{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-24b7042f4bb39b19", "name": "Stray `console.log` in TS/JS \u2014 migration-script.js:39", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 migration-script.js:39"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dcf9331b67163fcd", "name": "Stray `console.log` in TS/JS \u2014 validation-script.js:62", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 validation-script.js:62"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6be93ae5b4235db4", "name": "Stray `console.log` in TS/JS \u2014 rollback-script.js:59", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 rollback-script.js:59"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8f844348c6a2d9e6", "name": "Stray `console.log` in TS/JS \u2014 server.js:73", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 server.js:73"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8582127c67baac22", "name": "Stray `console.log` in TS/JS \u2014 models/roundModel.js:154", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 models/roundModel.js:154"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ef05dff125bc591e", "name": "Stray `console.log` in TS/JS \u2014 models/investorModel.js:319", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 models/investorModel.js:319"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5854d5f5a7ef9deb", "name": "Stray `console.log` in TS/JS \u2014 models/esopGrantModel.js:99", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 models/esopGrantModel.js:99"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-02da5f720b058599", "name": "Stray `console.log` in TS/JS \u2014 models/capTableEntryModel.js:194", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 models/capTableEntryModel.js:194"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5f309dd57b230e30", "name": "Stray `console.log` in TS/JS \u2014 config/db.js:14", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 config/db.js:14"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ad0e19cf7bd27bb6", "name": "Stray `console.log` in TS/JS \u2014 scripts/backfillTaskKeys.js:21", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/backfillTaskKeys.js:21"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e58a2e783446c5be", "name": "Stray `console.log` in TS/JS \u2014 scripts/importTasksFromJson.js:50", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/importTasksFromJson.js:50"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f3f22fcef588fc51", "name": "TODO/FIXME marker in shipping code \u2014 controllers/organizationController.js:44", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 controllers/organizationController.js:44"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-354e2e76a7bf0062", "name": "Stray `console.log` in TS/JS \u2014 controllers/headcountController.js:65", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 controllers/headcountController.js:65"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-261e131b5265ac82", "name": "Stray `console.log` in TS/JS \u2014 controllers/fundraisingController.js:59", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 controllers/fundraisingController.js:59"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b386d1105b85afe4", "name": "Stray `console.log` in TS/JS \u2014 services/briefingService.js:503", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 services/briefingService.js:503"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ad6b901064fe035f", "name": "Stray `console.log` in TS/JS \u2014 services/transactionCategorizer.js:55", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 services/transactionCategorizer.js:55"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b506407bdacfb11f", "name": "Stray `console.log` in TS/JS \u2014 services/notificationService.js:28", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 services/notificationService.js:28"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-299150de474562b9", "name": "Stray `console.log` in TS/JS \u2014 services/customKpiService.js:685", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 services/customKpiService.js:685"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6c1ad8f3aa518490", "name": "Stray `console.log` in TS/JS \u2014 services/fundraisingCalculationService.js:25", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 services/fundraisingCalculationService.js:25"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3af31c2cccfb756a", "name": "Stray `console.log` in TS/JS \u2014 services/recurringTransactionService.js:21", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 services/recurringTransactionService.js:21"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a58b36f9cbea4b8b", "name": "Stray `console.log` in TS/JS \u2014 services/advancedMLService.js:80", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 services/advancedMLService.js:80"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-28c4a04bd807da0c", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "appleboy/ssh-action@v1 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d120614767f036de", "name": "Very large file: controllers/predictiveAnalyticsController.js (1602 lines)", "shortDescription": {"text": "Very large file: controllers/predictiveAnalyticsController.js (1602 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f485a8697a897e36", "name": "Very large file: controllers/taskController.js (1635 lines)", "shortDescription": {"text": "Very large file: controllers/taskController.js (1635 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-90dc4e8193c69ae8", "name": "Very large file: controllers/fundraisingController.js (1821 lines)", "shortDescription": {"text": "Very large file: controllers/fundraisingController.js (1821 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "0 test file(s) for 105 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 250 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-11825279136b53a3", "name": "CI is configured but no tests are detected", "shortDescription": {"text": "CI is configured but no tests are detected"}, "fullDescription": {"text": "A CI pipeline exists, but the scan found no test files to gate. Opus labeled this generated-code pattern as config theater: release machinery exists, but it has little behavioral signal."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, tests. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b1171adbcc309cab", "name": "Commented-code block (6 lines) in models/productMilestoneModel.js:361", "shortDescription": {"text": "Commented-code block (6 lines) in models/productMilestoneModel.js:361"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5ca42dee6b6618e4", "name": "Commented-code block (5 lines) in models/investorReportModel.js:68", "shortDescription": {"text": "Commented-code block (5 lines) in models/investorReportModel.js:68"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e4c3d3925f355609", "name": "Commented-code block (5 lines) in models/headcountModel.js:340", "shortDescription": {"text": "Commented-code block (5 lines) in models/headcountModel.js:340"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-dec7b9eb6722d52f", "name": "Commented-code block (6 lines) in models/revenueModel.js:47", "shortDescription": {"text": "Commented-code block (6 lines) in models/revenueModel.js:47"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d59820bc6edd8b25", "name": "Commented-code block (5 lines) in models/investorMeetingModel.js:359", "shortDescription": {"text": "Commented-code block (5 lines) in models/investorMeetingModel.js:359"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bf1dd7e077696baa", "name": "Commented-code block (5 lines) in models/bankAccountModel.js:36", "shortDescription": {"text": "Commented-code block (5 lines) in models/bankAccountModel.js:36"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b66d11da0dbf6341", "name": "Commented-code block (5 lines) in middleware/authMiddleware.js:68", "shortDescription": {"text": "Commented-code block (5 lines) in middleware/authMiddleware.js:68"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6b6efdd50860196b", "name": "Commented-code block (6 lines) in scripts/importTasksFromJson.js:7", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/importTasksFromJson.js:7"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f0e173f389e50f64", "name": "Commented-code block (5 lines) in routes/kpiRoutes.js:75", "shortDescription": {"text": "Commented-code block (5 lines) in routes/kpiRoutes.js:75"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b2f6271dae87acbc", "name": "Commented-code block (5 lines) in routes/predictiveAnalyticsRoutes.js:38", "shortDescription": {"text": "Commented-code block (5 lines) in routes/predictiveAnalyticsRoutes.js:38"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-991d20af8f974dff", "name": "Commented-code block (5 lines) in controllers/advancedFeaturesController.js:111", "shortDescription": {"text": "Commented-code block (5 lines) in controllers/advancedFeaturesController.js:111"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8d9eecaf7c40e1fd", "name": "Commented-code block (6 lines) in services/apnsService.js:5", "shortDescription": {"text": "Commented-code block (6 lines) in services/apnsService.js:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2f897520ccb0c0b5", "name": "Commented-code block (5 lines) in services/investorUpdateService.js:1", "shortDescription": {"text": "Commented-code block (5 lines) in services/investorUpdateService.js:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ff640ca4436f2156", "name": "Commented-code block (5 lines) in services/briefingService.js:1", "shortDescription": {"text": "Commented-code block (5 lines) in services/briefingService.js:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-544843012caeaf19", "name": "Commented-code block (7 lines) in services/notificationService.js:1", "shortDescription": {"text": "Commented-code block (7 lines) in services/notificationService.js:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6452ef0d62d062dd", "name": "Commented-code block (8 lines) in services/chiefOfStaffService.js:1", "shortDescription": {"text": "Commented-code block (8 lines) in services/chiefOfStaffService.js:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-514d57feb26b6908", "name": "`fetch()` without try/.catch or AbortSignal \u2014 services/chiefOfStaffService.js:325", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/chiefOfStaffService.js:325"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0d9881aa31b735da", "name": "Dangling fetch: POST https://api.anthropic.com/v1/messages (services/chiefOfStaffService.js:325)", "shortDescription": {"text": "Dangling fetch: POST https://api.anthropic.com/v1/messages (services/chiefOfStaffService.js:325)"}, "fullDescription": {"text": "`services/chiefOfStaffService.js:325` calls `POST https://api.anthropic.com/v1/messages` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.anthropic.com/v1/messages`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7c38e6b0cc618f13", "name": "Unused endpoint: USE /api/horizon/auth/login", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/auth/login"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/auth/login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fc3891eef02488c0", "name": "Unused endpoint: USE /api/horizon/auth/register-owner", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/auth/register-owner"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/auth/register-owner` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ba6d4a99f2b92b55", "name": "Unused endpoint: USE /api/horizon/auth/complete-setup", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/auth/complete-setup"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/auth/complete-setup` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8ad5e22558c6470e", "name": "Unused endpoint: USE /api/horizon/auth/otp", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/auth/otp"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/auth/otp` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-074e0f67243623cc", "name": "Unused endpoint: USE /api/horizon/auth/phone", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/auth/phone"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/auth/phone` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-854f8a360bc3e5f5", "name": "Unused endpoint: USE /api/horizon/auth", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/auth"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/auth` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-88f1e257c6e88e2f", "name": "Unused endpoint: USE /api/horizon/fundraising", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/fundraising"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/fundraising` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-df38b1d2103a7c9d", "name": "Unused endpoint: USE /api/horizon/financials", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/financials"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/financials` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bbfbfdb4f6e359c3", "name": "Unused endpoint: USE /api/horizon/kpis", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/kpis"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/kpis` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-56a95c5a77e7f1ad", "name": "Unused endpoint: USE /api/horizon/advanced", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/advanced"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/advanced` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7814873a6c8f2b60", "name": "Unused endpoint: USE /api/horizon/analytics", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/analytics"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/analytics` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ef6a384ad0a0143", "name": "Unused endpoint: USE /api/horizon/investor-reports", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/investor-reports"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/investor-reports` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4c7699c927f0823b", "name": "Unused endpoint: USE /api/horizon/headcount", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/headcount"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/headcount` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-89e0dea63751f092", "name": "Unused endpoint: USE /api/horizon/product-milestones", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/product-milestones"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/product-milestones` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4491c5961fd86c99", "name": "Unused endpoint: USE /api/horizon/investor-meetings", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/investor-meetings"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/investor-meetings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9c423225a7b66626", "name": "Unused endpoint: USE /api/horizon/organizations", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/organizations"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/organizations` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1a5f23d6c0e96592", "name": "Unused endpoint: USE /api/horizon/tasks", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/tasks"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/tasks` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a34cbe687a69fe32", "name": "Unused endpoint: USE /api/horizon/notifications", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/notifications"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/notifications` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-00ad0fca882bfd3c", "name": "Unused endpoint: USE /api/horizon/dashboard", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/dashboard"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/dashboard` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5d3f85cbbdd1aef3", "name": "Unused endpoint: USE /api/horizon/investor-updates", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/investor-updates"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/investor-updates` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-358eb1cd6762eb25", "name": "Unused endpoint: USE /api/horizon/meetings", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/meetings"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/meetings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-28617e931a1aa02a", "name": "Unused endpoint: USE /api/horizon/devices", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/devices"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/devices` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f02d556a7aee1919", "name": "Unused endpoint: USE /api/horizon/chief-of-staff", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/chief-of-staff"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/chief-of-staff` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd4ef168a7e4f980", "name": "Unused endpoint: USE /api/horizon/data-rooms", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/data-rooms"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/data-rooms` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-94a7d5593bbd08c9", "name": "Unused endpoint: USE /api/horizon/outreach", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/outreach"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/outreach` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6f889fe9ebe0bca6", "name": "Unused endpoint: USE /api/horizon/public/data-rooms", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/public/data-rooms"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/public/data-rooms` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c57ba60ba5059521", "name": "Unused endpoint: USE /api/horizon/enhanced", "shortDescription": {"text": "Unused endpoint: USE /api/horizon/enhanced"}, "fullDescription": {"text": "`server.js` declares `USE /api/horizon/enhanced` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1febe67b70b7f53f", "name": "Unused endpoint: GET /api/horizon/health", "shortDescription": {"text": "Unused endpoint: GET /api/horizon/health"}, "fullDescription": {"text": "`server.js` declares `GET /api/horizon/health` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f67153fc3f7195b5", "name": "Unused endpoint: GET /api/horizon", "shortDescription": {"text": "Unused endpoint: GET /api/horizon"}, "fullDescription": {"text": "`server.js` declares `GET /api/horizon` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f1e9e2190a5bcfdf", "name": "Unused endpoint: GET /some-org-specific-data", "shortDescription": {"text": "Unused endpoint: GET /some-org-specific-data"}, "fullDescription": {"text": "`middleware/authMiddleware.js` declares `GET /some-org-specific-data` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c034668451907724", "name": "Unused endpoint: POST /create-something", "shortDescription": {"text": "Unused endpoint: POST /create-something"}, "fullDescription": {"text": "`middleware/authMiddleware.js` declares `POST /create-something` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0890d295d99bd14a", "name": "Unused endpoint: GET /command-center", "shortDescription": {"text": "Unused endpoint: GET /command-center"}, "fullDescription": {"text": "`routes/dashboardRoutes.js` declares `GET /command-center` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3f8670f2a29e2a18", "name": "Unused endpoint: GET /portfolio", "shortDescription": {"text": "Unused endpoint: GET /portfolio"}, "fullDescription": {"text": "`routes/dashboardRoutes.js` declares `GET /portfolio` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3194a0420a49c817", "name": "Unused endpoint: GET /briefing/preview", "shortDescription": {"text": "Unused endpoint: GET /briefing/preview"}, "fullDescription": {"text": "`routes/dashboardRoutes.js` declares `GET /briefing/preview` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3650bc18a2551ee4", "name": "Unused endpoint: POST /briefing/send", "shortDescription": {"text": "Unused endpoint: POST /briefing/send"}, "fullDescription": {"text": "`routes/dashboardRoutes.js` declares `POST /briefing/send` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-09ba298b33dc8b1b", "name": "Unused endpoint: POST /budgets", "shortDescription": {"text": "Unused endpoint: POST /budgets"}, "fullDescription": {"text": "`routes/advancedFeaturesRoutes.js` declares `POST /budgets` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ecc295f9c06e670c", "name": "Unused endpoint: GET /budgets", "shortDescription": {"text": "Unused endpoint: GET /budgets"}, "fullDescription": {"text": "`routes/advancedFeaturesRoutes.js` declares `GET /budgets` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e5b92e44dbeed13b", "name": "Unused endpoint: GET /budgets/:id", "shortDescription": {"text": "Unused endpoint: GET /budgets/:id"}, "fullDescription": {"text": "`routes/advancedFeaturesRoutes.js` declares `GET /budgets/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c1fee4918d870198", "name": "Unused endpoint: PUT /budgets/:id", "shortDescription": {"text": "Unused endpoint: PUT /budgets/:id"}, "fullDescription": {"text": "`routes/advancedFeaturesRoutes.js` declares `PUT /budgets/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b59fa201b0e51b64", "name": "Unused endpoint: DELETE /budgets/:id", "shortDescription": {"text": "Unused endpoint: DELETE /budgets/:id"}, "fullDescription": {"text": "`routes/advancedFeaturesRoutes.js` declares `DELETE /budgets/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2f7e897928d1a556", "name": "Unused endpoint: GET /reports/budget-vs-actuals", "shortDescription": {"text": "Unused endpoint: GET /reports/budget-vs-actuals"}, "fullDescription": {"text": "`routes/advancedFeaturesRoutes.js` declares `GET /reports/budget-vs-actuals` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b1c8fc58a4e17836", "name": "Unused endpoint: POST /documents/upload", "shortDescription": {"text": "Unused endpoint: POST /documents/upload"}, "fullDescription": {"text": "`routes/advancedFeaturesRoutes.js` declares `POST /documents/upload` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ffc9ad08ed6cdd74", "name": "Unused endpoint: GET /documents", "shortDescription": {"text": "Unused endpoint: GET /documents"}, "fullDescription": {"text": "`routes/advancedFeaturesRoutes.js` declares `GET /documents` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0684d1ce52b578b1", "name": "Unused endpoint: GET /documents/:id", "shortDescription": {"text": "Unused endpoint: GET /documents/:id"}, "fullDescription": {"text": "`routes/advancedFeaturesRoutes.js` declares `GET /documents/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c12468293f64beed", "name": "Unused endpoint: GET /documents/:id/download", "shortDescription": {"text": "Unused endpoint: GET /documents/:id/download"}, "fullDescription": {"text": "`routes/advancedFeaturesRoutes.js` declares `GET /documents/:id/download` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-04c69b8b8c527336", "name": "Unused endpoint: DELETE /documents/:id", "shortDescription": {"text": "Unused endpoint: DELETE /documents/:id"}, "fullDescription": {"text": "`routes/advancedFeaturesRoutes.js` declares `DELETE /documents/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-89fc99549b047e07", "name": "Unused endpoint: POST /esop-grants", "shortDescription": {"text": "Unused endpoint: POST /esop-grants"}, "fullDescription": {"text": "`routes/advancedFeaturesRoutes.js` declares `POST /esop-grants` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1cb3f88861e65ae1", "name": "Unused endpoint: GET /esop-grants", "shortDescription": {"text": "Unused endpoint: GET /esop-grants"}, "fullDescription": {"text": "`routes/advancedFeaturesRoutes.js` declares `GET /esop-grants` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1c33c324496aebe6", "name": "Unused endpoint: GET /esop-grants/:id", "shortDescription": {"text": "Unused endpoint: GET /esop-grants/:id"}, "fullDescription": {"text": "`routes/advancedFeaturesRoutes.js` declares `GET /esop-grants/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b8f913ccb9d5db0a", "name": "Unused endpoint: PUT /esop-grants/:id", "shortDescription": {"text": "Unused endpoint: PUT /esop-grants/:id"}, "fullDescription": {"text": "`routes/advancedFeaturesRoutes.js` declares `PUT /esop-grants/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/19028"}, "properties": {"repository": "Scaleupapp-nirpeksh/scaleup-horizon-backend", "repoUrl": "https://github.com/Scaleupapp-nirpeksh/scaleup-horizon-backend", "branch": "main"}, "results": [{"ruleId": "scanner-24b7042f4bb39b19", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 migration-script.js:39"}, "properties": {"repobilityId": "b69d2ce9b074baa7", "scanner": "scanner-primary", "fingerprint": "24b7042f4bb39b19", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-dcf9331b67163fcd", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 validation-script.js:62"}, "properties": {"repobilityId": "d3abde9f89ca4c3c", "scanner": "scanner-primary", "fingerprint": "dcf9331b67163fcd", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-6be93ae5b4235db4", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 rollback-script.js:59"}, "properties": {"repobilityId": "e10872c0d34aa6ed", "scanner": "scanner-primary", "fingerprint": "6be93ae5b4235db4", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8f844348c6a2d9e6", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 server.js:73"}, "properties": {"repobilityId": "a9deebb5fdc93edc", "scanner": "scanner-primary", "fingerprint": "8f844348c6a2d9e6", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8582127c67baac22", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 models/roundModel.js:154"}, "properties": {"repobilityId": "799e6932754a923d", "scanner": "scanner-primary", "fingerprint": "8582127c67baac22", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ef05dff125bc591e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 models/investorModel.js:319"}, "properties": {"repobilityId": "4b16bd12aa563202", "scanner": "scanner-primary", "fingerprint": "ef05dff125bc591e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5854d5f5a7ef9deb", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 models/esopGrantModel.js:99"}, "properties": {"repobilityId": "54ddd3d5eeae99dc", "scanner": "scanner-primary", "fingerprint": "5854d5f5a7ef9deb", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-02da5f720b058599", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 models/capTableEntryModel.js:194"}, "properties": {"repobilityId": "8991a2ebb9f15f49", "scanner": "scanner-primary", "fingerprint": "02da5f720b058599", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5f309dd57b230e30", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 config/db.js:14"}, "properties": {"repobilityId": "e41b920af47c3a6e", "scanner": "scanner-primary", "fingerprint": "5f309dd57b230e30", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ad0e19cf7bd27bb6", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/backfillTaskKeys.js:21"}, "properties": {"repobilityId": "a920d2247c5dbee7", "scanner": "scanner-primary", "fingerprint": "ad0e19cf7bd27bb6", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e58a2e783446c5be", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/importTasksFromJson.js:50"}, "properties": {"repobilityId": "64138c3a501793c2", "scanner": "scanner-primary", "fingerprint": "e58a2e783446c5be", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f3f22fcef588fc51", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 controllers/organizationController.js:44"}, "properties": {"repobilityId": "9344e677385c0390", "scanner": "scanner-primary", "fingerprint": "f3f22fcef588fc51", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-354e2e76a7bf0062", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 controllers/headcountController.js:65"}, "properties": {"repobilityId": "b946856ac73e9cd0", "scanner": "scanner-primary", "fingerprint": "354e2e76a7bf0062", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-261e131b5265ac82", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 controllers/fundraisingController.js:59"}, "properties": {"repobilityId": "ed57a8e9a2030986", "scanner": "scanner-primary", "fingerprint": "261e131b5265ac82", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b386d1105b85afe4", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 services/briefingService.js:503"}, "properties": {"repobilityId": "45f80e13bb564554", "scanner": "scanner-primary", "fingerprint": "b386d1105b85afe4", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ad6b901064fe035f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 services/transactionCategorizer.js:55"}, "properties": {"repobilityId": "e3df8e0e6c389b55", "scanner": "scanner-primary", "fingerprint": "ad6b901064fe035f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b506407bdacfb11f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 services/notificationService.js:28"}, "properties": {"repobilityId": "32b5e1e39036a39d", "scanner": "scanner-primary", "fingerprint": "b506407bdacfb11f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-299150de474562b9", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 services/customKpiService.js:685"}, "properties": {"repobilityId": "f21a86d4c6374212", "scanner": "scanner-primary", "fingerprint": "299150de474562b9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-6c1ad8f3aa518490", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 services/fundraisingCalculationService.js:25"}, "properties": {"repobilityId": "56e5c650cd16c834", "scanner": "scanner-primary", "fingerprint": "6c1ad8f3aa518490", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3af31c2cccfb756a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 services/recurringTransactionService.js:21"}, "properties": {"repobilityId": "4cb21004697613aa", "scanner": "scanner-primary", "fingerprint": "3af31c2cccfb756a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a58b36f9cbea4b8b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 services/advancedMLService.js:80"}, "properties": {"repobilityId": "a0f35e477df68b00", "scanner": "scanner-primary", "fingerprint": "a58b36f9cbea4b8b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-28c4a04bd807da0c", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "1e168e1594cfcd53", "scanner": "scanner-primary", "fingerprint": "28c4a04bd807da0c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy.yml"}, "region": {"startLine": 35}}}]}, {"ruleId": "scanner-d120614767f036de", "level": "note", "message": {"text": "Very large file: controllers/predictiveAnalyticsController.js (1602 lines)"}, "properties": {"repobilityId": "aa84ba88b0c6ed94", "scanner": "scanner-primary", "fingerprint": "d120614767f036de", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-f485a8697a897e36", "level": "note", "message": {"text": "Very large file: controllers/taskController.js (1635 lines)"}, "properties": {"repobilityId": "44b4b43cfc82f2b1", "scanner": "scanner-primary", "fingerprint": "f485a8697a897e36", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-90dc4e8193c69ae8", "level": "note", "message": {"text": "Very large file: controllers/fundraisingController.js (1821 lines)"}, "properties": {"repobilityId": "5aa794b01a4862c0", "scanner": "scanner-primary", "fingerprint": "90dc4e8193c69ae8", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "7e96d4b46597c856", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "83def68396cee93c", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "074158f3353bb835", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-11825279136b53a3", "level": "warning", "message": {"text": "CI is configured but no tests are detected"}, "properties": {"repobilityId": "910ad954966c4f00", "scanner": "scanner-primary", "fingerprint": "11825279136b53a3", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "ci", "config-theater", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "3624d30527bf2127", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "7300ca804825026e", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "06e3226e6a7ab3c4", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-b1171adbcc309cab", "level": "none", "message": {"text": "Commented-code block (6 lines) in models/productMilestoneModel.js:361"}, "properties": {"repobilityId": "5baa4d47e6c16039", "scanner": "scanner-primary", "fingerprint": "b1171adbcc309cab", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5ca42dee6b6618e4", "level": "none", "message": {"text": "Commented-code block (5 lines) in models/investorReportModel.js:68"}, "properties": {"repobilityId": "4749b13afe9a0a71", "scanner": "scanner-primary", "fingerprint": "5ca42dee6b6618e4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e4c3d3925f355609", "level": "none", "message": {"text": "Commented-code block (5 lines) in models/headcountModel.js:340"}, "properties": {"repobilityId": "3a11af196a90b040", "scanner": "scanner-primary", "fingerprint": "e4c3d3925f355609", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-dec7b9eb6722d52f", "level": "none", "message": {"text": "Commented-code block (6 lines) in models/revenueModel.js:47"}, "properties": {"repobilityId": "9263405b45580dd8", "scanner": "scanner-primary", "fingerprint": "dec7b9eb6722d52f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d59820bc6edd8b25", "level": "none", "message": {"text": "Commented-code block (5 lines) in models/investorMeetingModel.js:359"}, "properties": {"repobilityId": "026a8ebfb1715b94", "scanner": "scanner-primary", "fingerprint": "d59820bc6edd8b25", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-bf1dd7e077696baa", "level": "none", "message": {"text": "Commented-code block (5 lines) in models/bankAccountModel.js:36"}, "properties": {"repobilityId": "16f6e2a507bd22c8", "scanner": "scanner-primary", "fingerprint": "bf1dd7e077696baa", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b66d11da0dbf6341", "level": "none", "message": {"text": "Commented-code block (5 lines) in middleware/authMiddleware.js:68"}, "properties": {"repobilityId": "afa716971a0de40a", "scanner": "scanner-primary", "fingerprint": "b66d11da0dbf6341", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6b6efdd50860196b", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/importTasksFromJson.js:7"}, "properties": {"repobilityId": "d5059a56b144cd72", "scanner": "scanner-primary", "fingerprint": "6b6efdd50860196b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f0e173f389e50f64", "level": "none", "message": {"text": "Commented-code block (5 lines) in routes/kpiRoutes.js:75"}, "properties": {"repobilityId": "b11ea5dd48e5f091", "scanner": "scanner-primary", "fingerprint": "f0e173f389e50f64", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b2f6271dae87acbc", "level": "none", "message": {"text": "Commented-code block (5 lines) in routes/predictiveAnalyticsRoutes.js:38"}, "properties": {"repobilityId": "4f6ea6aaa7ed3148", "scanner": "scanner-primary", "fingerprint": "b2f6271dae87acbc", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-991d20af8f974dff", "level": "none", "message": {"text": "Commented-code block (5 lines) in controllers/advancedFeaturesController.js:111"}, "properties": {"repobilityId": "35cb8998c29a5b4c", "scanner": "scanner-primary", "fingerprint": "991d20af8f974dff", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8d9eecaf7c40e1fd", "level": "none", "message": {"text": "Commented-code block (6 lines) in services/apnsService.js:5"}, "properties": {"repobilityId": "2e83afcfeece6552", "scanner": "scanner-primary", "fingerprint": "8d9eecaf7c40e1fd", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2f897520ccb0c0b5", "level": "none", "message": {"text": "Commented-code block (5 lines) in services/investorUpdateService.js:1"}, "properties": {"repobilityId": "3381c2f3d94953eb", "scanner": "scanner-primary", "fingerprint": "2f897520ccb0c0b5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ff640ca4436f2156", "level": "none", "message": {"text": "Commented-code block (5 lines) in services/briefingService.js:1"}, "properties": {"repobilityId": "aad056049116b280", "scanner": "scanner-primary", "fingerprint": "ff640ca4436f2156", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-544843012caeaf19", "level": "none", "message": {"text": "Commented-code block (7 lines) in services/notificationService.js:1"}, "properties": {"repobilityId": "a591e1bd7a83415f", "scanner": "scanner-primary", "fingerprint": "544843012caeaf19", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6452ef0d62d062dd", "level": "none", "message": {"text": "Commented-code block (8 lines) in services/chiefOfStaffService.js:1"}, "properties": {"repobilityId": "0e4d0d443bff74d4", "scanner": "scanner-primary", "fingerprint": "6452ef0d62d062dd", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-514d57feb26b6908", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/chiefOfStaffService.js:325"}, "properties": {"repobilityId": "22119324291cf0de", "scanner": "scanner-primary", "fingerprint": "514d57feb26b6908", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-0d9881aa31b735da", "level": "error", "message": {"text": "Dangling fetch: POST https://api.anthropic.com/v1/messages (services/chiefOfStaffService.js:325)"}, "properties": {"repobilityId": "d8f33d3be02c1a17", "scanner": "scanner-primary", "fingerprint": "0d9881aa31b735da", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-7c38e6b0cc618f13", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/auth/login"}, "properties": {"repobilityId": "9897edbd3ecdeb11", "scanner": "scanner-primary", "fingerprint": "7c38e6b0cc618f13", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fc3891eef02488c0", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/auth/register-owner"}, "properties": {"repobilityId": "eb38279415d6902c", "scanner": "scanner-primary", "fingerprint": "fc3891eef02488c0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ba6d4a99f2b92b55", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/auth/complete-setup"}, "properties": {"repobilityId": "72b4221d2abbb300", "scanner": "scanner-primary", "fingerprint": "ba6d4a99f2b92b55", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8ad5e22558c6470e", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/auth/otp"}, "properties": {"repobilityId": "37dfd9650f837aed", "scanner": "scanner-primary", "fingerprint": "8ad5e22558c6470e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-074e0f67243623cc", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/auth/phone"}, "properties": {"repobilityId": "109e13b64d63b263", "scanner": "scanner-primary", "fingerprint": "074e0f67243623cc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-854f8a360bc3e5f5", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/auth"}, "properties": {"repobilityId": "4f9d7484550f2299", "scanner": "scanner-primary", "fingerprint": "854f8a360bc3e5f5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-88f1e257c6e88e2f", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/fundraising"}, "properties": {"repobilityId": "ee9d3cf2ce02fc94", "scanner": "scanner-primary", "fingerprint": "88f1e257c6e88e2f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-df38b1d2103a7c9d", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/financials"}, "properties": {"repobilityId": "59a749aa9a94f616", "scanner": "scanner-primary", "fingerprint": "df38b1d2103a7c9d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bbfbfdb4f6e359c3", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/kpis"}, "properties": {"repobilityId": "9f839cd437142fec", "scanner": "scanner-primary", "fingerprint": "bbfbfdb4f6e359c3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-56a95c5a77e7f1ad", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/advanced"}, "properties": {"repobilityId": "707471935b598795", "scanner": "scanner-primary", "fingerprint": "56a95c5a77e7f1ad", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7814873a6c8f2b60", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/analytics"}, "properties": {"repobilityId": "4bd26707d8f20299", "scanner": "scanner-primary", "fingerprint": "7814873a6c8f2b60", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3ef6a384ad0a0143", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/investor-reports"}, "properties": {"repobilityId": "19703968d4687d97", "scanner": "scanner-primary", "fingerprint": "3ef6a384ad0a0143", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4c7699c927f0823b", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/headcount"}, "properties": {"repobilityId": "ad47120df202a7dd", "scanner": "scanner-primary", "fingerprint": "4c7699c927f0823b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-89e0dea63751f092", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/product-milestones"}, "properties": {"repobilityId": "d20ffb2518b8a357", "scanner": "scanner-primary", "fingerprint": "89e0dea63751f092", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4491c5961fd86c99", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/investor-meetings"}, "properties": {"repobilityId": "9e29ea55df30ff9d", "scanner": "scanner-primary", "fingerprint": "4491c5961fd86c99", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9c423225a7b66626", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/organizations"}, "properties": {"repobilityId": "a277de68e8c075ca", "scanner": "scanner-primary", "fingerprint": "9c423225a7b66626", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1a5f23d6c0e96592", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/tasks"}, "properties": {"repobilityId": "1d54ae7ba8977033", "scanner": "scanner-primary", "fingerprint": "1a5f23d6c0e96592", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a34cbe687a69fe32", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/notifications"}, "properties": {"repobilityId": "aa6a953cca60cf73", "scanner": "scanner-primary", "fingerprint": "a34cbe687a69fe32", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-00ad0fca882bfd3c", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/dashboard"}, "properties": {"repobilityId": "cb6a5351aea6fa72", "scanner": "scanner-primary", "fingerprint": "00ad0fca882bfd3c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5d3f85cbbdd1aef3", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/investor-updates"}, "properties": {"repobilityId": "e8a3136ca00f6f52", "scanner": "scanner-primary", "fingerprint": "5d3f85cbbdd1aef3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-358eb1cd6762eb25", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/meetings"}, "properties": {"repobilityId": "315ec6a12869d910", "scanner": "scanner-primary", "fingerprint": "358eb1cd6762eb25", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-28617e931a1aa02a", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/devices"}, "properties": {"repobilityId": "89c33f89e372044d", "scanner": "scanner-primary", "fingerprint": "28617e931a1aa02a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f02d556a7aee1919", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/chief-of-staff"}, "properties": {"repobilityId": "b8eecdc38e30434c", "scanner": "scanner-primary", "fingerprint": "f02d556a7aee1919", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd4ef168a7e4f980", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/data-rooms"}, "properties": {"repobilityId": "9060fdeb8a5f2ee7", "scanner": "scanner-primary", "fingerprint": "fd4ef168a7e4f980", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-94a7d5593bbd08c9", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/outreach"}, "properties": {"repobilityId": "d2651983fc7bf966", "scanner": "scanner-primary", "fingerprint": "94a7d5593bbd08c9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6f889fe9ebe0bca6", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/public/data-rooms"}, "properties": {"repobilityId": "267d464ee8fdd28f", "scanner": "scanner-primary", "fingerprint": "6f889fe9ebe0bca6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c57ba60ba5059521", "level": "note", "message": {"text": "Unused endpoint: USE /api/horizon/enhanced"}, "properties": {"repobilityId": "918152db9b410817", "scanner": "scanner-primary", "fingerprint": "c57ba60ba5059521", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1febe67b70b7f53f", "level": "note", "message": {"text": "Unused endpoint: GET /api/horizon/health"}, "properties": {"repobilityId": "38048a90d4a21356", "scanner": "scanner-primary", "fingerprint": "1febe67b70b7f53f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f67153fc3f7195b5", "level": "note", "message": {"text": "Unused endpoint: GET /api/horizon"}, "properties": {"repobilityId": "27dfe5ba7de2e3f8", "scanner": "scanner-primary", "fingerprint": "f67153fc3f7195b5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f1e9e2190a5bcfdf", "level": "note", "message": {"text": "Unused endpoint: GET /some-org-specific-data"}, "properties": {"repobilityId": "93f1abe90557d464", "scanner": "scanner-primary", "fingerprint": "f1e9e2190a5bcfdf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c034668451907724", "level": "note", "message": {"text": "Unused endpoint: POST /create-something"}, "properties": {"repobilityId": "f270b896e2892530", "scanner": "scanner-primary", "fingerprint": "c034668451907724", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0890d295d99bd14a", "level": "note", "message": {"text": "Unused endpoint: GET /command-center"}, "properties": {"repobilityId": "353dd41994e86bb8", "scanner": "scanner-primary", "fingerprint": "0890d295d99bd14a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3f8670f2a29e2a18", "level": "note", "message": {"text": "Unused endpoint: GET /portfolio"}, "properties": {"repobilityId": "c8c5e4dab2ace64a", "scanner": "scanner-primary", "fingerprint": "3f8670f2a29e2a18", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3194a0420a49c817", "level": "note", "message": {"text": "Unused endpoint: GET /briefing/preview"}, "properties": {"repobilityId": "15c510354e65017f", "scanner": "scanner-primary", "fingerprint": "3194a0420a49c817", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3650bc18a2551ee4", "level": "note", "message": {"text": "Unused endpoint: POST /briefing/send"}, "properties": {"repobilityId": "c474bf8cf31c77ce", "scanner": "scanner-primary", "fingerprint": "3650bc18a2551ee4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-09ba298b33dc8b1b", "level": "note", "message": {"text": "Unused endpoint: POST /budgets"}, "properties": {"repobilityId": "5dfa1f9754c65247", "scanner": "scanner-primary", "fingerprint": "09ba298b33dc8b1b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ecc295f9c06e670c", "level": "note", "message": {"text": "Unused endpoint: GET /budgets"}, "properties": {"repobilityId": "7835ebf0bcbbc274", "scanner": "scanner-primary", "fingerprint": "ecc295f9c06e670c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e5b92e44dbeed13b", "level": "note", "message": {"text": "Unused endpoint: GET /budgets/:id"}, "properties": {"repobilityId": "5f0dd120508793e7", "scanner": "scanner-primary", "fingerprint": "e5b92e44dbeed13b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c1fee4918d870198", "level": "note", "message": {"text": "Unused endpoint: PUT /budgets/:id"}, "properties": {"repobilityId": "c1679fa89847beed", "scanner": "scanner-primary", "fingerprint": "c1fee4918d870198", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b59fa201b0e51b64", "level": "note", "message": {"text": "Unused endpoint: DELETE /budgets/:id"}, "properties": {"repobilityId": "75f41fca00d29812", "scanner": "scanner-primary", "fingerprint": "b59fa201b0e51b64", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2f7e897928d1a556", "level": "note", "message": {"text": "Unused endpoint: GET /reports/budget-vs-actuals"}, "properties": {"repobilityId": "93f66e5e93b199f2", "scanner": "scanner-primary", "fingerprint": "2f7e897928d1a556", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b1c8fc58a4e17836", "level": "note", "message": {"text": "Unused endpoint: POST /documents/upload"}, "properties": {"repobilityId": "1b018f8870b34713", "scanner": "scanner-primary", "fingerprint": "b1c8fc58a4e17836", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ffc9ad08ed6cdd74", "level": "note", "message": {"text": "Unused endpoint: GET /documents"}, "properties": {"repobilityId": "359f55c61ff0cd25", "scanner": "scanner-primary", "fingerprint": "ffc9ad08ed6cdd74", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0684d1ce52b578b1", "level": "note", "message": {"text": "Unused endpoint: GET /documents/:id"}, "properties": {"repobilityId": "df628c9e1ea524e9", "scanner": "scanner-primary", "fingerprint": "0684d1ce52b578b1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c12468293f64beed", "level": "note", "message": {"text": "Unused endpoint: GET /documents/:id/download"}, "properties": {"repobilityId": "5bedc79df31a7bb4", "scanner": "scanner-primary", "fingerprint": "c12468293f64beed", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-04c69b8b8c527336", "level": "note", "message": {"text": "Unused endpoint: DELETE /documents/:id"}, "properties": {"repobilityId": "d4773181d68cbfe0", "scanner": "scanner-primary", "fingerprint": "04c69b8b8c527336", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-89fc99549b047e07", "level": "note", "message": {"text": "Unused endpoint: POST /esop-grants"}, "properties": {"repobilityId": "c8d33e858cebbd97", "scanner": "scanner-primary", "fingerprint": "89fc99549b047e07", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1cb3f88861e65ae1", "level": "note", "message": {"text": "Unused endpoint: GET /esop-grants"}, "properties": {"repobilityId": "40bdbff3eeb46e86", "scanner": "scanner-primary", "fingerprint": "1cb3f88861e65ae1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1c33c324496aebe6", "level": "note", "message": {"text": "Unused endpoint: GET /esop-grants/:id"}, "properties": {"repobilityId": "bd8ee5b0fcf910d1", "scanner": "scanner-primary", "fingerprint": "1c33c324496aebe6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b8f913ccb9d5db0a", "level": "note", "message": {"text": "Unused endpoint: PUT /esop-grants/:id"}, "properties": {"repobilityId": "a9c4e557bd1814a1", "scanner": "scanner-primary", "fingerprint": "b8f913ccb9d5db0a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}