{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-4682a15d6f7d3f96", "name": "Possibly dead Python function: weekly_key_for_date", "shortDescription": {"text": "Possibly dead Python function: weekly_key_for_date"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-157b836c9ef8f430", "name": "Possibly dead Python function: create_checkout", "shortDescription": {"text": "Possibly dead Python function: create_checkout"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fbc368a770f97c25", "name": "Possibly dead Python function: create_checkout", "shortDescription": {"text": "Possibly dead Python function: create_checkout"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9e236910e66d0e68", "name": "Possibly dead Python function: needs_rehash", "shortDescription": {"text": "Possibly dead Python function: needs_rehash"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9f43bf4755f5296c", "name": "Possibly dead Python function: to_payload", "shortDescription": {"text": "Possibly dead Python function: to_payload"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cc1b5c3a6a979e9d", "name": "Possibly dead Python function: request_stop", "shortDescription": {"text": "Possibly dead Python function: request_stop"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-922fec377fec51b4", "name": "Possibly dead Python function: send_message", "shortDescription": {"text": "Possibly dead Python function: send_message"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8b7e6cb937eedd51", "name": "Possibly dead Python function: request_stop", "shortDescription": {"text": "Possibly dead Python function: request_stop"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8f06837d063e207f", "name": "Possibly dead Python function: telegram_by_user", "shortDescription": {"text": "Possibly dead Python function: telegram_by_user"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d52e39a519b833d", "name": "Stray `console.log` in TS/JS \u2014 apps/web/src/pages/LandingPage.vue:100", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/web/src/pages/LandingPage.vue:100"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f9334d8c10e3efa9", "name": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c36b30587c620ebd", "name": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4710e5c5088681d3", "name": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4654a46ae713f629", "name": "Dockerfile runs as root: apps/admin/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: apps/admin/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-da606e2888be7fe1", "name": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9b03f5a7efceda59", "name": "Docker base image is tag-pinned but not digest-pinned: nginx:1.27-alpine", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: nginx:1.27-alpine"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7673561931a5dd33", "name": "Dockerfile runs as root: apps/web/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: apps/web/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-744c132692cc6e12", "name": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c59f100803446097", "name": "Docker base image is tag-pinned but not digest-pinned: nginx:1.27-alpine", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: nginx:1.27-alpine"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c531edbaf4eef9bc", "name": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-46d83bc51ab073bf", "name": "Insecure pattern 'vue_v_html' in apps/web/src/pages/AiReviewPage.vue:60", "shortDescription": {"text": "Insecure pattern 'vue_v_html' in apps/web/src/pages/AiReviewPage.vue:60"}, "fullDescription": {"text": "Found a known-risky pattern (vue_v_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2f3625f97e9f441a", "name": "Possible secret in infra/load/k6/lib/common.js", "shortDescription": {"text": "Possible secret in infra/load/k6/lib/common.js"}, "fullDescription": {"text": "Detected pattern matching password_literal. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-cef6ff64d25cde41", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-28c4a04bd807da0c", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "docker/login-action@v3 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ad6701f0a8405e22", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e6ad6b8f753b7daa", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2b3d632df2d10715", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-844171341e6bbce3", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dfd9db5038437f79", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4c4c3396af24e8b4", "name": "Very large file: packages/contracts/src/api-types.ts (3145 lines)", "shortDescription": {"text": "Very large file: packages/contracts/src/api-types.ts (3145 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5c30f715681a4005", "name": "Node manifest has dependencies but no lockfile: apps/admin/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: apps/admin/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4a9eb7dc7c6e3880", "name": "Node manifest has dependencies but no lockfile: apps/web/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: apps/web/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-54058893046102be", "name": "Node manifest has dependencies but no lockfile: apps/realtime/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: apps/realtime/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f85d8f0719e22fa8", "name": "Node manifest has dependencies but no lockfile: packages/contracts/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/contracts/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing lockfile. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-998d9b0238d4e7ed", "name": "`fetch()` without try/.catch or AbortSignal \u2014 apps/admin/src/shared/api/client.ts:99", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/admin/src/shared/api/client.ts:99"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9eaa144c9e34b14a", "name": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/src/shared/api/client.ts:99", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/src/shared/api/client.ts:99"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-89c1b2779e5c1888", "name": "Commented-code block (6 lines) in infra/load/k6/answers_load.js:3", "shortDescription": {"text": "Commented-code block (6 lines) in infra/load/k6/answers_load.js:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-48529aa950fd7634", "name": "Commented-code block (6 lines) in infra/load/k6/duel_ws.js:14", "shortDescription": {"text": "Commented-code block (6 lines) in infra/load/k6/duel_ws.js:14"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-460e379735342e27", "name": "Commented-code block (5 lines) in infra/load/k6/lib/socketio.js:7", "shortDescription": {"text": "Commented-code block (5 lines) in infra/load/k6/lib/socketio.js:7"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-440101b977fbefa5", "name": "Commented-code block (5 lines) in infra/load/k6/lib/common.js:25", "shortDescription": {"text": "Commented-code block (5 lines) in infra/load/k6/lib/common.js:25"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2eafc3188c36bb02", "name": "3 env vars used in code but missing from .env.example", "shortDescription": {"text": "3 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `ADMIN_PASSWORD`, `VITE_API_URL`, `VITE_REALTIME_URL`. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-be46ea126aa5d8dc", "name": "Near-duplicate function bodies in 3 places", "shortDescription": {"text": "Near-duplicate function bodies in 3 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\napps/bot/src/bot/inline_store.py:aclose, apps/workers/src/workers/dedup.py:aclose, apps/workers/src/workers/inline_store.py:aclose\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\napps/api/src/duels/repository.py:get, apps/api/src/ai_review/repository.py:get_duel\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-947c8bde526c8aff", "name": "FastAPI POST `telegram_auth` without auth dependency \u2014 apps/api/src/auth/router.py:77", "shortDescription": {"text": "FastAPI POST `telegram_auth` without auth dependency \u2014 apps/api/src/auth/router.py:77"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f60a3a90a917e948", "name": "FastAPI POST `telegram_register` without auth dependency \u2014 apps/api/src/auth/router.py:106", "shortDescription": {"text": "FastAPI POST `telegram_register` without auth dependency \u2014 apps/api/src/auth/router.py:106"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-91e74783ee88c413", "name": "FastAPI POST `verify_email` without auth dependency \u2014 apps/api/src/auth/router.py:148", "shortDescription": {"text": "FastAPI POST `verify_email` without auth dependency \u2014 apps/api/src/auth/router.py:148"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fc3ad3d8f4e8ced6", "name": "FastAPI POST `verify_link` without auth dependency \u2014 apps/api/src/auth/router.py:162", "shortDescription": {"text": "FastAPI POST `verify_link` without auth dependency \u2014 apps/api/src/auth/router.py:162"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e894fb840e01c075", "name": "FastAPI POST `resend_code` without auth dependency \u2014 apps/api/src/auth/router.py:187", "shortDescription": {"text": "FastAPI POST `resend_code` without auth dependency \u2014 apps/api/src/auth/router.py:187"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f7b485d302654b56", "name": "FastAPI POST `refresh` without auth dependency \u2014 apps/api/src/auth/router.py:202", "shortDescription": {"text": "FastAPI POST `refresh` without auth dependency \u2014 apps/api/src/auth/router.py:202"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f4bc3cbd7fa2da9d", "name": "FastAPI POST `create_tournament` without auth dependency \u2014 apps/api/src/tournaments/admin_router.py:35", "shortDescription": {"text": "FastAPI POST `create_tournament` without auth dependency \u2014 apps/api/src/tournaments/admin_router.py:35"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-57b4628348bfd262", "name": "FastAPI PATCH `update_tournament` without auth dependency \u2014 apps/api/src/tournaments/admin_router.py:51", "shortDescription": {"text": "FastAPI PATCH `update_tournament` without auth dependency \u2014 apps/api/src/tournaments/admin_router.py:51"}, "fullDescription": {"text": "`@router.patch` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1bded6ae0c53ed43", "name": "FastAPI POST `grant_entry` without auth dependency \u2014 apps/api/src/tournaments/admin_router.py:60", "shortDescription": {"text": "FastAPI POST `grant_entry` without auth dependency \u2014 apps/api/src/tournaments/admin_router.py:60"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-77f1b365a2117692", "name": "FastAPI POST `recompute_places` without auth dependency \u2014 apps/api/src/tournaments/admin_router.py:72", "shortDescription": {"text": "FastAPI POST `recompute_places` without auth dependency \u2014 apps/api/src/tournaments/admin_router.py:72"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9cac86419f1e195a", "name": "FastAPI POST `create_duel` without auth dependency \u2014 apps/api/src/internal_api/router.py:46", "shortDescription": {"text": "FastAPI POST `create_duel` without auth dependency \u2014 apps/api/src/internal_api/router.py:46"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-02df46af3c96974c", "name": "FastAPI POST `finish_duel` without auth dependency \u2014 apps/api/src/internal_api/router.py:59", "shortDescription": {"text": "FastAPI POST `finish_duel` without auth dependency \u2014 apps/api/src/internal_api/router.py:59"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6b6dc723c47cb2eb", "name": "FastAPI POST `set_duel_share_card` without auth dependency \u2014 apps/api/src/internal_api/router.py:84", "shortDescription": {"text": "FastAPI POST `set_duel_share_card` without auth dependency \u2014 apps/api/src/internal_api/router.py:84"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d6a5836fb3348780", "name": "FastAPI POST `write_ai_review` without auth dependency \u2014 apps/api/src/internal_api/router.py:113", "shortDescription": {"text": "FastAPI POST `write_ai_review` without auth dependency \u2014 apps/api/src/internal_api/router.py:113"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c1452df65134d1d6", "name": "FastAPI POST `telegram_redeem` without auth dependency \u2014 apps/api/src/internal_api/router.py:130", "shortDescription": {"text": "FastAPI POST `telegram_redeem` without auth dependency \u2014 apps/api/src/internal_api/router.py:130"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ef240e5badcedfe0", "name": "FastAPI PATCH `update_task` without auth dependency \u2014 apps/api/src/admin/router.py:74", "shortDescription": {"text": "FastAPI PATCH `update_task` without auth dependency \u2014 apps/api/src/admin/router.py:74"}, "fullDescription": {"text": "`@router.patch` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-acc46106b4f95883", "name": "FastAPI POST `publish_task` without auth dependency \u2014 apps/api/src/admin/router.py:84", "shortDescription": {"text": "FastAPI POST `publish_task` without auth dependency \u2014 apps/api/src/admin/router.py:84"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9af87c7f21e69301", "name": "FastAPI PUT `upsert_flag` without auth dependency \u2014 apps/api/src/admin/router.py:185", "shortDescription": {"text": "FastAPI PUT `upsert_flag` without auth dependency \u2014 apps/api/src/admin/router.py:185"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-92be9953248d98c4", "name": "Dangling fetch: POST /auth/login (apps/admin/src/shared/api/endpoints.ts:30)", "shortDescription": {"text": "Dangling fetch: POST /auth/login (apps/admin/src/shared/api/endpoints.ts:30)"}, "fullDescription": {"text": "`apps/admin/src/shared/api/endpoints.ts:30` calls `POST /auth/login` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/login`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-216df8c3867d6e92", "name": "Dangling fetch: POST /auth/logout (apps/admin/src/shared/api/endpoints.ts:37)", "shortDescription": {"text": "Dangling fetch: POST /auth/logout (apps/admin/src/shared/api/endpoints.ts:37)"}, "fullDescription": {"text": "`apps/admin/src/shared/api/endpoints.ts:37` calls `POST /auth/logout` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/logout`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fb4e0882a8fc7722", "name": "Dangling fetch: POST /auth/refresh (apps/admin/src/shared/api/endpoints.ts:41)", "shortDescription": {"text": "Dangling fetch: POST /auth/refresh (apps/admin/src/shared/api/endpoints.ts:41)"}, "fullDescription": {"text": "`apps/admin/src/shared/api/endpoints.ts:41` calls `POST /auth/refresh` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/refresh`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8dd36ecd75d9d10b", "name": "Dangling fetch: GET /admin/metrics/overview (apps/admin/src/shared/api/endpoints.ts:59)", "shortDescription": {"text": "Dangling fetch: GET /admin/metrics/overview (apps/admin/src/shared/api/endpoints.ts:59)"}, "fullDescription": {"text": "`apps/admin/src/shared/api/endpoints.ts:59` calls `GET /admin/metrics/overview` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/admin/metrics/overview`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b6c07b382272bd80", "name": "Dangling fetch: POST /admin/tasks (apps/admin/src/shared/api/endpoints.ts:81)", "shortDescription": {"text": "Dangling fetch: POST /admin/tasks (apps/admin/src/shared/api/endpoints.ts:81)"}, "fullDescription": {"text": "`apps/admin/src/shared/api/endpoints.ts:81` calls `POST /admin/tasks` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/admin/tasks`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-89a20dfa3b918449", "name": "Dangling fetch: PATCH /admin/tasks/${id} (apps/admin/src/shared/api/endpoints.ts:84)", "shortDescription": {"text": "Dangling fetch: PATCH /admin/tasks/${id} (apps/admin/src/shared/api/endpoints.ts:84)"}, "fullDescription": {"text": "`apps/admin/src/shared/api/endpoints.ts:84` calls `PATCH /admin/tasks/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/admin/tasks/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d973af7d81b6947c", "name": "Dangling fetch: POST /admin/tasks/${id}/publish (apps/admin/src/shared/api/endpoints.ts:87)", "shortDescription": {"text": "Dangling fetch: POST /admin/tasks/${id}/publish (apps/admin/src/shared/api/endpoints.ts:87)"}, "fullDescription": {"text": "`apps/admin/src/shared/api/endpoints.ts:87` calls `POST /admin/tasks/${id}/publish` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/admin/tasks/<p>/publish`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-61f74b3857928d7e", "name": "Dangling fetch: POST /admin/tasks/${id}/reject (apps/admin/src/shared/api/endpoints.ts:90)", "shortDescription": {"text": "Dangling fetch: POST /admin/tasks/${id}/reject (apps/admin/src/shared/api/endpoints.ts:90)"}, "fullDescription": {"text": "`apps/admin/src/shared/api/endpoints.ts:90` calls `POST /admin/tasks/${id}/reject` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/admin/tasks/<p>/reject`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f13ba22b32581af8", "name": "Dangling fetch: POST /admin/users/${id}/ban (apps/admin/src/shared/api/endpoints.ts:110)", "shortDescription": {"text": "Dangling fetch: POST /admin/users/${id}/ban (apps/admin/src/shared/api/endpoints.ts:110)"}, "fullDescription": {"text": "`apps/admin/src/shared/api/endpoints.ts:110` calls `POST /admin/users/${id}/ban` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/admin/users/<p>/ban`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-831c9caea5cdcca9", "name": "Dangling fetch: POST /admin/users/${id}/unban (apps/admin/src/shared/api/endpoints.ts:113)", "shortDescription": {"text": "Dangling fetch: POST /admin/users/${id}/unban (apps/admin/src/shared/api/endpoints.ts:113)"}, "fullDescription": {"text": "`apps/admin/src/shared/api/endpoints.ts:113` calls `POST /admin/users/${id}/unban` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/admin/users/<p>/unban`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-712ad02e635cb916", "name": "Dangling fetch: POST /admin/users/${id}/grant-pro (apps/admin/src/shared/api/endpoints.ts:116)", "shortDescription": {"text": "Dangling fetch: POST /admin/users/${id}/grant-pro (apps/admin/src/shared/api/endpoints.ts:116)"}, "fullDescription": {"text": "`apps/admin/src/shared/api/endpoints.ts:116` calls `POST /admin/users/${id}/grant-pro` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/admin/users/<p>/grant-pro`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ae7b99cb5ef9f0b1", "name": "Dangling fetch: POST /admin/users/${id}/revoke-pro (apps/admin/src/shared/api/endpoints.ts:119)", "shortDescription": {"text": "Dangling fetch: POST /admin/users/${id}/revoke-pro (apps/admin/src/shared/api/endpoints.ts:119)"}, "fullDescription": {"text": "`apps/admin/src/shared/api/endpoints.ts:119` calls `POST /admin/users/${id}/revoke-pro` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/admin/users/<p>/revoke-pro`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-549c462228d358c0", "name": "Dangling fetch: GET /tournaments${qs} (apps/admin/src/shared/api/endpoints.ts:127)", "shortDescription": {"text": "Dangling fetch: GET /tournaments${qs} (apps/admin/src/shared/api/endpoints.ts:127)"}, "fullDescription": {"text": "`apps/admin/src/shared/api/endpoints.ts:127` calls `GET /tournaments${qs}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/tournaments/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0d8d6fe6452f3936", "name": "Dangling fetch: POST /admin/tournaments (apps/admin/src/shared/api/endpoints.ts:130)", "shortDescription": {"text": "Dangling fetch: POST /admin/tournaments (apps/admin/src/shared/api/endpoints.ts:130)"}, "fullDescription": {"text": "`apps/admin/src/shared/api/endpoints.ts:130` calls `POST /admin/tournaments` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/admin/tournaments`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-62891d986987d64c", "name": "Dangling fetch: PATCH /admin/tournaments/${id} (apps/admin/src/shared/api/endpoints.ts:133)", "shortDescription": {"text": "Dangling fetch: PATCH /admin/tournaments/${id} (apps/admin/src/shared/api/endpoints.ts:133)"}, "fullDescription": {"text": "`apps/admin/src/shared/api/endpoints.ts:133` calls `PATCH /admin/tournaments/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/admin/tournaments/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ea6f19da620a4a75", "name": "Dangling fetch: POST /admin/tournaments/${id}/grant-entry (apps/admin/src/shared/api/endpoints.ts:139)", "shortDescription": {"text": "Dangling fetch: POST /admin/tournaments/${id}/grant-entry (apps/admin/src/shared/api/endpoints.ts:139)"}, "fullDescription": {"text": "`apps/admin/src/shared/api/endpoints.ts:139` calls `POST /admin/tournaments/${id}/grant-entry` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/admin/tournaments/<p>/grant-entry`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4f868cf97d4a437e", "name": "Dangling fetch: GET /admin/feature-flags (apps/admin/src/shared/api/endpoints.ts:148)", "shortDescription": {"text": "Dangling fetch: GET /admin/feature-flags (apps/admin/src/shared/api/endpoints.ts:148)"}, "fullDescription": {"text": "`apps/admin/src/shared/api/endpoints.ts:148` calls `GET /admin/feature-flags` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/admin/feature-flags`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1b32673e1b0bb924", "name": "Dangling fetch: PUT /admin/feature-flags/${key} (apps/admin/src/shared/api/endpoints.ts:151)", "shortDescription": {"text": "Dangling fetch: PUT /admin/feature-flags/${key} (apps/admin/src/shared/api/endpoints.ts:151)"}, "fullDescription": {"text": "`apps/admin/src/shared/api/endpoints.ts:151` calls `PUT /admin/feature-flags/${key}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/admin/feature-flags/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1c9ec0da2f8b4c02", "name": "Dangling fetch: POST /auth/login (apps/admin/src/shared/api/client.test.ts:101)", "shortDescription": {"text": "Dangling fetch: POST /auth/login (apps/admin/src/shared/api/client.test.ts:101)"}, "fullDescription": {"text": "`apps/admin/src/shared/api/client.test.ts:101` calls `POST /auth/login` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/login`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2403a94da3a7334c", "name": "Dangling fetch: POST /auth/register (apps/web/src/shared/api/endpoints.ts:62)", "shortDescription": {"text": "Dangling fetch: POST /auth/register (apps/web/src/shared/api/endpoints.ts:62)"}, "fullDescription": {"text": "`apps/web/src/shared/api/endpoints.ts:62` calls `POST /auth/register` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/register`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a7e47a808d46365e", "name": "Dangling fetch: POST /auth/verify-email (apps/web/src/shared/api/endpoints.ts:69)", "shortDescription": {"text": "Dangling fetch: POST /auth/verify-email (apps/web/src/shared/api/endpoints.ts:69)"}, "fullDescription": {"text": "`apps/web/src/shared/api/endpoints.ts:69` calls `POST /auth/verify-email` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/verify-email`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3eea6fef73ac178c", "name": "Dangling fetch: POST /auth/verify-link (apps/web/src/shared/api/endpoints.ts:76)", "shortDescription": {"text": "Dangling fetch: POST /auth/verify-link (apps/web/src/shared/api/endpoints.ts:76)"}, "fullDescription": {"text": "`apps/web/src/shared/api/endpoints.ts:76` calls `POST /auth/verify-link` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/verify-link`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7635e7deb585328d", "name": "Dangling fetch: POST /auth/resend-code (apps/web/src/shared/api/endpoints.ts:83)", "shortDescription": {"text": "Dangling fetch: POST /auth/resend-code (apps/web/src/shared/api/endpoints.ts:83)"}, "fullDescription": {"text": "`apps/web/src/shared/api/endpoints.ts:83` calls `POST /auth/resend-code` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/resend-code`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4f044a6afbb4ee76", "name": "Dangling fetch: POST /auth/login (apps/web/src/shared/api/endpoints.ts:90)", "shortDescription": {"text": "Dangling fetch: POST /auth/login (apps/web/src/shared/api/endpoints.ts:90)"}, "fullDescription": {"text": "`apps/web/src/shared/api/endpoints.ts:90` calls `POST /auth/login` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/login`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-41ab54c54b9a5f8d", "name": "Dangling fetch: POST /auth/logout (apps/web/src/shared/api/endpoints.ts:97)", "shortDescription": {"text": "Dangling fetch: POST /auth/logout (apps/web/src/shared/api/endpoints.ts:97)"}, "fullDescription": {"text": "`apps/web/src/shared/api/endpoints.ts:97` calls `POST /auth/logout` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/logout`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cf9149e1caf5f3f8", "name": "Dangling fetch: POST /auth/refresh (apps/web/src/shared/api/endpoints.ts:101)", "shortDescription": {"text": "Dangling fetch: POST /auth/refresh (apps/web/src/shared/api/endpoints.ts:101)"}, "fullDescription": {"text": "`apps/web/src/shared/api/endpoints.ts:101` calls `POST /auth/refresh` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/refresh`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cf667210bb1abf1b", "name": "Dangling fetch: POST /auth/telegram (apps/web/src/shared/api/endpoints.ts:139)", "shortDescription": {"text": "Dangling fetch: POST /auth/telegram (apps/web/src/shared/api/endpoints.ts:139)"}, "fullDescription": {"text": "`apps/web/src/shared/api/endpoints.ts:139` calls `POST /auth/telegram` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/telegram`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3a89d7650b6ea577", "name": "Dangling fetch: POST /auth/telegram/register (apps/web/src/shared/api/endpoints.ts:147)", "shortDescription": {"text": "Dangling fetch: POST /auth/telegram/register (apps/web/src/shared/api/endpoints.ts:147)"}, "fullDescription": {"text": "`apps/web/src/shared/api/endpoints.ts:147` calls `POST /auth/telegram/register` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/telegram/register`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-abb8d9b8b0a59597", "name": "Dangling fetch: GET /me/duels${qs} (apps/web/src/shared/api/endpoints.ts:180)", "shortDescription": {"text": "Dangling fetch: GET /me/duels${qs} (apps/web/src/shared/api/endpoints.ts:180)"}, "fullDescription": {"text": "`apps/web/src/shared/api/endpoints.ts:180` calls `GET /me/duels${qs}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/me/duels/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-62bbe45648465953", "name": "Dangling fetch: GET /me/stats${qs} (apps/web/src/shared/api/endpoints.ts:188)", "shortDescription": {"text": "Dangling fetch: GET /me/stats${qs} (apps/web/src/shared/api/endpoints.ts:188)"}, "fullDescription": {"text": "`apps/web/src/shared/api/endpoints.ts:188` calls `GET /me/stats${qs}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/me/stats/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dbde441f0fc0a3a8", "name": "Dangling fetch: GET /daily/leaderboard${qs} (apps/web/src/shared/api/endpoints.ts:217)", "shortDescription": {"text": "Dangling fetch: GET /daily/leaderboard${qs} (apps/web/src/shared/api/endpoints.ts:217)"}, "fullDescription": {"text": "`apps/web/src/shared/api/endpoints.ts:217` calls `GET /daily/leaderboard${qs}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/daily/leaderboard/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-98905545daf4383d", "name": "Dangling fetch: POST /ai/review/${duelId} (apps/web/src/shared/api/endpoints.ts:227)", "shortDescription": {"text": "Dangling fetch: POST /ai/review/${duelId} (apps/web/src/shared/api/endpoints.ts:227)"}, "fullDescription": {"text": "`apps/web/src/shared/api/endpoints.ts:227` calls `POST /ai/review/${duelId}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/ai/review/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7912daca0a0342be", "name": "Dangling fetch: GET /ai/review/${duelId} (apps/web/src/shared/api/endpoints.ts:230)", "shortDescription": {"text": "Dangling fetch: GET /ai/review/${duelId} (apps/web/src/shared/api/endpoints.ts:230)"}, "fullDescription": {"text": "`apps/web/src/shared/api/endpoints.ts:230` calls `GET /ai/review/${duelId}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/ai/review/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-af9f7c59d92dc8b6", "name": "Dangling fetch: GET /tournaments${qs} (apps/web/src/shared/api/endpoints.ts:291)", "shortDescription": {"text": "Dangling fetch: GET /tournaments${qs} (apps/web/src/shared/api/endpoints.ts:291)"}, "fullDescription": {"text": "`apps/web/src/shared/api/endpoints.ts:291` calls `GET /tournaments${qs}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/tournaments/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a071ed9184e86057", "name": "Dangling fetch: GET /tournaments/${id} (apps/web/src/shared/api/endpoints.ts:295)", "shortDescription": {"text": "Dangling fetch: GET /tournaments/${id} (apps/web/src/shared/api/endpoints.ts:295)"}, "fullDescription": {"text": "`apps/web/src/shared/api/endpoints.ts:295` calls `GET /tournaments/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/tournaments/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8f9117018d94fb4b", "name": "Dangling fetch: POST /tournaments/${id}/enter (apps/web/src/shared/api/endpoints.ts:299)", "shortDescription": {"text": "Dangling fetch: POST /tournaments/${id}/enter (apps/web/src/shared/api/endpoints.ts:299)"}, "fullDescription": {"text": "`apps/web/src/shared/api/endpoints.ts:299` calls `POST /tournaments/${id}/enter` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/tournaments/<p>/enter`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7f3fca0e761bf758", "name": "Dangling fetch: GET /tournaments/${id}/tasks (apps/web/src/shared/api/endpoints.ts:303)", "shortDescription": {"text": "Dangling fetch: GET /tournaments/${id}/tasks (apps/web/src/shared/api/endpoints.ts:303)"}, "fullDescription": {"text": "`apps/web/src/shared/api/endpoints.ts:303` calls `GET /tournaments/${id}/tasks` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/tournaments/<p>/tasks`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5cd1a2e70d58717c", "name": "Dangling fetch: POST /tournaments/${id}/answer (apps/web/src/shared/api/endpoints.ts:306)", "shortDescription": {"text": "Dangling fetch: POST /tournaments/${id}/answer (apps/web/src/shared/api/endpoints.ts:306)"}, "fullDescription": {"text": "`apps/web/src/shared/api/endpoints.ts:306` calls `POST /tournaments/${id}/answer` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/tournaments/<p>/answer`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e62f5a59acb1c5f0", "name": "Dangling fetch: GET /a (apps/web/src/shared/api/client.test.ts:118)", "shortDescription": {"text": "Dangling fetch: GET /a (apps/web/src/shared/api/client.test.ts:118)"}, "fullDescription": {"text": "`apps/web/src/shared/api/client.test.ts:118` calls `GET /a` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/a`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-702d298e60b7b9fc", "name": "Dangling fetch: GET /b (apps/web/src/shared/api/client.test.ts:119)", "shortDescription": {"text": "Dangling fetch: GET /b (apps/web/src/shared/api/client.test.ts:119)"}, "fullDescription": {"text": "`apps/web/src/shared/api/client.test.ts:119` calls `GET /b` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/b`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7678bea2abf4c546", "name": "Dangling fetch: POST /auth/login (apps/web/src/shared/api/client.test.ts:156)", "shortDescription": {"text": "Dangling fetch: POST /auth/login (apps/web/src/shared/api/client.test.ts:156)"}, "fullDescription": {"text": "`apps/web/src/shared/api/client.test.ts:156` calls `POST /auth/login` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/login`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2b3f3010d5f7ad78", "name": "Unused endpoint: GET /daily/leaderboard", "shortDescription": {"text": "Unused endpoint: GET /daily/leaderboard"}, "fullDescription": {"text": "`apps/api/src/daily/router.py` declares `GET /daily/leaderboard` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d7b32f79e0563454", "name": "Unused endpoint: GET /me/duels", "shortDescription": {"text": "Unused endpoint: GET /me/duels"}, "fullDescription": {"text": "`apps/api/src/users/router.py` declares `GET /me/duels` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4c4bac869e207a82", "name": "Unused endpoint: GET /me/stats", "shortDescription": {"text": "Unused endpoint: GET /me/stats"}, "fullDescription": {"text": "`apps/api/src/users/router.py` declares `GET /me/stats` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5ecaa41bc162e95c", "name": "Unused endpoint: POST /me/avatar/presign", "shortDescription": {"text": "Unused endpoint: POST /me/avatar/presign"}, "fullDescription": {"text": "`apps/api/src/users/router.py` declares `POST /me/avatar/presign` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c0a288688ee2e389", "name": "Unused endpoint: POST /me/avatar/confirm", "shortDescription": {"text": "Unused endpoint: POST /me/avatar/confirm"}, "fullDescription": {"text": "`apps/api/src/users/router.py` declares `POST /me/avatar/confirm` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-304b6f2b403d93f7", "name": "Unused endpoint: POST /register", "shortDescription": {"text": "Unused endpoint: POST /register"}, "fullDescription": {"text": "`apps/api/src/auth/router.py` declares `POST /register` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a2ad8a606e157795", "name": "Unused endpoint: POST /telegram", "shortDescription": {"text": "Unused endpoint: POST /telegram"}, "fullDescription": {"text": "`apps/api/src/auth/router.py` declares `POST /telegram` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-752a1b7edfb04e26", "name": "Unused endpoint: POST /telegram/register", "shortDescription": {"text": "Unused endpoint: POST /telegram/register"}, "fullDescription": {"text": "`apps/api/src/auth/router.py` declares `POST /telegram/register` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-618721b912bad1c2", "name": "Unused endpoint: POST /login", "shortDescription": {"text": "Unused endpoint: POST /login"}, "fullDescription": {"text": "`apps/api/src/auth/router.py` declares `POST /login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0c3bb6af93b4422a", "name": "Unused endpoint: POST /verify-email", "shortDescription": {"text": "Unused endpoint: POST /verify-email"}, "fullDescription": {"text": "`apps/api/src/auth/router.py` declares `POST /verify-email` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8252b449a87e376b", "name": "Unused endpoint: POST /verify-link", "shortDescription": {"text": "Unused endpoint: POST /verify-link"}, "fullDescription": {"text": "`apps/api/src/auth/router.py` declares `POST /verify-link` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b2d2f8473e8aab1d", "name": "Unused endpoint: POST /resend-code", "shortDescription": {"text": "Unused endpoint: POST /resend-code"}, "fullDescription": {"text": "`apps/api/src/auth/router.py` declares `POST /resend-code` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7ce17d6b092a81ca", "name": "Unused endpoint: POST /refresh", "shortDescription": {"text": "Unused endpoint: POST /refresh"}, "fullDescription": {"text": "`apps/api/src/auth/router.py` declares `POST /refresh` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-99fc36db98c134ce", "name": "Unused endpoint: POST /logout", "shortDescription": {"text": "Unused endpoint: POST /logout"}, "fullDescription": {"text": "`apps/api/src/auth/router.py` declares `POST /logout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a70d05575558dbd8", "name": "Unused endpoint: GET /share/{duel_id}", "shortDescription": {"text": "Unused endpoint: GET /share/{duel_id}"}, "fullDescription": {"text": "`apps/api/src/duels/router.py` declares `GET /share/{duel_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9d63e8e3f46a67b7", "name": "Unused endpoint: GET /widget/{username}.svg", "shortDescription": {"text": "Unused endpoint: GET /widget/{username}.svg"}, "fullDescription": {"text": "`apps/api/src/telegram/router.py` declares `GET /widget/{username}.svg` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`apps/api/src/tournaments/router.py` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-78c5306e1e421700", "name": "Unused endpoint: GET /{tournament_id}", "shortDescription": {"text": "Unused endpoint: GET /{tournament_id}"}, "fullDescription": {"text": "`apps/api/src/tournaments/router.py` declares `GET /{tournament_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-58607bfbfbca79df", "name": "Unused endpoint: POST /{tournament_id}/enter", "shortDescription": {"text": "Unused endpoint: POST /{tournament_id}/enter"}, "fullDescription": {"text": "`apps/api/src/tournaments/router.py` declares `POST /{tournament_id}/enter` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-602b09b452a6cd8a", "name": "Unused endpoint: GET /{tournament_id}/tasks", "shortDescription": {"text": "Unused endpoint: GET /{tournament_id}/tasks"}, "fullDescription": {"text": "`apps/api/src/tournaments/router.py` declares `GET /{tournament_id}/tasks` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-002ae51c53b1c766", "name": "Unused endpoint: POST /{tournament_id}/answer", "shortDescription": {"text": "Unused endpoint: POST /{tournament_id}/answer"}, "fullDescription": {"text": "`apps/api/src/tournaments/router.py` declares `POST /{tournament_id}/answer` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a009b1a56794f45", "name": "Unused endpoint: POST /", "shortDescription": {"text": "Unused endpoint: POST /"}, "fullDescription": {"text": "`apps/api/src/tournaments/admin_router.py` declares `POST /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7320d21a57de9181", "name": "Unused endpoint: PATCH /{tournament_id}", "shortDescription": {"text": "Unused endpoint: PATCH /{tournament_id}"}, "fullDescription": {"text": "`apps/api/src/tournaments/admin_router.py` declares `PATCH /{tournament_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-11045c40399183e3", "name": "Unused endpoint: POST /{tournament_id}/grant-entry", "shortDescription": {"text": "Unused endpoint: POST /{tournament_id}/grant-entry"}, "fullDescription": {"text": "`apps/api/src/tournaments/admin_router.py` declares `POST /{tournament_id}/grant-entry` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-03a557375ab0209f", "name": "Unused endpoint: POST /{tournament_id}/recompute-places", "shortDescription": {"text": "Unused endpoint: POST /{tournament_id}/recompute-places"}, "fullDescription": {"text": "`apps/api/src/tournaments/admin_router.py` declares `POST /{tournament_id}/recompute-places` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0aa218b4c0ac76bd", "name": "Unused endpoint: POST /{duel_id}", "shortDescription": {"text": "Unused endpoint: POST /{duel_id}"}, "fullDescription": {"text": "`apps/api/src/ai_review/router.py` declares `POST /{duel_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0f92f05ebeb0696d", "name": "Unused endpoint: GET /{duel_id}", "shortDescription": {"text": "Unused endpoint: GET /{duel_id}"}, "fullDescription": {"text": "`apps/api/src/ai_review/router.py` declares `GET /{duel_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f47fa02fb2e8297c", "name": "Unused endpoint: POST /duels", "shortDescription": {"text": "Unused endpoint: POST /duels"}, "fullDescription": {"text": "`apps/api/src/internal_api/router.py` declares `POST /duels` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bfe0f04415c47592", "name": "Unused endpoint: POST /duels/{duel_id}/finish", "shortDescription": {"text": "Unused endpoint: POST /duels/{duel_id}/finish"}, "fullDescription": {"text": "`apps/api/src/internal_api/router.py` declares `POST /duels/{duel_id}/finish` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-46d76cb7e506f379", "name": "Unused endpoint: GET /duels/{duel_id}/card", "shortDescription": {"text": "Unused endpoint: GET /duels/{duel_id}/card"}, "fullDescription": {"text": "`apps/api/src/internal_api/router.py` declares `GET /duels/{duel_id}/card` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c98451757ac32786", "name": "Unused endpoint: POST /duels/{duel_id}/share-card", "shortDescription": {"text": "Unused endpoint: POST /duels/{duel_id}/share-card"}, "fullDescription": {"text": "`apps/api/src/internal_api/router.py` declares `POST /duels/{duel_id}/share-card` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a59999b270f2cbbd", "name": "Unused endpoint: GET /duels/{duel_id}/review-data", "shortDescription": {"text": "Unused endpoint: GET /duels/{duel_id}/review-data"}, "fullDescription": {"text": "`apps/api/src/internal_api/router.py` declares `GET /duels/{duel_id}/review-data` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e3e042160aa8d3e8", "name": "Unused endpoint: POST /ai-reviews/{duel_id}/{user_id}", "shortDescription": {"text": "Unused endpoint: POST /ai-reviews/{duel_id}/{user_id}"}, "fullDescription": {"text": "`apps/api/src/internal_api/router.py` declares `POST /ai-reviews/{duel_id}/{user_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eb6edd531adbf537", "name": "Unused endpoint: POST /telegram/redeem", "shortDescription": {"text": "Unused endpoint: POST /telegram/redeem"}, "fullDescription": {"text": "`apps/api/src/internal_api/router.py` declares `POST /telegram/redeem` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8111d9b5bfb96a1e", "name": "Unused endpoint: GET /telegram/user/{telegram_user_id}", "shortDescription": {"text": "Unused endpoint: GET /telegram/user/{telegram_user_id}"}, "fullDescription": {"text": "`apps/api/src/internal_api/router.py` declares `GET /telegram/user/{telegram_user_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6ef3debbd64d5af6", "name": "Unused endpoint: GET /telegram/by-user/{user_id}", "shortDescription": {"text": "Unused endpoint: GET /telegram/by-user/{user_id}"}, "fullDescription": {"text": "`apps/api/src/internal_api/router.py` declares `GET /telegram/by-user/{user_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-add6dcb6007baef6", "name": "Unused endpoint: GET /leaderboard", "shortDescription": {"text": "Unused endpoint: GET /leaderboard"}, "fullDescription": {"text": "`apps/api/src/leaderboard/router.py` declares `GET /leaderboard` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9edf4d5d41f3e477", "name": "Unused endpoint: GET /leaderboard/me", "shortDescription": {"text": "Unused endpoint: GET /leaderboard/me"}, "fullDescription": {"text": "`apps/api/src/leaderboard/router.py` declares `GET /leaderboard/me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd0e06afbaab19b3", "name": "Unused endpoint: GET /tasks", "shortDescription": {"text": "Unused endpoint: GET /tasks"}, "fullDescription": {"text": "`apps/api/src/admin/router.py` declares `GET /tasks` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8b3eb3012ac06c04", "name": "Unused endpoint: POST /tasks", "shortDescription": {"text": "Unused endpoint: POST /tasks"}, "fullDescription": {"text": "`apps/api/src/admin/router.py` declares `POST /tasks` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eb67e5af706d0955", "name": "Unused endpoint: PATCH /tasks/{task_id}", "shortDescription": {"text": "Unused endpoint: PATCH /tasks/{task_id}"}, "fullDescription": {"text": "`apps/api/src/admin/router.py` declares `PATCH /tasks/{task_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1af61b5a0520bdf8", "name": "Unused endpoint: POST /tasks/{task_id}/publish", "shortDescription": {"text": "Unused endpoint: POST /tasks/{task_id}/publish"}, "fullDescription": {"text": "`apps/api/src/admin/router.py` declares `POST /tasks/{task_id}/publish` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0fc10d996ee27a8c", "name": "Unused endpoint: POST /tasks/{task_id}/reject", "shortDescription": {"text": "Unused endpoint: POST /tasks/{task_id}/reject"}, "fullDescription": {"text": "`apps/api/src/admin/router.py` declares `POST /tasks/{task_id}/reject` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-841e50bf821e4158", "name": "Unused endpoint: GET /users", "shortDescription": {"text": "Unused endpoint: GET /users"}, "fullDescription": {"text": "`apps/api/src/admin/router.py` declares `GET /users` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5f0f21526cc5fc9a", "name": "Unused endpoint: POST /users/{user_id}/ban", "shortDescription": {"text": "Unused endpoint: POST /users/{user_id}/ban"}, "fullDescription": {"text": "`apps/api/src/admin/router.py` declares `POST /users/{user_id}/ban` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aba2a22a8295c548", "name": "Unused endpoint: POST /users/{user_id}/unban", "shortDescription": {"text": "Unused endpoint: POST /users/{user_id}/unban"}, "fullDescription": {"text": "`apps/api/src/admin/router.py` declares `POST /users/{user_id}/unban` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2fa0850153b99685", "name": "Unused endpoint: POST /users/{user_id}/grant-pro", "shortDescription": {"text": "Unused endpoint: POST /users/{user_id}/grant-pro"}, "fullDescription": {"text": "`apps/api/src/admin/router.py` declares `POST /users/{user_id}/grant-pro` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5940160138f3b762", "name": "Unused endpoint: POST /users/{user_id}/revoke-pro", "shortDescription": {"text": "Unused endpoint: POST /users/{user_id}/revoke-pro"}, "fullDescription": {"text": "`apps/api/src/admin/router.py` declares `POST /users/{user_id}/revoke-pro` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-88c83fc10236fbb5", "name": "Unused endpoint: GET /feature-flags", "shortDescription": {"text": "Unused endpoint: GET /feature-flags"}, "fullDescription": {"text": "`apps/api/src/admin/router.py` declares `GET /feature-flags` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c7089f0c41314aff", "name": "Unused endpoint: PUT /feature-flags/{key}", "shortDescription": {"text": "Unused endpoint: PUT /feature-flags/{key}"}, "fullDescription": {"text": "`apps/api/src/admin/router.py` declares `PUT /feature-flags/{key}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/18151"}, "properties": {"repository": "Rifferd/diffduel", "repoUrl": "https://github.com/Rifferd/diffduel", "branch": "main"}, "results": [{"ruleId": "scanner-4682a15d6f7d3f96", "level": "note", "message": {"text": "Possibly dead Python function: weekly_key_for_date"}, "properties": {"repobilityId": "934d3507c31ab575", "scanner": "scanner-primary", "fingerprint": "4682a15d6f7d3f96", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/leaderboard/keys.py:27"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-157b836c9ef8f430", "level": "note", "message": {"text": "Possibly dead Python function: create_checkout"}, "properties": {"repobilityId": "3e7aae7936790356", "scanner": "scanner-primary", "fingerprint": "157b836c9ef8f430", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/billing/providers/base.py:58"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fbc368a770f97c25", "level": "note", "message": {"text": "Possibly dead Python function: create_checkout"}, "properties": {"repobilityId": "3e7aae7936790356", "scanner": "scanner-primary", "fingerprint": "fbc368a770f97c25", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/billing/providers/manual.py:20"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9e236910e66d0e68", "level": "note", "message": {"text": "Possibly dead Python function: needs_rehash"}, "properties": {"repobilityId": "24538a6be341ceac", "scanner": "scanner-primary", "fingerprint": "9e236910e66d0e68", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/core/security.py:44"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9f43bf4755f5296c", "level": "note", "message": {"text": "Possibly dead Python function: to_payload"}, "properties": {"repobilityId": "322ffd4313ad6b63", "scanner": "scanner-primary", "fingerprint": "9f43bf4755f5296c", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/core/errors.py:32"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cc1b5c3a6a979e9d", "level": "note", "message": {"text": "Possibly dead Python function: request_stop"}, "properties": {"repobilityId": "b263d74761677933", "scanner": "scanner-primary", "fingerprint": "cc1b5c3a6a979e9d", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/workers/src/workers/ai_review.py:235"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-922fec377fec51b4", "level": "note", "message": {"text": "Possibly dead Python function: send_message"}, "properties": {"repobilityId": "1249251570e4ca4d", "scanner": "scanner-primary", "fingerprint": "922fec377fec51b4", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/workers/src/workers/telegram_client.py:53"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8b7e6cb937eedd51", "level": "note", "message": {"text": "Possibly dead Python function: request_stop"}, "properties": {"repobilityId": "b263d74761677933", "scanner": "scanner-primary", "fingerprint": "8b7e6cb937eedd51", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/workers/src/workers/image_gen.py:145"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8f06837d063e207f", "level": "note", "message": {"text": "Possibly dead Python function: telegram_by_user"}, "properties": {"repobilityId": "5db21aff53d5e37a", "scanner": "scanner-primary", "fingerprint": "8f06837d063e207f", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/workers/src/workers/internal_client.py:176"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2d52e39a519b833d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/web/src/pages/LandingPage.vue:100"}, "properties": {"repobilityId": "d9a505e49a2f708e", "scanner": "scanner-primary", "fingerprint": "2d52e39a519b833d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f9334d8c10e3efa9", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "properties": {"repobilityId": "0086a3706580d431", "scanner": "scanner-primary", "fingerprint": "f9334d8c10e3efa9", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/bot/Dockerfile"}, "region": {"startLine": 4}}}]}, {"ruleId": "scanner-f9334d8c10e3efa9", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "properties": {"repobilityId": "f02a92f4d0d9a1a9", "scanner": "scanner-primary", "fingerprint": "f9334d8c10e3efa9", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/bot/Dockerfile"}, "region": {"startLine": 20}}}]}, {"ruleId": "scanner-c36b30587c620ebd", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "properties": {"repobilityId": "94a9bc2d8dada0b5", "scanner": "scanner-primary", "fingerprint": "c36b30587c620ebd", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/Dockerfile"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-c36b30587c620ebd", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "properties": {"repobilityId": "aafc13fc5083b4bb", "scanner": "scanner-primary", "fingerprint": "c36b30587c620ebd", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/Dockerfile"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-4710e5c5088681d3", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "properties": {"repobilityId": "8120aa64d4b9eab7", "scanner": "scanner-primary", "fingerprint": "4710e5c5088681d3", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/workers/Dockerfile"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-4710e5c5088681d3", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "properties": {"repobilityId": "a00e6cb925b694a4", "scanner": "scanner-primary", "fingerprint": "4710e5c5088681d3", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/workers/Dockerfile"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-4654a46ae713f629", "level": "warning", "message": {"text": "Dockerfile runs as root: apps/admin/Dockerfile"}, "properties": {"repobilityId": "cae29b04ac99f84e", "scanner": "scanner-primary", "fingerprint": "4654a46ae713f629", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-da606e2888be7fe1", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine"}, "properties": {"repobilityId": "f06b30282ef4e044", "scanner": "scanner-primary", "fingerprint": "da606e2888be7fe1", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/admin/Dockerfile"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-9b03f5a7efceda59", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: nginx:1.27-alpine"}, "properties": {"repobilityId": "feeba4dbe10d489f", "scanner": "scanner-primary", "fingerprint": "9b03f5a7efceda59", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/admin/Dockerfile"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-7673561931a5dd33", "level": "warning", "message": {"text": "Dockerfile runs as root: apps/web/Dockerfile"}, "properties": {"repobilityId": "d68d7937b96d047d", "scanner": "scanner-primary", "fingerprint": "7673561931a5dd33", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-744c132692cc6e12", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine"}, "properties": {"repobilityId": "59324bdad4e736d3", "scanner": "scanner-primary", "fingerprint": "744c132692cc6e12", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/Dockerfile"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-c59f100803446097", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: nginx:1.27-alpine"}, "properties": {"repobilityId": "412409b989c36c13", "scanner": "scanner-primary", "fingerprint": "c59f100803446097", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/Dockerfile"}, "region": {"startLine": 29}}}]}, {"ruleId": "scanner-c531edbaf4eef9bc", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine"}, "properties": {"repobilityId": "1b4fb6bc5bc03d0d", "scanner": "scanner-primary", "fingerprint": "c531edbaf4eef9bc", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/realtime/Dockerfile"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-c531edbaf4eef9bc", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine"}, "properties": {"repobilityId": "af8870138092e936", "scanner": "scanner-primary", "fingerprint": "c531edbaf4eef9bc", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/realtime/Dockerfile"}, "region": {"startLine": 14}}}]}, {"ruleId": "scanner-c531edbaf4eef9bc", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine"}, "properties": {"repobilityId": "6bb0973a7dc258c1", "scanner": "scanner-primary", "fingerprint": "c531edbaf4eef9bc", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/realtime/Dockerfile"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-46d83bc51ab073bf", "level": "warning", "message": {"text": "Insecure pattern 'vue_v_html' in apps/web/src/pages/AiReviewPage.vue:60"}, "properties": {"repobilityId": "2bd6686fb40b1a42", "scanner": "scanner-primary", "fingerprint": "46d83bc51ab073bf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "vue_v_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/src/pages/AiReviewPage.vue"}, "region": {"startLine": 60}}}]}, {"ruleId": "scanner-2f3625f97e9f441a", "level": "error", "message": {"text": "Possible secret in infra/load/k6/lib/common.js"}, "properties": {"repobilityId": "255b7fef6753ff8b", "scanner": "scanner-primary", "fingerprint": "2f3625f97e9f441a", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "infra/load/k6/lib/common.js"}, "region": {"startLine": 69}}}]}, {"ruleId": "scanner-cef6ff64d25cde41", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "fb881731a35f5f09", "scanner": "scanner-primary", "fingerprint": "cef6ff64d25cde41", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/workers-ci.yml"}, "region": {"startLine": 29}}}]}, {"ruleId": "scanner-cef6ff64d25cde41", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "cc5ced3d4366b96c", "scanner": "scanner-primary", "fingerprint": "cef6ff64d25cde41", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/workers-ci.yml"}, "region": {"startLine": 32}}}]}, {"ruleId": "scanner-28c4a04bd807da0c", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "5206950cf3c3cb8f", "scanner": "scanner-primary", "fingerprint": "28c4a04bd807da0c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy.yml"}, "region": {"startLine": 51}}}]}, {"ruleId": "scanner-28c4a04bd807da0c", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "cdd488c07b90bf4b", "scanner": "scanner-primary", "fingerprint": "28c4a04bd807da0c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy.yml"}, "region": {"startLine": 58}}}]}, {"ruleId": "scanner-28c4a04bd807da0c", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "1e168e1594cfcd53", "scanner": "scanner-primary", "fingerprint": "28c4a04bd807da0c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy.yml"}, "region": {"startLine": 74}}}]}, {"ruleId": "scanner-ad6701f0a8405e22", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "8384c23520d55657", "scanner": "scanner-primary", "fingerprint": "ad6701f0a8405e22", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e6ad6b8f753b7daa", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "b10fc60aebcaf3a5", "scanner": "scanner-primary", "fingerprint": "e6ad6b8f753b7daa", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/realtime-ci.yml"}, "region": {"startLine": 40}}}]}, {"ruleId": "scanner-e6ad6b8f753b7daa", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "de74fe727a3e8051", "scanner": "scanner-primary", "fingerprint": "e6ad6b8f753b7daa", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/realtime-ci.yml"}, "region": {"startLine": 44}}}]}, {"ruleId": "scanner-e6ad6b8f753b7daa", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "a560debb7cf87bde", "scanner": "scanner-primary", "fingerprint": "e6ad6b8f753b7daa", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/realtime-ci.yml"}, "region": {"startLine": 47}}}]}, {"ruleId": "scanner-2b3d632df2d10715", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "e570f0e15ec59835", "scanner": "scanner-primary", "fingerprint": "2b3d632df2d10715", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/api-ci.yml"}, "region": {"startLine": 62}}}]}, {"ruleId": "scanner-2b3d632df2d10715", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "cd86dc495c882105", "scanner": "scanner-primary", "fingerprint": "2b3d632df2d10715", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/api-ci.yml"}, "region": {"startLine": 65}}}]}, {"ruleId": "scanner-844171341e6bbce3", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "5697331f86341535", "scanner": "scanner-primary", "fingerprint": "844171341e6bbce3", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/bot-ci.yml"}, "region": {"startLine": 27}}}]}, {"ruleId": "scanner-844171341e6bbce3", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ba3dcc2cf9c4da06", "scanner": "scanner-primary", "fingerprint": "844171341e6bbce3", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/bot-ci.yml"}, "region": {"startLine": 29}}}]}, {"ruleId": "scanner-dfd9db5038437f79", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "4722bae7a62d626d", "scanner": "scanner-primary", "fingerprint": "dfd9db5038437f79", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/web-ci.yml"}, "region": {"startLine": 33}}}]}, {"ruleId": "scanner-dfd9db5038437f79", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "0e6d715877977e88", "scanner": "scanner-primary", "fingerprint": "dfd9db5038437f79", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/web-ci.yml"}, "region": {"startLine": 37}}}]}, {"ruleId": "scanner-dfd9db5038437f79", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "93c9c105a35be365", "scanner": "scanner-primary", "fingerprint": "dfd9db5038437f79", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/web-ci.yml"}, "region": {"startLine": 40}}}]}, {"ruleId": "scanner-4c4c3396af24e8b4", "level": "note", "message": {"text": "Very large file: packages/contracts/src/api-types.ts (3145 lines)"}, "properties": {"repobilityId": "16ca9844930c252f", "scanner": "scanner-primary", "fingerprint": "4c4c3396af24e8b4", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-5c30f715681a4005", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: apps/admin/package.json"}, "properties": {"repobilityId": "17d56c8f05bdd359", "scanner": "scanner-primary", "fingerprint": "5c30f715681a4005", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/admin/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4a9eb7dc7c6e3880", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: apps/web/package.json"}, "properties": {"repobilityId": "6c1704bf24cf19ac", "scanner": "scanner-primary", "fingerprint": "4a9eb7dc7c6e3880", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-54058893046102be", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: apps/realtime/package.json"}, "properties": {"repobilityId": "2c557bc4899a8730", "scanner": "scanner-primary", "fingerprint": "54058893046102be", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/realtime/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f85d8f0719e22fa8", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/contracts/package.json"}, "properties": {"repobilityId": "9533b27beaa7d171", "scanner": "scanner-primary", "fingerprint": "f85d8f0719e22fa8", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/contracts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "ccfa9450f193d971", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "dc4095836c70a050", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "68780f68429642be", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "ab208f887a87c66a", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-998d9b0238d4e7ed", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/admin/src/shared/api/client.ts:99"}, "properties": {"repobilityId": "7aac95e9c9998442", "scanner": "scanner-primary", "fingerprint": "998d9b0238d4e7ed", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-9eaa144c9e34b14a", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/src/shared/api/client.ts:99"}, "properties": {"repobilityId": "0696e6203d57df33", "scanner": "scanner-primary", "fingerprint": "9eaa144c9e34b14a", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-89c1b2779e5c1888", "level": "none", "message": {"text": "Commented-code block (6 lines) in infra/load/k6/answers_load.js:3"}, "properties": {"repobilityId": "676c42ecdea34a87", "scanner": "scanner-primary", "fingerprint": "89c1b2779e5c1888", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-48529aa950fd7634", "level": "none", "message": {"text": "Commented-code block (6 lines) in infra/load/k6/duel_ws.js:14"}, "properties": {"repobilityId": "5b4632385001432d", "scanner": "scanner-primary", "fingerprint": "48529aa950fd7634", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-460e379735342e27", "level": "none", "message": {"text": "Commented-code block (5 lines) in infra/load/k6/lib/socketio.js:7"}, "properties": {"repobilityId": "05051a8c552c6e2a", "scanner": "scanner-primary", "fingerprint": "460e379735342e27", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-440101b977fbefa5", "level": "none", "message": {"text": "Commented-code block (5 lines) in infra/load/k6/lib/common.js:25"}, "properties": {"repobilityId": "54cc34238a626f0d", "scanner": "scanner-primary", "fingerprint": "440101b977fbefa5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2eafc3188c36bb02", "level": "none", "message": {"text": "3 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "bd934ba112b02ffa", "scanner": "scanner-primary", "fingerprint": "2eafc3188c36bb02", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "83c928aba3422304", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "dc412fcecc039711", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "392535e57c161683", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "1325b7ee5860cc0f", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "f853732bad089945", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "424bad0e6da9de14", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "dcbdf4e2fef9b1f5", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "5225dee7fe70937c", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "3ad378d7698bca94", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "439d7948ffde8d6b", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-947c8bde526c8aff", "level": "error", "message": {"text": "FastAPI POST `telegram_auth` without auth dependency \u2014 apps/api/src/auth/router.py:77"}, "properties": {"repobilityId": "54e309f0d97d1293", "scanner": "scanner-primary", "fingerprint": "947c8bde526c8aff", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/auth/router.py"}, "region": {"startLine": 77}}}]}, {"ruleId": "scanner-f60a3a90a917e948", "level": "error", "message": {"text": "FastAPI POST `telegram_register` without auth dependency \u2014 apps/api/src/auth/router.py:106"}, "properties": {"repobilityId": "97877f60103a30e6", "scanner": "scanner-primary", "fingerprint": "f60a3a90a917e948", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/auth/router.py"}, "region": {"startLine": 106}}}]}, {"ruleId": "scanner-91e74783ee88c413", "level": "error", "message": {"text": "FastAPI POST `verify_email` without auth dependency \u2014 apps/api/src/auth/router.py:148"}, "properties": {"repobilityId": "210f870db31523a2", "scanner": "scanner-primary", "fingerprint": "91e74783ee88c413", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/auth/router.py"}, "region": {"startLine": 148}}}]}, {"ruleId": "scanner-fc3ad3d8f4e8ced6", "level": "error", "message": {"text": "FastAPI POST `verify_link` without auth dependency \u2014 apps/api/src/auth/router.py:162"}, "properties": {"repobilityId": "2f075084d2251ab5", "scanner": "scanner-primary", "fingerprint": "fc3ad3d8f4e8ced6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/auth/router.py"}, "region": {"startLine": 162}}}]}, {"ruleId": "scanner-e894fb840e01c075", "level": "error", "message": {"text": "FastAPI POST `resend_code` without auth dependency \u2014 apps/api/src/auth/router.py:187"}, "properties": {"repobilityId": "94314c5fa1d9f111", "scanner": "scanner-primary", "fingerprint": "e894fb840e01c075", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/auth/router.py"}, "region": {"startLine": 187}}}]}, {"ruleId": "scanner-f7b485d302654b56", "level": "error", "message": {"text": "FastAPI POST `refresh` without auth dependency \u2014 apps/api/src/auth/router.py:202"}, "properties": {"repobilityId": "576dfc9a416786e4", "scanner": "scanner-primary", "fingerprint": "f7b485d302654b56", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/auth/router.py"}, "region": {"startLine": 202}}}]}, {"ruleId": "scanner-f4bc3cbd7fa2da9d", "level": "error", "message": {"text": "FastAPI POST `create_tournament` without auth dependency \u2014 apps/api/src/tournaments/admin_router.py:35"}, "properties": {"repobilityId": "f0a7e0076282a906", "scanner": "scanner-primary", "fingerprint": "f4bc3cbd7fa2da9d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/tournaments/admin_router.py"}, "region": {"startLine": 35}}}]}, {"ruleId": "scanner-57b4628348bfd262", "level": "error", "message": {"text": "FastAPI PATCH `update_tournament` without auth dependency \u2014 apps/api/src/tournaments/admin_router.py:51"}, "properties": {"repobilityId": "187d0b05bc6aa394", "scanner": "scanner-primary", "fingerprint": "57b4628348bfd262", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/tournaments/admin_router.py"}, "region": {"startLine": 51}}}]}, {"ruleId": "scanner-1bded6ae0c53ed43", "level": "error", "message": {"text": "FastAPI POST `grant_entry` without auth dependency \u2014 apps/api/src/tournaments/admin_router.py:60"}, "properties": {"repobilityId": "ef12eb8f416f1767", "scanner": "scanner-primary", "fingerprint": "1bded6ae0c53ed43", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/tournaments/admin_router.py"}, "region": {"startLine": 60}}}]}, {"ruleId": "scanner-77f1b365a2117692", "level": "error", "message": {"text": "FastAPI POST `recompute_places` without auth dependency \u2014 apps/api/src/tournaments/admin_router.py:72"}, "properties": {"repobilityId": "425bb182e7893f90", "scanner": "scanner-primary", "fingerprint": "77f1b365a2117692", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/tournaments/admin_router.py"}, "region": {"startLine": 72}}}]}, {"ruleId": "scanner-9cac86419f1e195a", "level": "error", "message": {"text": "FastAPI POST `create_duel` without auth dependency \u2014 apps/api/src/internal_api/router.py:46"}, "properties": {"repobilityId": "ef49a1a053602067", "scanner": "scanner-primary", "fingerprint": "9cac86419f1e195a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/internal_api/router.py"}, "region": {"startLine": 46}}}]}, {"ruleId": "scanner-02df46af3c96974c", "level": "error", "message": {"text": "FastAPI POST `finish_duel` without auth dependency \u2014 apps/api/src/internal_api/router.py:59"}, "properties": {"repobilityId": "de21e8b8668b1e87", "scanner": "scanner-primary", "fingerprint": "02df46af3c96974c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/internal_api/router.py"}, "region": {"startLine": 59}}}]}, {"ruleId": "scanner-6b6dc723c47cb2eb", "level": "error", "message": {"text": "FastAPI POST `set_duel_share_card` without auth dependency \u2014 apps/api/src/internal_api/router.py:84"}, "properties": {"repobilityId": "06f4f6338b8689dc", "scanner": "scanner-primary", "fingerprint": "6b6dc723c47cb2eb", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/internal_api/router.py"}, "region": {"startLine": 84}}}]}, {"ruleId": "scanner-d6a5836fb3348780", "level": "error", "message": {"text": "FastAPI POST `write_ai_review` without auth dependency \u2014 apps/api/src/internal_api/router.py:113"}, "properties": {"repobilityId": "1360bb9eba72755e", "scanner": "scanner-primary", "fingerprint": "d6a5836fb3348780", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/internal_api/router.py"}, "region": {"startLine": 113}}}]}, {"ruleId": "scanner-c1452df65134d1d6", "level": "error", "message": {"text": "FastAPI POST `telegram_redeem` without auth dependency \u2014 apps/api/src/internal_api/router.py:130"}, "properties": {"repobilityId": "7075fa2653e649b8", "scanner": "scanner-primary", "fingerprint": "c1452df65134d1d6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/internal_api/router.py"}, "region": {"startLine": 130}}}]}, {"ruleId": "scanner-ef240e5badcedfe0", "level": "error", "message": {"text": "FastAPI PATCH `update_task` without auth dependency \u2014 apps/api/src/admin/router.py:74"}, "properties": {"repobilityId": "c790673b10c65482", "scanner": "scanner-primary", "fingerprint": "ef240e5badcedfe0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/admin/router.py"}, "region": {"startLine": 74}}}]}, {"ruleId": "scanner-acc46106b4f95883", "level": "error", "message": {"text": "FastAPI POST `publish_task` without auth dependency \u2014 apps/api/src/admin/router.py:84"}, "properties": {"repobilityId": "706469d4746109e8", "scanner": "scanner-primary", "fingerprint": "acc46106b4f95883", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/admin/router.py"}, "region": {"startLine": 84}}}]}, {"ruleId": "scanner-9af87c7f21e69301", "level": "error", "message": {"text": "FastAPI PUT `upsert_flag` without auth dependency \u2014 apps/api/src/admin/router.py:185"}, "properties": {"repobilityId": "f53a4e7ff03a5ab2", "scanner": "scanner-primary", "fingerprint": "9af87c7f21e69301", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/admin/router.py"}, "region": {"startLine": 185}}}]}, {"ruleId": "scanner-92be9953248d98c4", "level": "error", "message": {"text": "Dangling fetch: POST /auth/login (apps/admin/src/shared/api/endpoints.ts:30)"}, "properties": {"repobilityId": "cca511f5c24fbe16", "scanner": "scanner-primary", "fingerprint": "92be9953248d98c4", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-216df8c3867d6e92", "level": "error", "message": {"text": "Dangling fetch: POST /auth/logout (apps/admin/src/shared/api/endpoints.ts:37)"}, "properties": {"repobilityId": "d19b34c896017643", "scanner": "scanner-primary", "fingerprint": "216df8c3867d6e92", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-fb4e0882a8fc7722", "level": "error", "message": {"text": "Dangling fetch: POST /auth/refresh (apps/admin/src/shared/api/endpoints.ts:41)"}, "properties": {"repobilityId": "2851608913ac6b9a", "scanner": "scanner-primary", "fingerprint": "fb4e0882a8fc7722", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-8dd36ecd75d9d10b", "level": "error", "message": {"text": "Dangling fetch: GET /admin/metrics/overview (apps/admin/src/shared/api/endpoints.ts:59)"}, "properties": {"repobilityId": "bf5736cb8f051746", "scanner": "scanner-primary", "fingerprint": "8dd36ecd75d9d10b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-b6c07b382272bd80", "level": "error", "message": {"text": "Dangling fetch: POST /admin/tasks (apps/admin/src/shared/api/endpoints.ts:81)"}, "properties": {"repobilityId": "38a9e38aa191eb5f", "scanner": "scanner-primary", "fingerprint": "b6c07b382272bd80", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-89a20dfa3b918449", "level": "error", "message": {"text": "Dangling fetch: PATCH /admin/tasks/${id} (apps/admin/src/shared/api/endpoints.ts:84)"}, "properties": {"repobilityId": "f1a560ebf01ae3b4", "scanner": "scanner-primary", "fingerprint": "89a20dfa3b918449", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-d973af7d81b6947c", "level": "error", "message": {"text": "Dangling fetch: POST /admin/tasks/${id}/publish (apps/admin/src/shared/api/endpoints.ts:87)"}, "properties": {"repobilityId": "1eddd79b5af87ec2", "scanner": "scanner-primary", "fingerprint": "d973af7d81b6947c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-61f74b3857928d7e", "level": "error", "message": {"text": "Dangling fetch: POST /admin/tasks/${id}/reject (apps/admin/src/shared/api/endpoints.ts:90)"}, "properties": {"repobilityId": "40149a643535e618", "scanner": "scanner-primary", "fingerprint": "61f74b3857928d7e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-f13ba22b32581af8", "level": "error", "message": {"text": "Dangling fetch: POST /admin/users/${id}/ban (apps/admin/src/shared/api/endpoints.ts:110)"}, "properties": {"repobilityId": "827dd3d2cf553ed1", "scanner": "scanner-primary", "fingerprint": "f13ba22b32581af8", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-831c9caea5cdcca9", "level": "error", "message": {"text": "Dangling fetch: POST /admin/users/${id}/unban (apps/admin/src/shared/api/endpoints.ts:113)"}, "properties": {"repobilityId": "f4b23c9e750143cf", "scanner": "scanner-primary", "fingerprint": "831c9caea5cdcca9", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-712ad02e635cb916", "level": "error", "message": {"text": "Dangling fetch: POST /admin/users/${id}/grant-pro (apps/admin/src/shared/api/endpoints.ts:116)"}, "properties": {"repobilityId": "2b7bad66bdc0393f", "scanner": "scanner-primary", "fingerprint": "712ad02e635cb916", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-ae7b99cb5ef9f0b1", "level": "error", "message": {"text": "Dangling fetch: POST /admin/users/${id}/revoke-pro (apps/admin/src/shared/api/endpoints.ts:119)"}, "properties": {"repobilityId": "0f588fd335732382", "scanner": "scanner-primary", "fingerprint": "ae7b99cb5ef9f0b1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-549c462228d358c0", "level": "error", "message": {"text": "Dangling fetch: GET /tournaments${qs} (apps/admin/src/shared/api/endpoints.ts:127)"}, "properties": {"repobilityId": "d934b662f31edcd9", "scanner": "scanner-primary", "fingerprint": "549c462228d358c0", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-0d8d6fe6452f3936", "level": "error", "message": {"text": "Dangling fetch: POST /admin/tournaments (apps/admin/src/shared/api/endpoints.ts:130)"}, "properties": {"repobilityId": "f891d9f0073282c7", "scanner": "scanner-primary", "fingerprint": "0d8d6fe6452f3936", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-62891d986987d64c", "level": "error", "message": {"text": "Dangling fetch: PATCH /admin/tournaments/${id} (apps/admin/src/shared/api/endpoints.ts:133)"}, "properties": {"repobilityId": "3dff4742eca2234b", "scanner": "scanner-primary", "fingerprint": "62891d986987d64c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-ea6f19da620a4a75", "level": "error", "message": {"text": "Dangling fetch: POST /admin/tournaments/${id}/grant-entry (apps/admin/src/shared/api/endpoints.ts:139)"}, "properties": {"repobilityId": "3ff48b2bb7a329a4", "scanner": "scanner-primary", "fingerprint": "ea6f19da620a4a75", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-4f868cf97d4a437e", "level": "error", "message": {"text": "Dangling fetch: GET /admin/feature-flags (apps/admin/src/shared/api/endpoints.ts:148)"}, "properties": {"repobilityId": "aa8f48b93caab01a", "scanner": "scanner-primary", "fingerprint": "4f868cf97d4a437e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-1b32673e1b0bb924", "level": "error", "message": {"text": "Dangling fetch: PUT /admin/feature-flags/${key} (apps/admin/src/shared/api/endpoints.ts:151)"}, "properties": {"repobilityId": "1fc51f74d92e76fd", "scanner": "scanner-primary", "fingerprint": "1b32673e1b0bb924", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-1c9ec0da2f8b4c02", "level": "error", "message": {"text": "Dangling fetch: POST /auth/login (apps/admin/src/shared/api/client.test.ts:101)"}, "properties": {"repobilityId": "b1cbc5f7fccdc6d3", "scanner": "scanner-primary", "fingerprint": "1c9ec0da2f8b4c02", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-2403a94da3a7334c", "level": "error", "message": {"text": "Dangling fetch: POST /auth/register (apps/web/src/shared/api/endpoints.ts:62)"}, "properties": {"repobilityId": "0536e28a2b87ac45", "scanner": "scanner-primary", "fingerprint": "2403a94da3a7334c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-a7e47a808d46365e", "level": "error", "message": {"text": "Dangling fetch: POST /auth/verify-email (apps/web/src/shared/api/endpoints.ts:69)"}, "properties": {"repobilityId": "be8b4d7a77074fab", "scanner": "scanner-primary", "fingerprint": "a7e47a808d46365e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-3eea6fef73ac178c", "level": "error", "message": {"text": "Dangling fetch: POST /auth/verify-link (apps/web/src/shared/api/endpoints.ts:76)"}, "properties": {"repobilityId": "bc6b0cea8088fd2e", "scanner": "scanner-primary", "fingerprint": "3eea6fef73ac178c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-7635e7deb585328d", "level": "error", "message": {"text": "Dangling fetch: POST /auth/resend-code (apps/web/src/shared/api/endpoints.ts:83)"}, "properties": {"repobilityId": "4d342ae418aecba6", "scanner": "scanner-primary", "fingerprint": "7635e7deb585328d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-4f044a6afbb4ee76", "level": "error", "message": {"text": "Dangling fetch: POST /auth/login (apps/web/src/shared/api/endpoints.ts:90)"}, "properties": {"repobilityId": "d99460fa345ff058", "scanner": "scanner-primary", "fingerprint": "4f044a6afbb4ee76", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-41ab54c54b9a5f8d", "level": "error", "message": {"text": "Dangling fetch: POST /auth/logout (apps/web/src/shared/api/endpoints.ts:97)"}, "properties": {"repobilityId": "c50ad9c88bcc152e", "scanner": "scanner-primary", "fingerprint": "41ab54c54b9a5f8d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-cf9149e1caf5f3f8", "level": "error", "message": {"text": "Dangling fetch: POST /auth/refresh (apps/web/src/shared/api/endpoints.ts:101)"}, "properties": {"repobilityId": "531269bdeb370e65", "scanner": "scanner-primary", "fingerprint": "cf9149e1caf5f3f8", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-cf667210bb1abf1b", "level": "error", "message": {"text": "Dangling fetch: POST /auth/telegram (apps/web/src/shared/api/endpoints.ts:139)"}, "properties": {"repobilityId": "b1b9519243753097", "scanner": "scanner-primary", "fingerprint": "cf667210bb1abf1b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-3a89d7650b6ea577", "level": "error", "message": {"text": "Dangling fetch: POST /auth/telegram/register (apps/web/src/shared/api/endpoints.ts:147)"}, "properties": {"repobilityId": "d3bf31fad0d44e02", "scanner": "scanner-primary", "fingerprint": "3a89d7650b6ea577", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-abb8d9b8b0a59597", "level": "error", "message": {"text": "Dangling fetch: GET /me/duels${qs} (apps/web/src/shared/api/endpoints.ts:180)"}, "properties": {"repobilityId": "2cd7b0f2fa5df682", "scanner": "scanner-primary", "fingerprint": "abb8d9b8b0a59597", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-62bbe45648465953", "level": "error", "message": {"text": "Dangling fetch: GET /me/stats${qs} (apps/web/src/shared/api/endpoints.ts:188)"}, "properties": {"repobilityId": "244506ca9029882c", "scanner": "scanner-primary", "fingerprint": "62bbe45648465953", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-dbde441f0fc0a3a8", "level": "error", "message": {"text": "Dangling fetch: GET /daily/leaderboard${qs} (apps/web/src/shared/api/endpoints.ts:217)"}, "properties": {"repobilityId": "7b5255aa9a590219", "scanner": "scanner-primary", "fingerprint": "dbde441f0fc0a3a8", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-98905545daf4383d", "level": "error", "message": {"text": "Dangling fetch: POST /ai/review/${duelId} (apps/web/src/shared/api/endpoints.ts:227)"}, "properties": {"repobilityId": "318bfaf940ebce9b", "scanner": "scanner-primary", "fingerprint": "98905545daf4383d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-7912daca0a0342be", "level": "error", "message": {"text": "Dangling fetch: GET /ai/review/${duelId} (apps/web/src/shared/api/endpoints.ts:230)"}, "properties": {"repobilityId": "0ce88222b8852218", "scanner": "scanner-primary", "fingerprint": "7912daca0a0342be", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-af9f7c59d92dc8b6", "level": "error", "message": {"text": "Dangling fetch: GET /tournaments${qs} (apps/web/src/shared/api/endpoints.ts:291)"}, "properties": {"repobilityId": "b015ac7993e7a33b", "scanner": "scanner-primary", "fingerprint": "af9f7c59d92dc8b6", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-a071ed9184e86057", "level": "error", "message": {"text": "Dangling fetch: GET /tournaments/${id} (apps/web/src/shared/api/endpoints.ts:295)"}, "properties": {"repobilityId": "8de37528f6c887c1", "scanner": "scanner-primary", "fingerprint": "a071ed9184e86057", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-8f9117018d94fb4b", "level": "error", "message": {"text": "Dangling fetch: POST /tournaments/${id}/enter (apps/web/src/shared/api/endpoints.ts:299)"}, "properties": {"repobilityId": "1b56585d52228626", "scanner": "scanner-primary", "fingerprint": "8f9117018d94fb4b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-7f3fca0e761bf758", "level": "error", "message": {"text": "Dangling fetch: GET /tournaments/${id}/tasks (apps/web/src/shared/api/endpoints.ts:303)"}, "properties": {"repobilityId": "5db2d7b72050ef59", "scanner": "scanner-primary", "fingerprint": "7f3fca0e761bf758", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-5cd1a2e70d58717c", "level": "error", "message": {"text": "Dangling fetch: POST /tournaments/${id}/answer (apps/web/src/shared/api/endpoints.ts:306)"}, "properties": {"repobilityId": "d835eb7a1e3b98fb", "scanner": "scanner-primary", "fingerprint": "5cd1a2e70d58717c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-e62f5a59acb1c5f0", "level": "error", "message": {"text": "Dangling fetch: GET /a (apps/web/src/shared/api/client.test.ts:118)"}, "properties": {"repobilityId": "e5a8876f0d995854", "scanner": "scanner-primary", "fingerprint": "e62f5a59acb1c5f0", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-702d298e60b7b9fc", "level": "error", "message": {"text": "Dangling fetch: GET /b (apps/web/src/shared/api/client.test.ts:119)"}, "properties": {"repobilityId": "768a769af03f9131", "scanner": "scanner-primary", "fingerprint": "702d298e60b7b9fc", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-7678bea2abf4c546", "level": "error", "message": {"text": "Dangling fetch: POST /auth/login (apps/web/src/shared/api/client.test.ts:156)"}, "properties": {"repobilityId": "7beed4bbd10c139f", "scanner": "scanner-primary", "fingerprint": "7678bea2abf4c546", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-2b3f3010d5f7ad78", "level": "note", "message": {"text": "Unused endpoint: GET /daily/leaderboard"}, "properties": {"repobilityId": "97855ff496370b4f", "scanner": "scanner-primary", "fingerprint": "2b3f3010d5f7ad78", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d7b32f79e0563454", "level": "note", "message": {"text": "Unused endpoint: GET /me/duels"}, "properties": {"repobilityId": "09ce398af11bda1f", "scanner": "scanner-primary", "fingerprint": "d7b32f79e0563454", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4c4bac869e207a82", "level": "note", "message": {"text": "Unused endpoint: GET /me/stats"}, "properties": {"repobilityId": "bd50a7ed24bfcb4a", "scanner": "scanner-primary", "fingerprint": "4c4bac869e207a82", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5ecaa41bc162e95c", "level": "note", "message": {"text": "Unused endpoint: POST /me/avatar/presign"}, "properties": {"repobilityId": "b71e5b5d8a423fe5", "scanner": "scanner-primary", "fingerprint": "5ecaa41bc162e95c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c0a288688ee2e389", "level": "note", "message": {"text": "Unused endpoint: POST /me/avatar/confirm"}, "properties": {"repobilityId": "18d2009fcd2a12ef", "scanner": "scanner-primary", "fingerprint": "c0a288688ee2e389", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-304b6f2b403d93f7", "level": "note", "message": {"text": "Unused endpoint: POST /register"}, "properties": {"repobilityId": "533412ed2f81f8ea", "scanner": "scanner-primary", "fingerprint": "304b6f2b403d93f7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a2ad8a606e157795", "level": "note", "message": {"text": "Unused endpoint: POST /telegram"}, "properties": {"repobilityId": "d2ef7c07efe8e731", "scanner": "scanner-primary", "fingerprint": "a2ad8a606e157795", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-752a1b7edfb04e26", "level": "note", "message": {"text": "Unused endpoint: POST /telegram/register"}, "properties": {"repobilityId": "953db3501fd0fde3", "scanner": "scanner-primary", "fingerprint": "752a1b7edfb04e26", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-618721b912bad1c2", "level": "note", "message": {"text": "Unused endpoint: POST /login"}, "properties": {"repobilityId": "62fe14c2f0889f51", "scanner": "scanner-primary", "fingerprint": "618721b912bad1c2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0c3bb6af93b4422a", "level": "note", "message": {"text": "Unused endpoint: POST /verify-email"}, "properties": {"repobilityId": "b561b11959a70a81", "scanner": "scanner-primary", "fingerprint": "0c3bb6af93b4422a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8252b449a87e376b", "level": "note", "message": {"text": "Unused endpoint: POST /verify-link"}, "properties": {"repobilityId": "36334ea4c1937d50", "scanner": "scanner-primary", "fingerprint": "8252b449a87e376b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b2d2f8473e8aab1d", "level": "note", "message": {"text": "Unused endpoint: POST /resend-code"}, "properties": {"repobilityId": "1f8f8168a5a904ca", "scanner": "scanner-primary", "fingerprint": "b2d2f8473e8aab1d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7ce17d6b092a81ca", "level": "note", "message": {"text": "Unused endpoint: POST /refresh"}, "properties": {"repobilityId": "6ffd131112f827e9", "scanner": "scanner-primary", "fingerprint": "7ce17d6b092a81ca", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-99fc36db98c134ce", "level": "note", "message": {"text": "Unused endpoint: POST /logout"}, "properties": {"repobilityId": "be8285240a69f16f", "scanner": "scanner-primary", "fingerprint": "99fc36db98c134ce", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a70d05575558dbd8", "level": "note", "message": {"text": "Unused endpoint: GET /share/{duel_id}"}, "properties": {"repobilityId": "106b33bcbb828465", "scanner": "scanner-primary", "fingerprint": "a70d05575558dbd8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9d63e8e3f46a67b7", "level": "note", "message": {"text": "Unused endpoint: GET /widget/{username}.svg"}, "properties": {"repobilityId": "5a8d9bcfcf4030d0", "scanner": "scanner-primary", "fingerprint": "9d63e8e3f46a67b7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "2a4327eb60072179", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-78c5306e1e421700", "level": "note", "message": {"text": "Unused endpoint: GET /{tournament_id}"}, "properties": {"repobilityId": "9b4d23b3013ffff1", "scanner": "scanner-primary", "fingerprint": "78c5306e1e421700", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-58607bfbfbca79df", "level": "note", "message": {"text": "Unused endpoint: POST /{tournament_id}/enter"}, "properties": {"repobilityId": "abaff1881b12ca9a", "scanner": "scanner-primary", "fingerprint": "58607bfbfbca79df", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-602b09b452a6cd8a", "level": "note", "message": {"text": "Unused endpoint: GET /{tournament_id}/tasks"}, "properties": {"repobilityId": "9cd268ade3254553", "scanner": "scanner-primary", "fingerprint": "602b09b452a6cd8a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-002ae51c53b1c766", "level": "note", "message": {"text": "Unused endpoint: POST /{tournament_id}/answer"}, "properties": {"repobilityId": "8427c05782b532d8", "scanner": "scanner-primary", "fingerprint": "002ae51c53b1c766", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a009b1a56794f45", "level": "note", "message": {"text": "Unused endpoint: POST /"}, "properties": {"repobilityId": "a26190736f74d125", "scanner": "scanner-primary", "fingerprint": "7a009b1a56794f45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7320d21a57de9181", "level": "note", "message": {"text": "Unused endpoint: PATCH /{tournament_id}"}, "properties": {"repobilityId": "3903fb68ed1893a5", "scanner": "scanner-primary", "fingerprint": "7320d21a57de9181", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-11045c40399183e3", "level": "note", "message": {"text": "Unused endpoint: POST /{tournament_id}/grant-entry"}, "properties": {"repobilityId": "d422ff25edfa69fb", "scanner": "scanner-primary", "fingerprint": "11045c40399183e3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-03a557375ab0209f", "level": "note", "message": {"text": "Unused endpoint: POST /{tournament_id}/recompute-places"}, "properties": {"repobilityId": "f2590e7659054a26", "scanner": "scanner-primary", "fingerprint": "03a557375ab0209f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0aa218b4c0ac76bd", "level": "note", "message": {"text": "Unused endpoint: POST /{duel_id}"}, "properties": {"repobilityId": "582f4b67906a5c31", "scanner": "scanner-primary", "fingerprint": "0aa218b4c0ac76bd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0f92f05ebeb0696d", "level": "note", "message": {"text": "Unused endpoint: GET /{duel_id}"}, "properties": {"repobilityId": "cc038ba60eadee6d", "scanner": "scanner-primary", "fingerprint": "0f92f05ebeb0696d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f47fa02fb2e8297c", "level": "note", "message": {"text": "Unused endpoint: POST /duels"}, "properties": {"repobilityId": "f8ff378e64b5dfcc", "scanner": "scanner-primary", "fingerprint": "f47fa02fb2e8297c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bfe0f04415c47592", "level": "note", "message": {"text": "Unused endpoint: POST /duels/{duel_id}/finish"}, "properties": {"repobilityId": "c69c9ea88a76e182", "scanner": "scanner-primary", "fingerprint": "bfe0f04415c47592", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-46d76cb7e506f379", "level": "note", "message": {"text": "Unused endpoint: GET /duels/{duel_id}/card"}, "properties": {"repobilityId": "cbe170dac4d5564e", "scanner": "scanner-primary", "fingerprint": "46d76cb7e506f379", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c98451757ac32786", "level": "note", "message": {"text": "Unused endpoint: POST /duels/{duel_id}/share-card"}, "properties": {"repobilityId": "78741c606b342ba0", "scanner": "scanner-primary", "fingerprint": "c98451757ac32786", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a59999b270f2cbbd", "level": "note", "message": {"text": "Unused endpoint: GET /duels/{duel_id}/review-data"}, "properties": {"repobilityId": "e318efee78112b88", "scanner": "scanner-primary", "fingerprint": "a59999b270f2cbbd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e3e042160aa8d3e8", "level": "note", "message": {"text": "Unused endpoint: POST /ai-reviews/{duel_id}/{user_id}"}, "properties": {"repobilityId": "ab89ba49346f1fcc", "scanner": "scanner-primary", "fingerprint": "e3e042160aa8d3e8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-eb6edd531adbf537", "level": "note", "message": {"text": "Unused endpoint: POST /telegram/redeem"}, "properties": {"repobilityId": "3cc5dcc4092c5670", "scanner": "scanner-primary", "fingerprint": "eb6edd531adbf537", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8111d9b5bfb96a1e", "level": "note", "message": {"text": "Unused endpoint: GET /telegram/user/{telegram_user_id}"}, "properties": {"repobilityId": "793d767b79d73e3f", "scanner": "scanner-primary", "fingerprint": "8111d9b5bfb96a1e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6ef3debbd64d5af6", "level": "note", "message": {"text": "Unused endpoint: GET /telegram/by-user/{user_id}"}, "properties": {"repobilityId": "73e972001893616f", "scanner": "scanner-primary", "fingerprint": "6ef3debbd64d5af6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-add6dcb6007baef6", "level": "note", "message": {"text": "Unused endpoint: GET /leaderboard"}, "properties": {"repobilityId": "675026253240dc41", "scanner": "scanner-primary", "fingerprint": "add6dcb6007baef6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9edf4d5d41f3e477", "level": "note", "message": {"text": "Unused endpoint: GET /leaderboard/me"}, "properties": {"repobilityId": "9e57d3594a5c8b76", "scanner": "scanner-primary", "fingerprint": "9edf4d5d41f3e477", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd0e06afbaab19b3", "level": "note", "message": {"text": "Unused endpoint: GET /tasks"}, "properties": {"repobilityId": "ed9f5a864e905661", "scanner": "scanner-primary", "fingerprint": "fd0e06afbaab19b3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8b3eb3012ac06c04", "level": "note", "message": {"text": "Unused endpoint: POST /tasks"}, "properties": {"repobilityId": "2d079a706a6169bb", "scanner": "scanner-primary", "fingerprint": "8b3eb3012ac06c04", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-eb67e5af706d0955", "level": "note", "message": {"text": "Unused endpoint: PATCH /tasks/{task_id}"}, "properties": {"repobilityId": "4fcafc7297d45168", "scanner": "scanner-primary", "fingerprint": "eb67e5af706d0955", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1af61b5a0520bdf8", "level": "note", "message": {"text": "Unused endpoint: POST /tasks/{task_id}/publish"}, "properties": {"repobilityId": "33c11f9100f77eff", "scanner": "scanner-primary", "fingerprint": "1af61b5a0520bdf8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0fc10d996ee27a8c", "level": "note", "message": {"text": "Unused endpoint: POST /tasks/{task_id}/reject"}, "properties": {"repobilityId": "256de815d426e5f6", "scanner": "scanner-primary", "fingerprint": "0fc10d996ee27a8c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-841e50bf821e4158", "level": "note", "message": {"text": "Unused endpoint: GET /users"}, "properties": {"repobilityId": "0e4f912394638291", "scanner": "scanner-primary", "fingerprint": "841e50bf821e4158", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5f0f21526cc5fc9a", "level": "note", "message": {"text": "Unused endpoint: POST /users/{user_id}/ban"}, "properties": {"repobilityId": "9023f38a7fae05de", "scanner": "scanner-primary", "fingerprint": "5f0f21526cc5fc9a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-aba2a22a8295c548", "level": "note", "message": {"text": "Unused endpoint: POST /users/{user_id}/unban"}, "properties": {"repobilityId": "5d46c4f207bc7ef0", "scanner": "scanner-primary", "fingerprint": "aba2a22a8295c548", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2fa0850153b99685", "level": "note", "message": {"text": "Unused endpoint: POST /users/{user_id}/grant-pro"}, "properties": {"repobilityId": "3b372ba126d612a5", "scanner": "scanner-primary", "fingerprint": "2fa0850153b99685", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5940160138f3b762", "level": "note", "message": {"text": "Unused endpoint: POST /users/{user_id}/revoke-pro"}, "properties": {"repobilityId": "be1a88037b3e20dc", "scanner": "scanner-primary", "fingerprint": "5940160138f3b762", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-88c83fc10236fbb5", "level": "note", "message": {"text": "Unused endpoint: GET /feature-flags"}, "properties": {"repobilityId": "f82e833b7ee146f1", "scanner": "scanner-primary", "fingerprint": "88c83fc10236fbb5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c7089f0c41314aff", "level": "note", "message": {"text": "Unused endpoint: PUT /feature-flags/{key}"}, "properties": {"repobilityId": "ae56579050621041", "scanner": "scanner-primary", "fingerprint": "c7089f0c41314aff", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}