{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-8ee06ca4a7d8e860", "name": "Possibly dead Python function: do_GET", "shortDescription": {"text": "Possibly dead Python function: do_GET"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-97220fa50d145c5d", "name": "Possibly dead Python function: log_message", "shortDescription": {"text": "Possibly dead Python function: log_message"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ae37ab4fba33543f", "name": "Possibly dead Python function: do_run_migrations", "shortDescription": {"text": "Possibly dead Python function: do_run_migrations"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b8ddcf47d2d88f42", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4b98bdfe068286a4", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72c864b5b4d49908", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8f884f37e8119740", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-39de4ece2a8e0ab6", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-130b6c69051eff1e", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b78b67c79cec404b", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0535fe2202a4b7c4", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-18fb9e0171858311", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7133dabdc7d1a5a9", "name": "Stray `console.log` in TS/JS \u2014 frontend/App.tsx:37", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 frontend/App.tsx:37"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5671b46087eaee2e", "name": "Insecure pattern 'local_storage_auth_token' in frontend/e2e/chat-smoke.spec.ts:21", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in frontend/e2e/chat-smoke.spec.ts:21"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3323e810ff2bc878", "name": "Insecure pattern 'debug_true' in backend/cli/main.py:194", "shortDescription": {"text": "Insecure pattern 'debug_true' in backend/cli/main.py:194"}, "fullDescription": {"text": "Found a known-risky pattern (debug_true). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-22a10ba55a4adefe", "name": "Very large file: backend/tests/test_fake_factory_chain.py (1413 lines)", "shortDescription": {"text": "Very large file: backend/tests/test_fake_factory_chain.py (1413 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2ee07b213b754ecf", "name": "Very large file: backend/app/routes/chat.py (1602 lines)", "shortDescription": {"text": "Very large file: backend/app/routes/chat.py (1602 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 29 placeholder/mock markers across 11 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license, ci. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-027d69a3963188a5", "name": "Commented-code block (6 lines) in frontend/services/api.ts:47", "shortDescription": {"text": "Commented-code block (6 lines) in frontend/services/api.ts:47"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cb728a70fe994efa", "name": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/services/api.ts:37", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/services/api.ts:37"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-168e3614023a069b", "name": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/services/auth.ts:115", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/services/auth.ts:115"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fd9c56eeec18d936", "name": "Network/subprocess call without timeout or try/except \u2014 backend/e2e_test.py:273", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 backend/e2e_test.py:273"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7bca7ae2d3d2aff3", "name": "Commented-code block (7 lines) in backend/tests/test_dashboard.py:205", "shortDescription": {"text": "Commented-code block (7 lines) in backend/tests/test_dashboard.py:205"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a43511a1d5f06ac5", "name": "Legacy-named symbol `youtube_video_v2` in backend/tests/test_fake_factory_chain.py:8", "shortDescription": {"text": "Legacy-named symbol `youtube_video_v2` in backend/tests/test_fake_factory_chain.py:8"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f2f8ba1a32ea6c41", "name": "Legacy-named symbol `youtube_video_v2` in backend/tests/fixtures/llm_responses/youtube_video_v2_module.py:1", "shortDescription": {"text": "Legacy-named symbol `youtube_video_v2` in backend/tests/fixtures/llm_responses/youtube_video_v2_module.py:1"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4687430f731823ab", "name": "Stub function `log_message` (body is just `pass`/`return`) \u2014 backend/cli/main.py:128", "shortDescription": {"text": "Stub function `log_message` (body is just `pass`/`return`) \u2014 backend/cli/main.py:128"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ac859a41075b9389", "name": "Legacy-named symbol `github_callback_legacy` in backend/app/main.py:52", "shortDescription": {"text": "Legacy-named symbol `github_callback_legacy` in backend/app/main.py:52"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6d126633dfb2e40f", "name": "Commented-code block (5 lines) in backend/app/routes/auth.py:442", "shortDescription": {"text": "Commented-code block (5 lines) in backend/app/routes/auth.py:442"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b8fb948b3c0d693a", "name": "Commented-code block (5 lines) in backend/app/routes/chat.py:294", "shortDescription": {"text": "Commented-code block (5 lines) in backend/app/routes/chat.py:294"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d363f0bf09805697", "name": "Commented-code block (5 lines) in backend/app/services/auth.py:163", "shortDescription": {"text": "Commented-code block (5 lines) in backend/app/services/auth.py:163"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-589c226f2237d351", "name": "Stub function `downgrade` (body is just `pass`/`return`) \u2014 backend/alembic/versions/4c2a1b8f9d3e_add_github_repo_goal_ty", "shortDescription": {"text": "Stub function `downgrade` (body is just `pass`/`return`) \u2014 backend/alembic/versions/4c2a1b8f9d3e_add_github_repo_goal_type.py:24"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d0b17c8c07a7421d", "name": "8 env vars used in code but missing from .env.example", "shortDescription": {"text": "8 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `E2E_API_URL`, `E2E_BASE_URL`, `EXPO_PUBLIC_GITHUB_CLIENT_ID`, `EXPO_PUBLIC_GOOGLE_CLIENT_ID`, `SACRIFICE_API_URL`, `SACRIFICE_CMD`, `SACRIFICE_TOKEN`, `SACRIFICE_VENV`. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be46ea126aa5d8dc", "name": "Near-duplicate function bodies in 3 places", "shortDescription": {"text": "Near-duplicate function bodies in 3 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nbackend/app/routes/goals.py:get_goal, backend/app/routes/goals.py:delete_goal_endpoint, backend/app/routes/goals.py:get_verification_status\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nbackend/app/routes/auth.py:google_login, backend/app/routes/auth.py:github_login\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-49c98f7cedd9c977", "name": "Near-duplicate function bodies in 4 places", "shortDescription": {"text": "Near-duplicate function bodies in 4 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nbackend/app/workers/youtube.py:run_youtube_verification, backend/app/workers/github_repo.py:run_github_repo_verification, backend/app/workers/api_check.py:run_api_verification, backend/app/workers/dev_sandbox.py:run_dev_sandbox_verification\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eede9d2621565fde", "name": "FastAPI POST `auth_google` without auth dependency \u2014 backend/app/routes/auth.py:46", "shortDescription": {"text": "FastAPI POST `auth_google` without auth dependency \u2014 backend/app/routes/auth.py:46"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e1fcfd261abf740a", "name": "FastAPI POST `auth_github` without auth dependency \u2014 backend/app/routes/auth.py:87", "shortDescription": {"text": "FastAPI POST `auth_github` without auth dependency \u2014 backend/app/routes/auth.py:87"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a7ef30bceaab45e5", "name": "FastAPI POST `email_register` without auth dependency \u2014 backend/app/routes/auth.py:449", "shortDescription": {"text": "FastAPI POST `email_register` without auth dependency \u2014 backend/app/routes/auth.py:449"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-678ab47e4ff4cae9", "name": "FastAPI POST `email_login` without auth dependency \u2014 backend/app/routes/auth.py:493", "shortDescription": {"text": "FastAPI POST `email_login` without auth dependency \u2014 backend/app/routes/auth.py:493"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-167270048ad24faf", "name": "Unused endpoint: GET /auth/github/callback", "shortDescription": {"text": "Unused endpoint: GET /auth/github/callback"}, "fullDescription": {"text": "`backend/app/main.py` declares `GET /auth/github/callback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`backend/app/routes/notifications.py` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1de80da0b27387f7", "name": "Unused endpoint: GET /unread-count", "shortDescription": {"text": "Unused endpoint: GET /unread-count"}, "fullDescription": {"text": "`backend/app/routes/notifications.py` declares `GET /unread-count` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9a40211c2378ea55", "name": "Unused endpoint: PUT /{notification_id}/read", "shortDescription": {"text": "Unused endpoint: PUT /{notification_id}/read"}, "fullDescription": {"text": "`backend/app/routes/notifications.py` declares `PUT /{notification_id}/read` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0535da675f219221", "name": "Unused endpoint: PUT /read-all", "shortDescription": {"text": "Unused endpoint: PUT /read-all"}, "fullDescription": {"text": "`backend/app/routes/notifications.py` declares `PUT /read-all` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4756b4c4da7d2088", "name": "Unused endpoint: GET /api/health", "shortDescription": {"text": "Unused endpoint: GET /api/health"}, "fullDescription": {"text": "`backend/app/routes/health.py` declares `GET /api/health` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-428cd85b9bd97a16", "name": "Unused endpoint: GET /api/goal-types", "shortDescription": {"text": "Unused endpoint: GET /api/goal-types"}, "fullDescription": {"text": "`backend/app/routes/goals.py` declares `GET /api/goal-types` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a009b1a56794f45", "name": "Unused endpoint: POST /", "shortDescription": {"text": "Unused endpoint: POST /"}, "fullDescription": {"text": "`backend/app/routes/goals.py` declares `POST /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fe075e0ce50f32ec", "name": "Unused endpoint: GET /{goal_id}", "shortDescription": {"text": "Unused endpoint: GET /{goal_id}"}, "fullDescription": {"text": "`backend/app/routes/goals.py` declares `GET /{goal_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-253f95f695b1d235", "name": "Unused endpoint: PUT /{goal_id}", "shortDescription": {"text": "Unused endpoint: PUT /{goal_id}"}, "fullDescription": {"text": "`backend/app/routes/goals.py` declares `PUT /{goal_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-750ef798a989378f", "name": "Unused endpoint: DELETE /{goal_id}", "shortDescription": {"text": "Unused endpoint: DELETE /{goal_id}"}, "fullDescription": {"text": "`backend/app/routes/goals.py` declares `DELETE /{goal_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-879446c4d38daf68", "name": "Unused endpoint: POST /{goal_id}/submit-proof", "shortDescription": {"text": "Unused endpoint: POST /{goal_id}/submit-proof"}, "fullDescription": {"text": "`backend/app/routes/goals.py` declares `POST /{goal_id}/submit-proof` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b2486172e4ea732a", "name": "Unused endpoint: GET /{goal_id}/verification-status", "shortDescription": {"text": "Unused endpoint: GET /{goal_id}/verification-status"}, "fullDescription": {"text": "`backend/app/routes/goals.py` declares `GET /{goal_id}/verification-status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cd8dc4599ec52a08", "name": "Unused endpoint: GET /stats", "shortDescription": {"text": "Unused endpoint: GET /stats"}, "fullDescription": {"text": "`backend/app/routes/dashboard.py` declares `GET /stats` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-afc064028ae39ea9", "name": "Unused endpoint: GET /history", "shortDescription": {"text": "Unused endpoint: GET /history"}, "fullDescription": {"text": "`backend/app/routes/dashboard.py` declares `GET /history` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5887f6beb60dee57", "name": "Unused endpoint: POST /google", "shortDescription": {"text": "Unused endpoint: POST /google"}, "fullDescription": {"text": "`backend/app/routes/auth.py` declares `POST /google` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3003bf9873755e58", "name": "Unused endpoint: POST /github", "shortDescription": {"text": "Unused endpoint: POST /github"}, "fullDescription": {"text": "`backend/app/routes/auth.py` declares `POST /github` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c78a2d9a8576f0ce", "name": "Unused endpoint: GET /cli/login/{provider}", "shortDescription": {"text": "Unused endpoint: GET /cli/login/{provider}"}, "fullDescription": {"text": "`backend/app/routes/auth.py` declares `GET /cli/login/{provider}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ce76f421efcebeb3", "name": "Unused endpoint: GET /google/login", "shortDescription": {"text": "Unused endpoint: GET /google/login"}, "fullDescription": {"text": "`backend/app/routes/auth.py` declares `GET /google/login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-424854ab10436e86", "name": "Unused endpoint: GET /google/callback", "shortDescription": {"text": "Unused endpoint: GET /google/callback"}, "fullDescription": {"text": "`backend/app/routes/auth.py` declares `GET /google/callback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d3e7ea2e66c60941", "name": "Unused endpoint: GET /github/login", "shortDescription": {"text": "Unused endpoint: GET /github/login"}, "fullDescription": {"text": "`backend/app/routes/auth.py` declares `GET /github/login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-575393330d444728", "name": "Unused endpoint: GET /github/callback", "shortDescription": {"text": "Unused endpoint: GET /github/callback"}, "fullDescription": {"text": "`backend/app/routes/auth.py` declares `GET /github/callback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e8be5cad993f3428", "name": "Unused endpoint: GET /dev/token", "shortDescription": {"text": "Unused endpoint: GET /dev/token"}, "fullDescription": {"text": "`backend/app/routes/auth.py` declares `GET /dev/token` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cccbdd566f153fed", "name": "Unused endpoint: POST /email/register", "shortDescription": {"text": "Unused endpoint: POST /email/register"}, "fullDescription": {"text": "`backend/app/routes/auth.py` declares `POST /email/register` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ef4460865d68011e", "name": "Unused endpoint: POST /email/login", "shortDescription": {"text": "Unused endpoint: POST /email/login"}, "fullDescription": {"text": "`backend/app/routes/auth.py` declares `POST /email/login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd1dc91abf32142d", "name": "Unused endpoint: GET /me", "shortDescription": {"text": "Unused endpoint: GET /me"}, "fullDescription": {"text": "`backend/app/routes/auth.py` declares `GET /me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7ce17d6b092a81ca", "name": "Unused endpoint: POST /refresh", "shortDescription": {"text": "Unused endpoint: POST /refresh"}, "fullDescription": {"text": "`backend/app/routes/auth.py` declares `POST /refresh` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-11c60d02a66bf33d", "name": "Unused endpoint: POST /api/payment/setup-intent", "shortDescription": {"text": "Unused endpoint: POST /api/payment/setup-intent"}, "fullDescription": {"text": "`backend/app/routes/payment.py` declares `POST /api/payment/setup-intent` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-309757f07f84c496", "name": "Unused endpoint: GET /api/payment/methods", "shortDescription": {"text": "Unused endpoint: GET /api/payment/methods"}, "fullDescription": {"text": "`backend/app/routes/payment.py` declares `GET /api/payment/methods` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-14b3e98a813f5bd3", "name": "Unused endpoint: DELETE /api/payment/methods/{method_id}", "shortDescription": {"text": "Unused endpoint: DELETE /api/payment/methods/{method_id}"}, "fullDescription": {"text": "`backend/app/routes/payment.py` declares `DELETE /api/payment/methods/{method_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a0b39ee962bbc236", "name": "Unused endpoint: GET /api/payments", "shortDescription": {"text": "Unused endpoint: GET /api/payments"}, "fullDescription": {"text": "`backend/app/routes/payment.py` declares `GET /api/payments` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9243acb53e5acc55", "name": "Unused endpoint: GET /api/charities/search", "shortDescription": {"text": "Unused endpoint: GET /api/charities/search"}, "fullDescription": {"text": "`backend/app/routes/payment.py` declares `GET /api/charities/search` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8ad816262b88fef4", "name": "Unused endpoint: POST /video", "shortDescription": {"text": "Unused endpoint: POST /video"}, "fullDescription": {"text": "`backend/app/routes/uploads.py` declares `POST /video` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-49038f1e80fce7b7", "name": "Unused endpoint: GET /{upload_id}", "shortDescription": {"text": "Unused endpoint: GET /{upload_id}"}, "fullDescription": {"text": "`backend/app/routes/uploads.py` declares `GET /{upload_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-04eb8ec4b4b98444", "name": "Unused endpoint: POST /sessions/{session_id}/request-new-goal-type", "shortDescription": {"text": "Unused endpoint: POST /sessions/{session_id}/request-new-goal-type"}, "fullDescription": {"text": "`backend/app/routes/chat.py` declares `POST /sessions/{session_id}/request-new-goal-type` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c89b653c8e2ad19b", "name": "Unused endpoint: GET /sessions/{session_id}/generation-status", "shortDescription": {"text": "Unused endpoint: GET /sessions/{session_id}/generation-status"}, "fullDescription": {"text": "`backend/app/routes/chat.py` declares `GET /sessions/{session_id}/generation-status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bb0f7b8873809d03", "name": "Unused endpoint: POST /sessions/{session_id}/accept-generated-type", "shortDescription": {"text": "Unused endpoint: POST /sessions/{session_id}/accept-generated-type"}, "fullDescription": {"text": "`backend/app/routes/chat.py` declares `POST /sessions/{session_id}/accept-generated-type` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d333ae764d475391", "name": "Unused endpoint: POST /sessions/{session_id}/iterate-generated-type", "shortDescription": {"text": "Unused endpoint: POST /sessions/{session_id}/iterate-generated-type"}, "fullDescription": {"text": "`backend/app/routes/chat.py` declares `POST /sessions/{session_id}/iterate-generated-type` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-92efb2dc9205e7a4", "name": "Unused endpoint: POST /sessions", "shortDescription": {"text": "Unused endpoint: POST /sessions"}, "fullDescription": {"text": "`backend/app/routes/chat.py` declares `POST /sessions` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6c30e2c319be21a9", "name": "Unused endpoint: POST /sessions/{session_id}/messages", "shortDescription": {"text": "Unused endpoint: POST /sessions/{session_id}/messages"}, "fullDescription": {"text": "`backend/app/routes/chat.py` declares `POST /sessions/{session_id}/messages` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-36a86f55beee2c6c", "name": "Unused endpoint: POST /sessions/{session_id}/create-goal", "shortDescription": {"text": "Unused endpoint: POST /sessions/{session_id}/create-goal"}, "fullDescription": {"text": "`backend/app/routes/chat.py` declares `POST /sessions/{session_id}/create-goal` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/23077"}, "properties": {"repository": "xvanov/sacrifice", "repoUrl": "https://github.com/xvanov/sacrifice", "branch": "main"}, "results": [{"ruleId": "scanner-8ee06ca4a7d8e860", "level": "note", "message": {"text": "Possibly dead Python function: do_GET"}, "properties": {"repobilityId": "2d943bb45e4f13bd", "scanner": "scanner-primary", "fingerprint": "8ee06ca4a7d8e860", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/cli/main.py:108"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-97220fa50d145c5d", "level": "note", "message": {"text": "Possibly dead Python function: log_message"}, "properties": {"repobilityId": "965f3150b4af5b2e", "scanner": "scanner-primary", "fingerprint": "97220fa50d145c5d", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/cli/main.py:128"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ae37ab4fba33543f", "level": "note", "message": {"text": "Possibly dead Python function: do_run_migrations"}, "properties": {"repobilityId": "087acb17722cfd2f", "scanner": "scanner-primary", "fingerprint": "ae37ab4fba33543f", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/alembic/env.py:45"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b8ddcf47d2d88f42", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "b8ddcf47d2d88f42", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/alembic/versions/9b9c8f738404_merge_media_uploads_and_chat_sessions_.py:26"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4b98bdfe068286a4", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "4b98bdfe068286a4", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/alembic/versions/4c2a1b8f9d3e_add_github_repo_goal_type.py:24"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-72c864b5b4d49908", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "72c864b5b4d49908", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/alembic/versions/a7b8c9d0e1f2_add_chat_spend_ledger_and_notification_type.py:41"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8f884f37e8119740", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "8f884f37e8119740", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/alembic/versions/e22b7086c9bd_add_chat_sessions.py:47"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-39de4ece2a8e0ab6", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "39de4ece2a8e0ab6", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/alembic/versions/f1a2b3c4d5e6_add_awaiting_goal_type_status_and_direction_.py:38"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-130b6c69051eff1e", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "130b6c69051eff1e", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/alembic/versions/e897b89aaf97_initial_models.py:104"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b78b67c79cec404b", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "b78b67c79cec404b", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/alembic/versions/9d4f2a6e1c70_add_user_password_hash.py:27"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0535fe2202a4b7c4", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "0535fe2202a4b7c4", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/alembic/versions/b2d3e4f5a6c7_update_chat_sessions_schema.py:41"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-18fb9e0171858311", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "18fb9e0171858311", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/alembic/versions/9c9bfbf53f11_switch_goal_type_to_varchar.py:29"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7133dabdc7d1a5a9", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 frontend/App.tsx:37"}, "properties": {"repobilityId": "fdcae81124ac9e87", "scanner": "scanner-primary", "fingerprint": "7133dabdc7d1a5a9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-5671b46087eaee2e", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in frontend/e2e/chat-smoke.spec.ts:21"}, "properties": {"repobilityId": "2c6223165045d296", "scanner": "scanner-primary", "fingerprint": "5671b46087eaee2e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/e2e/chat-smoke.spec.ts"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-3323e810ff2bc878", "level": "note", "message": {"text": "Insecure pattern 'debug_true' in backend/cli/main.py:194"}, "properties": {"repobilityId": "769c19d892131c40", "scanner": "scanner-primary", "fingerprint": "3323e810ff2bc878", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["owasp", "debug_true"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/cli/main.py"}, "region": {"startLine": 194}}}]}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-22a10ba55a4adefe", "level": "note", "message": {"text": "Very large file: backend/tests/test_fake_factory_chain.py (1413 lines)"}, "properties": {"repobilityId": "b3cc4d1ef190dbc9", "scanner": "scanner-primary", "fingerprint": "22a10ba55a4adefe", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-2ee07b213b754ecf", "level": "note", "message": {"text": "Very large file: backend/app/routes/chat.py (1602 lines)"}, "properties": {"repobilityId": "ec5decc342031f50", "scanner": "scanner-primary", "fingerprint": "2ee07b213b754ecf", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "b62fc581825b0176", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "d997b1b0f7111206", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "72c24e14752ab19a", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "22040445a6e07bec", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "3c0061ff4a7def60", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "25486e8734eee31e", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "aca846c0d916a226", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-027d69a3963188a5", "level": "none", "message": {"text": "Commented-code block (6 lines) in frontend/services/api.ts:47"}, "properties": {"repobilityId": "39a3b7f2afb054bb", "scanner": "scanner-primary", "fingerprint": "027d69a3963188a5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-cb728a70fe994efa", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/services/api.ts:37"}, "properties": {"repobilityId": "7a0b96e406ebdc09", "scanner": "scanner-primary", "fingerprint": "cb728a70fe994efa", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-168e3614023a069b", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/services/auth.ts:115"}, "properties": {"repobilityId": "ed5251471366d3d0", "scanner": "scanner-primary", "fingerprint": "168e3614023a069b", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-fd9c56eeec18d936", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 backend/e2e_test.py:273"}, "properties": {"repobilityId": "41f88275f5751ceb", "scanner": "scanner-primary", "fingerprint": "fd9c56eeec18d936", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-7bca7ae2d3d2aff3", "level": "none", "message": {"text": "Commented-code block (7 lines) in backend/tests/test_dashboard.py:205"}, "properties": {"repobilityId": "8b434663c73c0f13", "scanner": "scanner-primary", "fingerprint": "7bca7ae2d3d2aff3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a43511a1d5f06ac5", "level": "note", "message": {"text": "Legacy-named symbol `youtube_video_v2` in backend/tests/test_fake_factory_chain.py:8"}, "properties": {"repobilityId": "680bc067931e2a56", "scanner": "scanner-primary", "fingerprint": "a43511a1d5f06ac5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-f2f8ba1a32ea6c41", "level": "note", "message": {"text": "Legacy-named symbol `youtube_video_v2` in backend/tests/fixtures/llm_responses/youtube_video_v2_module.py:1"}, "properties": {"repobilityId": "7a51d927ee9a019b", "scanner": "scanner-primary", "fingerprint": "f2f8ba1a32ea6c41", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-4687430f731823ab", "level": "note", "message": {"text": "Stub function `log_message` (body is just `pass`/`return`) \u2014 backend/cli/main.py:128"}, "properties": {"repobilityId": "478fe3a1ee6148cb", "scanner": "scanner-primary", "fingerprint": "4687430f731823ab", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-ac859a41075b9389", "level": "note", "message": {"text": "Legacy-named symbol `github_callback_legacy` in backend/app/main.py:52"}, "properties": {"repobilityId": "6ec7289ffdad9ed9", "scanner": "scanner-primary", "fingerprint": "ac859a41075b9389", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-6d126633dfb2e40f", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/app/routes/auth.py:442"}, "properties": {"repobilityId": "e2e85ed3c772b3c7", "scanner": "scanner-primary", "fingerprint": "6d126633dfb2e40f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b8fb948b3c0d693a", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/app/routes/chat.py:294"}, "properties": {"repobilityId": "6d5bb1d3bafa51b6", "scanner": "scanner-primary", "fingerprint": "b8fb948b3c0d693a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d363f0bf09805697", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/app/services/auth.py:163"}, "properties": {"repobilityId": "650f061dab965b5f", "scanner": "scanner-primary", "fingerprint": "d363f0bf09805697", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-589c226f2237d351", "level": "note", "message": {"text": "Stub function `downgrade` (body is just `pass`/`return`) \u2014 backend/alembic/versions/4c2a1b8f9d3e_add_github_repo_goal_type.py:24"}, "properties": {"repobilityId": "70b2eb0665feaaed", "scanner": "scanner-primary", "fingerprint": "589c226f2237d351", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-d0b17c8c07a7421d", "level": "note", "message": {"text": "8 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "17fe720e8247f9df", "scanner": "scanner-primary", "fingerprint": "d0b17c8c07a7421d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "74cf8796dfe2fec2", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "3da49e5724d0284d", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "ecd960956871d171", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "a67fb21a9ecd9f29", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "d6436cd118eed832", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "8070407b71338a2a", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "2a53500b63ee3218", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "5abb74f154e7ee4f", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "091c48ad85263c6a", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "9a4d139af5e1d8d7", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "f91d712eb9c6015c", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-eede9d2621565fde", "level": "error", "message": {"text": "FastAPI POST `auth_google` without auth dependency \u2014 backend/app/routes/auth.py:46"}, "properties": {"repobilityId": "97e9bb542a47182b", "scanner": "scanner-primary", "fingerprint": "eede9d2621565fde", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/auth.py"}, "region": {"startLine": 46}}}]}, {"ruleId": "scanner-e1fcfd261abf740a", "level": "error", "message": {"text": "FastAPI POST `auth_github` without auth dependency \u2014 backend/app/routes/auth.py:87"}, "properties": {"repobilityId": "b7af0eefe5df5aab", "scanner": "scanner-primary", "fingerprint": "e1fcfd261abf740a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/auth.py"}, "region": {"startLine": 87}}}]}, {"ruleId": "scanner-a7ef30bceaab45e5", "level": "error", "message": {"text": "FastAPI POST `email_register` without auth dependency \u2014 backend/app/routes/auth.py:449"}, "properties": {"repobilityId": "aead0d6856c76909", "scanner": "scanner-primary", "fingerprint": "a7ef30bceaab45e5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/auth.py"}, "region": {"startLine": 449}}}]}, {"ruleId": "scanner-678ab47e4ff4cae9", "level": "error", "message": {"text": "FastAPI POST `email_login` without auth dependency \u2014 backend/app/routes/auth.py:493"}, "properties": {"repobilityId": "89d87b020f605e84", "scanner": "scanner-primary", "fingerprint": "678ab47e4ff4cae9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/auth.py"}, "region": {"startLine": 493}}}]}, {"ruleId": "scanner-167270048ad24faf", "level": "note", "message": {"text": "Unused endpoint: GET /auth/github/callback"}, "properties": {"repobilityId": "0b665cb575f15032", "scanner": "scanner-primary", "fingerprint": "167270048ad24faf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "c22ce7c6d9486593", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1de80da0b27387f7", "level": "note", "message": {"text": "Unused endpoint: GET /unread-count"}, "properties": {"repobilityId": "e8752f51fa852343", "scanner": "scanner-primary", "fingerprint": "1de80da0b27387f7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9a40211c2378ea55", "level": "note", "message": {"text": "Unused endpoint: PUT /{notification_id}/read"}, "properties": {"repobilityId": "426c6ef0588211a0", "scanner": "scanner-primary", "fingerprint": "9a40211c2378ea55", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0535da675f219221", "level": "note", "message": {"text": "Unused endpoint: PUT /read-all"}, "properties": {"repobilityId": "463ca41c445e7dfa", "scanner": "scanner-primary", "fingerprint": "0535da675f219221", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4756b4c4da7d2088", "level": "note", "message": {"text": "Unused endpoint: GET /api/health"}, "properties": {"repobilityId": "65b779b5e91315e7", "scanner": "scanner-primary", "fingerprint": "4756b4c4da7d2088", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-428cd85b9bd97a16", "level": "note", "message": {"text": "Unused endpoint: GET /api/goal-types"}, "properties": {"repobilityId": "6cd0a4accd63ca3e", "scanner": "scanner-primary", "fingerprint": "428cd85b9bd97a16", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a009b1a56794f45", "level": "note", "message": {"text": "Unused endpoint: POST /"}, "properties": {"repobilityId": "b7ba510c20411e6f", "scanner": "scanner-primary", "fingerprint": "7a009b1a56794f45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fe075e0ce50f32ec", "level": "note", "message": {"text": "Unused endpoint: GET /{goal_id}"}, "properties": {"repobilityId": "d57edbb58cb4d45d", "scanner": "scanner-primary", "fingerprint": "fe075e0ce50f32ec", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-253f95f695b1d235", "level": "note", "message": {"text": "Unused endpoint: PUT /{goal_id}"}, "properties": {"repobilityId": "a07872f50bc45d2f", "scanner": "scanner-primary", "fingerprint": "253f95f695b1d235", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-750ef798a989378f", "level": "note", "message": {"text": "Unused endpoint: DELETE /{goal_id}"}, "properties": {"repobilityId": "23ce76fbb2a0e6b4", "scanner": "scanner-primary", "fingerprint": "750ef798a989378f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-879446c4d38daf68", "level": "note", "message": {"text": "Unused endpoint: POST /{goal_id}/submit-proof"}, "properties": {"repobilityId": "c9d1f37f4d9cf058", "scanner": "scanner-primary", "fingerprint": "879446c4d38daf68", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b2486172e4ea732a", "level": "note", "message": {"text": "Unused endpoint: GET /{goal_id}/verification-status"}, "properties": {"repobilityId": "6fc08e676e690b5a", "scanner": "scanner-primary", "fingerprint": "b2486172e4ea732a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cd8dc4599ec52a08", "level": "note", "message": {"text": "Unused endpoint: GET /stats"}, "properties": {"repobilityId": "2776d3f7bbfd0209", "scanner": "scanner-primary", "fingerprint": "cd8dc4599ec52a08", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-afc064028ae39ea9", "level": "note", "message": {"text": "Unused endpoint: GET /history"}, "properties": {"repobilityId": "e2ff1dd2ddad1323", "scanner": "scanner-primary", "fingerprint": "afc064028ae39ea9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5887f6beb60dee57", "level": "note", "message": {"text": "Unused endpoint: POST /google"}, "properties": {"repobilityId": "c64a4324714a6fb9", "scanner": "scanner-primary", "fingerprint": "5887f6beb60dee57", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3003bf9873755e58", "level": "note", "message": {"text": "Unused endpoint: POST /github"}, "properties": {"repobilityId": "52e5e69b097f093e", "scanner": "scanner-primary", "fingerprint": "3003bf9873755e58", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c78a2d9a8576f0ce", "level": "note", "message": {"text": "Unused endpoint: GET /cli/login/{provider}"}, "properties": {"repobilityId": "95bfe956d5fa19df", "scanner": "scanner-primary", "fingerprint": "c78a2d9a8576f0ce", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ce76f421efcebeb3", "level": "note", "message": {"text": "Unused endpoint: GET /google/login"}, "properties": {"repobilityId": "02c4a1827a3ccf95", "scanner": "scanner-primary", "fingerprint": "ce76f421efcebeb3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-424854ab10436e86", "level": "note", "message": {"text": "Unused endpoint: GET /google/callback"}, "properties": {"repobilityId": "a689bbdde603ca0b", "scanner": "scanner-primary", "fingerprint": "424854ab10436e86", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d3e7ea2e66c60941", "level": "note", "message": {"text": "Unused endpoint: GET /github/login"}, "properties": {"repobilityId": "17d548fd7ef62223", "scanner": "scanner-primary", "fingerprint": "d3e7ea2e66c60941", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-575393330d444728", "level": "note", "message": {"text": "Unused endpoint: GET /github/callback"}, "properties": {"repobilityId": "53636cd4c4fbabbd", "scanner": "scanner-primary", "fingerprint": "575393330d444728", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e8be5cad993f3428", "level": "note", "message": {"text": "Unused endpoint: GET /dev/token"}, "properties": {"repobilityId": "1627196ac4aa974f", "scanner": "scanner-primary", "fingerprint": "e8be5cad993f3428", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cccbdd566f153fed", "level": "note", "message": {"text": "Unused endpoint: POST /email/register"}, "properties": {"repobilityId": "bd412c2be5792bce", "scanner": "scanner-primary", "fingerprint": "cccbdd566f153fed", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ef4460865d68011e", "level": "note", "message": {"text": "Unused endpoint: POST /email/login"}, "properties": {"repobilityId": "43584fc70f023be7", "scanner": "scanner-primary", "fingerprint": "ef4460865d68011e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd1dc91abf32142d", "level": "note", "message": {"text": "Unused endpoint: GET /me"}, "properties": {"repobilityId": "db0eb8772a51bc22", "scanner": "scanner-primary", "fingerprint": "fd1dc91abf32142d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7ce17d6b092a81ca", "level": "note", "message": {"text": "Unused endpoint: POST /refresh"}, "properties": {"repobilityId": "cd766c9c7918d512", "scanner": "scanner-primary", "fingerprint": "7ce17d6b092a81ca", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-11c60d02a66bf33d", "level": "note", "message": {"text": "Unused endpoint: POST /api/payment/setup-intent"}, "properties": {"repobilityId": "267b717d27fb0303", "scanner": "scanner-primary", "fingerprint": "11c60d02a66bf33d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-309757f07f84c496", "level": "note", "message": {"text": "Unused endpoint: GET /api/payment/methods"}, "properties": {"repobilityId": "4008879f9b0c9b15", "scanner": "scanner-primary", "fingerprint": "309757f07f84c496", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-14b3e98a813f5bd3", "level": "note", "message": {"text": "Unused endpoint: DELETE /api/payment/methods/{method_id}"}, "properties": {"repobilityId": "4433e5aa425b197b", "scanner": "scanner-primary", "fingerprint": "14b3e98a813f5bd3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a0b39ee962bbc236", "level": "note", "message": {"text": "Unused endpoint: GET /api/payments"}, "properties": {"repobilityId": "39c131f0785e5d8d", "scanner": "scanner-primary", "fingerprint": "a0b39ee962bbc236", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9243acb53e5acc55", "level": "note", "message": {"text": "Unused endpoint: GET /api/charities/search"}, "properties": {"repobilityId": "2a9b8d01b43dd2d1", "scanner": "scanner-primary", "fingerprint": "9243acb53e5acc55", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8ad816262b88fef4", "level": "note", "message": {"text": "Unused endpoint: POST /video"}, "properties": {"repobilityId": "f99930f9b22c3897", "scanner": "scanner-primary", "fingerprint": "8ad816262b88fef4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-49038f1e80fce7b7", "level": "note", "message": {"text": "Unused endpoint: GET /{upload_id}"}, "properties": {"repobilityId": "673a4eb5d49aae3d", "scanner": "scanner-primary", "fingerprint": "49038f1e80fce7b7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-04eb8ec4b4b98444", "level": "note", "message": {"text": "Unused endpoint: POST /sessions/{session_id}/request-new-goal-type"}, "properties": {"repobilityId": "4cee120508815c68", "scanner": "scanner-primary", "fingerprint": "04eb8ec4b4b98444", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c89b653c8e2ad19b", "level": "note", "message": {"text": "Unused endpoint: GET /sessions/{session_id}/generation-status"}, "properties": {"repobilityId": "ee882159c2743ee5", "scanner": "scanner-primary", "fingerprint": "c89b653c8e2ad19b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bb0f7b8873809d03", "level": "note", "message": {"text": "Unused endpoint: POST /sessions/{session_id}/accept-generated-type"}, "properties": {"repobilityId": "e4963eff584dca43", "scanner": "scanner-primary", "fingerprint": "bb0f7b8873809d03", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d333ae764d475391", "level": "note", "message": {"text": "Unused endpoint: POST /sessions/{session_id}/iterate-generated-type"}, "properties": {"repobilityId": "b3462cbc04f4a158", "scanner": "scanner-primary", "fingerprint": "d333ae764d475391", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-92efb2dc9205e7a4", "level": "note", "message": {"text": "Unused endpoint: POST /sessions"}, "properties": {"repobilityId": "f55e5b646f3d5f1e", "scanner": "scanner-primary", "fingerprint": "92efb2dc9205e7a4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6c30e2c319be21a9", "level": "note", "message": {"text": "Unused endpoint: POST /sessions/{session_id}/messages"}, "properties": {"repobilityId": "cbf34198b25b9ff9", "scanner": "scanner-primary", "fingerprint": "6c30e2c319be21a9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-36a86f55beee2c6c", "level": "note", "message": {"text": "Unused endpoint: POST /sessions/{session_id}/create-goal"}, "properties": {"repobilityId": "63d016315f7674d7", "scanner": "scanner-primary", "fingerprint": "36a86f55beee2c6c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}