{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-6a48db4e8b33dba4", "name": "Possibly dead Python function: destroy", "shortDescription": {"text": "Possibly dead Python function: destroy"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-97bca46674f6a36d", "name": "Possibly dead Python function: getHierarchicalDelimiter", "shortDescription": {"text": "Possibly dead Python function: getHierarchicalDelimiter"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0122ea9e979fcac2", "name": "Possibly dead Python function: getUID", "shortDescription": {"text": "Possibly dead Python function: getUID"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bc3fd7fc8f01fd99", "name": "Possibly dead Python function: expunge", "shortDescription": {"text": "Possibly dead Python function: expunge"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-87ce8313a4beb143", "name": "Possibly dead Python function: getUID", "shortDescription": {"text": "Possibly dead Python function: getUID"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-07cface9112856f1", "name": "Possibly dead Python function: getHeaders", "shortDescription": {"text": "Possibly dead Python function: getHeaders"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ff0c73be878789d5", "name": "Possibly dead Python function: isMultipart", "shortDescription": {"text": "Possibly dead Python function: isMultipart"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a9a77aa6c2abc9a8", "name": "Possibly dead Python function: getSubPart", "shortDescription": {"text": "Possibly dead Python function: getSubPart"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-29b1f0d0cbf7cd9e", "name": "Possibly dead Python function: getBodyFile", "shortDescription": {"text": "Possibly dead Python function: getBodyFile"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fcf06dfb3d09d655", "name": "Possibly dead Python function: getSize", "shortDescription": {"text": "Possibly dead Python function: getSize"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-47a932ebf970be36", "name": "Possibly dead Python function: getInternalDate", "shortDescription": {"text": "Possibly dead Python function: getInternalDate"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-84a471a3c9e88776", "name": "Possibly dead Python function: open", "shortDescription": {"text": "Possibly dead Python function: open"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0d6ab3c525d365bf", "name": "Possibly dead Python function: authenticator", "shortDescription": {"text": "Possibly dead Python function: authenticator"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e91433e4bba11d6d", "name": "Possibly dead Python function: handle_DATA", "shortDescription": {"text": "Possibly dead Python function: handle_DATA"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e17ed342a3ac9476", "name": "Possibly dead Python function: logging_write_seq", "shortDescription": {"text": "Possibly dead Python function: logging_write_seq"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2bee511a32420dcb", "name": "Possibly dead Python function: listMailboxes", "shortDescription": {"text": "Possibly dead Python function: listMailboxes"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-68d03c81899996f2", "name": "Possibly dead Python function: requestAvatar", "shortDescription": {"text": "Possibly dead Python function: requestAvatar"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b6d6e5f76c69cb72", "name": "Possibly dead Python function: buildProtocol", "shortDescription": {"text": "Possibly dead Python function: buildProtocol"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0a5870fa03e8ebdb", "name": "Possibly dead Python function: requestAvatarId", "shortDescription": {"text": "Possibly dead Python function: requestAvatarId"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4b413e24c1046026", "name": "Stray `console.log` in TS/JS \u2014 frontend/src/api/index.js:178", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/api/index.js:178"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0195371fb677e652", "name": "Stray `console.log` in TS/JS \u2014 frontend/src/utils/email-parser.js:36", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/utils/email-parser.js:36"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cbe758400bf3fd3b", "name": "Stray `console.log` in TS/JS \u2014 frontend/src/components/SendBox.vue:81", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/components/SendBox.vue:81"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e35adb6d8a2deb99", "name": "Stray `console.log` in TS/JS \u2014 frontend/src/views/admin/UserAddressManagement.vue:28", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/views/admin/UserAddressManagement.vue:28"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4b553a69d428e78a", "name": "Stray `console.log` in TS/JS \u2014 frontend/src/views/admin/RoleAddressConfig.vue:22", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/views/admin/RoleAddressConfig.vue:22"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8bc6d65ed178544e", "name": "Stray `console.log` in TS/JS \u2014 frontend/src/views/admin/UserManagement.vue:50", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/views/admin/UserManagement.vue:50"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-13704be7ee90aeac", "name": "Stray `console.log` in TS/JS \u2014 frontend/src/views/admin/Statistics.vue:36", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/views/admin/Statistics.vue:36"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-88a1e769e5670f9e", "name": "Stray `console.log` in TS/JS \u2014 frontend/src/views/admin/SenderAccess.vue:57", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/views/admin/SenderAccess.vue:57"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-af1658c3fa14a857", "name": "Stray `console.log` in TS/JS \u2014 frontend/src/views/index/Attachment.vue:23", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/views/index/Attachment.vue:23"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-df82ef8a12c84162", "name": "Stray `console.log` in TS/JS \u2014 frontend/src/views/user/UserMailBox.vue:44", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/views/user/UserMailBox.vue:44"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-13e9da4bc92a205e", "name": "Stray `console.log` in TS/JS \u2014 frontend/src/views/user/AddressManagement.vue:37", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/views/user/AddressManagement.vue:37"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-849f99baad9b4443", "name": "Stray `console.log` in TS/JS \u2014 worker/src/scheduled.ts:9", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/src/scheduled.ts:9"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-423d57e3098593ae", "name": "Stray `console.log` in TS/JS \u2014 worker/src/utils.ts:409", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/src/utils.ts:409"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-993292cc7445688a", "name": "Stray `console.log` in TS/JS \u2014 worker/src/common.ts:473", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/src/common.ts:473"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-50d9fad9b4755aa5", "name": "Stray `console.log` in TS/JS \u2014 worker/src/admin_api/cleanup_api.ts:84", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/src/admin_api/cleanup_api.ts:84"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8c4c9a698b4e3ad6", "name": "Stray `console.log` in TS/JS \u2014 worker/src/email/index.ts:21", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/src/email/index.ts:21"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c9ce6a7708b64d6e", "name": "Stray `console.log` in TS/JS \u2014 worker/src/email/auto_reply.ts:38", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/src/email/auto_reply.ts:38"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4f96bbfc46b34af5", "name": "Stray `console.log` in TS/JS \u2014 worker/src/email/ai_extract.ts:275", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/src/email/ai_extract.ts:275"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3c0410a4a7e1e1a1", "name": "Stray `console.log` in TS/JS \u2014 worker/src/mails_api/send_mail_api.ts:102", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/src/mails_api/send_mail_api.ts:102"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5450797292e6c16a", "name": "TODO/FIXME marker in shipping code \u2014 worker/src/mails_api/mails_crud.ts:40", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 worker/src/mails_api/mails_crud.ts:40"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b5235d729df04a1e", "name": "TODO/FIXME marker in shipping code \u2014 worker/src/user_api/user.ts:202", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 worker/src/user_api/user.ts:202"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a751249b772c91c9", "name": "Stray `console.log` in TS/JS \u2014 worker/src/telegram_api/index.ts:54", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/src/telegram_api/index.ts:54"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2ec92c136faeb8f3", "name": "Stray `console.log` in TS/JS \u2014 worker/src/telegram_api/tg_file_upload.ts:12", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/src/telegram_api/tg_file_upload.ts:12"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-de37460735eeb1f5", "name": "Stray `console.log` in TS/JS \u2014 worker/src/telegram_api/common.ts:80", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/src/telegram_api/common.ts:80"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-363c50c894d645ce", "name": "Stray `console.log` in TS/JS \u2014 worker/src/telegram_api/telegram.ts:419", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/src/telegram_api/telegram.ts:419"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-13af2157ed0afcb3", "name": "GHSA-c2j3-45gr-mqc4: dompurify 3.4.11 \u2014 frontend/pnpm-lock.yaml", "shortDescription": {"text": "GHSA-c2j3-45gr-mqc4: dompurify 3.4.11 \u2014 frontend/pnpm-lock.yaml"}, "fullDescription": {"text": "DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.\n\n## Summary\n\nThere is a possible hook-policy inconsistency in DOMPurify 3.4.11 involving `CUSTOM_ELEMENT_HANDLING`.\n\nWhen a custom element is allowed via `CUSTOM_ELEMENT_HANDLING.tagNameCheck`, it appears that the element does not go through `afterSanitizeElements` in the same way as a normal element. As a result, an application that relies on `afterSanitizeElements` as a security policy layer to strip sensitive attributes from all elements may see those attributes removed from normal elements bu\n\nPackage: dompurify\nInstalled: 3.4.11\nFixed in: 3.4.12\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8b1daa248b301633", "name": "CVE-2026-25896: fast-xml-parser 5.2.5 \u2014 worker/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-25896: fast-xml-parser 5.2.5 \u2014 worker/pnpm-lock.yaml"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling\n\nfast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (&lt;, &gt;, &amp;, &quot;, &apos;) with arbitrary values. This bypasses entity encoding and leads to XSS when parsed output is rendered. This vulnerability is fixed in 5.3.5.\n\nPackage: fast-xml-parser\nInstalled: 5.2.5\nFixed in: 5.3.5, 4.5.4\nSeverity: CRITICAL\nFix: Upgrade fast-xml-parser to 5.3.5, 4.5.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-f57ae428d9e02736", "name": "CVE-2026-25128: fast-xml-parser 5.2.5 \u2014 worker/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-25128: fast-xml-parser 5.2.5 \u2014 worker/pnpm-lock.yaml"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser has RangeError DoS Numeric Entities Bug\n\nfast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 5.0.9 through 5.3.3, a RangeError vulnerability exists in the numeric entity processing of fast-xml-parser when parsing XML with out-of-range entity code points (e.g., `&#9999999;` or `&#xFFFFFF;`). This causes the parser to throw an uncaught exception, crashing any application that processes untrusted XML input. Version 5.3.4 fixes the issu\n\nPackage: fast-xml-parser\nInstalled: 5.2.5\nFixed in: 5.3.4\nSeverity: HIGH\nFix: Upgrade fast-xml-parser to 5.3.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a11eba3bd5565198", "name": "CVE-2026-26278: fast-xml-parser 5.2.5 \u2014 worker/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-26278: fast-xml-parser 5.2.5 \u2014 worker/pnpm-lock.yaml"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansion\n\nfast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of entity expansion. With a very small XML input, it\u2019s possible to make the parser spend seconds or even minutes processing a single request, effectively freezing the application. Version 5.3.6 fixes the issue. As a workaround, avoid using DOCTYPE parsing by `process\n\nPackage: fast-xml-parser\nInstalled: 5.2.5\nFixed in: 4.5.4, 5.3.6\nSeverity: HIGH\nFix: Upgrade fast-xml-parser to 4.5.4, 5.3.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-71fc735cfa250c3c", "name": "CVE-2026-33036: fast-xml-parser 5.2.5 \u2014 worker/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-33036: fast-xml-parser 5.2.5 \u2014 worker/pnpm-lock.yaml"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser: Denial of Service via XML entity expansion bypass\n\nfast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Versions 4.0.0-beta.3 through 5.5.5 contain a bypass vulnerability where numeric character references (&#NNN;, &#xHH;) and standard XML entities completely evade the entity expansion limits (e.g., maxTotalExpansions, maxExpandedLength) added to fix CVE-2026-26278, enabling XML entity expansion Denial of Service. The root cause is that replaceEntitiesValue() in OrderedObjParser.js only enforces \n\nPackage: fast-xml-parser\nInstalled: 5.2.5\nFixed in: 5.5.6, 4.5.5\nSeverity: HIGH\nFix: Upgrade fast-xml-parser to 5.5.6, 4.5.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2e9e1af78b98866d", "name": "CVE-2026-33349: fast-xml-parser 5.2.5 \u2014 worker/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-33349: fast-xml-parser 5.2.5 \u2014 worker/pnpm-lock.yaml"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser: Denial of Service via unbounded entity expansion due to incorrect configuration limit handling\n\nfast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0.0-beta.3 to before version 5.5.7, the DocTypeReader in fast-xml-parser uses JavaScript truthy checks to evaluate maxEntityCount and maxEntitySize configuration limits. When a developer explicitly sets either limit to 0 \u2014 intending to disallow all entities or restrict entity size to zero bytes \u2014 the falsy nature of 0 in JavaScript causes the guard conditions to short-circuit, co\n\nPackage: fast-xml-parser\nInstalled: 5.2.5\nFixed in: 4.5.5, 5.5.7\nSeverity: MEDIUM\nFix: Upgrade fast-xml-parser to 4.5.5, 5.5.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e058f72fa92dc423", "name": "CVE-2026-41650: fast-xml-parser 5.2.5 \u2014 worker/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41650: fast-xml-parser 5.2.5 \u2014 worker/pnpm-lock.yaml"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser: XML injection via improper escaping of comment and CDATA sequences\n\nfast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version 5.7.0, XMLBuilder does not escape the \"-->\" sequence in comment content or the \"]]>\" sequence in CDATA sections when building XML from JavaScript objects. This allows XML injection when user-controlled data flows into comments or CDATA elements, leading to XSS, SOAP injection, or data manipulation. This issue has been patched in version 5.7.0.\n\nPackage: fast-xml-parser\nInstalled: 5.2.5\nFixed in: 5.7.0\nSeverity: MEDIUM\nFix: Upgrade fast-xml-parser to 5.7.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-54e3f33366db739f", "name": "CVE-2026-27942: fast-xml-parser 5.2.5 \u2014 worker/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-27942: fast-xml-parser 5.2.5 \u2014 worker/pnpm-lock.yaml"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser: Stack overflow leads to Denial of Service\n\nfast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the application crashes with stack overflow when user use XML builder with `preserveOrder:true`. Version 5.3.8 fixes the issue. As a workaround, use XML builder with `preserveOrder:false` or check the input data before passing to builder.\n\nPackage: fast-xml-parser\nInstalled: 5.2.5\nFixed in: 5.3.8, 4.5.4\nSeverity: LOW\nFix: Upgrade fast-xml-parser to 5.3.8, 4.5.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-911760a135c17723", "name": "CVE-2026-41907: uuid 9.0.1 \u2014 worker/pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41907: uuid 9.0.1 \u2014 worker/pnpm-lock.yaml"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 9.0.1\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-abdf8ffff8a53bfd", "name": "DS-0002: Image user should not be 'root' \u2014 e2e/Dockerfile.e2e", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 e2e/Dockerfile.e2e"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: e2e/Dockerfile.e2e"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2958d920a759518f", "name": "DS-0026: No HEALTHCHECK defined \u2014 e2e/Dockerfile.e2e", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 e2e/Dockerfile.e2e"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: e2e/Dockerfile.e2e"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-30ba2cb3625cd87c", "name": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 e2e/Dockerfile.e2e", "shortDescription": {"text": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 e2e/Dockerfile.e2e"}, "fullDescription": {"text": "'apt-get' missing '--no-install-recommends'\n\n'--no-install-recommends' flag is missed: 'apt-get update && apt-get install -y curl netcat-openbsd && rm -rf /var/lib/apt/lists/*'\n\nRule: DS-0029\nSeverity: HIGH\nTarget: e2e/Dockerfile.e2e"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e2cb0c151718c884", "name": "DS-0002: Image user should not be 'root' \u2014 e2e/Dockerfile.frontend", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 e2e/Dockerfile.frontend"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: e2e/Dockerfile.frontend"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-628262edcfb88c1f", "name": "DS-0026: No HEALTHCHECK defined \u2014 e2e/Dockerfile.frontend", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 e2e/Dockerfile.frontend"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: e2e/Dockerfile.frontend"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ad514955c7a246d3", "name": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 e2e/Dockerfile.frontend", "shortDescription": {"text": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 e2e/Dockerfile.frontend"}, "fullDescription": {"text": "'apt-get' missing '--no-install-recommends'\n\n'--no-install-recommends' flag is missed: 'apt-get update && apt-get install -y openssl && rm -rf /var/lib/apt/lists/*'\n\nRule: DS-0029\nSeverity: HIGH\nTarget: e2e/Dockerfile.frontend"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8de7e2facdfaf627", "name": "DS-0002: Image user should not be 'root' \u2014 e2e/Dockerfile.worker", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 e2e/Dockerfile.worker"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: e2e/Dockerfile.worker"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-885f2050cc394bb4", "name": "DS-0026: No HEALTHCHECK defined \u2014 e2e/Dockerfile.worker", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 e2e/Dockerfile.worker"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: e2e/Dockerfile.worker"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-02b4497c73e84ed8", "name": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 e2e/Dockerfile.worker", "shortDescription": {"text": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 e2e/Dockerfile.worker"}, "fullDescription": {"text": "'apt-get' missing '--no-install-recommends'\n\n'--no-install-recommends' flag is missed: 'apt-get update && apt-get install -y curl && rm -rf /var/lib/apt/lists/*'\n\nRule: DS-0029\nSeverity: HIGH\nTarget: e2e/Dockerfile.worker"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-92cafc9e1b52dc81", "name": "Agent instruction contains unpinned remote install: .claude/skills/cf-temp-mail-release-notify/SKILL.md", "shortDescription": {"text": "Agent instruction contains unpinned remote install: .claude/skills/cf-temp-mail-release-notify/SKILL.md"}, "fullDescription": {"text": "Remote install commands in agent instructions are a supply-chain risk, especially when an agent can execute shell commands."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-baccb0bd5c74f971", "name": "SkillSpector E1 (data-exfil) in skills/cf-temp-mail-agent-mail/SKILL.md", "shortDescription": {"text": "SkillSpector E1 (data-exfil) in skills/cf-temp-mail-agent-mail/SKILL.md"}, "fullDescription": {"text": "curl -s -X POST \"$BASE/api/send_mail\" \\\n  -H \"Authorization: Bearer $JWT\" \\\n  -H \"Content-Type: application/json\" \\\n  -d\n\nData is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.\n\nSkill: cf-temp-mail-agent-mail\nRule: E1  Category: data-exfil\nSeverity: MEDIUM  Confidence: 0.60\n\nRemediation: Verify the destination URL is trusted and necessary. Remove or replace with documented APIs. Ensure no secrets, tokens, or PII are transmitted."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.6}}, {"id": "scanner-fd6812afc3a7b462", "name": "SkillSpector RA2 (rogue-agent) in skills/cf-temp-mail-agent-mail/SKILL.md", "shortDescription": {"text": "SkillSpector RA2 (rogue-agent) in skills/cf-temp-mail-agent-mail/SKILL.md"}, "fullDescription": {"text": "create or log into a mailbox address. This step may require passing a Turnstile CAPTCHA that agents cannot complete. After that, the **Address JWT** is displayed in the frontend UI and can be copied d\n\nSkill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.\n\nSkill: cf-temp-mail-agent-mail\nRule: RA2  Category: rogue-agent\nSeverity: MEDIUM  Confidence: 0.60\n\nRemediation: Remove any persistence mechanisms (cron jobs, startup scripts, state files). Skills should not maintain state across sessions without explicit user consent."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.6}}, {"id": "scanner-184f66595329d628", "name": "SkillSpector AST4 (behavioral-ast) in .claude/skills/cf-temp-mail-release-notify/scripts/send_release_to_telegram.py", "shortDescription": {"text": "SkillSpector AST4 (behavioral-ast) in .claude/skills/cf-temp-mail-release-notify/scripts/send_release_to_telegram.py"}, "fullDescription": {"text": "out = subprocess.run(\n        [\"gh\", \"release\", \"view\", tag, \"--json\", \"tagName,name,body,url\"],\n        capture_output=True, text=True, check=False,\n    )\n\nsubprocess module calls execute external commands. Without careful input validation, this enables command injection.\n\nSkill: cf-temp-mail-release-notify\nRule: AST4  Category: behavioral-ast\nSeverity: MEDIUM  Confidence: 0.60\n\nRemediation: Use subprocess.run() with shell=False and an explicit argument list. Validate all inputs and avoid passing user-controlled data to commands."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.6}}, {"id": "scanner-4c887dd4fdfecb8b", "name": "SkillSpector LP3 (mcp-least-priv) in .claude/skills/cf-temp-mail-release-notify/SKILL.md", "shortDescription": {"text": "SkillSpector LP3 (mcp-least-priv) in .claude/skills/cf-temp-mail-release-notify/SKILL.md"}, "fullDescription": {"text": "MCP Least Privilege\n\nWithout declared permissions the skill's intent is opaque and cannot be validated.\n\nSkill: cf-temp-mail-release-notify\nRule: LP3  Category: mcp-least-priv\nSeverity: MEDIUM  Confidence: 0.70\n\nRemediation: Add a 'permissions' field to SKILL.md listing the capabilities this skill requires."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-523177d2e7851d72", "name": "SkillSpector OH1 (output-handling) in .claude/skills/cf-temp-mail-release-notify/scripts/send_release_to_telegram.py", "shortDescription": {"text": "SkillSpector OH1 (output-handling) in .claude/skills/cf-temp-mail-release-notify/scripts/send_release_to_telegram.py"}, "fullDescription": {"text": "subprocess.run(\n        [\"gh\", \"release\", \"view\", tag, \"--json\", \"tagName,name,body,url\"],\n        capture_output\n\nModel output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.\n\nSkill: cf-temp-mail-release-notify\nRule: OH1  Category: output-handling\nSeverity: HIGH  Confidence: 0.95\n\nRemediation: Validate and sanitize all model output before using it in downstream contexts. Use parameterized queries for SQL, shell quoting for commands, and HTML encoding for web output."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.95}}, {"id": "scanner-1523aec9791f6435", "name": "SkillSpector SC2 (supply-chain) in .claude/skills/cf-temp-mail-release-notify/SKILL.md", "shortDescription": {"text": "SkillSpector SC2 (supply-chain) in .claude/skills/cf-temp-mail-release-notify/SKILL.md"}, "fullDescription": {"text": "curl -LsSf https://astral.sh/uv/install.sh | sh\n\nRemote code is downloaded and executed. This bypasses code review and could introduce malicious code.\n\nSkill: cf-temp-mail-release-notify\nRule: SC2  Category: supply-chain\nSeverity: LOW  Confidence: 0.15\n\nRemediation: Avoid downloading and executing remote scripts. Use trusted packages from PyPI/npm. If remote fetch is required, verify checksums and use HTTPS."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.15}}, {"id": "scanner-e637c415447867e4", "name": "Run SkillSpector's LLM-backed analysis in your own pipeline", "shortDescription": {"text": "Run SkillSpector's LLM-backed analysis in your own pipeline"}, "fullDescription": {"text": "Repobility ran SkillSpector's static rules server-side. The deeper LLM-backed analyzers \u2014 tool-poisoning (TP*), semantic security discovery (SSD*), developer-intent mismatch (SDI*) \u2014 are meant to run on YOUR machine with YOUR model; repobility never sends your code to an LLM. Recipe:\n\n# 1. Install SkillSpector in your own isolated env\npipx install \"skillspector @ git+https://github.com/NVIDIA/SkillSpector.git\"\n\n# 2. Point it at YOUR LLM pipeline (pick one) - your code stays on your machine\nexport SKILLSPECTOR_PROVIDER=anthropic && export ANTHROPIC_API_KEY=sk-ant-...\n# export SKILLSPECTOR_PROVIDER=openai   && export OPENAI_API_KEY=sk-...\n# export SKILLSPECTOR_PROVIDER=openai OPENAI_API_KEY=ollama OPENAI_BASE_URL=http://localhost:11434/v1 SKILLSPECTOR_MODEL=llama3.1:8b\n# export SKILLSPECTOR_PROVIDER=nv_build && export NVIDIA_INFERENCE_KEY=nvapi-...\n\n# 3. Run the LLM-backed scan per skill (omit --no-llm to enable the LLM analyzers)\nskillspector scan skills/cf-temp-mail-agent-mail --format"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5aa14659cf62526f", "name": "Runtime dotenv file present in repo: frontend/.env.pages", "shortDescription": {"text": "Runtime dotenv file present in repo: frontend/.env.pages"}, "fullDescription": {"text": "`frontend/.env.pages` looks like a runtime dotenv file. No high-confidence secret value was matched, but runtime dotenv files often drift into live credentials. Move real values to a secret manager and keep only `.env.example` style templates in source control."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-c4260abb09461c56", "name": "Insecure pattern 'direct_innerhtml_assignment' in frontend/src/components/ShadowHtmlComponent.vue:53", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in frontend/src/components/ShadowHtmlComponent.vue:53"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-021697c5c90a65cb", "name": "Insecure pattern 'vue_v_html' in frontend/src/components/ShadowHtmlComponent.vue:2", "shortDescription": {"text": "Insecure pattern 'vue_v_html' in frontend/src/components/ShadowHtmlComponent.vue:2"}, "fullDescription": {"text": "Found a known-risky pattern (vue_v_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-bfa10fac8f24be40", "name": "Insecure pattern 'vue_v_html' in frontend/src/components/SendBox.vue:276", "shortDescription": {"text": "Insecure pattern 'vue_v_html' in frontend/src/components/SendBox.vue:276"}, "fullDescription": {"text": "Found a known-risky pattern (vue_v_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-b6a93fdba5645236", "name": "Insecure pattern 'vue_v_html' in frontend/src/views/common/About.vue:10", "shortDescription": {"text": "Insecure pattern 'vue_v_html' in frontend/src/views/common/About.vue:10"}, "fullDescription": {"text": "Found a known-risky pattern (vue_v_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-a8e40047059fc300", "name": "Possible secret in frontend/src/views/admin/CreateAccount.vue", "shortDescription": {"text": "Possible secret in frontend/src/views/admin/CreateAccount.vue"}, "fullDescription": {"text": "Detected 1 occurrence(s) matching password_literal. Rotate real credentials and move them to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.58}}, {"id": "scanner-81b92103b3c32336", "name": "Insecure pattern 'vue_v_html' in frontend/src/views/admin/UserOauth2Settings.vue:179", "shortDescription": {"text": "Insecure pattern 'vue_v_html' in frontend/src/views/admin/UserOauth2Settings.vue:179"}, "fullDescription": {"text": "Found a known-risky pattern (vue_v_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-58fb4bb10c6fd75f", "name": "Insecure pattern 'direct_innerhtml_assignment' in frontend/src/views/admin/SendMail.vue:49", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in frontend/src/views/admin/SendMail.vue:49"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-1b8005a9ccd0d323", "name": "Insecure pattern 'vue_v_html' in frontend/src/views/admin/SendMail.vue:183", "shortDescription": {"text": "Insecure pattern 'vue_v_html' in frontend/src/views/admin/SendMail.vue:183"}, "fullDescription": {"text": "Found a known-risky pattern (vue_v_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-9a7061198416a070", "name": "Possible secret in frontend/src/views/index/AddressBar.vue", "shortDescription": {"text": "Possible secret in frontend/src/views/index/AddressBar.vue"}, "fullDescription": {"text": "Detected 1 occurrence(s) matching password_literal. Rotate real credentials and move them to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.58}}, {"id": "scanner-a7fbc07279891bf7", "name": "Insecure pattern 'direct_innerhtml_assignment' in frontend/src/views/index/SendMail.vue:44", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in frontend/src/views/index/SendMail.vue:44"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-0ba16b0904f5c1b0", "name": "Insecure pattern 'vue_v_html' in frontend/src/views/index/SendMail.vue:206", "shortDescription": {"text": "Insecure pattern 'vue_v_html' in frontend/src/views/index/SendMail.vue:206"}, "fullDescription": {"text": "Found a known-risky pattern (vue_v_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-e5f8a19bdd6c5f3a", "name": "Insecure pattern 'vue_v_html' in frontend/src/views/user/UserLogin.vue:210", "shortDescription": {"text": "Insecure pattern 'vue_v_html' in frontend/src/views/user/UserLogin.vue:210"}, "fullDescription": {"text": "Found a known-risky pattern (vue_v_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-f0d335d7b8dddbb9", "name": "Insecure pattern 'cors_wildcard' in worker/src/worker.ts:31", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in worker/src/worker.ts:31"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-edf004534a1d6cc3", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cef20eb037ed675b", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-13be22ba5c4cc750", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-87844b112e00597b", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e1733b99f89dec51", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2747252967b56857", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4fb027b1aa6e08d1", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9c1aced86dabc7c0", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-65c9bd56493a81d3", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/upload-artifact@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-de1cb5bf057f8e10", "name": "GitHub Action tracks a moving branch", "shortDescription": {"text": "GitHub Action tracks a moving branch"}, "fullDescription": {"text": "qodo-ai/pr-agent@main can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bbd7b12427dd8d2c", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4990c9c3fe3c9c5a", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "docker/login-action@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-053a2e3dc43e8119", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d0b820547b2ea1a0", "name": "Very large file: frontend/src/i18n/message-registry.ts (2591 lines)", "shortDescription": {"text": "Very large file: frontend/src/i18n/message-registry.ts (2591 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1cb907756974e99e", "name": "Node manifest has dependencies but no lockfile: pages/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: pages/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 33 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing lockfile. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-be60ebffd923acf8", "name": "`fetch()` without try/.catch or AbortSignal \u2014 worker/src/utils.ts:439", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/src/utils.ts:439"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9e2605727e2aab44", "name": "Commented-code block (19 lines) in worker/src/common.ts:705", "shortDescription": {"text": "Commented-code block (19 lines) in worker/src/common.ts:705"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f33da899d71907a9", "name": "`fetch()` without try/.catch or AbortSignal \u2014 worker/src/common.ts:796", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/src/common.ts:796"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-69bb2600fdf0283e", "name": "`fetch()` without try/.catch or AbortSignal \u2014 worker/src/worker.ts:46", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/src/worker.ts:46"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c610c12b2a06235e", "name": "`fetch()` without try/.catch or AbortSignal \u2014 worker/src/user_api/oauth2.ts:40", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/src/user_api/oauth2.ts:40"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-152a713178dd7822", "name": "`fetch()` without try/.catch or AbortSignal \u2014 worker/src/telegram_api/tg_file_upload.ts:37", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/src/telegram_api/tg_file_upload.ts:37"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dbfab12a4a7cc804", "name": "`fetch()` without try/.catch or AbortSignal \u2014 worker/src/telegram_api/telegram.ts:503", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/src/telegram_api/telegram.ts:503"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0f425fd0abb8e6d6", "name": "`fetch()` without try/.catch or AbortSignal \u2014 pages/functions/_middleware.js:13", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 pages/functions/_middleware.js:13"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-109ccba5fd984a0d", "name": "Network/subprocess call without timeout or try/except \u2014 .claude/skills/cf-temp-mail-release-notify/scripts/send_release_", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 .claude/skills/cf-temp-mail-release-notify/scripts/send_release_to_telegram.py:93"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-891a3f8d90901a4e", "name": "Stub function `destroy` (body is just `pass`/`return`) \u2014 smtp_proxy_server/imap_mailbox.py:84", "shortDescription": {"text": "Stub function `destroy` (body is just `pass`/`return`) \u2014 smtp_proxy_server/imap_mailbox.py:84"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be4b0dae2e7a2d7a", "name": "Blocking `httpx.post(...)` inside `async def handle_DATA` \u2014 smtp_proxy_server/smtp_server.py:116", "shortDescription": {"text": "Blocking `httpx.post(...)` inside `async def handle_DATA` \u2014 smtp_proxy_server/smtp_server.py:116"}, "fullDescription": {"text": "Sync I/O inside an async function blocks the event loop. While `httpx.post(...)` is running, *all* other coroutines on this loop are paused \u2014 silent throughput collapse under concurrency. Use the async equivalent (`httpx.AsyncClient`, `asyncio.sleep`, `aiofiles`) or wrap with `await asyncio.to_thread(...)`."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "high", "confidence": 1.0}}, {"id": "scanner-250f57e8a1dbd3c5", "name": "4 env vars used in code but missing from .env.example", "shortDescription": {"text": "4 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `FRONTEND_URL`, `PACKAGE_VERSION`, `WORKER_GZIP_URL`, `WORKER_URL`. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nsmtp_proxy_server/imap_mailbox.py:getUIDValidity, smtp_proxy_server/imap_mailbox.py:getUID\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d62b55978491e2db", "name": "JS POST `/admin/new_address` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:26", "shortDescription": {"text": "JS POST `/admin/new_address` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:26"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4226085a692f1c56", "name": "JS DELETE `/admin/delete_address/:id` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:27", "shortDescription": {"text": "JS DELETE `/admin/delete_address/:id` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:27"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8733dc32b11efe6b", "name": "JS DELETE `/admin/clear_inbox/:id` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:28", "shortDescription": {"text": "JS DELETE `/admin/clear_inbox/:id` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:28"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f7242b360a35bb58", "name": "JS DELETE `/admin/clear_sent_items/:id` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:29", "shortDescription": {"text": "JS DELETE `/admin/clear_sent_items/:id` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:29"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e57b9cc56dcccb1d", "name": "JS POST `/admin/address/:id/reset_password` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:31", "shortDescription": {"text": "JS POST `/admin/address/:id/reset_password` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:31"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b392ecb70b339017", "name": "JS DELETE `/admin/mails/:id` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:36", "shortDescription": {"text": "JS DELETE `/admin/mails/:id` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:36"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1b5197f658fe775c", "name": "JS POST `/admin/address_sender` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:40", "shortDescription": {"text": "JS POST `/admin/address_sender` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:40"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1e020d61532b1753", "name": "JS DELETE `/admin/address_sender/:id` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:41", "shortDescription": {"text": "JS DELETE `/admin/address_sender/:id` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:41"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b5c3074d4907cd8a", "name": "JS DELETE `/admin/sendbox/:id` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:45", "shortDescription": {"text": "JS DELETE `/admin/sendbox/:id` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:45"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8de3ca774fa4d72a", "name": "JS POST `/admin/account_settings` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:52", "shortDescription": {"text": "JS POST `/admin/account_settings` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:52"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-64dae13f38b14acf", "name": "JS POST `/admin/cleanup` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:55", "shortDescription": {"text": "JS POST `/admin/cleanup` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:55"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3fed96a8c7e416c6", "name": "JS POST `/admin/auto_cleanup` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:57", "shortDescription": {"text": "JS POST `/admin/auto_cleanup` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:57"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a7f17ac0e5a66436", "name": "JS POST `/admin/user_roles` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:67", "shortDescription": {"text": "JS POST `/admin/user_roles` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:67"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-04b1b22c5de5b845", "name": "JS POST `/admin/role_address_config` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:69", "shortDescription": {"text": "JS POST `/admin/role_address_config` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:69"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f1cf3ffcb0e30762", "name": "JS POST `/admin/users/bind_address` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:71", "shortDescription": {"text": "JS POST `/admin/users/bind_address` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:71"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b12bf0fd94c6cbfe", "name": "JS POST `/admin/user_oauth2_settings` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:75", "shortDescription": {"text": "JS POST `/admin/user_oauth2_settings` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:75"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1d169fa98d75018b", "name": "JS POST `/admin/webhook/settings` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:79", "shortDescription": {"text": "JS POST `/admin/webhook/settings` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:79"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d8fac49ff55dbc10", "name": "JS POST `/admin/mail_webhook/settings` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:83", "shortDescription": {"text": "JS POST `/admin/mail_webhook/settings` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:83"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-28ca8657f9215025", "name": "JS POST `/admin/mail_webhook/test` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:84", "shortDescription": {"text": "JS POST `/admin/mail_webhook/test` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:84"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2ac04ade8f6fd008", "name": "JS POST `/admin/send_mail` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:90", "shortDescription": {"text": "JS POST `/admin/send_mail` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:90"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-25d89bf2bcbadc6b", "name": "JS POST `/admin/send_mail_by_binding` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:91", "shortDescription": {"text": "JS POST `/admin/send_mail_by_binding` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:91"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-83067bda8005e23b", "name": "JS POST `/admin/ip_blacklist/settings` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:100", "shortDescription": {"text": "JS POST `/admin/ip_blacklist/settings` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:100"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ca5a5020e46b26b7", "name": "JS POST `/admin/ai_extract/settings` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:104", "shortDescription": {"text": "JS POST `/admin/ai_extract/settings` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:104"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-586e454e111c9df6", "name": "JS POST `/admin/test/seed_mail` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:107", "shortDescription": {"text": "JS POST `/admin/test/seed_mail` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:107"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b7f21337dcd25ebf", "name": "JS POST `/admin/test/receive_mail` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:108", "shortDescription": {"text": "JS POST `/admin/test/receive_mail` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:108"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c922424c0d2d913b", "name": "JS POST `/admin/telegram/init` admin endpoint without auth \u2014 worker/src/telegram_api/index.ts:50", "shortDescription": {"text": "JS POST `/admin/telegram/init` admin endpoint without auth \u2014 worker/src/telegram_api/index.ts:50"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-782f38f0a7803380", "name": "JS POST `/admin/telegram/settings` admin endpoint without auth \u2014 worker/src/telegram_api/index.ts:72", "shortDescription": {"text": "JS POST `/admin/telegram/settings` admin endpoint without auth \u2014 worker/src/telegram_api/index.ts:72"}, "fullDescription": {"text": "Admin-scoped JS route with no recognizable auth: no middleware-position guard, no router-level guard above it in this file, and no inline permission call within the first 15 lines of the handler. If auth is applied where this router is mounted, dismiss with reason `by_design` or tag the route `// public-by-design`."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e32f2a37d0d026fe", "name": "Vulnerable dependency ws 8.19.0: GHSA-58qx-3vcg-4xpx", "shortDescription": {"text": "Vulnerable dependency ws 8.19.0: GHSA-58qx-3vcg-4xpx"}, "fullDescription": {"text": "OSV.dev reports `ws` at version `8.19.0` (resolved in `e2e/package-lock.json`) is affected by GHSA-58qx-3vcg-4xpx (aka CVE-2026-45736).\n\nws: Uninitialized memory disclosure\n\nAliases: CVE-2026-45736\nAdvisory: https://osv.dev/vulnerability/GHSA-58qx-3vcg-4xpx\nFix: upgrade `ws` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-f3ae3aa9231d3a92", "name": "Vulnerable dependency ws 8.19.0: GHSA-96hv-2xvq-fx4p", "shortDescription": {"text": "Vulnerable dependency ws 8.19.0: GHSA-96hv-2xvq-fx4p"}, "fullDescription": {"text": "OSV.dev reports `ws` at version `8.19.0` (resolved in `e2e/package-lock.json`) is affected by GHSA-96hv-2xvq-fx4p (aka CVE-2026-48779).\n\nws: Memory exhaustion DoS from tiny fragments and data chunks\n\nAliases: CVE-2026-48779\nAdvisory: https://osv.dev/vulnerability/GHSA-96hv-2xvq-fx4p\nFix: upgrade `ws` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-ff41bdfbb2e4fc86", "name": "Vulnerable dependency dompurify 3.4.11: GHSA-c2j3-45gr-mqc4", "shortDescription": {"text": "Vulnerable dependency dompurify 3.4.11: GHSA-c2j3-45gr-mqc4"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.4.11` (resolved in `frontend/pnpm-lock.yaml`) is affected by GHSA-c2j3-45gr-mqc4.\n\nDOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-c2j3-45gr-mqc4\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-22f63597718494d2", "name": "Vulnerable dependency vite 5.4.21: GHSA-4w7w-66w2-5vf9", "shortDescription": {"text": "Vulnerable dependency vite 5.4.21: GHSA-4w7w-66w2-5vf9"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `5.4.21` (resolved in `vitepress-docs/pnpm-lock.yaml`) is affected by GHSA-4w7w-66w2-5vf9 (aka CVE-2026-39365).\n\nVite Vulnerable to Path Traversal in Optimized Deps `.map` Handling\n\nAliases: CVE-2026-39365\nAdvisory: https://osv.dev/vulnerability/GHSA-4w7w-66w2-5vf9\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9e70152493820fa4", "name": "Vulnerable dependency vite 5.4.21: GHSA-fx2h-pf6j-xcff", "shortDescription": {"text": "Vulnerable dependency vite 5.4.21: GHSA-fx2h-pf6j-xcff"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `5.4.21` (resolved in `vitepress-docs/pnpm-lock.yaml`) is affected by GHSA-fx2h-pf6j-xcff (aka CVE-2026-53571).\n\nvite: `server.fs.deny` bypass on Windows alternate paths\n\nAliases: CVE-2026-53571\nAdvisory: https://osv.dev/vulnerability/GHSA-fx2h-pf6j-xcff\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b62ee8a5a271cf0a", "name": "Vulnerable dependency vite 5.4.21: GHSA-v6wh-96g9-6wx3", "shortDescription": {"text": "Vulnerable dependency vite 5.4.21: GHSA-v6wh-96g9-6wx3"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `5.4.21` (resolved in `vitepress-docs/pnpm-lock.yaml`) is affected by GHSA-v6wh-96g9-6wx3 (aka CVE-2026-53632).\n\nlaunch-editor: NTLMv2 hash disclosure via UNC path handling on Windows\n\nAliases: CVE-2026-53632\nAdvisory: https://osv.dev/vulnerability/GHSA-v6wh-96g9-6wx3\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-90de3b604ee8cebc", "name": "Vulnerable dependency brace-expansion 2.1.1: GHSA-3jxr-9vmj-r5cp", "shortDescription": {"text": "Vulnerable dependency brace-expansion 2.1.1: GHSA-3jxr-9vmj-r5cp"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `2.1.1` (resolved in `frontend/pnpm-lock.yaml`) is affected by GHSA-3jxr-9vmj-r5cp (aka CVE-2026-13149).\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbrace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups\n\nAliases: CVE-2026-13149\nAdvisory: https://osv.dev/vulnerability/GHSA-3jxr-9vmj-r5cp\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-feb9ad299d6be074", "name": "Vulnerable dependency brace-expansion 5.0.6: GHSA-3jxr-9vmj-r5cp", "shortDescription": {"text": "Vulnerable dependency brace-expansion 5.0.6: GHSA-3jxr-9vmj-r5cp"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `5.0.6` (resolved in `frontend/pnpm-lock.yaml`) is affected by GHSA-3jxr-9vmj-r5cp (aka CVE-2026-13149).\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbrace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups\n\nAliases: CVE-2026-13149\nAdvisory: https://osv.dev/vulnerability/GHSA-3jxr-9vmj-r5cp\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-0044a7bcb37b461b", "name": "Vulnerable dependency esbuild 0.27.7: GHSA-g7r4-m6w7-qqqr", "shortDescription": {"text": "Vulnerable dependency esbuild 0.27.7: GHSA-g7r4-m6w7-qqqr"}, "fullDescription": {"text": "OSV.dev reports `esbuild` at version `0.27.7` (resolved in `frontend/pnpm-lock.yaml`) is affected by GHSA-g7r4-m6w7-qqqr.\nNote: `esbuild` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nesbuild allows arbitrary file read when running the development server on Windows\n\nAdvisory: https://osv.dev/vulnerability/GHSA-g7r4-m6w7-qqqr\nFix: upgrade `esbuild` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-38e2ece8fb1a2538", "name": "Vulnerable dependency fast-uri 3.1.2: GHSA-4c8g-83qw-93j6", "shortDescription": {"text": "Vulnerable dependency fast-uri 3.1.2: GHSA-4c8g-83qw-93j6"}, "fullDescription": {"text": "OSV.dev reports `fast-uri` at version `3.1.2` (resolved in `frontend/pnpm-lock.yaml`) is affected by GHSA-4c8g-83qw-93j6 (aka CVE-2026-13676).\nNote: `fast-uri` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nfast-uri vulnerable to host confusion via failed IDN canonicalization\n\nAliases: CVE-2026-13676\nAdvisory: https://osv.dev/vulnerability/GHSA-4c8g-83qw-93j6\nFix: upgrade `fast-uri` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-fb4791bf81cc5360", "name": "Vulnerable dependency fast-uri 3.1.2: GHSA-v2hh-gcrm-f6hx", "shortDescription": {"text": "Vulnerable dependency fast-uri 3.1.2: GHSA-v2hh-gcrm-f6hx"}, "fullDescription": {"text": "OSV.dev reports `fast-uri` at version `3.1.2` (resolved in `frontend/pnpm-lock.yaml`) is affected by GHSA-v2hh-gcrm-f6hx (aka CVE-2026-16221).\nNote: `fast-uri` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nfast-uri vulnerable to host confusion via literal backslash authority delimiter\n\nAliases: CVE-2026-16221\nAdvisory: https://osv.dev/vulnerability/GHSA-v2hh-gcrm-f6hx\nFix: upgrade `fast-uri` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-100b1a1830ea26ed", "name": "Dependency @unhead/vue is a major version behind", "shortDescription": {"text": "Dependency @unhead/vue is a major version behind"}, "fullDescription": {"text": "`@unhead/vue` is pinned at `2.1.15` in `frontend/package.json` while the latest release on the npm registry is `3.2.3` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@unhead/vue` to `3.2.3`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-5ea3bc7a603abc72", "name": "Dependency @wangeditor/editor-for-vue declares a version newer than the registry latest", "shortDescription": {"text": "Dependency @wangeditor/editor-for-vue declares a version newer than the registry latest"}, "fullDescription": {"text": "`@wangeditor/editor-for-vue` is declared at `5.1.12` in `frontend/package.json`, but the latest release currently visible on the npm registry is `1.0.2`. The declared major version is 4 major version(s) ahead of the registry. This often indicates a typo, a private fork assumption, or an AI-hallucinated package version that will break reproducible installs."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.4}}, {"id": "scanner-18e15032274486a1", "name": "Dependency vue-router is a major version behind", "shortDescription": {"text": "Dependency vue-router is a major version behind"}, "fullDescription": {"text": "`vue-router` is pinned at `4.6.4` in `frontend/package.json` while the latest release on the npm registry is `5.2.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `vue-router` to `5.2.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-cbb9e08da8060249", "name": "Dependency service-identity is two or more major versions behind", "shortDescription": {"text": "Dependency service-identity is two or more major versions behind"}, "fullDescription": {"text": "`service-identity` is pinned at `24.2.0` in `smtp_proxy_server/requirements.txt` while the latest release on the pypi registry is `26.1.0` \u2014 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `service-identity` to `26.1.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-78654bfc245e794c", "name": "Dangling fetch: POST https://api.telegram.org/bot${botToken}/sendMediaGroup (worker/src/telegram_api/tg_file_upload.ts:3", "shortDescription": {"text": "Dangling fetch: POST https://api.telegram.org/bot${botToken}/sendMediaGroup (worker/src/telegram_api/tg_file_upload.ts:37)"}, "fullDescription": {"text": "`worker/src/telegram_api/tg_file_upload.ts:37` calls `POST https://api.telegram.org/bot${botToken}/sendMediaGroup` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.telegram.org/bot/<p>/sendmediagroup`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3abf952b8d28d710", "name": "Unused endpoint: USE /*", "shortDescription": {"text": "Unused endpoint: USE /*"}, "fullDescription": {"text": "`worker/src/worker.ts` declares `USE /*` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b8073f7bf758f6d0", "name": "Unused endpoint: USE /api/*", "shortDescription": {"text": "Unused endpoint: USE /api/*"}, "fullDescription": {"text": "`worker/src/worker.ts` declares `USE /api/*` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ba965a5b35a8e884", "name": "Unused endpoint: USE /user_api/*", "shortDescription": {"text": "Unused endpoint: USE /user_api/*"}, "fullDescription": {"text": "`worker/src/worker.ts` declares `USE /user_api/*` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-48f839e5dc386ef9", "name": "Unused endpoint: USE /admin/*", "shortDescription": {"text": "Unused endpoint: USE /admin/*"}, "fullDescription": {"text": "`worker/src/worker.ts` declares `USE /admin/*` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`worker/src/worker.ts` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-933c0b014d21f21d", "name": "Unused endpoint: ALL /*", "shortDescription": {"text": "Unused endpoint: ALL /*"}, "fullDescription": {"text": "`worker/src/worker.ts` declares `ALL /*` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a39562f15dca4ac2", "name": "Unused endpoint: GET /admin/address", "shortDescription": {"text": "Unused endpoint: GET /admin/address"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `GET /admin/address` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ec5a6adfe87e7c13", "name": "Unused endpoint: POST /admin/new_address", "shortDescription": {"text": "Unused endpoint: POST /admin/new_address"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `POST /admin/new_address` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d01bc73d315ca837", "name": "Unused endpoint: DELETE /admin/delete_address/:id", "shortDescription": {"text": "Unused endpoint: DELETE /admin/delete_address/:id"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `DELETE /admin/delete_address/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4cc9f6b6a0cea78f", "name": "Unused endpoint: DELETE /admin/clear_inbox/:id", "shortDescription": {"text": "Unused endpoint: DELETE /admin/clear_inbox/:id"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `DELETE /admin/clear_inbox/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-34fe9b18932b0dd3", "name": "Unused endpoint: DELETE /admin/clear_sent_items/:id", "shortDescription": {"text": "Unused endpoint: DELETE /admin/clear_sent_items/:id"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `DELETE /admin/clear_sent_items/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ba58844b23b17302", "name": "Unused endpoint: GET /admin/show_password/:id", "shortDescription": {"text": "Unused endpoint: GET /admin/show_password/:id"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `GET /admin/show_password/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-08373199c0b1289a", "name": "Unused endpoint: POST /admin/address/:id/reset_password", "shortDescription": {"text": "Unused endpoint: POST /admin/address/:id/reset_password"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `POST /admin/address/:id/reset_password` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-822597617779ed24", "name": "Unused endpoint: GET /admin/mails", "shortDescription": {"text": "Unused endpoint: GET /admin/mails"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `GET /admin/mails` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c14a32ff3a00b0cf", "name": "Unused endpoint: GET /admin/mails_unknow", "shortDescription": {"text": "Unused endpoint: GET /admin/mails_unknow"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `GET /admin/mails_unknow` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f047ecee072c87ed", "name": "Unused endpoint: DELETE /admin/mails/:id", "shortDescription": {"text": "Unused endpoint: DELETE /admin/mails/:id"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `DELETE /admin/mails/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-80483c5203ceca55", "name": "Unused endpoint: GET /admin/address_sender", "shortDescription": {"text": "Unused endpoint: GET /admin/address_sender"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `GET /admin/address_sender` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fde7b4789031c99e", "name": "Unused endpoint: POST /admin/address_sender", "shortDescription": {"text": "Unused endpoint: POST /admin/address_sender"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `POST /admin/address_sender` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f507025a899d9d8e", "name": "Unused endpoint: DELETE /admin/address_sender/:id", "shortDescription": {"text": "Unused endpoint: DELETE /admin/address_sender/:id"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `DELETE /admin/address_sender/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-80a8029ab1e38c56", "name": "Unused endpoint: GET /admin/sendbox", "shortDescription": {"text": "Unused endpoint: GET /admin/sendbox"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `GET /admin/sendbox` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dc7a6fbb10249031", "name": "Unused endpoint: DELETE /admin/sendbox/:id", "shortDescription": {"text": "Unused endpoint: DELETE /admin/sendbox/:id"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `DELETE /admin/sendbox/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4f19f3685db95649", "name": "Unused endpoint: GET /admin/statistics", "shortDescription": {"text": "Unused endpoint: GET /admin/statistics"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `GET /admin/statistics` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-940650abfcf7db10", "name": "Unused endpoint: GET /admin/account_settings", "shortDescription": {"text": "Unused endpoint: GET /admin/account_settings"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `GET /admin/account_settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2083e8676561acce", "name": "Unused endpoint: POST /admin/account_settings", "shortDescription": {"text": "Unused endpoint: POST /admin/account_settings"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `POST /admin/account_settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8754601194d5f53c", "name": "Unused endpoint: POST /admin/cleanup", "shortDescription": {"text": "Unused endpoint: POST /admin/cleanup"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `POST /admin/cleanup` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ff5c9810be5826c7", "name": "Unused endpoint: GET /admin/auto_cleanup", "shortDescription": {"text": "Unused endpoint: GET /admin/auto_cleanup"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `GET /admin/auto_cleanup` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bfd3000ee7fc7791", "name": "Unused endpoint: POST /admin/auto_cleanup", "shortDescription": {"text": "Unused endpoint: POST /admin/auto_cleanup"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `POST /admin/auto_cleanup` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f656571ced0048f5", "name": "Unused endpoint: GET /admin/user_settings", "shortDescription": {"text": "Unused endpoint: GET /admin/user_settings"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `GET /admin/user_settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0f87c6e8df4fe86c", "name": "Unused endpoint: POST /admin/user_settings", "shortDescription": {"text": "Unused endpoint: POST /admin/user_settings"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `POST /admin/user_settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0aba7f1883cb96f2", "name": "Unused endpoint: GET /admin/users", "shortDescription": {"text": "Unused endpoint: GET /admin/users"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `GET /admin/users` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9fe091788c4b2bc0", "name": "Unused endpoint: DELETE /admin/users/:user_id", "shortDescription": {"text": "Unused endpoint: DELETE /admin/users/:user_id"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `DELETE /admin/users/:user_id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-31fd9c1bbfc177f4", "name": "Unused endpoint: POST /admin/users", "shortDescription": {"text": "Unused endpoint: POST /admin/users"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `POST /admin/users` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-394f80138c311b0d", "name": "Unused endpoint: POST /admin/users/:user_id/reset_password", "shortDescription": {"text": "Unused endpoint: POST /admin/users/:user_id/reset_password"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `POST /admin/users/:user_id/reset_password` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8fcb0611dbbaca99", "name": "Unused endpoint: GET /admin/user_roles", "shortDescription": {"text": "Unused endpoint: GET /admin/user_roles"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `GET /admin/user_roles` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cbe75cc29fa16b94", "name": "Unused endpoint: POST /admin/user_roles", "shortDescription": {"text": "Unused endpoint: POST /admin/user_roles"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `POST /admin/user_roles` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f1cbdac3b7b1cb6c", "name": "Unused endpoint: GET /admin/role_address_config", "shortDescription": {"text": "Unused endpoint: GET /admin/role_address_config"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `GET /admin/role_address_config` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1b89de2d2e48fda8", "name": "Unused endpoint: POST /admin/role_address_config", "shortDescription": {"text": "Unused endpoint: POST /admin/role_address_config"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `POST /admin/role_address_config` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-100e1d80dc87fe8c", "name": "Unused endpoint: GET /admin/users/bind_address/:user_id", "shortDescription": {"text": "Unused endpoint: GET /admin/users/bind_address/:user_id"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `GET /admin/users/bind_address/:user_id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1a373bd45abaf6b6", "name": "Unused endpoint: POST /admin/users/bind_address", "shortDescription": {"text": "Unused endpoint: POST /admin/users/bind_address"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `POST /admin/users/bind_address` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1436919efd7f5a99", "name": "Unused endpoint: GET /admin/user_oauth2_settings", "shortDescription": {"text": "Unused endpoint: GET /admin/user_oauth2_settings"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `GET /admin/user_oauth2_settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4e014007142cdfb5", "name": "Unused endpoint: POST /admin/user_oauth2_settings", "shortDescription": {"text": "Unused endpoint: POST /admin/user_oauth2_settings"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `POST /admin/user_oauth2_settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d00df48df172808b", "name": "Unused endpoint: GET /admin/webhook/settings", "shortDescription": {"text": "Unused endpoint: GET /admin/webhook/settings"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `GET /admin/webhook/settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-671e373a81ea081a", "name": "Unused endpoint: POST /admin/webhook/settings", "shortDescription": {"text": "Unused endpoint: POST /admin/webhook/settings"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `POST /admin/webhook/settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-85f8f8faee595ac4", "name": "Unused endpoint: GET /admin/mail_webhook/settings", "shortDescription": {"text": "Unused endpoint: GET /admin/mail_webhook/settings"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `GET /admin/mail_webhook/settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8cb08d9f5dc63621", "name": "Unused endpoint: POST /admin/mail_webhook/settings", "shortDescription": {"text": "Unused endpoint: POST /admin/mail_webhook/settings"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `POST /admin/mail_webhook/settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-498bbf0522063016", "name": "Unused endpoint: POST /admin/mail_webhook/test", "shortDescription": {"text": "Unused endpoint: POST /admin/mail_webhook/test"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `POST /admin/mail_webhook/test` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c510d97a04b95967", "name": "Unused endpoint: GET /admin/worker/configs", "shortDescription": {"text": "Unused endpoint: GET /admin/worker/configs"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `GET /admin/worker/configs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-95ef79880961e423", "name": "Unused endpoint: POST /admin/send_mail", "shortDescription": {"text": "Unused endpoint: POST /admin/send_mail"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `POST /admin/send_mail` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d935e1e553ae1fc7", "name": "Unused endpoint: POST /admin/send_mail_by_binding", "shortDescription": {"text": "Unused endpoint: POST /admin/send_mail_by_binding"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `POST /admin/send_mail_by_binding` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-25787414b327d0b1", "name": "Unused endpoint: GET /admin/ip_blacklist/settings", "shortDescription": {"text": "Unused endpoint: GET /admin/ip_blacklist/settings"}, "fullDescription": {"text": "`worker/src/admin_api/index.ts` declares `GET /admin/ip_blacklist/settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/30751"}, "properties": {"repository": "dreamhunter2333/cloudflare_temp_email", "repoUrl": "https://github.com/dreamhunter2333/cloudflare_temp_email", "branch": "main"}, "results": [{"ruleId": "scanner-6a48db4e8b33dba4", "level": "note", "message": {"text": "Possibly dead Python function: destroy"}, "properties": {"repobilityId": "a6948a4d6a39f413", "scanner": "scanner-primary", "fingerprint": "6a48db4e8b33dba4", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "smtp_proxy_server/imap_mailbox.py:84"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-97bca46674f6a36d", "level": "note", "message": {"text": "Possibly dead Python function: getHierarchicalDelimiter"}, "properties": {"repobilityId": "c368d11fc7ca081c", "scanner": "scanner-primary", "fingerprint": "97bca46674f6a36d", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "smtp_proxy_server/imap_mailbox.py:87"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0122ea9e979fcac2", "level": "note", "message": {"text": "Possibly dead Python function: getUID"}, "properties": {"repobilityId": "7addc88924b7b1ba", "scanner": "scanner-primary", "fingerprint": "0122ea9e979fcac2", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "smtp_proxy_server/imap_mailbox.py:301"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bc3fd7fc8f01fd99", "level": "note", "message": {"text": "Possibly dead Python function: expunge"}, "properties": {"repobilityId": "20ad10c07b211175", "scanner": "scanner-primary", "fingerprint": "bc3fd7fc8f01fd99", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "smtp_proxy_server/imap_mailbox.py:359"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-87ce8313a4beb143", "level": "note", "message": {"text": "Possibly dead Python function: getUID"}, "properties": {"repobilityId": "7addc88924b7b1ba", "scanner": "scanner-primary", "fingerprint": "87ce8313a4beb143", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "smtp_proxy_server/imap_message.py:66"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-07cface9112856f1", "level": "note", "message": {"text": "Possibly dead Python function: getHeaders"}, "properties": {"repobilityId": "7e4de3e3a35c9277", "scanner": "scanner-primary", "fingerprint": "07cface9112856f1", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "smtp_proxy_server/imap_message.py:69"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ff0c73be878789d5", "level": "note", "message": {"text": "Possibly dead Python function: isMultipart"}, "properties": {"repobilityId": "c9f9590b9519b042", "scanner": "scanner-primary", "fingerprint": "ff0c73be878789d5", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "smtp_proxy_server/imap_message.py:90"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a9a77aa6c2abc9a8", "level": "note", "message": {"text": "Possibly dead Python function: getSubPart"}, "properties": {"repobilityId": "c384ef7ff1e7568f", "scanner": "scanner-primary", "fingerprint": "a9a77aa6c2abc9a8", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "smtp_proxy_server/imap_message.py:93"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-29b1f0d0cbf7cd9e", "level": "note", "message": {"text": "Possibly dead Python function: getBodyFile"}, "properties": {"repobilityId": "fe7db4aa6008d2e2", "scanner": "scanner-primary", "fingerprint": "29b1f0d0cbf7cd9e", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "smtp_proxy_server/imap_message.py:100"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fcf06dfb3d09d655", "level": "note", "message": {"text": "Possibly dead Python function: getSize"}, "properties": {"repobilityId": "bb6dd581c75eb1d1", "scanner": "scanner-primary", "fingerprint": "fcf06dfb3d09d655", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "smtp_proxy_server/imap_message.py:103"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-47a932ebf970be36", "level": "note", "message": {"text": "Possibly dead Python function: getInternalDate"}, "properties": {"repobilityId": "a5e36597c5f8afb8", "scanner": "scanner-primary", "fingerprint": "47a932ebf970be36", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "smtp_proxy_server/imap_message.py:111"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-84a471a3c9e88776", "level": "note", "message": {"text": "Possibly dead Python function: open"}, "properties": {"repobilityId": "06f8cadb554057a1", "scanner": "scanner-primary", "fingerprint": "84a471a3c9e88776", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "smtp_proxy_server/imap_message.py:119"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0d6ab3c525d365bf", "level": "note", "message": {"text": "Possibly dead Python function: authenticator"}, "properties": {"repobilityId": "5a98d478d83e3e14", "scanner": "scanner-primary", "fingerprint": "0d6ab3c525d365bf", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "smtp_proxy_server/smtp_server.py:28"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e91433e4bba11d6d", "level": "note", "message": {"text": "Possibly dead Python function: handle_DATA"}, "properties": {"repobilityId": "72d8301ebdc19fa9", "scanner": "scanner-primary", "fingerprint": "e91433e4bba11d6d", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "smtp_proxy_server/smtp_server.py:38"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e17ed342a3ac9476", "level": "note", "message": {"text": "Possibly dead Python function: logging_write_seq"}, "properties": {"repobilityId": "b94e8f7636e45193", "scanner": "scanner-primary", "fingerprint": "e17ed342a3ac9476", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "smtp_proxy_server/imap_server.py:43"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2bee511a32420dcb", "level": "note", "message": {"text": "Possibly dead Python function: listMailboxes"}, "properties": {"repobilityId": "a857bad612b0d091", "scanner": "scanner-primary", "fingerprint": "2bee511a32420dcb", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "smtp_proxy_server/imap_server.py:93"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-68d03c81899996f2", "level": "note", "message": {"text": "Possibly dead Python function: requestAvatar"}, "properties": {"repobilityId": "7bb7fbb7a1fae53e", "scanner": "scanner-primary", "fingerprint": "68d03c81899996f2", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "smtp_proxy_server/imap_server.py:107"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b6d6e5f76c69cb72", "level": "note", "message": {"text": "Possibly dead Python function: buildProtocol"}, "properties": {"repobilityId": "f73d21dbe01bd1f5", "scanner": "scanner-primary", "fingerprint": "b6d6e5f76c69cb72", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "smtp_proxy_server/imap_server.py:130"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0a5870fa03e8ebdb", "level": "note", "message": {"text": "Possibly dead Python function: requestAvatarId"}, "properties": {"repobilityId": "492b00fbc03e2341", "scanner": "scanner-primary", "fingerprint": "0a5870fa03e8ebdb", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "smtp_proxy_server/imap_server.py:146"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4b413e24c1046026", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/api/index.js:178"}, "properties": {"repobilityId": "a61b5bd052a0c0f9", "scanner": "scanner-primary", "fingerprint": "4b413e24c1046026", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0195371fb677e652", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/utils/email-parser.js:36"}, "properties": {"repobilityId": "0f23e73f38817af0", "scanner": "scanner-primary", "fingerprint": "0195371fb677e652", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-cbe758400bf3fd3b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/components/SendBox.vue:81"}, "properties": {"repobilityId": "159e232babf9b030", "scanner": "scanner-primary", "fingerprint": "cbe758400bf3fd3b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e35adb6d8a2deb99", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/views/admin/UserAddressManagement.vue:28"}, "properties": {"repobilityId": "b17dfa1a49b9682f", "scanner": "scanner-primary", "fingerprint": "e35adb6d8a2deb99", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4b553a69d428e78a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/views/admin/RoleAddressConfig.vue:22"}, "properties": {"repobilityId": "f1d86365c58bf5fb", "scanner": "scanner-primary", "fingerprint": "4b553a69d428e78a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8bc6d65ed178544e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/views/admin/UserManagement.vue:50"}, "properties": {"repobilityId": "35896be0fcc82b09", "scanner": "scanner-primary", "fingerprint": "8bc6d65ed178544e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-13704be7ee90aeac", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/views/admin/Statistics.vue:36"}, "properties": {"repobilityId": "5181fe7fb13d27ef", "scanner": "scanner-primary", "fingerprint": "13704be7ee90aeac", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-88a1e769e5670f9e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/views/admin/SenderAccess.vue:57"}, "properties": {"repobilityId": "85f82eac2b477a59", "scanner": "scanner-primary", "fingerprint": "88a1e769e5670f9e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-af1658c3fa14a857", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/views/index/Attachment.vue:23"}, "properties": {"repobilityId": "3eea8aed881df6bf", "scanner": "scanner-primary", "fingerprint": "af1658c3fa14a857", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-df82ef8a12c84162", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/views/user/UserMailBox.vue:44"}, "properties": {"repobilityId": "69373211a19f989f", "scanner": "scanner-primary", "fingerprint": "df82ef8a12c84162", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-13e9da4bc92a205e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/views/user/AddressManagement.vue:37"}, "properties": {"repobilityId": "741e24968dc80db0", "scanner": "scanner-primary", "fingerprint": "13e9da4bc92a205e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-849f99baad9b4443", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/src/scheduled.ts:9"}, "properties": {"repobilityId": "b86054467eef7a10", "scanner": "scanner-primary", "fingerprint": "849f99baad9b4443", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-423d57e3098593ae", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/src/utils.ts:409"}, "properties": {"repobilityId": "00d400af514e5fea", "scanner": "scanner-primary", "fingerprint": "423d57e3098593ae", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-993292cc7445688a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/src/common.ts:473"}, "properties": {"repobilityId": "1dfd910470413edc", "scanner": "scanner-primary", "fingerprint": "993292cc7445688a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-50d9fad9b4755aa5", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/src/admin_api/cleanup_api.ts:84"}, "properties": {"repobilityId": "a595c23e3db9eb0a", "scanner": "scanner-primary", "fingerprint": "50d9fad9b4755aa5", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8c4c9a698b4e3ad6", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/src/email/index.ts:21"}, "properties": {"repobilityId": "50c1aca098947481", "scanner": "scanner-primary", "fingerprint": "8c4c9a698b4e3ad6", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c9ce6a7708b64d6e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/src/email/auto_reply.ts:38"}, "properties": {"repobilityId": "66d8dfdb32b70265", "scanner": "scanner-primary", "fingerprint": "c9ce6a7708b64d6e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4f96bbfc46b34af5", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/src/email/ai_extract.ts:275"}, "properties": {"repobilityId": "1f9f10865979edfd", "scanner": "scanner-primary", "fingerprint": "4f96bbfc46b34af5", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3c0410a4a7e1e1a1", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/src/mails_api/send_mail_api.ts:102"}, "properties": {"repobilityId": "be3194c0def666e7", "scanner": "scanner-primary", "fingerprint": "3c0410a4a7e1e1a1", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5450797292e6c16a", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 worker/src/mails_api/mails_crud.ts:40"}, "properties": {"repobilityId": "7c8201bf58e1549d", "scanner": "scanner-primary", "fingerprint": "5450797292e6c16a", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-b5235d729df04a1e", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 worker/src/user_api/user.ts:202"}, "properties": {"repobilityId": "82f9e7ccdca8e98f", "scanner": "scanner-primary", "fingerprint": "b5235d729df04a1e", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-a751249b772c91c9", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/src/telegram_api/index.ts:54"}, "properties": {"repobilityId": "6218c379e4660130", "scanner": "scanner-primary", "fingerprint": "a751249b772c91c9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2ec92c136faeb8f3", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/src/telegram_api/tg_file_upload.ts:12"}, "properties": {"repobilityId": "dd2aa48dd54dae55", "scanner": "scanner-primary", "fingerprint": "2ec92c136faeb8f3", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-de37460735eeb1f5", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/src/telegram_api/common.ts:80"}, "properties": {"repobilityId": "eb9a0ae6178b2f24", "scanner": "scanner-primary", "fingerprint": "de37460735eeb1f5", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-363c50c894d645ce", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/src/telegram_api/telegram.ts:419"}, "properties": {"repobilityId": "72159ea8fe3e8d0d", "scanner": "scanner-primary", "fingerprint": "363c50c894d645ce", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-13af2157ed0afcb3", "level": "note", "message": {"text": "GHSA-c2j3-45gr-mqc4: dompurify 3.4.11 \u2014 frontend/pnpm-lock.yaml"}, "properties": {"repobilityId": "23cb9c9e359db504", "scanner": "scanner-primary", "fingerprint": "13af2157ed0afcb3", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-c2j3-45gr-mqc4"]}}, {"ruleId": "scanner-8b1daa248b301633", "level": "error", "message": {"text": "CVE-2026-25896: fast-xml-parser 5.2.5 \u2014 worker/pnpm-lock.yaml"}, "properties": {"repobilityId": "9ab98d1ec8352a00", "scanner": "scanner-primary", "fingerprint": "8b1daa248b301633", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25896"]}}, {"ruleId": "scanner-f57ae428d9e02736", "level": "error", "message": {"text": "CVE-2026-25128: fast-xml-parser 5.2.5 \u2014 worker/pnpm-lock.yaml"}, "properties": {"repobilityId": "1b5c9110642a5afa", "scanner": "scanner-primary", "fingerprint": "f57ae428d9e02736", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25128"]}}, {"ruleId": "scanner-a11eba3bd5565198", "level": "error", "message": {"text": "CVE-2026-26278: fast-xml-parser 5.2.5 \u2014 worker/pnpm-lock.yaml"}, "properties": {"repobilityId": "10053a6050061608", "scanner": "scanner-primary", "fingerprint": "a11eba3bd5565198", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-26278"]}}, {"ruleId": "scanner-71fc735cfa250c3c", "level": "error", "message": {"text": "CVE-2026-33036: fast-xml-parser 5.2.5 \u2014 worker/pnpm-lock.yaml"}, "properties": {"repobilityId": "e793d105d2763268", "scanner": "scanner-primary", "fingerprint": "71fc735cfa250c3c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33036"]}}, {"ruleId": "scanner-2e9e1af78b98866d", "level": "warning", "message": {"text": "CVE-2026-33349: fast-xml-parser 5.2.5 \u2014 worker/pnpm-lock.yaml"}, "properties": {"repobilityId": "0661ef8cc0afe18d", "scanner": "scanner-primary", "fingerprint": "2e9e1af78b98866d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33349"]}}, {"ruleId": "scanner-e058f72fa92dc423", "level": "warning", "message": {"text": "CVE-2026-41650: fast-xml-parser 5.2.5 \u2014 worker/pnpm-lock.yaml"}, "properties": {"repobilityId": "7a2103199898668f", "scanner": "scanner-primary", "fingerprint": "e058f72fa92dc423", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41650"]}}, {"ruleId": "scanner-54e3f33366db739f", "level": "note", "message": {"text": "CVE-2026-27942: fast-xml-parser 5.2.5 \u2014 worker/pnpm-lock.yaml"}, "properties": {"repobilityId": "1946fb592fea5d4e", "scanner": "scanner-primary", "fingerprint": "54e3f33366db739f", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27942"]}}, {"ruleId": "scanner-911760a135c17723", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 9.0.1 \u2014 worker/pnpm-lock.yaml"}, "properties": {"repobilityId": "2e7fbdaded8cb501", "scanner": "scanner-primary", "fingerprint": "911760a135c17723", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-abdf8ffff8a53bfd", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 e2e/Dockerfile.e2e"}, "properties": {"repobilityId": "91ace659bffff613", "scanner": "scanner-primary", "fingerprint": "abdf8ffff8a53bfd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-2958d920a759518f", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 e2e/Dockerfile.e2e"}, "properties": {"repobilityId": "e5b5f6f33897a72f", "scanner": "scanner-primary", "fingerprint": "2958d920a759518f", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-30ba2cb3625cd87c", "level": "error", "message": {"text": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 e2e/Dockerfile.e2e"}, "properties": {"repobilityId": "79b0ad642f36fd0b", "scanner": "scanner-primary", "fingerprint": "30ba2cb3625cd87c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-e2cb0c151718c884", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 e2e/Dockerfile.frontend"}, "properties": {"repobilityId": "4dc924b7aff83166", "scanner": "scanner-primary", "fingerprint": "e2cb0c151718c884", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-628262edcfb88c1f", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 e2e/Dockerfile.frontend"}, "properties": {"repobilityId": "df7a53b457e77c32", "scanner": "scanner-primary", "fingerprint": "628262edcfb88c1f", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-ad514955c7a246d3", "level": "error", "message": {"text": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 e2e/Dockerfile.frontend"}, "properties": {"repobilityId": "e6820921b07302a7", "scanner": "scanner-primary", "fingerprint": "ad514955c7a246d3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-8de7e2facdfaf627", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 e2e/Dockerfile.worker"}, "properties": {"repobilityId": "2d8d2155f3dbdb32", "scanner": "scanner-primary", "fingerprint": "8de7e2facdfaf627", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-885f2050cc394bb4", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 e2e/Dockerfile.worker"}, "properties": {"repobilityId": "2349e501d35f45b8", "scanner": "scanner-primary", "fingerprint": "885f2050cc394bb4", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-02b4497c73e84ed8", "level": "error", "message": {"text": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 e2e/Dockerfile.worker"}, "properties": {"repobilityId": "9bccbec3fa6de811", "scanner": "scanner-primary", "fingerprint": "02b4497c73e84ed8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-92cafc9e1b52dc81", "level": "warning", "message": {"text": "Agent instruction contains unpinned remote install: .claude/skills/cf-temp-mail-release-notify/SKILL.md"}, "properties": {"repobilityId": "3130b08a220be374", "scanner": "scanner-primary", "fingerprint": "92cafc9e1b52dc81", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "supply-chain", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/cf-temp-mail-release-notify/SKILL.md"}, "region": {"startLine": 14}}}]}, {"ruleId": "scanner-baccb0bd5c74f971", "level": "warning", "message": {"text": "SkillSpector E1 (data-exfil) in skills/cf-temp-mail-agent-mail/SKILL.md"}, "properties": {"repobilityId": "0be94a577cacea8b", "scanner": "scanner-primary", "fingerprint": "baccb0bd5c74f971", "layer": "security", "severity": "medium", "confidence": 0.6, "tags": ["skillspector", "mcp-skill", "data-exfil", "E1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/cf-temp-mail-agent-mail/SKILL.md"}, "region": {"startLine": 124}}}]}, {"ruleId": "scanner-fd6812afc3a7b462", "level": "warning", "message": {"text": "SkillSpector RA2 (rogue-agent) in skills/cf-temp-mail-agent-mail/SKILL.md"}, "properties": {"repobilityId": "0c3fefdd03887a99", "scanner": "scanner-primary", "fingerprint": "fd6812afc3a7b462", "layer": "security", "severity": "medium", "confidence": 0.6, "tags": ["skillspector", "mcp-skill", "rogue-agent", "RA2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/cf-temp-mail-agent-mail/SKILL.md"}, "region": {"startLine": 10}}}]}, {"ruleId": "scanner-184f66595329d628", "level": "warning", "message": {"text": "SkillSpector AST4 (behavioral-ast) in .claude/skills/cf-temp-mail-release-notify/scripts/send_release_to_telegram.py"}, "properties": {"repobilityId": "f70bcb9eea273eae", "scanner": "scanner-primary", "fingerprint": "184f66595329d628", "layer": "security", "severity": "medium", "confidence": 0.6, "tags": ["skillspector", "mcp-skill", "behavioral-ast", "AST4", "code-exec"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/cf-temp-mail-release-notify/scripts/send_release_to_telegram.py"}, "region": {"startLine": 93}}}]}, {"ruleId": "scanner-4c887dd4fdfecb8b", "level": "warning", "message": {"text": "SkillSpector LP3 (mcp-least-priv) in .claude/skills/cf-temp-mail-release-notify/SKILL.md"}, "properties": {"repobilityId": "a7672e7397b648db", "scanner": "scanner-primary", "fingerprint": "4c887dd4fdfecb8b", "layer": "security", "severity": "medium", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "mcp-least-priv", "LP3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/cf-temp-mail-release-notify/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-523177d2e7851d72", "level": "error", "message": {"text": "SkillSpector OH1 (output-handling) in .claude/skills/cf-temp-mail-release-notify/scripts/send_release_to_telegram.py"}, "properties": {"repobilityId": "1fe975641d129999", "scanner": "scanner-primary", "fingerprint": "523177d2e7851d72", "layer": "security", "severity": "high", "confidence": 0.95, "tags": ["skillspector", "mcp-skill", "output-handling", "OH1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/cf-temp-mail-release-notify/scripts/send_release_to_telegram.py"}, "region": {"startLine": 93}}}]}, {"ruleId": "scanner-1523aec9791f6435", "level": "note", "message": {"text": "SkillSpector SC2 (supply-chain) in .claude/skills/cf-temp-mail-release-notify/SKILL.md"}, "properties": {"repobilityId": "e24a9c87d9f919a6", "scanner": "scanner-primary", "fingerprint": "1523aec9791f6435", "layer": "security", "severity": "low", "confidence": 0.15, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/cf-temp-mail-release-notify/SKILL.md"}, "region": {"startLine": 14}}}]}, {"ruleId": "scanner-e637c415447867e4", "level": "none", "message": {"text": "Run SkillSpector's LLM-backed analysis in your own pipeline"}, "properties": {"repobilityId": "1936f198ff5212bf", "scanner": "scanner-primary", "fingerprint": "e637c415447867e4", "layer": "security", "severity": "info", "confidence": 1.0, "tags": ["skillspector", "mcp-skill", "llm-advisory", "ai-coder"]}}, {"ruleId": "scanner-5aa14659cf62526f", "level": "warning", "message": {"text": "Runtime dotenv file present in repo: frontend/.env.pages"}, "properties": {"repobilityId": "7ee491e111875d50", "scanner": "scanner-primary", "fingerprint": "5aa14659cf62526f", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["secrets", "config", "env-file", "runtime-env"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/.env.pages"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c4260abb09461c56", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in frontend/src/components/ShadowHtmlComponent.vue:53"}, "properties": {"repobilityId": "9df2e84259b2a0d1", "scanner": "scanner-primary", "fingerprint": "c4260abb09461c56", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/src/components/ShadowHtmlComponent.vue"}, "region": {"startLine": 53}}}]}, {"ruleId": "scanner-021697c5c90a65cb", "level": "warning", "message": {"text": "Insecure pattern 'vue_v_html' in frontend/src/components/ShadowHtmlComponent.vue:2"}, "properties": {"repobilityId": "3ec74eed90f6d337", "scanner": "scanner-primary", "fingerprint": "021697c5c90a65cb", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "vue_v_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/src/components/ShadowHtmlComponent.vue"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-bfa10fac8f24be40", "level": "warning", "message": {"text": "Insecure pattern 'vue_v_html' in frontend/src/components/SendBox.vue:276"}, "properties": {"repobilityId": "e64e14220aac9418", "scanner": "scanner-primary", "fingerprint": "bfa10fac8f24be40", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "vue_v_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/src/components/SendBox.vue"}, "region": {"startLine": 276}}}]}, {"ruleId": "scanner-b6a93fdba5645236", "level": "warning", "message": {"text": "Insecure pattern 'vue_v_html' in frontend/src/views/common/About.vue:10"}, "properties": {"repobilityId": "261522e53f95251f", "scanner": "scanner-primary", "fingerprint": "b6a93fdba5645236", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "vue_v_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/src/views/common/About.vue"}, "region": {"startLine": 10}}}]}, {"ruleId": "scanner-a8e40047059fc300", "level": "warning", "message": {"text": "Possible secret in frontend/src/views/admin/CreateAccount.vue"}, "properties": {"repobilityId": "a8313e64b8d56ca0", "scanner": "scanner-primary", "fingerprint": "a8e40047059fc300", "layer": "security", "severity": "medium", "confidence": 0.58, "tags": ["secrets", "password_literal"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/src/views/admin/CreateAccount.vue"}, "region": {"startLine": 74}}}]}, {"ruleId": "scanner-81b92103b3c32336", "level": "warning", "message": {"text": "Insecure pattern 'vue_v_html' in frontend/src/views/admin/UserOauth2Settings.vue:179"}, "properties": {"repobilityId": "687f3a55ffe20a99", "scanner": "scanner-primary", "fingerprint": "81b92103b3c32336", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "vue_v_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/src/views/admin/UserOauth2Settings.vue"}, "region": {"startLine": 179}}}]}, {"ruleId": "scanner-58fb4bb10c6fd75f", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in frontend/src/views/admin/SendMail.vue:49"}, "properties": {"repobilityId": "ccfadb2c40f106ec", "scanner": "scanner-primary", "fingerprint": "58fb4bb10c6fd75f", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/src/views/admin/SendMail.vue"}, "region": {"startLine": 49}}}]}, {"ruleId": "scanner-1b8005a9ccd0d323", "level": "warning", "message": {"text": "Insecure pattern 'vue_v_html' in frontend/src/views/admin/SendMail.vue:183"}, "properties": {"repobilityId": "41eb1b445098146c", "scanner": "scanner-primary", "fingerprint": "1b8005a9ccd0d323", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "vue_v_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/src/views/admin/SendMail.vue"}, "region": {"startLine": 183}}}]}, {"ruleId": "scanner-9a7061198416a070", "level": "warning", "message": {"text": "Possible secret in frontend/src/views/index/AddressBar.vue"}, "properties": {"repobilityId": "22a83cd858f7ff28", "scanner": "scanner-primary", "fingerprint": "9a7061198416a070", "layer": "security", "severity": "medium", "confidence": 0.58, "tags": ["secrets", "password_literal"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/src/views/index/AddressBar.vue"}, "region": {"startLine": 79}}}]}, {"ruleId": "scanner-a7fbc07279891bf7", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in frontend/src/views/index/SendMail.vue:44"}, "properties": {"repobilityId": "d48745c7bbe37def", "scanner": "scanner-primary", "fingerprint": "a7fbc07279891bf7", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/src/views/index/SendMail.vue"}, "region": {"startLine": 44}}}]}, {"ruleId": "scanner-0ba16b0904f5c1b0", "level": "warning", "message": {"text": "Insecure pattern 'vue_v_html' in frontend/src/views/index/SendMail.vue:206"}, "properties": {"repobilityId": "bcec7d08ffc5497a", "scanner": "scanner-primary", "fingerprint": "0ba16b0904f5c1b0", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "vue_v_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/src/views/index/SendMail.vue"}, "region": {"startLine": 206}}}]}, {"ruleId": "scanner-e5f8a19bdd6c5f3a", "level": "warning", "message": {"text": "Insecure pattern 'vue_v_html' in frontend/src/views/user/UserLogin.vue:210"}, "properties": {"repobilityId": "df61197b0a01bd60", "scanner": "scanner-primary", "fingerprint": "e5f8a19bdd6c5f3a", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "vue_v_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/src/views/user/UserLogin.vue"}, "region": {"startLine": 210}}}]}, {"ruleId": "scanner-f0d335d7b8dddbb9", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in worker/src/worker.ts:31"}, "properties": {"repobilityId": "fb56dde2dac4c39e", "scanner": "scanner-primary", "fingerprint": "f0d335d7b8dddbb9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/worker.ts"}, "region": {"startLine": 31}}}]}, {"ruleId": "scanner-edf004534a1d6cc3", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "d628da83b3c4557b", "scanner": "scanner-primary", "fingerprint": "edf004534a1d6cc3", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend_pagefunction_deploy.yaml"}, "region": {"startLine": 35}}}]}, {"ruleId": "scanner-cef20eb037ed675b", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "53600e1c110509e0", "scanner": "scanner-primary", "fingerprint": "cef20eb037ed675b", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/tag_build.yml"}, "region": {"startLine": 13}}}]}, {"ruleId": "scanner-13be22ba5c4cc750", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "ce53bcaa6727b68b", "scanner": "scanner-primary", "fingerprint": "13be22ba5c4cc750", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/tag_build.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-87844b112e00597b", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "273cc30e942899db", "scanner": "scanner-primary", "fingerprint": "87844b112e00597b", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend_deploy.yaml"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-e1733b99f89dec51", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "b0b9104711b5e330", "scanner": "scanner-primary", "fingerprint": "e1733b99f89dec51", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/docs_deploy.yml"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-2747252967b56857", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "f476f4e7c0c332ba", "scanner": "scanner-primary", "fingerprint": "2747252967b56857", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/docs_deploy.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4fb027b1aa6e08d1", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "dd0829ffe8104978", "scanner": "scanner-primary", "fingerprint": "4fb027b1aa6e08d1", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/backend_deploy.yaml"}, "region": {"startLine": 19}}}]}, {"ruleId": "scanner-9c1aced86dabc7c0", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "0de2d5353239e87c", "scanner": "scanner-primary", "fingerprint": "9c1aced86dabc7c0", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/backend_deploy.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-65c9bd56493a81d3", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "802f2de8621fdede", "scanner": "scanner-primary", "fingerprint": "65c9bd56493a81d3", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/e2e.yml"}, "region": {"startLine": 22}}}]}, {"ruleId": "scanner-de1cb5bf057f8e10", "level": "error", "message": {"text": "GitHub Action tracks a moving branch"}, "properties": {"repobilityId": "8f3193995c8d9a9d", "scanner": "scanner-primary", "fingerprint": "de1cb5bf057f8e10", "layer": "cicd", "severity": "high", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/pr_agent.yml"}, "region": {"startLine": 19}}}]}, {"ruleId": "scanner-bbd7b12427dd8d2c", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "6a3b374ea16bc729", "scanner": "scanner-primary", "fingerprint": "bbd7b12427dd8d2c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/pr_agent.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4990c9c3fe3c9c5a", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "b20bdcae75d76ea1", "scanner": "scanner-primary", "fingerprint": "4990c9c3fe3c9c5a", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/smtp_proxy_server.yml"}, "region": {"startLine": 27}}}]}, {"ruleId": "scanner-053a2e3dc43e8119", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "141fe827996be7fb", "scanner": "scanner-primary", "fingerprint": "053a2e3dc43e8119", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/smtp_proxy_server.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d0b820547b2ea1a0", "level": "note", "message": {"text": "Very large file: frontend/src/i18n/message-registry.ts (2591 lines)"}, "properties": {"repobilityId": "9bf20c9cf11bb7ca", "scanner": "scanner-primary", "fingerprint": "d0b820547b2ea1a0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-1cb907756974e99e", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: pages/package.json"}, "properties": {"repobilityId": "aa1f95d2d4ba510c", "scanner": "scanner-primary", "fingerprint": "1cb907756974e99e", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pages/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "715f8788fdaddba3", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "41cb7a1726b34333", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "44d0a352e10ab54e", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-be60ebffd923acf8", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/src/utils.ts:439"}, "properties": {"repobilityId": "4cdccd5be88f6144", "scanner": "scanner-primary", "fingerprint": "be60ebffd923acf8", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-9e2605727e2aab44", "level": "none", "message": {"text": "Commented-code block (19 lines) in worker/src/common.ts:705"}, "properties": {"repobilityId": "342d5e4572bbb00f", "scanner": "scanner-primary", "fingerprint": "9e2605727e2aab44", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f33da899d71907a9", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/src/common.ts:796"}, "properties": {"repobilityId": "dcec704b6fd3a9b4", "scanner": "scanner-primary", "fingerprint": "f33da899d71907a9", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-69bb2600fdf0283e", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/src/worker.ts:46"}, "properties": {"repobilityId": "8e3ef740cbd8c9ea", "scanner": "scanner-primary", "fingerprint": "69bb2600fdf0283e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-c610c12b2a06235e", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/src/user_api/oauth2.ts:40"}, "properties": {"repobilityId": "d4d3c32991ff9b7b", "scanner": "scanner-primary", "fingerprint": "c610c12b2a06235e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-152a713178dd7822", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/src/telegram_api/tg_file_upload.ts:37"}, "properties": {"repobilityId": "4a78f5e2e08d1af5", "scanner": "scanner-primary", "fingerprint": "152a713178dd7822", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-dbfab12a4a7cc804", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/src/telegram_api/telegram.ts:503"}, "properties": {"repobilityId": "5b9d1a8067e4baf8", "scanner": "scanner-primary", "fingerprint": "dbfab12a4a7cc804", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-0f425fd0abb8e6d6", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 pages/functions/_middleware.js:13"}, "properties": {"repobilityId": "7357ca1ea47caba1", "scanner": "scanner-primary", "fingerprint": "0f425fd0abb8e6d6", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-109ccba5fd984a0d", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 .claude/skills/cf-temp-mail-release-notify/scripts/send_release_to_telegram.py:93"}, "properties": {"repobilityId": "e607b8a6583afded", "scanner": "scanner-primary", "fingerprint": "109ccba5fd984a0d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-891a3f8d90901a4e", "level": "note", "message": {"text": "Stub function `destroy` (body is just `pass`/`return`) \u2014 smtp_proxy_server/imap_mailbox.py:84"}, "properties": {"repobilityId": "2fc7462559fd1a7e", "scanner": "scanner-primary", "fingerprint": "891a3f8d90901a4e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-be4b0dae2e7a2d7a", "level": "error", "message": {"text": "Blocking `httpx.post(...)` inside `async def handle_DATA` \u2014 smtp_proxy_server/smtp_server.py:116"}, "properties": {"repobilityId": "4296bee12dcd0038", "scanner": "scanner-primary", "fingerprint": "be4b0dae2e7a2d7a", "layer": "quality", "severity": "high", "confidence": 1.0, "tags": ["integrity", "sync-io-in-async", "performance"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "smtp_proxy_server/smtp_server.py"}, "region": {"startLine": 116}}}]}, {"ruleId": "scanner-250f57e8a1dbd3c5", "level": "none", "message": {"text": "4 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "57584f22b735b5ee", "scanner": "scanner-primary", "fingerprint": "250f57e8a1dbd3c5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "092737c7ef19fe92", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-d62b55978491e2db", "level": "error", "message": {"text": "JS POST `/admin/new_address` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:26"}, "properties": {"repobilityId": "239b0380c06e89d9", "scanner": "scanner-primary", "fingerprint": "d62b55978491e2db", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 26}}}]}, {"ruleId": "scanner-4226085a692f1c56", "level": "error", "message": {"text": "JS DELETE `/admin/delete_address/:id` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:27"}, "properties": {"repobilityId": "16660ed4de18e951", "scanner": "scanner-primary", "fingerprint": "4226085a692f1c56", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 27}}}]}, {"ruleId": "scanner-8733dc32b11efe6b", "level": "error", "message": {"text": "JS DELETE `/admin/clear_inbox/:id` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:28"}, "properties": {"repobilityId": "318f3e3c6235f66f", "scanner": "scanner-primary", "fingerprint": "8733dc32b11efe6b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 28}}}]}, {"ruleId": "scanner-f7242b360a35bb58", "level": "error", "message": {"text": "JS DELETE `/admin/clear_sent_items/:id` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:29"}, "properties": {"repobilityId": "827b2a50f9875c27", "scanner": "scanner-primary", "fingerprint": "f7242b360a35bb58", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 29}}}]}, {"ruleId": "scanner-e57b9cc56dcccb1d", "level": "error", "message": {"text": "JS POST `/admin/address/:id/reset_password` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:31"}, "properties": {"repobilityId": "381400f145317cc4", "scanner": "scanner-primary", "fingerprint": "e57b9cc56dcccb1d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 31}}}]}, {"ruleId": "scanner-b392ecb70b339017", "level": "error", "message": {"text": "JS DELETE `/admin/mails/:id` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:36"}, "properties": {"repobilityId": "20429db6290b4bcd", "scanner": "scanner-primary", "fingerprint": "b392ecb70b339017", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 36}}}]}, {"ruleId": "scanner-1b5197f658fe775c", "level": "error", "message": {"text": "JS POST `/admin/address_sender` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:40"}, "properties": {"repobilityId": "d402acfcd1e6bdc4", "scanner": "scanner-primary", "fingerprint": "1b5197f658fe775c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 40}}}]}, {"ruleId": "scanner-1e020d61532b1753", "level": "error", "message": {"text": "JS DELETE `/admin/address_sender/:id` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:41"}, "properties": {"repobilityId": "10c81b514aa7fc26", "scanner": "scanner-primary", "fingerprint": "1e020d61532b1753", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 41}}}]}, {"ruleId": "scanner-b5c3074d4907cd8a", "level": "error", "message": {"text": "JS DELETE `/admin/sendbox/:id` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:45"}, "properties": {"repobilityId": "f53ceee4e3199a3c", "scanner": "scanner-primary", "fingerprint": "b5c3074d4907cd8a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 45}}}]}, {"ruleId": "scanner-8de3ca774fa4d72a", "level": "error", "message": {"text": "JS POST `/admin/account_settings` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:52"}, "properties": {"repobilityId": "f2b7bc666b113398", "scanner": "scanner-primary", "fingerprint": "8de3ca774fa4d72a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 52}}}]}, {"ruleId": "scanner-64dae13f38b14acf", "level": "error", "message": {"text": "JS POST `/admin/cleanup` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:55"}, "properties": {"repobilityId": "d2d60c353ef2bba5", "scanner": "scanner-primary", "fingerprint": "64dae13f38b14acf", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 55}}}]}, {"ruleId": "scanner-3fed96a8c7e416c6", "level": "error", "message": {"text": "JS POST `/admin/auto_cleanup` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:57"}, "properties": {"repobilityId": "232ed041cf383572", "scanner": "scanner-primary", "fingerprint": "3fed96a8c7e416c6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 57}}}]}, {"ruleId": "scanner-a7f17ac0e5a66436", "level": "error", "message": {"text": "JS POST `/admin/user_roles` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:67"}, "properties": {"repobilityId": "8d9ad79f0298853d", "scanner": "scanner-primary", "fingerprint": "a7f17ac0e5a66436", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 67}}}]}, {"ruleId": "scanner-04b1b22c5de5b845", "level": "error", "message": {"text": "JS POST `/admin/role_address_config` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:69"}, "properties": {"repobilityId": "fba78f2f01a7fd31", "scanner": "scanner-primary", "fingerprint": "04b1b22c5de5b845", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 69}}}]}, {"ruleId": "scanner-f1cf3ffcb0e30762", "level": "error", "message": {"text": "JS POST `/admin/users/bind_address` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:71"}, "properties": {"repobilityId": "2f3368109eb47012", "scanner": "scanner-primary", "fingerprint": "f1cf3ffcb0e30762", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 71}}}]}, {"ruleId": "scanner-b12bf0fd94c6cbfe", "level": "error", "message": {"text": "JS POST `/admin/user_oauth2_settings` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:75"}, "properties": {"repobilityId": "eeb10488e359ced6", "scanner": "scanner-primary", "fingerprint": "b12bf0fd94c6cbfe", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 75}}}]}, {"ruleId": "scanner-1d169fa98d75018b", "level": "error", "message": {"text": "JS POST `/admin/webhook/settings` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:79"}, "properties": {"repobilityId": "827e71bbeda24cc9", "scanner": "scanner-primary", "fingerprint": "1d169fa98d75018b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 79}}}]}, {"ruleId": "scanner-d8fac49ff55dbc10", "level": "error", "message": {"text": "JS POST `/admin/mail_webhook/settings` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:83"}, "properties": {"repobilityId": "92663e294a7abead", "scanner": "scanner-primary", "fingerprint": "d8fac49ff55dbc10", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 83}}}]}, {"ruleId": "scanner-28ca8657f9215025", "level": "error", "message": {"text": "JS POST `/admin/mail_webhook/test` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:84"}, "properties": {"repobilityId": "07b37e108aca68d0", "scanner": "scanner-primary", "fingerprint": "28ca8657f9215025", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 84}}}]}, {"ruleId": "scanner-2ac04ade8f6fd008", "level": "error", "message": {"text": "JS POST `/admin/send_mail` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:90"}, "properties": {"repobilityId": "4026968aa48b8517", "scanner": "scanner-primary", "fingerprint": "2ac04ade8f6fd008", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 90}}}]}, {"ruleId": "scanner-25d89bf2bcbadc6b", "level": "error", "message": {"text": "JS POST `/admin/send_mail_by_binding` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:91"}, "properties": {"repobilityId": "778e61706f64c940", "scanner": "scanner-primary", "fingerprint": "25d89bf2bcbadc6b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 91}}}]}, {"ruleId": "scanner-83067bda8005e23b", "level": "error", "message": {"text": "JS POST `/admin/ip_blacklist/settings` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:100"}, "properties": {"repobilityId": "cb44e0ad53b66a6f", "scanner": "scanner-primary", "fingerprint": "83067bda8005e23b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 100}}}]}, {"ruleId": "scanner-ca5a5020e46b26b7", "level": "error", "message": {"text": "JS POST `/admin/ai_extract/settings` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:104"}, "properties": {"repobilityId": "a4d9cf6a64ccd50d", "scanner": "scanner-primary", "fingerprint": "ca5a5020e46b26b7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 104}}}]}, {"ruleId": "scanner-586e454e111c9df6", "level": "error", "message": {"text": "JS POST `/admin/test/seed_mail` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:107"}, "properties": {"repobilityId": "9f53af75a927b9b8", "scanner": "scanner-primary", "fingerprint": "586e454e111c9df6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 107}}}]}, {"ruleId": "scanner-b7f21337dcd25ebf", "level": "error", "message": {"text": "JS POST `/admin/test/receive_mail` admin endpoint without auth \u2014 worker/src/admin_api/index.ts:108"}, "properties": {"repobilityId": "fc56209375d085b1", "scanner": "scanner-primary", "fingerprint": "b7f21337dcd25ebf", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/admin_api/index.ts"}, "region": {"startLine": 108}}}]}, {"ruleId": "scanner-c922424c0d2d913b", "level": "error", "message": {"text": "JS POST `/admin/telegram/init` admin endpoint without auth \u2014 worker/src/telegram_api/index.ts:50"}, "properties": {"repobilityId": "80e8fbb93c968508", "scanner": "scanner-primary", "fingerprint": "c922424c0d2d913b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/telegram_api/index.ts"}, "region": {"startLine": 50}}}]}, {"ruleId": "scanner-782f38f0a7803380", "level": "error", "message": {"text": "JS POST `/admin/telegram/settings` admin endpoint without auth \u2014 worker/src/telegram_api/index.ts:72"}, "properties": {"repobilityId": "07bb221aae792c41", "scanner": "scanner-primary", "fingerprint": "782f38f0a7803380", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.js.admin_unauth"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/src/telegram_api/index.ts"}, "region": {"startLine": 72}}}]}, {"ruleId": "scanner-e32f2a37d0d026fe", "level": "warning", "message": {"text": "Vulnerable dependency ws 8.19.0: GHSA-58qx-3vcg-4xpx"}, "properties": {"repobilityId": "55a9c2f96fc090b6", "scanner": "scanner-primary", "fingerprint": "e32f2a37d0d026fe", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-58qx-3vcg-4xpx", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "e2e/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f3ae3aa9231d3a92", "level": "error", "message": {"text": "Vulnerable dependency ws 8.19.0: GHSA-96hv-2xvq-fx4p"}, "properties": {"repobilityId": "84b0003d43ab4c82", "scanner": "scanner-primary", "fingerprint": "f3ae3aa9231d3a92", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-96hv-2xvq-fx4p", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "e2e/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ff41bdfbb2e4fc86", "level": "note", "message": {"text": "Vulnerable dependency dompurify 3.4.11: GHSA-c2j3-45gr-mqc4"}, "properties": {"repobilityId": "f00e188764eee076", "scanner": "scanner-primary", "fingerprint": "ff41bdfbb2e4fc86", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-c2j3-45gr-mqc4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-22f63597718494d2", "level": "warning", "message": {"text": "Vulnerable dependency vite 5.4.21: GHSA-4w7w-66w2-5vf9"}, "properties": {"repobilityId": "90685dbb72b15019", "scanner": "scanner-primary", "fingerprint": "22f63597718494d2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4w7w-66w2-5vf9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vitepress-docs/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9e70152493820fa4", "level": "error", "message": {"text": "Vulnerable dependency vite 5.4.21: GHSA-fx2h-pf6j-xcff"}, "properties": {"repobilityId": "d9b9604813f5ec55", "scanner": "scanner-primary", "fingerprint": "9e70152493820fa4", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-fx2h-pf6j-xcff"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vitepress-docs/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b62ee8a5a271cf0a", "level": "warning", "message": {"text": "Vulnerable dependency vite 5.4.21: GHSA-v6wh-96g9-6wx3"}, "properties": {"repobilityId": "6d8cd9b06e1669ff", "scanner": "scanner-primary", "fingerprint": "b62ee8a5a271cf0a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-v6wh-96g9-6wx3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vitepress-docs/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-90de3b604ee8cebc", "level": "error", "message": {"text": "Vulnerable dependency brace-expansion 2.1.1: GHSA-3jxr-9vmj-r5cp"}, "properties": {"repobilityId": "91dc449d0086dea5", "scanner": "scanner-primary", "fingerprint": "90de3b604ee8cebc", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3jxr-9vmj-r5cp", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-feb9ad299d6be074", "level": "error", "message": {"text": "Vulnerable dependency brace-expansion 5.0.6: GHSA-3jxr-9vmj-r5cp"}, "properties": {"repobilityId": "d33b0db2b7d6b674", "scanner": "scanner-primary", "fingerprint": "feb9ad299d6be074", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3jxr-9vmj-r5cp", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0044a7bcb37b461b", "level": "note", "message": {"text": "Vulnerable dependency esbuild 0.27.7: GHSA-g7r4-m6w7-qqqr"}, "properties": {"repobilityId": "dbc426c2dd693105", "scanner": "scanner-primary", "fingerprint": "0044a7bcb37b461b", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-g7r4-m6w7-qqqr", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-38e2ece8fb1a2538", "level": "error", "message": {"text": "Vulnerable dependency fast-uri 3.1.2: GHSA-4c8g-83qw-93j6"}, "properties": {"repobilityId": "b415b1056beb5b08", "scanner": "scanner-primary", "fingerprint": "38e2ece8fb1a2538", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-4c8g-83qw-93j6", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fb4791bf81cc5360", "level": "error", "message": {"text": "Vulnerable dependency fast-uri 3.1.2: GHSA-v2hh-gcrm-f6hx"}, "properties": {"repobilityId": "963ee1409fedeb90", "scanner": "scanner-primary", "fingerprint": "fb4791bf81cc5360", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-v2hh-gcrm-f6hx", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-100b1a1830ea26ed", "level": "note", "message": {"text": "Dependency @unhead/vue is a major version behind"}, "properties": {"repobilityId": "4ca502b22da38a77", "scanner": "scanner-primary", "fingerprint": "100b1a1830ea26ed", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5ea3bc7a603abc72", "level": "note", "message": {"text": "Dependency @wangeditor/editor-for-vue declares a version newer than the registry latest"}, "properties": {"repobilityId": "fa45b5adfa278ac5", "scanner": "scanner-primary", "fingerprint": "5ea3bc7a603abc72", "layer": "dependencies", "severity": "low", "confidence": 0.4, "tags": ["dependency", "freshness", "future-version", "ai-generated-signal"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-18e15032274486a1", "level": "note", "message": {"text": "Dependency vue-router is a major version behind"}, "properties": {"repobilityId": "c249c0f09a26203b", "scanner": "scanner-primary", "fingerprint": "18e15032274486a1", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cbb9e08da8060249", "level": "warning", "message": {"text": "Dependency service-identity is two or more major versions behind"}, "properties": {"repobilityId": "96d06f250451dcc7", "scanner": "scanner-primary", "fingerprint": "cbb9e08da8060249", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "smtp_proxy_server/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-78654bfc245e794c", "level": "error", "message": {"text": "Dangling fetch: POST https://api.telegram.org/bot${botToken}/sendMediaGroup (worker/src/telegram_api/tg_file_upload.ts:37)"}, "properties": {"repobilityId": "5eba4d78b15b162a", "scanner": "scanner-primary", "fingerprint": "78654bfc245e794c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-3abf952b8d28d710", "level": "note", "message": {"text": "Unused endpoint: USE /*"}, "properties": {"repobilityId": "86c6d76c91e06365", "scanner": "scanner-primary", "fingerprint": "3abf952b8d28d710", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b8073f7bf758f6d0", "level": "note", "message": {"text": "Unused endpoint: USE /api/*"}, "properties": {"repobilityId": "cda8e2ad1639e466", "scanner": "scanner-primary", "fingerprint": "b8073f7bf758f6d0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ba965a5b35a8e884", "level": "note", "message": {"text": "Unused endpoint: USE /user_api/*"}, "properties": {"repobilityId": "03cd7875f9c7c4cc", "scanner": "scanner-primary", "fingerprint": "ba965a5b35a8e884", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-48f839e5dc386ef9", "level": "note", "message": {"text": "Unused endpoint: USE /admin/*"}, "properties": {"repobilityId": "8473ac34be5957ea", "scanner": "scanner-primary", "fingerprint": "48f839e5dc386ef9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "66d62716ab94567e", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-933c0b014d21f21d", "level": "note", "message": {"text": "Unused endpoint: ALL /*"}, "properties": {"repobilityId": "8f0dbe0417ce3695", "scanner": "scanner-primary", "fingerprint": "933c0b014d21f21d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a39562f15dca4ac2", "level": "note", "message": {"text": "Unused endpoint: GET /admin/address"}, "properties": {"repobilityId": "7b5502955a9d7980", "scanner": "scanner-primary", "fingerprint": "a39562f15dca4ac2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ec5a6adfe87e7c13", "level": "note", "message": {"text": "Unused endpoint: POST /admin/new_address"}, "properties": {"repobilityId": "c601ae6d2fb21679", "scanner": "scanner-primary", "fingerprint": "ec5a6adfe87e7c13", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d01bc73d315ca837", "level": "note", "message": {"text": "Unused endpoint: DELETE /admin/delete_address/:id"}, "properties": {"repobilityId": "8f42d4556e76c069", "scanner": "scanner-primary", "fingerprint": "d01bc73d315ca837", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4cc9f6b6a0cea78f", "level": "note", "message": {"text": "Unused endpoint: DELETE /admin/clear_inbox/:id"}, "properties": {"repobilityId": "a54f08f827467e13", "scanner": "scanner-primary", "fingerprint": "4cc9f6b6a0cea78f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-34fe9b18932b0dd3", "level": "note", "message": {"text": "Unused endpoint: DELETE /admin/clear_sent_items/:id"}, "properties": {"repobilityId": "c67d17dc9240153e", "scanner": "scanner-primary", "fingerprint": "34fe9b18932b0dd3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ba58844b23b17302", "level": "note", "message": {"text": "Unused endpoint: GET /admin/show_password/:id"}, "properties": {"repobilityId": "b896a01a2167cc28", "scanner": "scanner-primary", "fingerprint": "ba58844b23b17302", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-08373199c0b1289a", "level": "note", "message": {"text": "Unused endpoint: POST /admin/address/:id/reset_password"}, "properties": {"repobilityId": "cbc14524452e5beb", "scanner": "scanner-primary", "fingerprint": "08373199c0b1289a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-822597617779ed24", "level": "note", "message": {"text": "Unused endpoint: GET /admin/mails"}, "properties": {"repobilityId": "dd961998ae28d2d9", "scanner": "scanner-primary", "fingerprint": "822597617779ed24", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c14a32ff3a00b0cf", "level": "note", "message": {"text": "Unused endpoint: GET /admin/mails_unknow"}, "properties": {"repobilityId": "e958ee4df00dcd74", "scanner": "scanner-primary", "fingerprint": "c14a32ff3a00b0cf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f047ecee072c87ed", "level": "note", "message": {"text": "Unused endpoint: DELETE /admin/mails/:id"}, "properties": {"repobilityId": "c90184d9c7f9bb3f", "scanner": "scanner-primary", "fingerprint": "f047ecee072c87ed", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-80483c5203ceca55", "level": "note", "message": {"text": "Unused endpoint: GET /admin/address_sender"}, "properties": {"repobilityId": "efbf597368e6d5b9", "scanner": "scanner-primary", "fingerprint": "80483c5203ceca55", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fde7b4789031c99e", "level": "note", "message": {"text": "Unused endpoint: POST /admin/address_sender"}, "properties": {"repobilityId": "b09db2e1e30ffdf2", "scanner": "scanner-primary", "fingerprint": "fde7b4789031c99e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f507025a899d9d8e", "level": "note", "message": {"text": "Unused endpoint: DELETE /admin/address_sender/:id"}, "properties": {"repobilityId": "fd705c0784dcb2b4", "scanner": "scanner-primary", "fingerprint": "f507025a899d9d8e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-80a8029ab1e38c56", "level": "note", "message": {"text": "Unused endpoint: GET /admin/sendbox"}, "properties": {"repobilityId": "2f6957e674b64773", "scanner": "scanner-primary", "fingerprint": "80a8029ab1e38c56", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dc7a6fbb10249031", "level": "note", "message": {"text": "Unused endpoint: DELETE /admin/sendbox/:id"}, "properties": {"repobilityId": "e75a91ea832d553c", "scanner": "scanner-primary", "fingerprint": "dc7a6fbb10249031", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4f19f3685db95649", "level": "note", "message": {"text": "Unused endpoint: GET /admin/statistics"}, "properties": {"repobilityId": "0f7060690d87a243", "scanner": "scanner-primary", "fingerprint": "4f19f3685db95649", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-940650abfcf7db10", "level": "note", "message": {"text": "Unused endpoint: GET /admin/account_settings"}, "properties": {"repobilityId": "d816c991e34ff434", "scanner": "scanner-primary", "fingerprint": "940650abfcf7db10", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2083e8676561acce", "level": "note", "message": {"text": "Unused endpoint: POST /admin/account_settings"}, "properties": {"repobilityId": "3540622f2decf7b7", "scanner": "scanner-primary", "fingerprint": "2083e8676561acce", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8754601194d5f53c", "level": "note", "message": {"text": "Unused endpoint: POST /admin/cleanup"}, "properties": {"repobilityId": "4d59215cbf2ea731", "scanner": "scanner-primary", "fingerprint": "8754601194d5f53c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ff5c9810be5826c7", "level": "note", "message": {"text": "Unused endpoint: GET /admin/auto_cleanup"}, "properties": {"repobilityId": "b8e50a88c37ee13a", "scanner": "scanner-primary", "fingerprint": "ff5c9810be5826c7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bfd3000ee7fc7791", "level": "note", "message": {"text": "Unused endpoint: POST /admin/auto_cleanup"}, "properties": {"repobilityId": "d496255f36e0d720", "scanner": "scanner-primary", "fingerprint": "bfd3000ee7fc7791", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f656571ced0048f5", "level": "note", "message": {"text": "Unused endpoint: GET /admin/user_settings"}, "properties": {"repobilityId": "04c77117bf73b8d8", "scanner": "scanner-primary", "fingerprint": "f656571ced0048f5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0f87c6e8df4fe86c", "level": "note", "message": {"text": "Unused endpoint: POST /admin/user_settings"}, "properties": {"repobilityId": "5bbad07dc28d4268", "scanner": "scanner-primary", "fingerprint": "0f87c6e8df4fe86c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0aba7f1883cb96f2", "level": "note", "message": {"text": "Unused endpoint: GET /admin/users"}, "properties": {"repobilityId": "83790a672203f961", "scanner": "scanner-primary", "fingerprint": "0aba7f1883cb96f2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9fe091788c4b2bc0", "level": "note", "message": {"text": "Unused endpoint: DELETE /admin/users/:user_id"}, "properties": {"repobilityId": "1edd09ec820b9243", "scanner": "scanner-primary", "fingerprint": "9fe091788c4b2bc0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-31fd9c1bbfc177f4", "level": "note", "message": {"text": "Unused endpoint: POST /admin/users"}, "properties": {"repobilityId": "bc053165aa400504", "scanner": "scanner-primary", "fingerprint": "31fd9c1bbfc177f4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-394f80138c311b0d", "level": "note", "message": {"text": "Unused endpoint: POST /admin/users/:user_id/reset_password"}, "properties": {"repobilityId": "b4a9d3b27510cd15", "scanner": "scanner-primary", "fingerprint": "394f80138c311b0d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8fcb0611dbbaca99", "level": "note", "message": {"text": "Unused endpoint: GET /admin/user_roles"}, "properties": {"repobilityId": "f8bb20f535d8943b", "scanner": "scanner-primary", "fingerprint": "8fcb0611dbbaca99", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cbe75cc29fa16b94", "level": "note", "message": {"text": "Unused endpoint: POST /admin/user_roles"}, "properties": {"repobilityId": "a85fc5f9dbbe6d71", "scanner": "scanner-primary", "fingerprint": "cbe75cc29fa16b94", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f1cbdac3b7b1cb6c", "level": "note", "message": {"text": "Unused endpoint: GET /admin/role_address_config"}, "properties": {"repobilityId": "4457bce3c5b27a1d", "scanner": "scanner-primary", "fingerprint": "f1cbdac3b7b1cb6c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1b89de2d2e48fda8", "level": "note", "message": {"text": "Unused endpoint: POST /admin/role_address_config"}, "properties": {"repobilityId": "87f4644d8b61a8bb", "scanner": "scanner-primary", "fingerprint": "1b89de2d2e48fda8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-100e1d80dc87fe8c", "level": "note", "message": {"text": "Unused endpoint: GET /admin/users/bind_address/:user_id"}, "properties": {"repobilityId": "6db8cba314957e2a", "scanner": "scanner-primary", "fingerprint": "100e1d80dc87fe8c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1a373bd45abaf6b6", "level": "note", "message": {"text": "Unused endpoint: POST /admin/users/bind_address"}, "properties": {"repobilityId": "1aeffe3c95a0ecce", "scanner": "scanner-primary", "fingerprint": "1a373bd45abaf6b6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1436919efd7f5a99", "level": "note", "message": {"text": "Unused endpoint: GET /admin/user_oauth2_settings"}, "properties": {"repobilityId": "2843938a3fd33c30", "scanner": "scanner-primary", "fingerprint": "1436919efd7f5a99", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4e014007142cdfb5", "level": "note", "message": {"text": "Unused endpoint: POST /admin/user_oauth2_settings"}, "properties": {"repobilityId": "8720bd75ba073bd6", "scanner": "scanner-primary", "fingerprint": "4e014007142cdfb5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d00df48df172808b", "level": "note", "message": {"text": "Unused endpoint: GET /admin/webhook/settings"}, "properties": {"repobilityId": "5c4ae374f8a4e722", "scanner": "scanner-primary", "fingerprint": "d00df48df172808b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-671e373a81ea081a", "level": "note", "message": {"text": "Unused endpoint: POST /admin/webhook/settings"}, "properties": {"repobilityId": "059cdd927abd4e55", "scanner": "scanner-primary", "fingerprint": "671e373a81ea081a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-85f8f8faee595ac4", "level": "note", "message": {"text": "Unused endpoint: GET /admin/mail_webhook/settings"}, "properties": {"repobilityId": "b4a0de5e67463f64", "scanner": "scanner-primary", "fingerprint": "85f8f8faee595ac4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8cb08d9f5dc63621", "level": "note", "message": {"text": "Unused endpoint: POST /admin/mail_webhook/settings"}, "properties": {"repobilityId": "eda3841d7c295c83", "scanner": "scanner-primary", "fingerprint": "8cb08d9f5dc63621", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-498bbf0522063016", "level": "note", "message": {"text": "Unused endpoint: POST /admin/mail_webhook/test"}, "properties": {"repobilityId": "5c15c590be507044", "scanner": "scanner-primary", "fingerprint": "498bbf0522063016", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c510d97a04b95967", "level": "note", "message": {"text": "Unused endpoint: GET /admin/worker/configs"}, "properties": {"repobilityId": "397c91f8af6bb107", "scanner": "scanner-primary", "fingerprint": "c510d97a04b95967", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-95ef79880961e423", "level": "note", "message": {"text": "Unused endpoint: POST /admin/send_mail"}, "properties": {"repobilityId": "f16916ad69680e38", "scanner": "scanner-primary", "fingerprint": "95ef79880961e423", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d935e1e553ae1fc7", "level": "note", "message": {"text": "Unused endpoint: POST /admin/send_mail_by_binding"}, "properties": {"repobilityId": "4429ace215889ee1", "scanner": "scanner-primary", "fingerprint": "d935e1e553ae1fc7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-25787414b327d0b1", "level": "note", "message": {"text": "Unused endpoint: GET /admin/ip_blacklist/settings"}, "properties": {"repobilityId": "e260821d642fe20c", "scanner": "scanner-primary", "fingerprint": "25787414b327d0b1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}