", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "7640466c92034bac", "scanner": "scanner-primary", "fingerprint": "65aa740cba4a4a73", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/codeql.yml"}, "region": {"startLine": 55}}}]}, {"ruleId": "scanner-65aa740cba4a4a73", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "8805470db04747b3", "scanner": "scanner-primary", "fingerprint": "65aa740cba4a4a73", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/codeql.yml"}, "region": {"startLine": 66}}}]}, {"ruleId": "scanner-65aa740cba4a4a73", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "3130c0a2c5ea460e", "scanner": "scanner-primary", "fingerprint": "65aa740cba4a4a73", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/codeql.yml"}, "region": {"startLine": 69}}}]}, {"ruleId": "scanner-6eb37d0775531fdd", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "2a326310aa5b2c3e", "scanner": "scanner-primary", "fingerprint": "6eb37d0775531fdd", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/auto-tag-on-release.yml"}, "region": {"startLine": 82}}}]}, {"ruleId": "scanner-6eb37d0775531fdd", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "81032eef3f4f2935", "scanner": "scanner-primary", "fingerprint": "6eb37d0775531fdd", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/auto-tag-on-release.yml"}, "region": {"startLine": 90}}}]}, {"ruleId": "scanner-9e7af4f8ebfcb421", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "f5675f1675f3ead5", "scanner": "scanner-primary", "fingerprint": "9e7af4f8ebfcb421", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci-server.yml"}, "region": {"startLine": 42}}}]}, {"ruleId": "scanner-9e7af4f8ebfcb421", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "90dc6aa033bd5571", "scanner": "scanner-primary", "fingerprint": "9e7af4f8ebfcb421", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci-server.yml"}, "region": {"startLine": 45}}}]}, {"ruleId": "scanner-9e7af4f8ebfcb421", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "f5675f1675f3ead5", "scanner": "scanner-primary", "fingerprint": "9e7af4f8ebfcb421", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci-server.yml"}, "region": {"startLine": 77}}}]}, {"ruleId": "scanner-9e7af4f8ebfcb421", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "1cc41e4c56329892", "scanner": "scanner-primary", "fingerprint": "9e7af4f8ebfcb421", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci-server.yml"}, "region": {"startLine": 80}}}]}, {"ruleId": "scanner-9e7af4f8ebfcb421", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "a9de6a1ca5a8f986", "scanner": "scanner-primary", "fingerprint": "9e7af4f8ebfcb421", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci-server.yml"}, "region": {"startLine": 83}}}]}, {"ruleId": "scanner-9e7af4f8ebfcb421", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "f5675f1675f3ead5", "scanner": "scanner-primary", "fingerprint": "9e7af4f8ebfcb421", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci-server.yml"}, "region": {"startLine": 100}}}]}, {"ruleId": "scanner-9e7af4f8ebfcb421", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "1cc41e4c56329892", "scanner": "scanner-primary", "fingerprint": "9e7af4f8ebfcb421", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci-server.yml"}, "region": {"startLine": 103}}}]}, {"ruleId": "scanner-9e7af4f8ebfcb421", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "a9de6a1ca5a8f986", "scanner": "scanner-primary", "fingerprint": "9e7af4f8ebfcb421", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci-server.yml"}, "region": {"startLine": 106}}}]}, {"ruleId": "scanner-9e7af4f8ebfcb421", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "1ff50946f06cf01c", "scanner": "scanner-primary", "fingerprint": "9e7af4f8ebfcb421", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci-server.yml"}, "region": {"startLine": 114}}}]}, {"ruleId": "scanner-324315fc59926125", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "f18178e1d6ce5698", "scanner": "scanner-primary", "fingerprint": "324315fc59926125", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/promote-release.yml"}, "region": {"startLine": 57}}}]}, {"ruleId": "scanner-324315fc59926125", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "c445bfc47afe2ee9", "scanner": "scanner-primary", "fingerprint": "324315fc59926125", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/promote-release.yml"}, "region": {"startLine": 62}}}]}, {"ruleId": "scanner-324315fc59926125", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "482145336d6b233d", "scanner": "scanner-primary", "fingerprint": "324315fc59926125", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/promote-release.yml"}, "region": {"startLine": 69}}}]}, {"ruleId": "scanner-324315fc59926125", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "45a89b72c368fc75", "scanner": "scanner-primary", "fingerprint": "324315fc59926125", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/promote-release.yml"}, "region": {"startLine": 76}}}]}, {"ruleId": "scanner-096f9e90022db85e", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "9bc5eb811e2ed8bc", "scanner": "scanner-primary", "fingerprint": "096f9e90022db85e", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/promote-release.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f77fc1ddc9ad242c", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "c2260db0df3da889", "scanner": "scanner-primary", "fingerprint": "f77fc1ddc9ad242c", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/sonar.yml"}, "region": {"startLine": 38}}}]}, {"ruleId": "scanner-f77fc1ddc9ad242c", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "544c150b644fdf7f", "scanner": "scanner-primary", "fingerprint": "f77fc1ddc9ad242c", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/sonar.yml"}, "region": {"startLine": 45}}}]}, {"ruleId": "scanner-f77fc1ddc9ad242c", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "2abfc23b1a3cd577", "scanner": "scanner-primary", "fingerprint": "f77fc1ddc9ad242c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/sonar.yml"}, "region": {"startLine": 82}}}]}, {"ruleId": "scanner-0e92f17cd1ad9214", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "34e27be2590be204", "scanner": "scanner-primary", "fingerprint": "0e92f17cd1ad9214", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci-collection.yml"}, "region": {"startLine": 36}}}]}, {"ruleId": "scanner-0e92f17cd1ad9214", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "7511a4cc6cad0aca", "scanner": "scanner-primary", "fingerprint": "0e92f17cd1ad9214", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci-collection.yml"}, "region": {"startLine": 39}}}]}, {"ruleId": "scanner-af9fb474dc7a6503", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "6bd48468b9e01461", "scanner": "scanner-primary", "fingerprint": "af9fb474dc7a6503", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/publish-image.yml"}, "region": {"startLine": 44}}}]}, {"ruleId": "scanner-af9fb474dc7a6503", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "db97ee0741b4ac10", "scanner": "scanner-primary", "fingerprint": "af9fb474dc7a6503", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/publish-image.yml"}, "region": {"startLine": 47}}}]}, {"ruleId": "scanner-af9fb474dc7a6503", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "39eee9f18b2733d3", "scanner": "scanner-primary", "fingerprint": "af9fb474dc7a6503", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/publish-image.yml"}, "region": {"startLine": 56}}}]}, {"ruleId": "scanner-af9fb474dc7a6503", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "2fe176a0dc1081cd", "scanner": "scanner-primary", "fingerprint": "af9fb474dc7a6503", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/publish-image.yml"}, "region": {"startLine": 68}}}]}, {"ruleId": "scanner-af9fb474dc7a6503", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "d3670ffc60a5759b", "scanner": "scanner-primary", "fingerprint": "af9fb474dc7a6503", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/publish-image.yml"}, "region": {"startLine": 77}}}]}, {"ruleId": "scanner-0fb7308b9dc643a3", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "5abe9128c064b9f6", "scanner": "scanner-primary", "fingerprint": "0fb7308b9dc643a3", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/publish-image.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d1b928f8f8d158f1", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "2917140821335586", "scanner": "scanner-primary", "fingerprint": "d1b928f8f8d158f1", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/gitleaks.yml"}, "region": {"startLine": 38}}}]}, {"ruleId": "scanner-d1b928f8f8d158f1", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "01a4a94926d8036a", "scanner": "scanner-primary", "fingerprint": "d1b928f8f8d158f1", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/gitleaks.yml"}, "region": {"startLine": 43}}}]}, {"ruleId": "scanner-3f003244c96a70bd", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "7f32e132d97c0eeb", "scanner": "scanner-primary", "fingerprint": "3f003244c96a70bd", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/render-docs-pdf.yml"}, "region": {"startLine": 36}}}]}, {"ruleId": "scanner-3f003244c96a70bd", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "8ee78714ed768d57", "scanner": "scanner-primary", "fingerprint": "3f003244c96a70bd", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/render-docs-pdf.yml"}, "region": {"startLine": 42}}}]}, {"ruleId": "scanner-3ec932018dd52049", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "eef0d202207c56a9", "scanner": "scanner-primary", "fingerprint": "3ec932018dd52049", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/render-docs-pdf.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-917bb02476171dfe", "level": "note", "message": {"text": "Very large file: Oscar_Server/public/js/scenarios.js (6900 lines)"}, "properties": {"repobilityId": "72866349113ea133", "scanner": "scanner-primary", "fingerprint": "917bb02476171dfe", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-b0d5410e6c33622e", "level": "note", "message": {"text": "Very large file: Oscar_Server/src/api/routes/runs.js (1219 lines)"}, "properties": {"repobilityId": "953eb43793ced1a6", "scanner": "scanner-primary", "fingerprint": "b0d5410e6c33622e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-aa9c15a8a785d348", "level": "note", "message": {"text": "Very large file: Oscar_Server/src/worker/runner.js (1076 lines)"}, "properties": {"repobilityId": "4b1aa69e76a3f94d", "scanner": "scanner-primary", "fingerprint": "aa9c15a8a785d348", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ed1d752c4e8fad98", "level": "note", "message": {"text": "Very large file: Bruno_Collection/library-bruno/scenarioParser.js (1555 lines)"}, "properties": {"repobilityId": "5baf5d4245aedc26", "scanner": "scanner-primary", "fingerprint": "ed1d752c4e8fad98", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ba184d9b38a11e7c", "level": "note", "message": {"text": "Very large file: Bruno_Collection/library-bruno/offers.js (1838 lines)"}, "properties": {"repobilityId": "106d02a645313748", "scanner": "scanner-primary", "fingerprint": "ba184d9b38a11e7c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-48b0a3cf128f4d15", "level": "note", "message": {"text": "Very large file: Bruno_Collection/library-bruno/bookings.js (1121 lines)"}, "properties": {"repobilityId": "8acda99523be91da", "scanner": "scanner-primary", "fingerprint": "48b0a3cf128f4d15", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "206aad4e58779a8f", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "eab3586f182573ab", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "25973bf3a91e3f0d", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "99c20732cc7e0552", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "146d52934df6887e", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-c8f8960d0a75107b", "level": "none", "message": {"text": "Commented-code block (7 lines) in Oscar_Server/tests/integration/company-routes.test.js:232"}, "properties": {"repobilityId": "e8fb41058be40eef", "scanner": "scanner-primary", "fingerprint": "c8f8960d0a75107b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4166ecea4d14bab4", "level": "none", "message": {"text": "Commented-code block (5 lines) in Oscar_Server/tests/integration/admin-routes.test.js:63"}, "properties": {"repobilityId": "01c15c29d0078080", "scanner": "scanner-primary", "fingerprint": "4166ecea4d14bab4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6e14de5caab6c5dd", "level": "none", "message": {"text": "Commented-code block (7 lines) in Oscar_Server/tests/unit/bruno-partialrefund.test.js:235"}, "properties": {"repobilityId": "9d42fe107a44c783", "scanner": "scanner-primary", "fingerprint": "6e14de5caab6c5dd", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-fa2904bd33c0f32e", "level": "none", "message": {"text": "Commented-code block (5 lines) in Oscar_Server/tests/unit/access-token.test.js:75"}, "properties": {"repobilityId": "19d5b6d05faa8809", "scanner": "scanner-primary", "fingerprint": "fa2904bd33c0f32e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1921891650d243f5", "level": "none", "message": {"text": "Commented-code block (6 lines) in Oscar_Server/tests/unit/at-rest.test.js:29"}, "properties": {"repobilityId": "c52962bbd387a631", "scanner": "scanner-primary", "fingerprint": "1921891650d243f5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4b7f15eda198f891", "level": "none", "message": {"text": "Commented-code block (5 lines) in Oscar_Server/tests/unit/bruno-expiredflow.test.js:33"}, "properties": {"repobilityId": "6051d10bfaaead5d", "scanner": "scanner-primary", "fingerprint": "4b7f15eda198f891", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c7f866b8eac8484a", "level": "none", "message": {"text": "Commented-code block (7 lines) in Oscar_Server/public/nav.js:24"}, "properties": {"repobilityId": "217c9b9348da21ba", "scanner": "scanner-primary", "fingerprint": "c7f866b8eac8484a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-fbad523f5c7d773a", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 Oscar_Server/public/nav.js:25"}, "properties": {"repobilityId": "ca140699c745f121", "scanner": "scanner-primary", "fingerprint": "fbad523f5c7d773a", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-c062b7abf8fad7b2", "level": "none", "message": {"text": "Commented-code block (5 lines) in Oscar_Server/public/js/scenarios.js:108"}, "properties": {"repobilityId": "76c59ece1b80279b", "scanner": "scanner-primary", "fingerprint": "c062b7abf8fad7b2", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0371d572c544aacf", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 Oscar_Server/public/js/scenarios.js:736"}, "properties": {"repobilityId": "6e383d5c448fa1fb", "scanner": "scanner-primary", "fingerprint": "0371d572c544aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-83607ff8ff43944b", "level": "none", "message": {"text": "Commented-code block (5 lines) in Oscar_Server/public/js/findings.js:137"}, "properties": {"repobilityId": "2ffa49abf7883aa7", "scanner": "scanner-primary", "fingerprint": "83607ff8ff43944b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3d5a33a3c5609dd9", "level": "none", "message": {"text": "Commented-code block (9 lines) in Oscar_Server/src/server.js:79"}, "properties": {"repobilityId": "9ad597f08d027004", "scanner": "scanner-primary", "fingerprint": "3d5a33a3c5609dd9", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-de27ac77ae3aaad8", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 Oscar_Server/src/server.js:365"}, "properties": {"repobilityId": "ae4758766acc73df", "scanner": "scanner-primary", "fingerprint": "de27ac77ae3aaad8", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-9b0912c2612055d0", "level": "none", "message": {"text": "Commented-code block (9 lines) in Oscar_Server/src/api/middleware/auth.js:42"}, "properties": {"repobilityId": "56aac94f8ada79d9", "scanner": "scanner-primary", "fingerprint": "9b0912c2612055d0", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-69f034d56ff48548", "level": "none", "message": {"text": "Commented-code block (6 lines) in Oscar_Server/src/api/middleware/tenant.js:28"}, "properties": {"repobilityId": "12de98539943cea1", "scanner": "scanner-primary", "fingerprint": "69f034d56ff48548", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-9ee763112a862c2c", "level": "none", "message": {"text": "Commented-code block (8 lines) in Oscar_Server/src/api/routes/admin.js:36"}, "properties": {"repobilityId": "2e8f1ace2ba4b831", "scanner": "scanner-primary", "fingerprint": "9ee763112a862c2c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-dba4b3e494846fbe", "level": "none", "message": {"text": "Commented-code block (5 lines) in Oscar_Server/src/api/routes/company-test-framework.js:33"}, "properties": {"repobilityId": "7f34b70dd1672daf", "scanner": "scanner-primary", "fingerprint": "dba4b3e494846fbe", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-15cc5ff74533c80f", "level": "none", "message": {"text": "Commented-code block (5 lines) in Oscar_Server/src/api/routes/auth.js:39"}, "properties": {"repobilityId": "7ba8955c33b14cbc", "scanner": "scanner-primary", "fingerprint": "15cc5ff74533c80f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2c8c4982985e08f5", "level": "none", "message": {"text": "Commented-code block (7 lines) in Oscar_Server/src/api/routes/reports.js:306"}, "properties": {"repobilityId": "81043fe9fe5f6175", "scanner": "scanner-primary", "fingerprint": "2c8c4982985e08f5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f7ef7f604fe943f7", "level": "none", "message": {"text": "Commented-code block (5 lines) in Oscar_Server/src/api/routes/me-credentials.js:102"}, "properties": {"repobilityId": "c3c28d9abf9d4458", "scanner": "scanner-primary", "fingerprint": "f7ef7f604fe943f7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-be5e702d1d8a4cde", "level": "none", "message": {"text": "Commented-code block (6 lines) in Oscar_Server/src/api/routes/company.js:217"}, "properties": {"repobilityId": "a903a5dcc90ea729", "scanner": "scanner-primary", "fingerprint": "be5e702d1d8a4cde", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d3ca7d3dfe2d9d64", "level": "none", "message": {"text": "Commented-code block (6 lines) in Oscar_Server/src/api/routes/runs.js:69"}, "properties": {"repobilityId": "54eaa004780be1f1", "scanner": "scanner-primary", "fingerprint": "d3ca7d3dfe2d9d64", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ab9ccc7e41b61e80", "level": "none", "message": {"text": "Commented-code block (7 lines) in Oscar_Server/src/api/routes/company-test-resources.js:33"}, "properties": {"repobilityId": "30a1a07dc37b8942", "scanner": "scanner-primary", "fingerprint": "ab9ccc7e41b61e80", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-bf82d867f6764903", "level": "none", "message": {"text": "Commented-code block (5 lines) in Oscar_Server/src/api/helpers/run-access.js:64"}, "properties": {"repobilityId": "c5b46f1a30f1da38", "scanner": "scanner-primary", "fingerprint": "bf82d867f6764903", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-09917431e5266827", "level": "none", "message": {"text": "Commented-code block (5 lines) in Oscar_Server/src/utils/alertmanagerConfig.js:87"}, "properties": {"repobilityId": "21efcf314b5dd4bb", "scanner": "scanner-primary", "fingerprint": "09917431e5266827", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-dfb0bcc2bad87cee", "level": "none", "message": {"text": "Commented-code block (5 lines) in Oscar_Server/src/utils/metrics.js:88"}, "properties": {"repobilityId": "c7983963cd85a686", "scanner": "scanner-primary", "fingerprint": "dfb0bcc2bad87cee", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2ae32103c8a5f7c2", "level": "none", "message": {"text": "Commented-code block (5 lines) in Oscar_Server/src/worker/access-token.js:69"}, "properties": {"repobilityId": "ea3fe2edde1dc143", "scanner": "scanner-primary", "fingerprint": "2ae32103c8a5f7c2", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-fcea7960dee75715", "level": "none", "message": {"text": "Commented-code block (6 lines) in Oscar_Server/src/worker/runner.js:42"}, "properties": {"repobilityId": "0aa397400e63adff", "scanner": "scanner-primary", "fingerprint": "fcea7960dee75715", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e1272be5b434819e", "level": "none", "message": {"text": "Commented-code block (5 lines) in Oscar_Server/src/services/timetable-discovery.js:237"}, "properties": {"repobilityId": "16363bcee7f4acb7", "scanner": "scanner-primary", "fingerprint": "e1272be5b434819e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-276214ac7eda0e74", "level": "none", "message": {"text": "Commented-code block (7 lines) in Oscar_Server/src/db/db.js:145"}, "properties": {"repobilityId": "640baf142f81ca89", "scanner": "scanner-primary", "fingerprint": "276214ac7eda0e74", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6376ec85ee9b884b", "level": "none", "message": {"text": "Commented-code block (7 lines) in Oscar_Server/src/reports/structureResults.js:97"}, "properties": {"repobilityId": "154c23ca7f6f3bf3", "scanner": "scanner-primary", "fingerprint": "6376ec85ee9b884b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4ea71615d562d45f", "level": "none", "message": {"text": "Commented-code block (6 lines) in Oscar_Server/src/reports/diff.js:32"}, "properties": {"repobilityId": "35a9e9c2b7558cc2", "scanner": "scanner-primary", "fingerprint": "4ea71615d562d45f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f2b883d67fd5627e", "level": "none", "message": {"text": "Commented-code block (5 lines) in Oscar_Server/src/reports/contextExtractors.js:37"}, "properties": {"repobilityId": "fb58eab6994d91b1", "scanner": "scanner-primary", "fingerprint": "f2b883d67fd5627e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-15a852ce7210492c", "level": "none", "message": {"text": "Commented-code block (9 lines) in Bruno_Collection/library-bruno/osdmVersion.js:121"}, "properties": {"repobilityId": "5899e3f3907ff929", "scanner": "scanner-primary", "fingerprint": "15a852ce7210492c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-17229c1ea1714bf0", "level": "none", "message": {"text": "Commented-code block (8 lines) in Bruno_Collection/library-bruno/scenarioParser.js:38"}, "properties": {"repobilityId": "0c38d299fdf4d7c1", "scanner": "scanner-primary", "fingerprint": "17229c1ea1714bf0", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-73a2e4a86f4102fb", "level": "none", "message": {"text": "Commented-code block (23 lines) in Bruno_Collection/library-bruno/expiredFlow.js:176"}, "properties": {"repobilityId": "7eb046b738ed5327", "scanner": "scanner-primary", "fingerprint": "73a2e4a86f4102fb", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-9fda6b173d9c8acb", "level": "none", "message": {"text": "Commented-code block (5 lines) in Bruno_Collection/library-bruno/osdmSchema.js:115"}, "properties": {"repobilityId": "593e2d4a49c461e7", "scanner": "scanner-primary", "fingerprint": "9fda6b173d9c8acb", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-92b2cf389c8d361c", "level": "none", "message": {"text": "Commented-code block (8 lines) in Bruno_Collection/library-bruno/exchanges.js:44"}, "properties": {"repobilityId": "47c9eece69492fc5", "scanner": "scanner-primary", "fingerprint": "92b2cf389c8d361c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-98331a867e5ddaaa", "level": "none", "message": {"text": "Commented-code block (6 lines) in Bruno_Collection/library-bruno/mergeReport.js:44"}, "properties": {"repobilityId": "077c078cab74d6c0", "scanner": "scanner-primary", "fingerprint": "98331a867e5ddaaa", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-eb897eb20021a11b", "level": "none", "message": {"text": "Commented-code block (16 lines) in Bruno_Collection/library-bruno/offers.js:41"}, "properties": {"repobilityId": "30154ce9a07a5fb7", "scanner": "scanner-primary", "fingerprint": "eb897eb20021a11b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-258f24f89ded090e", "level": "none", "message": {"text": "Commented-code block (5 lines) in Bruno_Collection/library-bruno/requestedInformation.js:758"}, "properties": {"repobilityId": "590fe1c47002a124", "scanner": "scanner-primary", "fingerprint": "258f24f89ded090e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-bff4e9d43a48bbd1", "level": "none", "message": {"text": "Commented-code block (5 lines) in Bruno_Collection/library-bruno/partialRefund.js:280"}, "properties": {"repobilityId": "9617fa6ee1fd30e8", "scanner": "scanner-primary", "fingerprint": "bff4e9d43a48bbd1", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-721b7b71c8d9c9f1", "level": "none", "message": {"text": "Commented-code block (6 lines) in Bruno_Collection/library-bruno/envUtils.js:14"}, "properties": {"repobilityId": "f3ee32b56b9b2e15", "scanner": "scanner-primary", "fingerprint": "721b7b71c8d9c9f1", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7cebac830fdfdae4", "level": "none", "message": {"text": "Commented-code block (6 lines) in Bruno_Collection/library-bruno/loopback.js:34"}, "properties": {"repobilityId": "5efca174ea04c268", "scanner": "scanner-primary", "fingerprint": "7cebac830fdfdae4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4490619d67606d38", "level": "none", "message": {"text": "Commented-code block (5 lines) in Bruno_Collection/library-bruno/reportGenerator.js:51"}, "properties": {"repobilityId": "f518eda45b60aad6", "scanner": "scanner-primary", "fingerprint": "4490619d67606d38", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-15f524c20892e7bb", "level": "none", "message": {"text": "Commented-code block (8 lines) in Bruno_Collection/library-bruno/bookings.js:148"}, "properties": {"repobilityId": "348ec1898a982e19", "scanner": "scanner-primary", "fingerprint": "15f524c20892e7bb", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a3b94a6afec05263", "level": "none", "message": {"text": "Commented-code block (8 lines) in Bruno_Collection/library-bruno/refunds.js:55"}, "properties": {"repobilityId": "54d187b93167fce4", "scanner": "scanner-primary", "fingerprint": "a3b94a6afec05263", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e39371973f4639f1", "level": "none", "message": {"text": "Commented-code block (6 lines) in Bruno_Collection/library-bruno/passengers.js:22"}, "properties": {"repobilityId": "2b2ada04d94f7598", "scanner": "scanner-primary", "fingerprint": "e39371973f4639f1", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7cbebd71a8f953eb", "level": "none", "message": {"text": "Commented-code block (8 lines) in Bruno_Collection/library-bruno/requestsBuilder.js:25"}, "properties": {"repobilityId": "512952ab4e7f53c3", "scanner": "scanner-primary", "fingerprint": "7cbebd71a8f953eb", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4fc0102891b9ee3f", "level": "none", "message": {"text": "Commented-code block (8 lines) in Bruno_Collection/library-bruno/displays.js:83"}, "properties": {"repobilityId": "2f7414da10a0af7f", "scanner": "scanner-primary", "fingerprint": "4fc0102891b9ee3f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-42f22b98a5f33839", "level": "none", "message": {"text": "Commented-code block (9 lines) in Bruno_Collection/library-bruno/validators.js:258"}, "properties": {"repobilityId": "6bb2984f8aa19cd2", "scanner": "scanner-primary", "fingerprint": "42f22b98a5f33839", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-56331e3aac77e2e6", "level": "none", "message": {"text": "Commented-code block (7 lines) in Bruno_Collection/library-bruno/osdmCompliance.js:60"}, "properties": {"repobilityId": "23cd90a00186cecf", "scanner": "scanner-primary", "fingerprint": "56331e3aac77e2e6", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1c2ce67dc5bc6db9", "level": "none", "message": {"text": "Commented-code block (8 lines) in Documentation/Test_Coverage/_build_coverage_matrix.py:75"}, "properties": {"repobilityId": "64a548e8ea1f5f79", "scanner": "scanner-primary", "fingerprint": "1c2ce67dc5bc6db9", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e41d8fa03eaebf74", "level": "none", "message": {"text": "Commented-code block (5 lines) in Documentation/Test_Coverage/_build_field_level_coverage.py:227"}, "properties": {"repobilityId": "904f493bf0a962e9", "scanner": "scanner-primary", "fingerprint": "e41d8fa03eaebf74", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-cc0f9d8e41b33b0e", "level": "note", "message": {"text": "11 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "c82cd8cd626c3599", "scanner": "scanner-primary", "fingerprint": "cc0f9d8e41b33b0e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "8e0e00293db0fccb", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-4c1cbcc7e6732a66", "level": "error", "message": {"text": "Dangling fetch: POST /v1/auth/logout (Oscar_Server/public/nav.js:341)"}, "properties": {"repobilityId": "2e00713fe5371e08", "scanner": "scanner-primary", "fingerprint": "4c1cbcc7e6732a66", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-7643838e6643fe71", "level": "error", "message": {"text": "Dangling fetch: GET /v1/company/test-framework (Oscar_Server/public/js/scenarios.js:324)"}, "properties": {"repobilityId": "d5a6f996aaec9aa0", "scanner": "scanner-primary", "fingerprint": "7643838e6643fe71", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-9f3dd14830e6cc2d", "level": "error", "message": {"text": "Dangling fetch: GET /v1/company/test-resources (Oscar_Server/public/js/scenarios.js:325)"}, "properties": {"repobilityId": "27b1f9ad05f14aa5", "scanner": "scanner-primary", "fingerprint": "9f3dd14830e6cc2d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-4bf0cff404c5a593", "level": "error", "message": {"text": "Dangling fetch: GET /v1/company (Oscar_Server/public/js/scenarios.js:326)"}, "properties": {"repobilityId": "1f266a5dae22bb6b", "scanner": "scanner-primary", "fingerprint": "4bf0cff404c5a593", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-b6a85068dde14f7b", "level": "error", "message": {"text": "Dangling fetch: GET /v1/company/datafile (Oscar_Server/public/js/scenarios.js:355)"}, "properties": {"repobilityId": "d6a20c6882ab372d", "scanner": "scanner-primary", "fingerprint": "b6a85068dde14f7b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-6639c2367bdc17d1", "level": "error", "message": {"text": "Dangling fetch: PUT /v1/company/test-framework (Oscar_Server/public/js/scenarios.js:612)"}, "properties": {"repobilityId": "f7f6f1963d2b152c", "scanner": "scanner-primary", "fingerprint": "6639c2367bdc17d1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-d005f210320eee71", "level": "error", "message": {"text": "Dangling fetch: DELETE /v1/company/datafile (Oscar_Server/public/js/scenarios.js:644)"}, "properties": {"repobilityId": "5b31e6b2414096e2", "scanner": "scanner-primary", "fingerprint": "d005f210320eee71", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-b5c0373eea33241f", "level": "error", "message": {"text": "Dangling fetch: DELETE /v1/company/test-resources/${r.id} (Oscar_Server/public/js/scenarios.js:647)"}, "properties": {"repobilityId": "c137bc4848bf9fba", "scanner": "scanner-primary", "fingerprint": "b5c0373eea33241f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-a9cd73f3f8dc4616", "level": "error", "message": {"text": "Dangling fetch: DELETE /v1/company/test-framework (Oscar_Server/public/js/scenarios.js:650)"}, "properties": {"repobilityId": "b25a52319093e006", "scanner": "scanner-primary", "fingerprint": "a9cd73f3f8dc4616", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-4544b0fbb5a429f3", "level": "error", "message": {"text": "Dangling fetch: DELETE /v1/company/datafile (Oscar_Server/public/js/scenarios.js:672)"}, "properties": {"repobilityId": "80a5049839620a8d", "scanner": "scanner-primary", "fingerprint": "4544b0fbb5a429f3", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-615a26c0f8755bb7", "level": "error", "message": {"text": "Dangling fetch: DELETE /v1/company/test-resources/${r.id} (Oscar_Server/public/js/scenarios.js:675)"}, "properties": {"repobilityId": "3601a064cbde5e1d", "scanner": "scanner-primary", "fingerprint": "615a26c0f8755bb7", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-18c1bc7402b43c89", "level": "error", "message": {"text": "Dangling fetch: DELETE /v1/company/test-resources/${resourceId} (Oscar_Server/public/js/scenarios.js:726)"}, "properties": {"repobilityId": "9868dbaeef7accf1", "scanner": "scanner-primary", "fingerprint": "18c1bc7402b43c89", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-b0f10765a1b3d08b", "level": "error", "message": {"text": "Dangling fetch: PUT /v1/company/datafile/json (Oscar_Server/public/js/scenarios.js:736)"}, "properties": {"repobilityId": "dc93fea798385fd6", "scanner": "scanner-primary", "fingerprint": "b0f10765a1b3d08b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-e206b679fd39b407", "level": "error", "message": {"text": "Dangling fetch: DELETE /v1/company/datafile (Oscar_Server/public/js/scenarios.js:785)"}, "properties": {"repobilityId": "8268bbb054dfc670", "scanner": "scanner-primary", "fingerprint": "e206b679fd39b407", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-f140c30ed842301f", "level": "error", "message": {"text": "Dangling fetch: POST /v1/company/datafile (Oscar_Server/public/js/scenarios.js:999)"}, "properties": {"repobilityId": "170f80f1a87fe799", "scanner": "scanner-primary", "fingerprint": "f140c30ed842301f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-016af9fa92b8a253", "level": "error", "message": {"text": "Dangling fetch: PUT /v1/company/test-framework (Oscar_Server/public/js/scenarios.js:1113)"}, "properties": {"repobilityId": "2796379404440997", "scanner": "scanner-primary", "fingerprint": "016af9fa92b8a253", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-d23a9d93856587e6", "level": "error", "message": {"text": "Dangling fetch: GET /v1/company/test-resources (Oscar_Server/public/js/scenarios.js:1123)"}, "properties": {"repobilityId": "47df829aee05e748", "scanner": "scanner-primary", "fingerprint": "d23a9d93856587e6", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-bebba8a005a03d2a", "level": "error", "message": {"text": "Dangling fetch: POST /v1/company/test-resources (Oscar_Server/public/js/scenarios.js:1140)"}, "properties": {"repobilityId": "80f6d31bf76aae1c", "scanner": "scanner-primary", "fingerprint": "bebba8a005a03d2a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-1bfd943e8aeb2a07", "level": "error", "message": {"text": "Dangling fetch: DELETE /v1/company/datafile (Oscar_Server/public/js/scenarios.js:1158)"}, "properties": {"repobilityId": "fcc9b5b240cab4e8", "scanner": "scanner-primary", "fingerprint": "1bfd943e8aeb2a07", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-268594b2cc892de6", "level": "error", "message": {"text": "Dangling fetch: PUT /v1/company/datafile/json (Oscar_Server/public/js/scenarios.js:2896)"}, "properties": {"repobilityId": "f7064ade619897d1", "scanner": "scanner-primary", "fingerprint": "268594b2cc892de6", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-e1af1fbba7cb6f32", "level": "error", "message": {"text": "Dangling fetch: GET /v1/company/datafile (Oscar_Server/public/js/scenarios.js:2912)"}, "properties": {"repobilityId": "d3e2079fabebe609", "scanner": "scanner-primary", "fingerprint": "e1af1fbba7cb6f32", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-6d33e158437c3e65", "level": "error", "message": {"text": "Dangling fetch: POST /v1/company/test-resources/discover-timetable (Oscar_Server/public/js/scenarios.js:4284)"}, "properties": {"repobilityId": "bb1d2e91601ad981", "scanner": "scanner-primary", "fingerprint": "6d33e158437c3e65", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-da25e3e52a12e254", "level": "error", "message": {"text": "Dangling fetch: DELETE /v1/company/test-resources/${id} (Oscar_Server/public/js/scenarios.js:4753)"}, "properties": {"repobilityId": "4136330e2c3483b9", "scanner": "scanner-primary", "fingerprint": "da25e3e52a12e254", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-66a267fc65c5b836", "level": "error", "message": {"text": "Dangling fetch: GET /v1/company/datafile (Oscar_Server/public/js/scenarios.js:5470)"}, "properties": {"repobilityId": "f9c3cf1d7e075184", "scanner": "scanner-primary", "fingerprint": "66a267fc65c5b836", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-84ae552c777f3df2", "level": "error", "message": {"text": "Dangling fetch: PUT /v1/company/datafile/json (Oscar_Server/public/js/scenarios.js:5736)"}, "properties": {"repobilityId": "62d11ef2fc10eea9", "scanner": "scanner-primary", "fingerprint": "84ae552c777f3df2", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-38322f96e31c7b14", "level": "error", "message": {"text": "Dangling fetch: POST /v1/company/test-resources/reprobe-offers (Oscar_Server/public/js/scenarios.js:6184)"}, "properties": {"repobilityId": "5bbdc36c4e76208f", "scanner": "scanner-primary", "fingerprint": "38322f96e31c7b14", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-7e13c3f2244bf384", "level": "note", "message": {"text": "Unused endpoint: GET /json_validator/datafile.schema.json"}, "properties": {"repobilityId": "f3c3edf100d739ad", "scanner": "scanner-primary", "fingerprint": "7e13c3f2244bf384", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-777c5acb045bc546", "level": "note", "message": {"text": "Unused endpoint: GET /data/:filename"}, "properties": {"repobilityId": "60e1fd4708a30533", "scanner": "scanner-primary", "fingerprint": "777c5acb045bc546", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-87b2f887faa50a10", "level": "note", "message": {"text": "Unused endpoint: POST /v1/runs/:runId/refresh-access-token"}, "properties": {"repobilityId": "bea95e558cefad79", "scanner": "scanner-primary", "fingerprint": "87b2f887faa50a10", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3d17e43986ccff67", "level": "note", "message": {"text": "Unused endpoint: GET /artifacts/:runId/:filename"}, "properties": {"repobilityId": "804f0e1ec69bdc72", "scanner": "scanner-primary", "fingerprint": "3d17e43986ccff67", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8839ee8182dff27d", "level": "note", "message": {"text": "Unused endpoint: USE /v1/auth"}, "properties": {"repobilityId": "e7c5899e79739d53", "scanner": "scanner-primary", "fingerprint": "8839ee8182dff27d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b578af8a81516f0d", "level": "note", "message": {"text": "Unused endpoint: USE /v1/me/credentials"}, "properties": {"repobilityId": "e998dd7e3db5534a", "scanner": "scanner-primary", "fingerprint": "b578af8a81516f0d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-315abca8c5ee3d14", "level": "note", "message": {"text": "Unused endpoint: USE /v1/company/users"}, "properties": {"repobilityId": "9d92d2359e575814", "scanner": "scanner-primary", "fingerprint": "315abca8c5ee3d14", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c7af28756bda791e", "level": "note", "message": {"text": "Unused endpoint: USE /v1/company"}, "properties": {"repobilityId": "0a35adaf8985318a", "scanner": "scanner-primary", "fingerprint": "c7af28756bda791e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c6e3207389235c58", "level": "note", "message": {"text": "Unused endpoint: USE /v1/runs"}, "properties": {"repobilityId": "5a5bec85f2be00c2", "scanner": "scanner-primary", "fingerprint": "c6e3207389235c58", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b233a496d1ed0ab5", "level": "note", "message": {"text": "Unused endpoint: USE /v1/reports"}, "properties": {"repobilityId": "b54e585e39067584", "scanner": "scanner-primary", "fingerprint": "b233a496d1ed0ab5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2d0ce96799aac655", "level": "note", "message": {"text": "Unused endpoint: USE /v1/admin"}, "properties": {"repobilityId": "132d5ff1f8f11ce8", "scanner": "scanner-primary", "fingerprint": "2d0ce96799aac655", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3a10a160de68aa02", "level": "note", "message": {"text": "Unused endpoint: GET /v1/openapi.json"}, "properties": {"repobilityId": "26746d34bb9cfe95", "scanner": "scanner-primary", "fingerprint": "3a10a160de68aa02", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-388a8dd37b6782cb", "level": "note", "message": {"text": "Unused endpoint: USE /v1/docs"}, "properties": {"repobilityId": "a518af84e05a14da", "scanner": "scanner-primary", "fingerprint": "388a8dd37b6782cb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-618721b912bad1c2", "level": "note", "message": {"text": "Unused endpoint: POST /login"}, "properties": {"repobilityId": "dc56cbd5912b734f", "scanner": "scanner-primary", "fingerprint": "618721b912bad1c2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-841e50bf821e4158", "level": "note", "message": {"text": "Unused endpoint: GET /users"}, "properties": {"repobilityId": "c8a0a7410baf716f", "scanner": "scanner-primary", "fingerprint": "841e50bf821e4158", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1bca8100a44f7f25", "level": "note", "message": {"text": "Unused endpoint: POST /users"}, "properties": {"repobilityId": "2109f4206f3bc829", "scanner": "scanner-primary", "fingerprint": "1bca8100a44f7f25", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a2da8d08e12b122c", "level": "note", "message": {"text": "Unused endpoint: PATCH /users/:id"}, "properties": {"repobilityId": "5cd59a6ef5ad32aa", "scanner": "scanner-primary", "fingerprint": "a2da8d08e12b122c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fa4e1071fc9bdadb", "level": "note", "message": {"text": "Unused endpoint: POST /users/:id/reset-password"}, "properties": {"repobilityId": "8e660de5dd164b2c", "scanner": "scanner-primary", "fingerprint": "fa4e1071fc9bdadb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-833b8e34e489bb10", "level": "note", "message": {"text": "Unused endpoint: POST /users/:id/generate-reset-link"}, "properties": {"repobilityId": "634d45d83fc61be5", "scanner": "scanner-primary", "fingerprint": "833b8e34e489bb10", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-79406b9fd85263bf", "level": "note", "message": {"text": "Unused endpoint: DELETE /users/:id"}, "properties": {"repobilityId": "4b6c6a7e451c5e8c", "scanner": "scanner-primary", "fingerprint": "79406b9fd85263bf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2a366262a6be358f", "level": "note", "message": {"text": "Unused endpoint: GET /activity"}, "properties": {"repobilityId": "9f5d7a03861629c1", "scanner": "scanner-primary", "fingerprint": "2a366262a6be358f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a35ce3e9c9f59e0a", "level": "note", "message": {"text": "Unused endpoint: GET /companies"}, "properties": {"repobilityId": "d32583a99cdcc6af", "scanner": "scanner-primary", "fingerprint": "a35ce3e9c9f59e0a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ec39abb0b24cc5b2", "level": "note", "message": {"text": "Unused endpoint: POST /companies"}, "properties": {"repobilityId": "595eabc899c39367", "scanner": "scanner-primary", "fingerprint": "ec39abb0b24cc5b2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-799efc4b396984aa", "level": "note", "message": {"text": "Unused endpoint: PATCH /companies/:id"}, "properties": {"repobilityId": "4df315fb77c2b0c6", "scanner": "scanner-primary", "fingerprint": "799efc4b396984aa", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b4108b6c06c6b5c0", "level": "note", "message": {"text": "Unused endpoint: DELETE /companies/:id"}, "properties": {"repobilityId": "4787022de6c9dabc", "scanner": "scanner-primary", "fingerprint": "b4108b6c06c6b5c0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a6f48e60c30777ab", "level": "note", "message": {"text": "Unused endpoint: GET /config"}, "properties": {"repobilityId": "b4aebab3db68df3f", "scanner": "scanner-primary", "fingerprint": "a6f48e60c30777ab", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4cff4b2e8c2f239b", "level": "note", "message": {"text": "Unused endpoint: PATCH /config"}, "properties": {"repobilityId": "a4120c80812c06b6", "scanner": "scanner-primary", "fingerprint": "4cff4b2e8c2f239b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-660cc9b103629ed8", "level": "note", "message": {"text": "Unused endpoint: POST /alertmanager/apply"}, "properties": {"repobilityId": "d6f6443a977f71e1", "scanner": "scanner-primary", "fingerprint": "660cc9b103629ed8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3f93fbf292efc28e", "level": "note", "message": {"text": "Unused endpoint: POST /rotate-jwt-secret"}, "properties": {"repobilityId": "2ebe439f60a58182", "scanner": "scanner-primary", "fingerprint": "3f93fbf292efc28e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ea016db9a638f359", "level": "note", "message": {"text": "Unused endpoint: POST /test-email"}, "properties": {"repobilityId": "316e6f267fd834dd", "scanner": "scanner-primary", "fingerprint": "ea016db9a638f359", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4b92445a61b01e81", "level": "note", "message": {"text": "Unused endpoint: GET /test-framework"}, "properties": {"repobilityId": "6198f9b8ff98c284", "scanner": "scanner-primary", "fingerprint": "4b92445a61b01e81", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5a05bf952e88c699", "level": "note", "message": {"text": "Unused endpoint: PUT /test-framework"}, "properties": {"repobilityId": "a8afa19e01286127", "scanner": "scanner-primary", "fingerprint": "5a05bf952e88c699", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6b971a208a6475ad", "level": "note", "message": {"text": "Unused endpoint: DELETE /test-framework"}, "properties": {"repobilityId": "75977f0acfcd5aa9", "scanner": "scanner-primary", "fingerprint": "6b971a208a6475ad", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-74a694079368f227", "level": "note", "message": {"text": "Unused endpoint: USE /login"}, "properties": {"repobilityId": "655f33228b58c59d", "scanner": "scanner-primary", "fingerprint": "74a694079368f227", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0aea1f429e292d45", "level": "note", "message": {"text": "Unused endpoint: USE /register"}, "properties": {"repobilityId": "5f11f4f31afa85d0", "scanner": "scanner-primary", "fingerprint": "0aea1f429e292d45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c81619fbcb39d276", "level": "note", "message": {"text": "Unused endpoint: USE /bootstrap"}, "properties": {"repobilityId": "65460009f2eea689", "scanner": "scanner-primary", "fingerprint": "c81619fbcb39d276", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0e9f62ffdc857013", "level": "note", "message": {"text": "Unused endpoint: GET /register/companies"}, "properties": {"repobilityId": "774903e1e1b3f5f0", "scanner": "scanner-primary", "fingerprint": "0e9f62ffdc857013", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-111e16b3687be06d", "level": "note", "message": {"text": "Unused endpoint: POST /register/request"}, "properties": {"repobilityId": "9146e993b6b2cc6f", "scanner": "scanner-primary", "fingerprint": "111e16b3687be06d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a3446a5f74053792", "level": "note", "message": {"text": "Unused endpoint: POST /register/confirm"}, "properties": {"repobilityId": "cb1db6dc7c23a4eb", "scanner": "scanner-primary", "fingerprint": "a3446a5f74053792", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cf634f331f1be47c", "level": "note", "message": {"text": "Unused endpoint: POST /password-reset/request"}, "properties": {"repobilityId": "9f3f7a493a388c60", "scanner": "scanner-primary", "fingerprint": "cf634f331f1be47c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bfe9ab88a9863c25", "level": "note", "message": {"text": "Unused endpoint: GET /password-reset/check-token"}, "properties": {"repobilityId": "6089f31a1b92e818", "scanner": "scanner-primary", "fingerprint": "bfe9ab88a9863c25", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4c74973257c0143d", "level": "note", "message": {"text": "Unused endpoint: POST /password-reset/confirm"}, "properties": {"repobilityId": "53b288abae9f018d", "scanner": "scanner-primary", "fingerprint": "4c74973257c0143d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f7748d198147c107", "level": "note", "message": {"text": "Unused endpoint: GET /register/check-token"}, "properties": {"repobilityId": "cafea17cd538c067", "scanner": "scanner-primary", "fingerprint": "f7748d198147c107", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-662ed1659363a8c1", "level": "note", "message": {"text": "Unused endpoint: POST /bootstrap/platform-user"}, "properties": {"repobilityId": "92ec0c65c674c5da", "scanner": "scanner-primary", "fingerprint": "662ed1659363a8c1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd1dc91abf32142d", "level": "note", "message": {"text": "Unused endpoint: GET /me"}, "properties": {"repobilityId": "1c98a330f9588f2f", "scanner": "scanner-primary", "fingerprint": "fd1dc91abf32142d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-99fc36db98c134ce", "level": "note", "message": {"text": "Unused endpoint: POST /logout"}, "properties": {"repobilityId": "0d7b5eb1c1aaf259", "scanner": "scanner-primary", "fingerprint": "99fc36db98c134ce", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5eed2447bf4a087f", "level": "note", "message": {"text": "Unused endpoint: GET /sso-check"}, "properties": {"repobilityId": "377ae738a46cb7d5", "scanner": "scanner-primary", "fingerprint": "5eed2447bf4a087f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5cf10967b5fa0cac", "level": "note", "message": {"text": "Unused endpoint: POST /compare"}, "properties": {"repobilityId": "764a44d572c44c8f", "scanner": "scanner-primary", "fingerprint": "5cf10967b5fa0cac", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e8f8fc83db4ff640", "level": "note", "message": {"text": "Unused endpoint: GET /comparisons"}, "properties": {"repobilityId": "8e676ef840b4e177", "scanner": "scanner-primary", "fingerprint": "e8f8fc83db4ff640", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-215dc02c4e24d666", "level": "note", "message": {"text": "Unused endpoint: GET /comparisons/:id"}, "properties": {"repobilityId": "c50805998d422da6", "scanner": "scanner-primary", "fingerprint": "215dc02c4e24d666", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}