{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-c7d22218b2ca3192", "name": "Possibly dead Python function: replay_until", "shortDescription": {"text": "Possibly dead Python function: replay_until"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-29afac5b0ae2c205", "name": "Stray `console.log` in TS/JS \u2014 src/api/server.ts:33", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/api/server.ts:33"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0158870388c58cdc", "name": "Stray `console.log` in TS/JS \u2014 src/scripts/seed-database.ts:11", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/seed-database.ts:11"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-70e3306597797fd8", "name": "Stray `console.log` in TS/JS \u2014 src/scripts/test-connectivity.ts:52", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-connectivity.ts:52"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aacaa855e393d52b", "name": "Stray `console.log` in TS/JS \u2014 src/agents/wolfman/poll.ts:194", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/agents/wolfman/poll.ts:194"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b4b994e7fc99d10a", "name": "Stray `console.log` in TS/JS \u2014 src/db/seed.ts:167", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/db/seed.ts:167"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a75da13d47752450", "name": "Insecure pattern 'direct_innerhtml_assignment' in src/api/public/treasurer.html:49", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in src/api/public/treasurer.html:49"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-22800e4027a3b887", "name": "Insecure pattern 'direct_innerhtml_assignment' in src/api/public/match.html:118", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in src/api/public/match.html:118"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e0ae1cc283c54cf8", "name": "Insecure pattern 'direct_innerhtml_assignment' in src/api/public/index.html:76", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in src/api/public/index.html:76"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-86fcf51e1086c3f4", "name": "Insecure pattern 'direct_innerhtml_assignment' in src/api/public/bets.html:65", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in src/api/public/bets.html:65"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-19b8f1d2bffa5800", "name": "Insecure pattern 'direct_innerhtml_assignment' in src/api/public/app.js:61", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in src/api/public/app.js:61"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f41cff4d7a568a2b", "name": "Insecure pattern 'direct_innerhtml_assignment' in src/api/public/verdict.html:48", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in src/api/public/verdict.html:48"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 16 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5400b1e9696f0b18", "name": "Legacy-named symbol `model_copy` in src/agents/quant/api/service.py:260", "shortDescription": {"text": "Legacy-named symbol `model_copy` in src/agents/quant/api/service.py:260"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b3431016782ef680", "name": "Legacy-named symbol `model_copy` in src/agents/quant/calibration/backtest.py:252", "shortDescription": {"text": "Legacy-named symbol `model_copy` in src/agents/quant/calibration/backtest.py:252"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1ded583630bcd7bf", "name": "Legacy-named symbol `model_copy` in src/agents/quant/model/bootstrap.py:37", "shortDescription": {"text": "Legacy-named symbol `model_copy` in src/agents/quant/model/bootstrap.py:37"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-250f57e8a1dbd3c5", "name": "4 env vars used in code but missing from .env.example", "shortDescription": {"text": "4 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `APIFOOTBALL_KEY`, `CEO_MODEL`, `QUANT_SERVICE_URL`, `WOLFMAN_MODEL`. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-be46ea126aa5d8dc", "name": "Near-duplicate function bodies in 3 places", "shortDescription": {"text": "Near-duplicate function bodies in 3 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nsrc/agents/quant/model/bootstrap.py:bootstrap_confidence, src/agents/quant/model/bivariate_poisson.py:compute_lambdas, src/agents/quant/model/bivariate_poisson.py:predict_match\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-40ea5ed1a612fe31", "name": "FastAPI POST `predict` without auth dependency \u2014 src/agents/quant/api/routes.py:35", "shortDescription": {"text": "FastAPI POST `predict` without auth dependency \u2014 src/agents/quant/api/routes.py:35"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4ea0ab99d546ecf6", "name": "FastAPI POST `ratings_update` without auth dependency \u2014 src/agents/quant/api/routes.py:43", "shortDescription": {"text": "FastAPI POST `ratings_update` without auth dependency \u2014 src/agents/quant/api/routes.py:43"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0f7c451f7c7266ac", "name": "FastAPI POST `backtest` without auth dependency \u2014 src/agents/quant/api/routes.py:48", "shortDescription": {"text": "FastAPI POST `backtest` without auth dependency \u2014 src/agents/quant/api/routes.py:48"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-25d3af48cd83c9e6", "name": "Unused endpoint: POST /predict", "shortDescription": {"text": "Unused endpoint: POST /predict"}, "fullDescription": {"text": "`src/agents/quant/api/routes.py` declares `POST /predict` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4c4c6c00defc3c3d", "name": "Unused endpoint: POST /ratings/update", "shortDescription": {"text": "Unused endpoint: POST /ratings/update"}, "fullDescription": {"text": "`src/agents/quant/api/routes.py` declares `POST /ratings/update` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7563b119d2657acd", "name": "Unused endpoint: POST /backtest", "shortDescription": {"text": "Unused endpoint: POST /backtest"}, "fullDescription": {"text": "`src/agents/quant/api/routes.py` declares `POST /backtest` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`src/api/server.ts` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b967a831df734eac", "name": "Unused endpoint: GET /matches/:id", "shortDescription": {"text": "Unused endpoint: GET /matches/:id"}, "fullDescription": {"text": "`src/api/server.ts` declares `GET /matches/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-834e3a819a2b812e", "name": "Unused endpoint: GET /bets", "shortDescription": {"text": "Unused endpoint: GET /bets"}, "fullDescription": {"text": "`src/api/server.ts` declares `GET /bets` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c8332a1a0e639f80", "name": "Unused endpoint: GET /verdicts/:id", "shortDescription": {"text": "Unused endpoint: GET /verdicts/:id"}, "fullDescription": {"text": "`src/api/server.ts` declares `GET /verdicts/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-84c907b487a5d6fe", "name": "Unused endpoint: GET /treasurer", "shortDescription": {"text": "Unused endpoint: GET /treasurer"}, "fullDescription": {"text": "`src/api/server.ts` declares `GET /treasurer` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e9df1633093a56a3", "name": "Unused endpoint: GET /api/slate", "shortDescription": {"text": "Unused endpoint: GET /api/slate"}, "fullDescription": {"text": "`src/api/routes.ts` declares `GET /api/slate` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9545fc9a75c181a5", "name": "Unused endpoint: GET /api/matches/:id", "shortDescription": {"text": "Unused endpoint: GET /api/matches/:id"}, "fullDescription": {"text": "`src/api/routes.ts` declares `GET /api/matches/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1b6da9daa0ccb924", "name": "Unused endpoint: POST /api/poll", "shortDescription": {"text": "Unused endpoint: POST /api/poll"}, "fullDescription": {"text": "`src/api/routes.ts` declares `POST /api/poll` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b77c504074ec83e9", "name": "Unused endpoint: POST /api/fixtures/sync", "shortDescription": {"text": "Unused endpoint: POST /api/fixtures/sync"}, "fullDescription": {"text": "`src/api/routes.ts` declares `POST /api/fixtures/sync` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6786015ea3c1e4a9", "name": "Unused endpoint: POST /bets/place", "shortDescription": {"text": "Unused endpoint: POST /bets/place"}, "fullDescription": {"text": "`src/api/routes.ts` declares `POST /bets/place` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d4579ed0861dc80b", "name": "Unused endpoint: POST /bets/:id/settle", "shortDescription": {"text": "Unused endpoint: POST /bets/:id/settle"}, "fullDescription": {"text": "`src/api/routes.ts` declares `POST /bets/:id/settle` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9fac77fa4fa707a0", "name": "Unused endpoint: POST /bankroll/deposit", "shortDescription": {"text": "Unused endpoint: POST /bankroll/deposit"}, "fullDescription": {"text": "`src/api/routes.ts` declares `POST /bankroll/deposit` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-235163998797986b", "name": "Unused endpoint: GET /api/bets", "shortDescription": {"text": "Unused endpoint: GET /api/bets"}, "fullDescription": {"text": "`src/api/routes.ts` declares `GET /api/bets` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-963710f42a2c8219", "name": "Unused endpoint: GET /api/status", "shortDescription": {"text": "Unused endpoint: GET /api/status"}, "fullDescription": {"text": "`src/api/routes.ts` declares `GET /api/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e8ee8fb5a483d355", "name": "Unused endpoint: POST /api/matches/:id/tactician/run", "shortDescription": {"text": "Unused endpoint: POST /api/matches/:id/tactician/run"}, "fullDescription": {"text": "`src/api/routes.ts` declares `POST /api/matches/:id/tactician/run` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c3d3c7a7d98618c4", "name": "Unused endpoint: GET /api/treasurer", "shortDescription": {"text": "Unused endpoint: GET /api/treasurer"}, "fullDescription": {"text": "`src/api/routes.ts` declares `GET /api/treasurer` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7e1843b9cd790771", "name": "Unused endpoint: POST /api/matches/:id/ceo/run", "shortDescription": {"text": "Unused endpoint: POST /api/matches/:id/ceo/run"}, "fullDescription": {"text": "`src/api/routes.ts` declares `POST /api/matches/:id/ceo/run` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eebbb7e080fb37b2", "name": "Unused endpoint: GET /api/matches/:id/verdicts", "shortDescription": {"text": "Unused endpoint: GET /api/matches/:id/verdicts"}, "fullDescription": {"text": "`src/api/routes.ts` declares `GET /api/matches/:id/verdicts` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-28905652df277485", "name": "Unused endpoint: GET /api/verdicts/:id", "shortDescription": {"text": "Unused endpoint: GET /api/verdicts/:id"}, "fullDescription": {"text": "`src/api/routes.ts` declares `GET /api/verdicts/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fbbdda81c9babe84", "name": "Unused endpoint: POST /api/matches/:id/lineup", "shortDescription": {"text": "Unused endpoint: POST /api/matches/:id/lineup"}, "fullDescription": {"text": "`src/api/routes.ts` declares `POST /api/matches/:id/lineup` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/23419"}, "properties": {"repository": "yungdeeej/SoccerSB", "repoUrl": "https://github.com/yungdeeej/SoccerSB", "branch": "main"}, "results": [{"ruleId": "scanner-c7d22218b2ca3192", "level": "note", "message": {"text": "Possibly dead Python function: replay_until"}, "properties": {"repobilityId": "0831ef34ad1d1799", "scanner": "scanner-primary", "fingerprint": "c7d22218b2ca3192", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/agents/quant/calibration/elo_engine.py:80"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-29afac5b0ae2c205", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/api/server.ts:33"}, "properties": {"repobilityId": "7542565750146616", "scanner": "scanner-primary", "fingerprint": "29afac5b0ae2c205", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0158870388c58cdc", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/seed-database.ts:11"}, "properties": {"repobilityId": "f9c601650c9ebb25", "scanner": "scanner-primary", "fingerprint": "0158870388c58cdc", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-70e3306597797fd8", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-connectivity.ts:52"}, "properties": {"repobilityId": "6c56e3e58e070241", "scanner": "scanner-primary", "fingerprint": "70e3306597797fd8", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-aacaa855e393d52b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/agents/wolfman/poll.ts:194"}, "properties": {"repobilityId": "a33723f292d477d8", "scanner": "scanner-primary", "fingerprint": "aacaa855e393d52b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b4b994e7fc99d10a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/db/seed.ts:167"}, "properties": {"repobilityId": "019f0f0087f0b197", "scanner": "scanner-primary", "fingerprint": "b4b994e7fc99d10a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-a75da13d47752450", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in src/api/public/treasurer.html:49"}, "properties": {"repobilityId": "8d6c73d39a5ccbed", "scanner": "scanner-primary", "fingerprint": "a75da13d47752450", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/api/public/treasurer.html"}, "region": {"startLine": 49}}}]}, {"ruleId": "scanner-22800e4027a3b887", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in src/api/public/match.html:118"}, "properties": {"repobilityId": "484d2dad5e0dbada", "scanner": "scanner-primary", "fingerprint": "22800e4027a3b887", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/api/public/match.html"}, "region": {"startLine": 118}}}]}, {"ruleId": "scanner-e0ae1cc283c54cf8", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in src/api/public/index.html:76"}, "properties": {"repobilityId": "e0cfc254994df46b", "scanner": "scanner-primary", "fingerprint": "e0ae1cc283c54cf8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/api/public/index.html"}, "region": {"startLine": 76}}}]}, {"ruleId": "scanner-86fcf51e1086c3f4", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in src/api/public/bets.html:65"}, "properties": {"repobilityId": "5ea433be403f57b4", "scanner": "scanner-primary", "fingerprint": "86fcf51e1086c3f4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/api/public/bets.html"}, "region": {"startLine": 65}}}]}, {"ruleId": "scanner-19b8f1d2bffa5800", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in src/api/public/app.js:61"}, "properties": {"repobilityId": "7336d46877d00813", "scanner": "scanner-primary", "fingerprint": "19b8f1d2bffa5800", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/api/public/app.js"}, "region": {"startLine": 61}}}]}, {"ruleId": "scanner-f41cff4d7a568a2b", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in src/api/public/verdict.html:48"}, "properties": {"repobilityId": "96db82d8088ab526", "scanner": "scanner-primary", "fingerprint": "f41cff4d7a568a2b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/api/public/verdict.html"}, "region": {"startLine": 48}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "c0fc7684f2f42104", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "c517115d8c7bbffd", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "c22e5a462e3f9c26", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "f81e4733e1940697", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "4c1f7bf2cba10c33", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-5400b1e9696f0b18", "level": "note", "message": {"text": "Legacy-named symbol `model_copy` in src/agents/quant/api/service.py:260"}, "properties": {"repobilityId": "4b1ba707caa27c51", "scanner": "scanner-primary", "fingerprint": "5400b1e9696f0b18", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-b3431016782ef680", "level": "note", "message": {"text": "Legacy-named symbol `model_copy` in src/agents/quant/calibration/backtest.py:252"}, "properties": {"repobilityId": "cb4f79843889ac90", "scanner": "scanner-primary", "fingerprint": "b3431016782ef680", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-1ded583630bcd7bf", "level": "note", "message": {"text": "Legacy-named symbol `model_copy` in src/agents/quant/model/bootstrap.py:37"}, "properties": {"repobilityId": "e1a389c0dbaed8b2", "scanner": "scanner-primary", "fingerprint": "1ded583630bcd7bf", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-250f57e8a1dbd3c5", "level": "none", "message": {"text": "4 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "57584f22b735b5ee", "scanner": "scanner-primary", "fingerprint": "250f57e8a1dbd3c5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "c2109c6728e97cb4", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-40ea5ed1a612fe31", "level": "error", "message": {"text": "FastAPI POST `predict` without auth dependency \u2014 src/agents/quant/api/routes.py:35"}, "properties": {"repobilityId": "7c62041f9dceede3", "scanner": "scanner-primary", "fingerprint": "40ea5ed1a612fe31", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/agents/quant/api/routes.py"}, "region": {"startLine": 35}}}]}, {"ruleId": "scanner-4ea0ab99d546ecf6", "level": "error", "message": {"text": "FastAPI POST `ratings_update` without auth dependency \u2014 src/agents/quant/api/routes.py:43"}, "properties": {"repobilityId": "20b2903aa0ac875f", "scanner": "scanner-primary", "fingerprint": "4ea0ab99d546ecf6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/agents/quant/api/routes.py"}, "region": {"startLine": 43}}}]}, {"ruleId": "scanner-0f7c451f7c7266ac", "level": "error", "message": {"text": "FastAPI POST `backtest` without auth dependency \u2014 src/agents/quant/api/routes.py:48"}, "properties": {"repobilityId": "e16a45519de6d2cc", "scanner": "scanner-primary", "fingerprint": "0f7c451f7c7266ac", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/agents/quant/api/routes.py"}, "region": {"startLine": 48}}}]}, {"ruleId": "scanner-25d3af48cd83c9e6", "level": "note", "message": {"text": "Unused endpoint: POST /predict"}, "properties": {"repobilityId": "77a55865601e3ba1", "scanner": "scanner-primary", "fingerprint": "25d3af48cd83c9e6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4c4c6c00defc3c3d", "level": "note", "message": {"text": "Unused endpoint: POST /ratings/update"}, "properties": {"repobilityId": "f52e6034f753a1ce", "scanner": "scanner-primary", "fingerprint": "4c4c6c00defc3c3d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7563b119d2657acd", "level": "note", "message": {"text": "Unused endpoint: POST /backtest"}, "properties": {"repobilityId": "030c73f710e7e11e", "scanner": "scanner-primary", "fingerprint": "7563b119d2657acd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "de34e2832f4d0353", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b967a831df734eac", "level": "note", "message": {"text": "Unused endpoint: GET /matches/:id"}, "properties": {"repobilityId": "2b4ef9ca4abe4ed4", "scanner": "scanner-primary", "fingerprint": "b967a831df734eac", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-834e3a819a2b812e", "level": "note", "message": {"text": "Unused endpoint: GET /bets"}, "properties": {"repobilityId": "c2b5798552011a16", "scanner": "scanner-primary", "fingerprint": "834e3a819a2b812e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c8332a1a0e639f80", "level": "note", "message": {"text": "Unused endpoint: GET /verdicts/:id"}, "properties": {"repobilityId": "6673103c5223cb84", "scanner": "scanner-primary", "fingerprint": "c8332a1a0e639f80", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-84c907b487a5d6fe", "level": "note", "message": {"text": "Unused endpoint: GET /treasurer"}, "properties": {"repobilityId": "e1816a9f5b78dcc5", "scanner": "scanner-primary", "fingerprint": "84c907b487a5d6fe", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e9df1633093a56a3", "level": "note", "message": {"text": "Unused endpoint: GET /api/slate"}, "properties": {"repobilityId": "55938aecc78fd112", "scanner": "scanner-primary", "fingerprint": "e9df1633093a56a3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9545fc9a75c181a5", "level": "note", "message": {"text": "Unused endpoint: GET /api/matches/:id"}, "properties": {"repobilityId": "1e69f428cadcd7fc", "scanner": "scanner-primary", "fingerprint": "9545fc9a75c181a5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1b6da9daa0ccb924", "level": "note", "message": {"text": "Unused endpoint: POST /api/poll"}, "properties": {"repobilityId": "c601127b32c1f868", "scanner": "scanner-primary", "fingerprint": "1b6da9daa0ccb924", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b77c504074ec83e9", "level": "note", "message": {"text": "Unused endpoint: POST /api/fixtures/sync"}, "properties": {"repobilityId": "77426907130f42aa", "scanner": "scanner-primary", "fingerprint": "b77c504074ec83e9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6786015ea3c1e4a9", "level": "note", "message": {"text": "Unused endpoint: POST /bets/place"}, "properties": {"repobilityId": "390bcf1a8398b6d0", "scanner": "scanner-primary", "fingerprint": "6786015ea3c1e4a9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d4579ed0861dc80b", "level": "note", "message": {"text": "Unused endpoint: POST /bets/:id/settle"}, "properties": {"repobilityId": "5d012f50691dc80a", "scanner": "scanner-primary", "fingerprint": "d4579ed0861dc80b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9fac77fa4fa707a0", "level": "note", "message": {"text": "Unused endpoint: POST /bankroll/deposit"}, "properties": {"repobilityId": "b6a2a52d90942d6e", "scanner": "scanner-primary", "fingerprint": "9fac77fa4fa707a0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-235163998797986b", "level": "note", "message": {"text": "Unused endpoint: GET /api/bets"}, "properties": {"repobilityId": "27c38313a11cafac", "scanner": "scanner-primary", "fingerprint": "235163998797986b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-963710f42a2c8219", "level": "note", "message": {"text": "Unused endpoint: GET /api/status"}, "properties": {"repobilityId": "65b94dca216aad05", "scanner": "scanner-primary", "fingerprint": "963710f42a2c8219", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e8ee8fb5a483d355", "level": "note", "message": {"text": "Unused endpoint: POST /api/matches/:id/tactician/run"}, "properties": {"repobilityId": "3a1354506f092bfe", "scanner": "scanner-primary", "fingerprint": "e8ee8fb5a483d355", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c3d3c7a7d98618c4", "level": "note", "message": {"text": "Unused endpoint: GET /api/treasurer"}, "properties": {"repobilityId": "6fad5aa3e39a40f2", "scanner": "scanner-primary", "fingerprint": "c3d3c7a7d98618c4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7e1843b9cd790771", "level": "note", "message": {"text": "Unused endpoint: POST /api/matches/:id/ceo/run"}, "properties": {"repobilityId": "49fc15345e4be348", "scanner": "scanner-primary", "fingerprint": "7e1843b9cd790771", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-eebbb7e080fb37b2", "level": "note", "message": {"text": "Unused endpoint: GET /api/matches/:id/verdicts"}, "properties": {"repobilityId": "c7cf010709195842", "scanner": "scanner-primary", "fingerprint": "eebbb7e080fb37b2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-28905652df277485", "level": "note", "message": {"text": "Unused endpoint: GET /api/verdicts/:id"}, "properties": {"repobilityId": "147d23487a7711ae", "scanner": "scanner-primary", "fingerprint": "28905652df277485", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fbbdda81c9babe84", "level": "note", "message": {"text": "Unused endpoint: POST /api/matches/:id/lineup"}, "properties": {"repobilityId": "457bd2678ef54edf", "scanner": "scanner-primary", "fingerprint": "fbbdda81c9babe84", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}