{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-27ed1c156f6bf844", "name": "Possibly dead Python function: find_libraries", "shortDescription": {"text": "Possibly dead Python function: find_libraries"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-32b7915f6db8afe6", "name": "Possibly dead Python function: safe_patch_mistral_regex", "shortDescription": {"text": "Possibly dead Python function: safe_patch_mistral_regex"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1a3423063a962d2a", "name": "Possibly dead Python function: forward", "shortDescription": {"text": "Possibly dead Python function: forward"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a323e2fb100f702b", "name": "Possibly dead Python function: trim_tts_output", "shortDescription": {"text": "Possibly dead Python function: trim_tts_output"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0704823b8c36377a", "name": "Possibly dead Python function: validate_reference_audio", "shortDescription": {"text": "Possibly dead Python function: validate_reference_audio"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6955c954477e6da4", "name": "Possibly dead Python function: patched_update", "shortDescription": {"text": "Possibly dead Python function: patched_update"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9d659e53a09addc7", "name": "Possibly dead Python function: callback", "shortDescription": {"text": "Possibly dead Python function: callback"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5f910336353cfa51", "name": "Possibly dead Python function: create_progress_callback", "shortDescription": {"text": "Possibly dead Python function: create_progress_callback"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5079b151c4b95cf0", "name": "Possibly dead Python function: callback", "shortDescription": {"text": "Possibly dead Python function: callback"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8a959a3981988ad6", "name": "Possibly dead Python function: reset_backends", "shortDescription": {"text": "Possibly dead Python function: reset_backends"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-181367faff37ca8a", "name": "Possibly dead Python function: generate_audio_sync", "shortDescription": {"text": "Possibly dead Python function: generate_audio_sync"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-afd3ef6534f99acd", "name": "Possibly dead Python function: delete_generations_by_profile", "shortDescription": {"text": "Possibly dead Python function: delete_generations_by_profile"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2f0bf93190596070", "name": "Possibly dead Python function: with_db", "shortDescription": {"text": "Possibly dead Python function: with_db"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c1679ad755d6aef2", "name": "Stray `console.log` in TS/JS \u2014 docs/scripts/generate-openapi.ts:10", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 docs/scripts/generate-openapi.ts:10"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a117d57ea177636a", "name": "Stray `console.log` in TS/JS \u2014 scripts/setup-dev-sidecar.js:62", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/setup-dev-sidecar.js:62"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a5c4e25b39206921", "name": "Stray `console.log` in TS/JS \u2014 app/src/App.tsx:155", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 app/src/App.tsx:155"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-51b98179e5258de1", "name": "Stray `console.log` in TS/JS \u2014 app/src/stores/storyStore.ts:72", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 app/src/stores/storyStore.ts:72"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e2e1879109d4b044", "name": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/Effects/GenerationPicker.tsx:46", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/Effects/GenerationPicker.tsx:46"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5570ba48a02d0e47", "name": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/CapturePill/CapturePill.tsx:194", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/CapturePill/CapturePill.tsx:194"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5ae645cd8e18275f", "name": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/History/HistoryTable.tsx:729", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/History/HistoryTable.tsx:729"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-486650debea17b4b", "name": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/CapturesTab/CapturesTab.tsx:757", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/CapturesTab/CapturesTab.tsx:757"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-563aeeebf4f96b72", "name": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/StoriesTab/StoryContent.tsx:439", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/StoriesTab/StoryContent.tsx:439"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-dfada1d726e6613f", "name": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/StoriesTab/StoryTrackEditor.tsx:1209", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/StoriesTab/StoryTrackEditor.tsx:1209"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6fb65d0b4117e4c0", "name": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/StoriesTab/StoryChatItem.tsx:109", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/StoriesTab/StoryChatItem.tsx:109"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f52808a9be7268b9", "name": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/AudioTab/AudioTab.tsx:190", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/AudioTab/AudioTab.tsx:190"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c51a80f81714a876", "name": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/ServerSettings/ModelManagement.tsx:575", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/ServerSettings/ModelManagement.tsx:575"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-82b8eebfc32c6154", "name": "Stray `console.log` in TS/JS \u2014 app/src/components/ServerSettings/ModelProgress.tsx:31", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 app/src/components/ServerSettings/ModelProgress.tsx:31"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a8195375f6050029", "name": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/ServerTab/MCPPage.tsx:168", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/ServerTab/MCPPage.tsx:168"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0d7001d638a3810f", "name": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/ServerTab/CapturesPage.tsx:476", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/ServerTab/CapturesPage.tsx:476"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-203d17054876fbc7", "name": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/EffectsTab/EffectsList.tsx:160", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/EffectsTab/EffectsList.tsx:160"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-475f689b6b4cda7e", "name": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/VoicesTab/VoicesTab.tsx:227", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/VoicesTab/VoicesTab.tsx:227"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5f58314cb093bf6e", "name": "Stray `console.log` in TS/JS \u2014 app/src/lib/api/client.ts:567", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 app/src/lib/api/client.ts:567"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-300b9702abb62396", "name": "Stray `console.log` in TS/JS \u2014 app/src/lib/utils/debug.ts:6", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 app/src/lib/utils/debug.ts:6"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dde9a742c298aea4", "name": "Stray `console.log` in TS/JS \u2014 app/src/lib/hooks/useModelDownloadToast.tsx:43", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 app/src/lib/hooks/useModelDownloadToast.tsx:43"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-efbbd5cfdd9c88d4", "name": "Stray `console.log` in TS/JS \u2014 app/src/lib/hooks/useStoryPlayback.ts:42", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 app/src/lib/hooks/useStoryPlayback.ts:42"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-96ed4b03127334cb", "name": "`truncate` class without `title=` for hover reveal \u2014 landing/src/components/CaptureSection.tsx:196", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 landing/src/components/CaptureSection.tsx:196"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a265bb5781d332a9", "name": "\"active\" state uses light bg in a dark theme \u2014 landing/src/components/CapturesMockup.tsx:64", "shortDescription": {"text": "\"active\" state uses light bg in a dark theme \u2014 landing/src/components/CapturesMockup.tsx:64"}, "fullDescription": {"text": "A ternary like `active ? 'bg-white' : '...'` (or bg-gray-100/200) on a dark theme produces jarring white pills. Use a dark-emphasized active state instead \u2014 border + ring or slightly brighter dark bg. Example: `active ? 'bg-gray-800 border-gray-500 ring-1 ring-blue-500/30' : '\u2026'`.\n\nWhy: P-E in CHECKLIST.md \u2014 light bg in a dark theme is a class of regression.\nRule id: fq.active-light-bg"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-26638f51f2919403", "name": "`truncate` class without `title=` for hover reveal \u2014 landing/src/components/ControlUI.tsx:389", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 landing/src/components/ControlUI.tsx:389"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-34000899e86ce09a", "name": "Stray `console.log` in TS/JS \u2014 landing/src/components/ControlUI.tsx:601", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 landing/src/components/ControlUI.tsx:601"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-786a7b7a646c0ffd", "name": "\"active\" state uses light bg in a dark theme \u2014 landing/src/components/ControlUI.tsx:759", "shortDescription": {"text": "\"active\" state uses light bg in a dark theme \u2014 landing/src/components/ControlUI.tsx:759"}, "fullDescription": {"text": "A ternary like `active ? 'bg-white' : '...'` (or bg-gray-100/200) on a dark theme produces jarring white pills. Use a dark-emphasized active state instead \u2014 border + ring or slightly brighter dark bg. Example: `active ? 'bg-gray-800 border-gray-500 ring-1 ring-blue-500/30' : '\u2026'`.\n\nWhy: P-E in CHECKLIST.md \u2014 light bg in a dark theme is a class of regression.\nRule id: fq.active-light-bg"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3896f19672966d09", "name": "\"active\" state uses light bg in a dark theme \u2014 landing/src/components/Personalities.tsx:84", "shortDescription": {"text": "\"active\" state uses light bg in a dark theme \u2014 landing/src/components/Personalities.tsx:84"}, "fullDescription": {"text": "A ternary like `active ? 'bg-white' : '...'` (or bg-gray-100/200) on a dark theme produces jarring white pills. Use a dark-emphasized active state instead \u2014 border + ring or slightly brighter dark bg. Example: `active ? 'bg-gray-800 border-gray-500 ring-1 ring-blue-500/30' : '\u2026'`.\n\nWhy: P-E in CHECKLIST.md \u2014 light bg in a dark theme is a class of regression.\nRule id: fq.active-light-bg"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d52a6d760113e6be", "name": "`truncate` class without `title=` for hover reveal \u2014 landing/src/components/TokenSection.tsx:74", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 landing/src/components/TokenSection.tsx:74"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-30bd41517e3ee2e6", "name": "`truncate` class without `title=` for hover reveal \u2014 landing/src/components/SupportedModels.tsx:160", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 landing/src/components/SupportedModels.tsx:160"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0cc57baeae5b6401", "name": "`truncate` class without `title=` for hover reveal \u2014 landing/src/components/LandingAudioPlayer.tsx:258", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 landing/src/components/LandingAudioPlayer.tsx:258"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ee84ada160ffdd8d", "name": "Stray `console.log` in TS/JS \u2014 landing/src/components/LandingAudioPlayer.tsx:135", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 landing/src/components/LandingAudioPlayer.tsx:135"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-97761e105d4b5989", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 landing/src/app/blog/[slug]/page.tsx:85", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 landing/src/app/blog/[slug]/page.tsx:85"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e973be083d678275", "name": "TODO/FIXME marker in shipping code \u2014 landing/src/lib/constants.ts:142", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 landing/src/lib/constants.ts:142"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-16a52601481598cd", "name": "Stray `console.log` in TS/JS \u2014 tauri/src/platform/lifecycle.ts:14", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tauri/src/platform/lifecycle.ts:14"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-476013846b8600a4", "name": "exec detected \u2014 backend/pyi_rth_torch_compiler_disable.py:335", "shortDescription": {"text": "exec detected \u2014 backend/pyi_rth_torch_compiler_disable.py:335"}, "fullDescription": {"text": "Detected the use of exec(). exec() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources.\n\nRule: python.lang.security.audit.exec-detected.exec-detected\nSeverity: WARNING\nOWASP: A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9aabd74304a56dea", "name": "exec detected \u2014 backend/pyi_rth_torch_compiler_disable.py:461", "shortDescription": {"text": "exec detected \u2014 backend/pyi_rth_torch_compiler_disable.py:461"}, "fullDescription": {"text": "Detected the use of exec(). exec() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources.\n\nRule: python.lang.security.audit.exec-detected.exec-detected\nSeverity: WARNING\nOWASP: A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9d99b96de9e13c92", "name": "CVE-2026-44573: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-44573: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data/<buildId>/<page>.json requests. In affected configurations, middleware does not run for the unprefixed data route, allowing an attacker to retrieve SSR JSON for protected pages without passing the intende\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-903d6275bc097612", "name": "CVE-2026-44574: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-44574: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "Next.js: Next.js: Authorization bypass via crafted query parameters\n\nNext.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic route value seen by the page while leaving the visible path unchanged, which can allow protected content to be rendered without passing the expected middleware check. This vulnerability is fixed in 1\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d5b29c11c3c406a5", "name": "CVE-2026-44575: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-44575: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "next.js: Next.js: Unauthorized access to protected content via middleware bypass\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetching. In affected configurations, specially crafted .rsc and segment-prefetch URLs can resolve to the same page without being matched by the intended middleware rule, which can allow protected content to\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-92dbe0b7b2a67144", "name": "CVE-2026-44578: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-44578: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests\n\nNext.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4b87f99bf2dd4847", "name": "CVE-2026-44579: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-44579: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service via crafted POST requests to server actions\n\nNext.js is a React framework for building full-stack web applications. From  to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurations, a malicious request can trigger a request-body handling deadlock that leaves connections open for an extended period, consuming file descriptors and server capacity until legitimate users are den\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-30a58c47ed74df81", "name": "CVE-2026-45109: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-45109: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure via security fix bypass in middleware with Turbopack\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 15.5.18, 16.2.6\nSeverity: HIGH\nFix: Upgrade next to 15.5.18, 16.2.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-372563b284b7c724", "name": "CVE-2026-64641: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-64641: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "Next.js: Denial of Service in App Router using Server Actions\n\n## Impact\n\nCrafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process.\n\n## Workarounds\n\nNo workaround exists besides upgrading. Applications using Pages Router or not using Server Actions are not vulnerable.\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9fb0ba5ab85a3c63", "name": "CVE-2026-64642: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-64642: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale\n\n## Impact\n\nCrafted requests targeting Next.js applications using App Router built with Turbopack and a **single** entry in `config.i18n.locales` can bypass middleware/proxy based authentication.\n\n## Workarounds\n\nIf you cannot upgrade immediately, enforce authorization in the page's server-side data path instead of relying solely on middleware.\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-65686f8cd76fb656", "name": "CVE-2026-64645: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-64645: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname\n\n## Impact\n\nA `rewrites()` or `redirects()` rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's\u00a0hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A `redirects()` rule configured this way is vulnerable to an Open Redirect.\n\nThis affects any destination that puts a dynamic segmen\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-020b28bcdaa5c695", "name": "CVE-2026-64649: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-64649: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in Server Actions on custom servers\n\n## Impact\n\nWhen a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker's request to control Host-associated headers. In some configurations, it's also possible to obtain internal values that weaken middleware/proxy authorization.\n\nApplications that use Server Actions are affected when the incoming host header is not fixed to a trusted value. This typically occurs\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-de98e22d9c14f9dc", "name": "GHSA-8h8q-6873-q5fj: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "GHSA-8h8q-6873-q5fj: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "Next.js Vulnerable to Denial of Service with Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23870](https://github.com/facebook/react/security/advisories/GHSA-rv78-f8rc-xrxh). \n\nA specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage. This can result in denial of \n\nPackage: next\nInstalled: 16.1.4\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b1ff9ca01e92400a", "name": "GHSA-h25m-26qc-wcjf: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "GHSA-h25m-26qc-wcjf: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.0.x, 19.1.x, and 19.2.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23864](https://github.com/facebook/react/security/advisories/GHSA-83fc-fqcc-2hmg).\n\nA specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage, out-of-m\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 15.0.8, 15.1.12, 15.2.9, 15.3.9, 15.4.11, 15.5.10, 15.6.0-canary.61, 16.0.11, 16.1.5\nSeverity: HIGH\nFix: Upgrade next to 15.0.8, 15.1.12, 15.2.9, 15.3.9, 15.4.11, 15.5.10, 15.6.0-canary.61, 16.0.11, 16.1.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b29f0e12ea37393d", "name": "GHSA-q4gf-8mx6-v5v3: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "GHSA-q4gf-8mx6-v5v3: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "Next.js has a Denial of Service with Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23869](https://github.com/facebook/react/security/advisories/GHSA-479c-33wc-g2pg). You can read more about this advisory our [this changelog](https://vercel.com/changelog/summary-of-cve-2026-23869).\n\nA specially crafted HTTP request can be sent to any App Rout\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 15.5.15, 16.2.3\nSeverity: HIGH\nFix: Upgrade next to 15.5.15, 16.2.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cd090f806c60bbe3", "name": "CVE-2025-59471: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2025-59471: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "next: NextJS Denial of Service in Image Optimizer\n\nA denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image optimization endpoint (`/_next/image`) loads external images entirely into memory without enforcing a maximum size limit, allowing an attacker to cause out-of-memory conditions by requesting optimization of arbitrarily large images. This vulnerability requires that `remotePatterns` is configured to allow image optimization from external domains and\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 15.5.10, 16.1.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.10, 16.1.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8f7e97a20dd6a8a2", "name": "CVE-2025-59472: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2025-59472: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "next: NextJS Denial of Service in Partial Pre Rendering\n\nA denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR resume endpoint accepts unauthenticated POST requests with the `Next-Resume: 1` header and processes attacker-controlled postponed state data. Two closely related vulnerabilities allow an attacker to crash the server process through memory exhaustion:\n\n1. **Unbounded request body buffering**: The server buffers the entire POST request body into memory using `\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 16.1.5, 15.6.0-canary.61\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.5, 15.6.0-canary.61"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-85b2bda42b124149", "name": "CVE-2026-27978: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-27978: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "next.js: Next.js: null origin can bypass Server Actions CSRF checks\n\nNext.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, `origin: null` was treated as a \"missing\" origin during Server Action CSRF validation. As a result, requests from opaque contexts (such as sandboxed iframes) could bypass origin verification instead of being validated as cross-origin requests. An attacker could induce a victim browser to submit Server Actions from a sandboxed context, potentially executing state-changing\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 16.1.7\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6b8f685bbc40fed4", "name": "CVE-2026-27979: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-27979: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "next.js: Next.js: Unbounded postponed resume buffering can lead to DoS\n\nNext.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, a request containing the `next-resume: 1` header (corresponding with a PPR resume request) would buffer request bodies without consistently enforcing `maxPostponedStateSize` in certain setups. The previous mitigation protected minimal-mode deployments, but equivalent non-minimal deployments remained vulnerable to the same unbounded postponed resume-body buffering behavio\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 16.1.7\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3d94421d17535df7", "name": "CVE-2026-27980: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-27980: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "next.js: Next.js: Unbounded next/image disk cache growth can exhaust storage\n\nNext.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js image optimization disk cache (`/_next/image`) did not have a configurable upper bound, allowing unbounded cache growth. An attacker could generate many unique image-optimization variants and exhaust disk space, causing denial of service. This is fixed in version 16.1.7 by adding an LRU-backed disk cache with `images.maximumDiskCacheSize`, including e\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 16.1.7, 15.5.14\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7, 15.5.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-877ae5426df8bdde", "name": "CVE-2026-29057: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-29057: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "next.js: Next.js: HTTP request smuggling in rewrites\n\nNext.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 15.5.13 and 16.1.7, when Next.js rewrites proxy traffic to an external backend, a crafted `DELETE`/`OPTIONS` request using `Transfer-Encoding: chunked` could trigger request boundary disagreement between the proxy and backend. This could allow request smuggling through rewritten routes. An attacker could smuggle a second request to unintended backend routes (for example, interna\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 16.1.7, 15.5.13\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7, 15.5.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6ce9b8c9342c54bc", "name": "CVE-2026-44576: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-44576: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning vulnerability in React Server Components\n\nNext.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not correctly partition response variants. Under affected conditions, an attacker can cause an RSC response to be served from the original URL and poison shared cache entries so later visitors receive component payloads instead of the expected HTML. This vulnerability is fixed in 15.5\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bc0a9dcc8ff3d201", "name": "CVE-2026-44577: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-44577: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "Next.js: Next.js: Denial of Service via Image Optimization API\n\nNext.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memory without enforcing a maximum size limit. An attacker could cause out-of-memory conditions by requesting large local assets from the /_next/image endpoint that match the images.localPatterns configuration (by default, all patterns are allowed). This vulnerability\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1867d5abea9f61db", "name": "CVE-2026-44580: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-44580: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "next.js: Next.js: Cross-site scripting allows arbitrary code execution via untrusted script content\n\nNext.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped safely before being embedded into the document, which could allow attacker-controlled input to break out of the intended script context and execute arbitrary JavaScript in a visitor's browser. This vu\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1bb0b9a130740958", "name": "CVE-2026-44581: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-44581: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "next.js: Next.js: Stored Cross-Site Scripting via malformed nonce values in cached responses\n\nNext.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived from request headers could be reflected into rendered HTML in an unsafe way, allowing an attacker to poison cached responses and cause script execution for later visitors. This vulnerability is fixed i\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3da289591305ca33", "name": "CVE-2026-64643: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-64643: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "Next.js: Unauthenticated disclosure of internal Server Function endpoints\n\n## Impact\n\nIn Next.js applications using App Router, Server Actions (`use server`) or `use cache` endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used.\n\nServer Action IDs can be disclosed to unauthenticated users via publicly served client artifacts (for example, static chunks containing action references).\n\nAffected users are applications using App Router + Server Actions.  \n\nBy itself, this disclosure is typically a recon/enumeration primi\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a4cba77015a32b49", "name": "CVE-2026-64644: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-64644: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "Next.js: Denial of Service in the Image Optimization API using SVGs\n\n### Impact\n\nWhen self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in  `/_next/image` endpoints.\n\n- If you are using `config.images.remotePatterns`, only the patterns in that array are impacted.\n- If you are using `config.images.unoptimized: true`, you are NOT impacted.\n- If you are using `config.images.loader: 'custom'`\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-75463bc9ee6a2e34", "name": "CVE-2026-64646: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-64646: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "Next.js: Unbounded Server Action payload in Edge runtime\n\n## Impact\n\nRequests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime\n\n## Workarounds\n\nIf you cannot upgrade, ensure your hosting provider limits the request's body size. 5 MiB should be allowed at max by your hosting provider.\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-10ee0918abcec617", "name": "CVE-2026-64647: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-64647: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis is only an issue when receiving request bodies with a content type charset other than UTF-8. For example, the UTF-16 byte sequences for `\uc083\uc083` and `\uc104\uc104` in the request body would share the same cache.\n\n##\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-78e3aa3a78a677e5", "name": "CVE-2026-64648: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-64648: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis only applies to `fetch` calls with a request that has a different init than the one passed to `fetch`.\nSafe: `fetch(new Request(init), init)`\nUnsafe: `fetch(new Request(init), aDifferentInit)`\n\n## Work\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-254de043012da6e5", "name": "CVE-2026-27977: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-27977: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "next.js: Next.js: null origin can bypass dev HMR websocket CSRF checks\n\nNext.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, in `next dev`, cross-site protection for internal websocket endpoints could treat `Origin: null` as a bypass case even if `allowedDevOrigins` is configured, allowing privacy-sensitive/opaque contexts (for example sandboxed documents) to connect unexpectedly. If a dev server is reachable from attacker-controlled content, an attacker may be able to connect to the HMR webso\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 16.1.7\nSeverity: LOW\nFix: Upgrade next to 16.1.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b67d8f4b96d27893", "name": "CVE-2026-44572: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-44572: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service due to improper handling of x-nextjs-data header with redirects\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path handled by middleware that returns a redirect. When that happened, the middleware/proxy could treat the request as a data request and replace the standard Location redirect header with the internal x-nextjs-redirect header. Browsers do not follow x-nextjs-redirect, so the response became an unusable red\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-166a578a055b7098", "name": "CVE-2026-44582: next 16.1.4 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-44582: next 16.1.4 \u2014 bun.lock"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning allows incorrect response delivery\n\nNext.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient response partitioning. In affected conditions, collisions in the _rsc cache-busting value can allow an attacker to poison cache entries so users receive the wrong response variant for a given URL. This vulnerability is fixed in 15.5.16 and 16.2.5.\n\nPackage: next\nInstalled: 16.1.4\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-81bf70461c6d53dc", "name": "CVE-2026-41305: postcss 8.5.6 \u2014 bun.lock", "shortDescription": {"text": "CVE-2026-41305: postcss 8.5.6 \u2014 bun.lock"}, "fullDescription": {"text": "postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags\n\nPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTML `<style>` tags, `</style>` in CSS values breaks out of the style context, enabling XSS. Version 8.5.10 fixes the issue.\n\nPackage: postcss\nInstalled: 8.5.6\nFixed in: 8.5.10\nSeverity: MEDIUM\nFix: Upgrade postcss to 8.5.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d81c376d5ca53406", "name": "CVE-2025-69873: ajv 8.17.1 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2025-69873: ajv 8.17.1 \u2014 docs/bun.lock"}, "fullDescription": {"text": "ajv: ReDoS via $data reference\n\najv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., \"^(a|a)*$\") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds\n\nPackage: ajv\nInstalled: 8.17.1\nFixed in: 8.18.0, 6.14.0\nSeverity: MEDIUM\nFix: Upgrade ajv to 8.18.0, 6.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-03154cb2c15c61bd", "name": "CVE-2026-13676: fast-uri 3.1.0 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 docs/bun.lock"}, "fullDescription": {"text": "fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization\n\nfast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) befo\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 4.0.1, 3.1.3, 2.4.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 4.0.1, 3.1.3, 2.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-63ab716201c59b73", "name": "CVE-2026-16221: fast-uri 3.1.0 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 docs/bun.lock"}, "fullDescription": {"text": "Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x  ...\n\nImpact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use f\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 2.4.3, 3.1.4, 4.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 2.4.3, 3.1.4, 4.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bbf9eccdbeab3c3e", "name": "CVE-2026-6321: fast-uri 3.1.0 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 docs/bun.lock"}, "fullDescription": {"text": "fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies\n\nfast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalized path. Applications that normalize or compare attacker-controlled URLs to enforce path-based policy can be bypassed, with a path that appears confined under an allowed prefix normalizing to a different location. Version\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eb2652f9be2f53ea", "name": "CVE-2026-6322: fast-uri 3.1.0 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 docs/bun.lock"}, "fullDescription": {"text": "fast-uri: fast-uri: URI authority bypass due to improper delimiter handling\n\nfast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI's authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a differ\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-83c8de6d82803a43", "name": "CVE-2026-25896: fast-xml-parser 4.5.3 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-25896: fast-xml-parser 4.5.3 \u2014 docs/bun.lock"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling\n\nfast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (&lt;, &gt;, &amp;, &quot;, &apos;) with arbitrary values. This bypasses entity encoding and leads to XSS when parsed output is rendered. This vulnerability is fixed in 5.3.5.\n\nPackage: fast-xml-parser\nInstalled: 4.5.3\nFixed in: 5.3.5, 4.5.4\nSeverity: CRITICAL\nFix: Upgrade fast-xml-parser to 5.3.5, 4.5.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-da27e12999ff1145", "name": "CVE-2026-26278: fast-xml-parser 4.5.3 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-26278: fast-xml-parser 4.5.3 \u2014 docs/bun.lock"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansion\n\nfast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of entity expansion. With a very small XML input, it\u2019s possible to make the parser spend seconds or even minutes processing a single request, effectively freezing the application. Version 5.3.6 fixes the issue. As a workaround, avoid using DOCTYPE parsing by `process\n\nPackage: fast-xml-parser\nInstalled: 4.5.3\nFixed in: 4.5.4, 5.3.6\nSeverity: HIGH\nFix: Upgrade fast-xml-parser to 4.5.4, 5.3.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c93f51df02714707", "name": "CVE-2026-33036: fast-xml-parser 4.5.3 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-33036: fast-xml-parser 4.5.3 \u2014 docs/bun.lock"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser: Denial of Service via XML entity expansion bypass\n\nfast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Versions 4.0.0-beta.3 through 5.5.5 contain a bypass vulnerability where numeric character references (&#NNN;, &#xHH;) and standard XML entities completely evade the entity expansion limits (e.g., maxTotalExpansions, maxExpandedLength) added to fix CVE-2026-26278, enabling XML entity expansion Denial of Service. The root cause is that replaceEntitiesValue() in OrderedObjParser.js only enforces \n\nPackage: fast-xml-parser\nInstalled: 4.5.3\nFixed in: 5.5.6, 4.5.5\nSeverity: HIGH\nFix: Upgrade fast-xml-parser to 5.5.6, 4.5.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f413ea4e707d61ef", "name": "CVE-2026-33349: fast-xml-parser 4.5.3 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-33349: fast-xml-parser 4.5.3 \u2014 docs/bun.lock"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser: Denial of Service via unbounded entity expansion due to incorrect configuration limit handling\n\nfast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0.0-beta.3 to before version 5.5.7, the DocTypeReader in fast-xml-parser uses JavaScript truthy checks to evaluate maxEntityCount and maxEntitySize configuration limits. When a developer explicitly sets either limit to 0 \u2014 intending to disallow all entities or restrict entity size to zero bytes \u2014 the falsy nature of 0 in JavaScript causes the guard conditions to short-circuit, co\n\nPackage: fast-xml-parser\nInstalled: 4.5.3\nFixed in: 4.5.5, 5.5.7\nSeverity: MEDIUM\nFix: Upgrade fast-xml-parser to 4.5.5, 5.5.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-55eb60fb3c721e88", "name": "CVE-2026-41650: fast-xml-parser 4.5.3 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-41650: fast-xml-parser 4.5.3 \u2014 docs/bun.lock"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser: XML injection via improper escaping of comment and CDATA sequences\n\nfast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version 5.7.0, XMLBuilder does not escape the \"-->\" sequence in comment content or the \"]]>\" sequence in CDATA sections when building XML from JavaScript objects. This allows XML injection when user-controlled data flows into comments or CDATA elements, leading to XSS, SOAP injection, or data manipulation. This issue has been patched in version 5.7.0.\n\nPackage: fast-xml-parser\nInstalled: 4.5.3\nFixed in: 5.7.0\nSeverity: MEDIUM\nFix: Upgrade fast-xml-parser to 5.7.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-55adbede539c82ac", "name": "CVE-2026-27942: fast-xml-parser 4.5.3 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-27942: fast-xml-parser 4.5.3 \u2014 docs/bun.lock"}, "fullDescription": {"text": "fast-xml-parser: fast-xml-parser: Stack overflow leads to Denial of Service\n\nfast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the application crashes with stack overflow when user use XML builder with `preserveOrder:true`. Version 5.3.8 fixes the issue. As a workaround, use XML builder with `preserveOrder:false` or check the input data before passing to builder.\n\nPackage: fast-xml-parser\nInstalled: 4.5.3\nFixed in: 5.3.8, 4.5.4\nSeverity: LOW\nFix: Upgrade fast-xml-parser to 5.3.8, 4.5.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d7a137dad00d2cd1", "name": "CVE-2026-59869: js-yaml 4.1.1 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-59869: js-yaml 4.1.1 \u2014 docs/bun.lock"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML documents\n\njs-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.\n\nPackage: js-yaml\nInstalled: 4.1.1\nFixed in: 3.15.0, 4.3.0\nSeverity: HIGH\nFix: Upgrade js-yaml to 3.15.0, 4.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d9ed915553a2487a", "name": "CVE-2026-53550: js-yaml 4.1.1 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-53550: js-yaml 4.1.1 \u2014 docs/bun.lock"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML merge keys\n\njs-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and can block a Node.js worker/event loop for seconds with a relatively small payload (tens of KB), resulting in denial of service. The issue is in merge handling inside lib/loader.js. This vulnerabil\n\nPackage: js-yaml\nInstalled: 4.1.1\nFixed in: 4.2.0, 3.15.0\nSeverity: MEDIUM\nFix: Upgrade js-yaml to 4.2.0, 3.15.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d7d76fdba7b1ae58", "name": "CVE-2026-44573: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-44573: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data/<buildId>/<page>.json requests. In affected configurations, middleware does not run for the unprefixed data route, allowing an attacker to retrieve SSR JSON for protected pages without passing the intende\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a35e220c9ec50445", "name": "CVE-2026-44574: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-44574: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "Next.js: Next.js: Authorization bypass via crafted query parameters\n\nNext.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic route value seen by the page while leaving the visible path unchanged, which can allow protected content to be rendered without passing the expected middleware check. This vulnerability is fixed in 1\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-082ab13dc17e4aaa", "name": "CVE-2026-44575: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-44575: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "next.js: Next.js: Unauthorized access to protected content via middleware bypass\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetching. In affected configurations, specially crafted .rsc and segment-prefetch URLs can resolve to the same page without being matched by the intended middleware rule, which can allow protected content to\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-66cd0097f30ada8d", "name": "CVE-2026-44578: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-44578: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests\n\nNext.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-87b71bb3b5cdc721", "name": "CVE-2026-44579: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-44579: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service via crafted POST requests to server actions\n\nNext.js is a React framework for building full-stack web applications. From  to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurations, a malicious request can trigger a request-body handling deadlock that leaves connections open for an extended period, consuming file descriptors and server capacity until legitimate users are den\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fb8130085eff3cf3", "name": "CVE-2026-45109: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-45109: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure via security fix bypass in middleware with Turbopack\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.18, 16.2.6\nSeverity: HIGH\nFix: Upgrade next to 15.5.18, 16.2.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c6f5d93fe1aacdc4", "name": "CVE-2026-64641: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-64641: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "Next.js: Denial of Service in App Router using Server Actions\n\n## Impact\n\nCrafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process.\n\n## Workarounds\n\nNo workaround exists besides upgrading. Applications using Pages Router or not using Server Actions are not vulnerable.\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c17c8a311e05e168", "name": "CVE-2026-64642: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-64642: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale\n\n## Impact\n\nCrafted requests targeting Next.js applications using App Router built with Turbopack and a **single** entry in `config.i18n.locales` can bypass middleware/proxy based authentication.\n\n## Workarounds\n\nIf you cannot upgrade immediately, enforce authorization in the page's server-side data path instead of relying solely on middleware.\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1fd524df056c2a0f", "name": "CVE-2026-64645: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-64645: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname\n\n## Impact\n\nA `rewrites()` or `redirects()` rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's\u00a0hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A `redirects()` rule configured this way is vulnerable to an Open Redirect.\n\nThis affects any destination that puts a dynamic segmen\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f989ed8f1261f106", "name": "CVE-2026-64649: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-64649: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in Server Actions on custom servers\n\n## Impact\n\nWhen a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker's request to control Host-associated headers. In some configurations, it's also possible to obtain internal values that weaken middleware/proxy authorization.\n\nApplications that use Server Actions are affected when the incoming host header is not fixed to a trusted value. This typically occurs\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7ad2be1d591ba333", "name": "GHSA-8h8q-6873-q5fj: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "GHSA-8h8q-6873-q5fj: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "Next.js Vulnerable to Denial of Service with Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23870](https://github.com/facebook/react/security/advisories/GHSA-rv78-f8rc-xrxh). \n\nA specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage. This can result in denial of \n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e78b32d2ef33a97e", "name": "GHSA-q4gf-8mx6-v5v3: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "GHSA-q4gf-8mx6-v5v3: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "Next.js has a Denial of Service with Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23869](https://github.com/facebook/react/security/advisories/GHSA-479c-33wc-g2pg). You can read more about this advisory our [this changelog](https://vercel.com/changelog/summary-of-cve-2026-23869).\n\nA specially crafted HTTP request can be sent to any App Rout\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.15, 16.2.3\nSeverity: HIGH\nFix: Upgrade next to 15.5.15, 16.2.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2004fa5544ead5f4", "name": "CVE-2026-27978: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-27978: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "next.js: Next.js: null origin can bypass Server Actions CSRF checks\n\nNext.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, `origin: null` was treated as a \"missing\" origin during Server Action CSRF validation. As a result, requests from opaque contexts (such as sandboxed iframes) could bypass origin verification instead of being validated as cross-origin requests. An attacker could induce a victim browser to submit Server Actions from a sandboxed context, potentially executing state-changing\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 16.1.7\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-28825b276f4f9b22", "name": "CVE-2026-27979: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-27979: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "next.js: Next.js: Unbounded postponed resume buffering can lead to DoS\n\nNext.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, a request containing the `next-resume: 1` header (corresponding with a PPR resume request) would buffer request bodies without consistently enforcing `maxPostponedStateSize` in certain setups. The previous mitigation protected minimal-mode deployments, but equivalent non-minimal deployments remained vulnerable to the same unbounded postponed resume-body buffering behavio\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 16.1.7\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1f81aec5ff7d0c58", "name": "CVE-2026-27980: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-27980: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "next.js: Next.js: Unbounded next/image disk cache growth can exhaust storage\n\nNext.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js image optimization disk cache (`/_next/image`) did not have a configurable upper bound, allowing unbounded cache growth. An attacker could generate many unique image-optimization variants and exhaust disk space, causing denial of service. This is fixed in version 16.1.7 by adding an LRU-backed disk cache with `images.maximumDiskCacheSize`, including e\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 16.1.7, 15.5.14\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7, 15.5.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-62e3b17ea55f357e", "name": "CVE-2026-29057: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-29057: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "next.js: Next.js: HTTP request smuggling in rewrites\n\nNext.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 15.5.13 and 16.1.7, when Next.js rewrites proxy traffic to an external backend, a crafted `DELETE`/`OPTIONS` request using `Transfer-Encoding: chunked` could trigger request boundary disagreement between the proxy and backend. This could allow request smuggling through rewritten routes. An attacker could smuggle a second request to unintended backend routes (for example, interna\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 16.1.7, 15.5.13\nSeverity: MEDIUM\nFix: Upgrade next to 16.1.7, 15.5.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b66b19a684566e34", "name": "CVE-2026-44576: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-44576: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning vulnerability in React Server Components\n\nNext.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not correctly partition response variants. Under affected conditions, an attacker can cause an RSC response to be served from the original URL and poison shared cache entries so later visitors receive component payloads instead of the expected HTML. This vulnerability is fixed in 15.5\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-15e542e78d9adfcd", "name": "CVE-2026-44577: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-44577: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "Next.js: Next.js: Denial of Service via Image Optimization API\n\nNext.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memory without enforcing a maximum size limit. An attacker could cause out-of-memory conditions by requesting large local assets from the /_next/image endpoint that match the images.localPatterns configuration (by default, all patterns are allowed). This vulnerability\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3678eb107805df4e", "name": "CVE-2026-44580: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-44580: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "next.js: Next.js: Cross-site scripting allows arbitrary code execution via untrusted script content\n\nNext.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped safely before being embedded into the document, which could allow attacker-controlled input to break out of the intended script context and execute arbitrary JavaScript in a visitor's browser. This vu\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d7a104ed827f4cbe", "name": "CVE-2026-44581: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-44581: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "next.js: Next.js: Stored Cross-Site Scripting via malformed nonce values in cached responses\n\nNext.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived from request headers could be reflected into rendered HTML in an unsafe way, allowing an attacker to poison cached responses and cause script execution for later visitors. This vulnerability is fixed i\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-75a3e95ce2417ab9", "name": "CVE-2026-64643: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-64643: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "Next.js: Unauthenticated disclosure of internal Server Function endpoints\n\n## Impact\n\nIn Next.js applications using App Router, Server Actions (`use server`) or `use cache` endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used.\n\nServer Action IDs can be disclosed to unauthenticated users via publicly served client artifacts (for example, static chunks containing action references).\n\nAffected users are applications using App Router + Server Actions.  \n\nBy itself, this disclosure is typically a recon/enumeration primi\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c5ad68df4c8178a0", "name": "CVE-2026-64644: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-64644: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "Next.js: Denial of Service in the Image Optimization API using SVGs\n\n### Impact\n\nWhen self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in  `/_next/image` endpoints.\n\n- If you are using `config.images.remotePatterns`, only the patterns in that array are impacted.\n- If you are using `config.images.unoptimized: true`, you are NOT impacted.\n- If you are using `config.images.loader: 'custom'`\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-164f175176c41ac0", "name": "CVE-2026-64646: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-64646: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "Next.js: Unbounded Server Action payload in Edge runtime\n\n## Impact\n\nRequests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime\n\n## Workarounds\n\nIf you cannot upgrade, ensure your hosting provider limits the request's body size. 5 MiB should be allowed at max by your hosting provider.\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-add3cd6b9238017c", "name": "CVE-2026-64647: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-64647: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis is only an issue when receiving request bodies with a content type charset other than UTF-8. For example, the UTF-16 byte sequences for `\uc083\uc083` and `\uc104\uc104` in the request body would share the same cache.\n\n##\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d6bacd205a993ccc", "name": "CVE-2026-64648: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-64648: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis only applies to `fetch` calls with a request that has a different init than the one passed to `fetch`.\nSafe: `fetch(new Request(init), init)`\nUnsafe: `fetch(new Request(init), aDifferentInit)`\n\n## Work\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8ee073ae0873b632", "name": "CVE-2026-27977: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-27977: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "next.js: Next.js: null origin can bypass dev HMR websocket CSRF checks\n\nNext.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, in `next dev`, cross-site protection for internal websocket endpoints could treat `Origin: null` as a bypass case even if `allowedDevOrigins` is configured, allowing privacy-sensitive/opaque contexts (for example sandboxed documents) to connect unexpectedly. If a dev server is reachable from attacker-controlled content, an attacker may be able to connect to the HMR webso\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 16.1.7\nSeverity: LOW\nFix: Upgrade next to 16.1.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a00cb6457eb5b4bb", "name": "CVE-2026-44572: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-44572: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service due to improper handling of x-nextjs-data header with redirects\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path handled by middleware that returns a redirect. When that happened, the middleware/proxy could treat the request as a data request and replace the standard Location redirect header with the internal x-nextjs-redirect header. Browsers do not follow x-nextjs-redirect, so the response became an unusable red\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-66457d9490129b53", "name": "CVE-2026-44582: next 16.1.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-44582: next 16.1.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning allows incorrect response delivery\n\nNext.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient response partitioning. In affected conditions, collisions in the _rsc cache-busting value can allow an attacker to poison cache entries so users receive the wrong response variant for a given URL. This vulnerability is fixed in 15.5.16 and 16.2.5.\n\nPackage: next\nInstalled: 16.1.6\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-db527dd683e48b97", "name": "CVE-2026-4926: path-to-regexp 8.3.0 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-4926: path-to-regexp 8.3.0 \u2014 docs/bun.lock"}, "fullDescription": {"text": "path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions\n\nImpact:\n\nA bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, causing denial of service.\n\nPatches:\n\nFixed in version 8.4.0.\n\nWorkarounds:\n\nLimit the number of sequential optional groups in route patterns. Avoid passing user-controlled input as route patterns.\n\nPackage: path-to-regexp\nInstalled: 8.3.0\nFixed in: 8.4.0\nSeverity: HIGH\nFix: Upgrade path-to-regexp to 8.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-956212369e0753bf", "name": "CVE-2026-4923: path-to-regexp 8.3.0 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-4923: path-to-regexp 8.3.0 \u2014 docs/bun.lock"}, "fullDescription": {"text": "path-to-regexp: path-to-regexp: Denial of Service via specially crafted paths with multiple wildcards\n\nImpact:\n\nWhen using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability requires the second wildcard to be somewhere other than the end of the path.\n\nUnsafe examples:\n\n/*foo-*bar-:baz\n/*a-:b-*c-:d\n/x/*a-:b/*c/y\n\nSafe examples:\n\n/*foo-:bar\n/*foo-:bar-*baz\n\nPatches:\n\nUpgrade to version 8.4.0.\n\nWorkarounds:\n\nIf you are using multiple wildcard parameters, you can check the regex output with a too\n\nPackage: path-to-regexp\nInstalled: 8.3.0\nFixed in: 8.4.0\nSeverity: MEDIUM\nFix: Upgrade path-to-regexp to 8.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-723b768ad3916852", "name": "CVE-2026-33671: picomatch 4.0.3 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-33671: picomatch 4.0.3 \u2014 docs/bun.lock"}, "fullDescription": {"text": "picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns\n\nPicomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when combined with overlapping alternatives or nested extglobs, are compiled into regular expressions that can exhibit catastrophic backtracking on non-matching input. Applications are impacted when they allow untrusted users \n\nPackage: picomatch\nInstalled: 4.0.3\nFixed in: 4.0.4, 3.0.2, 2.3.2\nSeverity: HIGH\nFix: Upgrade picomatch to 4.0.4, 3.0.2, 2.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-31580320c5cc187e", "name": "CVE-2026-33672: picomatch 4.0.3 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-33672: picomatch 4.0.3 \u2014 docs/bun.lock"}, "fullDescription": {"text": "picomatch: Picomatch: Data integrity compromised via method injection with crafted POSIX bracket expressions\n\nPicomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Because the object inherits from `Object.prototype`, specially crafted POSIX bracket expressions (e.g., `[[:constructor:]]`) can reference inherited method names. These methods are implicitly converted to strings and injected into the generated regular expression. This leads to incorrect glob matching behavior (int\n\nPackage: picomatch\nInstalled: 4.0.3\nFixed in: 4.0.4, 3.0.2, 2.3.2\nSeverity: MEDIUM\nFix: Upgrade picomatch to 4.0.4, 3.0.2, 2.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9be1b8d645950ec0", "name": "CVE-2026-41305: postcss 8.5.6 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-41305: postcss 8.5.6 \u2014 docs/bun.lock"}, "fullDescription": {"text": "postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags\n\nPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTML `<style>` tags, `</style>` in CSS values breaks out of the style context, enabling XSS. Version 8.5.10 fixes the issue.\n\nPackage: postcss\nInstalled: 8.5.6\nFixed in: 8.5.10\nSeverity: MEDIUM\nFix: Upgrade postcss to 8.5.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-362157786fedd921", "name": "CVE-2026-33532: yaml 2.8.2 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-33532: yaml 2.8.2 \u2014 docs/bun.lock"}, "fullDescription": {"text": "yaml: yaml: Denial of Service via deeply nested YAML document parsing\n\n`yaml` is a YAML parser and serialiser for JavaScript. Parsing a YAML document with a version of `yaml` on the 1.x branch prior to 1.10.3 or on the 2.x branch prior to 2.8.3 may throw a RangeError due to a stack overflow. The node resolution/composition phase uses recursive function calls without a depth bound. An attacker who can supply YAML for parsing can trigger a `RangeError: Maximum call stack size exceeded` with a small payload (~2\u201310 KB). The `RangeError` is not a `YAMLParseError`, so ap\n\nPackage: yaml\nInstalled: 2.8.2\nFixed in: 2.8.3, 1.10.3\nSeverity: MEDIUM\nFix: Upgrade yaml to 2.8.3, 1.10.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-eaa4814067c69709", "name": "CVE-2026-25541: bytes 1.11.0 \u2014 tauri/src-tauri/Cargo.lock", "shortDescription": {"text": "CVE-2026-25541: bytes 1.11.0 \u2014 tauri/src-tauri/Cargo.lock"}, "fullDescription": {"text": "Bytes is a utility library for working with bytes. From version 1.2.1  ...\n\nBytes is a utility library for working with bytes. From version 1.2.1 to before 1.11.1, Bytes is vulnerable to integer overflow in BytesMut::reserve. In the unique reclaim path of BytesMut::reserve, if the condition \"v_capacity >= new_cap + offset\" uses an unchecked addition. When new_cap + offset overflows usize in release builds, this condition may incorrectly pass, causing self.cap to be set to a value that exceeds the actual allocated capacity. Subsequent APIs such as spare_capacity_mut() th\n\nPackage: bytes\nInstalled: 1.11.0\nFixed in: 1.11.1\nSeverity: MEDIUM\nFix: Upgrade bytes to 1.11.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-00fbe39e74c730e4", "name": "GHSA-wrw7-89jp-8q8g: glib 0.18.5 \u2014 tauri/src-tauri/Cargo.lock", "shortDescription": {"text": "GHSA-wrw7-89jp-8q8g: glib 0.18.5 \u2014 tauri/src-tauri/Cargo.lock"}, "fullDescription": {"text": "Unsoundness in `Iterator` and `DoubleEndedIterator` impls for `glib::VariantStrIter`\n\nThe `VariantStrIter::impl_get` function (called internally by implementations of the `Iterator` and `DoubleEndedIterator` traits for this type) was unsound, resulting in undefined behaviour.\n\nAn immutable reference `&p` to a `*mut libc::c_char` pointer initialized to `NULL` was passed as an argument to a C function that that mutates the pointer behind `&p` in-place (i.e. as an out-argument), which was unsound. After changes in recent versions of the Rust compiler, these unsound writes through `&\n\nPackage: glib\nInstalled: 0.18.5\nFixed in: 0.20.0\nSeverity: MEDIUM\nFix: Upgrade glib to 0.20.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0248d32f8446f478", "name": "CVE-2026-41676: openssl 0.10.75 \u2014 tauri/src-tauri/Cargo.lock", "shortDescription": {"text": "CVE-2026-41676: openssl 0.10.75 \u2014 tauri/src-tauri/Cargo.lock"}, "fullDescription": {"text": "rust-openssl provides OpenSSL bindings for the Rust programming langua ...\n\nrust-openssl provides OpenSSL bindings for the Rust programming language.  From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519, X448, DH and HKDF-extract ignore the incoming *keylen, unconditionally writing the full shared secret (32/56/prime-size bytes). A caller passing a short slice gets a heap/stack overflow from safe code. OpenSSL 3.x provi\n\nPackage: openssl\nInstalled: 0.10.75\nFixed in: 0.10.78\nSeverity: HIGH\nFix: Upgrade openssl to 0.10.78"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-54d03506de399ab2", "name": "CVE-2026-41678: openssl 0.10.75 \u2014 tauri/src-tauri/Cargo.lock", "shortDescription": {"text": "CVE-2026-41678: openssl 0.10.75 \u2014 tauri/src-tauri/Cargo.lock"}, "fullDescription": {"text": "rust-openssl provides OpenSSL bindings for the Rust programming langua ...\n\nrust-openssl provides OpenSSL bindings for the Rust programming language.  From  to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8, ensuring the output buffer is large enough. Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function wil\n\nPackage: openssl\nInstalled: 0.10.75\nFixed in: 0.10.78\nSeverity: HIGH\nFix: Upgrade openssl to 0.10.78"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-55be30ff9b3840ea", "name": "CVE-2026-41681: openssl 0.10.75 \u2014 tauri/src-tauri/Cargo.lock", "shortDescription": {"text": "CVE-2026-41681: openssl 0.10.75 \u2014 tauri/src-tauri/Cargo.lock"}, "fullDescription": {"text": "rust-openssl provides OpenSSL bindings for the Rust programming langua ...\n\nrust-openssl provides OpenSSL bindings for the Rust programming language.  From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller than that, MdCtxRef::digest_final() writes past its end, usually corrupting the stack. This is reachable from safe Rust. This vulnerability is fixed in 0.10.78.\n\nPackage: openssl\nInstalled: 0.10.75\nFixed in: 0.10.78\nSeverity: HIGH\nFix: Upgrade openssl to 0.10.78"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8096ed4b4b177540", "name": "CVE-2026-41898: openssl 0.10.75 \u2014 tauri/src-tauri/Cargo.lock", "shortDescription": {"text": "CVE-2026-41898: openssl 0.10.75 \u2014 tauri/src-tauri/Cargo.lock"}, "fullDescription": {"text": "rust-openssl provides OpenSSL bindings for the Rust programming langua ...\n\nrust-openssl provides OpenSSL bindings for the Rust programming language.  From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the user closure's returned usize directly to OpenSSL without checking it against the &mut [u8] that was handed to the closure. This can lead to buffer overflows and other unintended consequences. This vulnerability is fixed in\n\nPackage: openssl\nInstalled: 0.10.75\nFixed in: 0.10.78\nSeverity: HIGH\nFix: Upgrade openssl to 0.10.78"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b3468ce3e64eb535", "name": "CVE-2026-42327: openssl 0.10.75 \u2014 tauri/src-tauri/Cargo.lock", "shortDescription": {"text": "CVE-2026-42327: openssl 0.10.75 \u2014 tauri/src-tauri/Cargo.lock"}, "fullDescription": {"text": "rust-openssl: rust-openssl: Arbitrary code execution via specially crafted certificate\n\nrust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target = str> wraps the raw bytes with str::from_utf8_unchecked. OpenSSL does not enforce that the underlying IA5String is ASCII, so a certificate with non-UTF-8 bytes in its OCSP accessLocation causes safe Rust code to construct a &str that violates the UTF-8 invariant \u2014 resul\n\nPackage: openssl\nInstalled: 0.10.75\nFixed in: 0.10.79\nSeverity: HIGH\nFix: Upgrade openssl to 0.10.79"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-efbef695bec7533e", "name": "CVE-2026-44662: openssl 0.10.75 \u2014 tauri/src-tauri/Cargo.lock", "shortDescription": {"text": "CVE-2026-44662: openssl 0.10.75 \u2014 tauri/src-tauri/Cargo.lock"}, "fullDescription": {"text": "rust-openssl provides OpenSSL bindings for the Rust programming langua ...\n\nrust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.0 to before 0.10.79, CipherCtxRef::cipher_update, CipherCtxRef::cipher_update_vec, and symm::Crypter::update incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers (EVP_aes_{128,192,256}_wrap_pad). For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corruption when the plaintext length is attacker-i\n\nPackage: openssl\nInstalled: 0.10.75\nFixed in: 0.10.79\nSeverity: MEDIUM\nFix: Upgrade openssl to 0.10.79"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8260af519bd7792b", "name": "CVE-2026-45784: openssl 0.10.75 \u2014 tauri/src-tauri/Cargo.lock", "shortDescription": {"text": "CVE-2026-45784: openssl 0.10.75 \u2014 tauri/src-tauri/Cargo.lock"}, "fullDescription": {"text": "rust-openssl provides OpenSSL bindings for the Rust programming langua ...\n\nrust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad. For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corruption when the plaintext length is attacker-influenced. This issue is fix\n\nPackage: openssl\nInstalled: 0.10.75\nFixed in: 0.10.80\nSeverity: MEDIUM\nFix: Upgrade openssl to 0.10.80"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8e769a07375eca21", "name": "CVE-2026-41677: openssl 0.10.75 \u2014 tauri/src-tauri/Cargo.lock", "shortDescription": {"text": "CVE-2026-41677: openssl 0.10.75 \u2014 tauri/src-tauri/Cargo.lock"}, "fullDescription": {"text": "rust-openssl provides OpenSSL bindings for the Rust programming langua ...\n\nrust-openssl provides OpenSSL bindings for the Rust programming language.  From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the user's callback. A password callback that returns a value larger than the buffer it was given can cause some versions of OpenSSL to over-read this buffer. OpenSSL 3.x is not affected by this. This vulnerability is fixed in 0.10.78.\n\nPackage: openssl\nInstalled: 0.10.75\nFixed in: 0.10.78\nSeverity: LOW\nFix: Upgrade openssl to 0.10.78"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6afab34c2fdab321", "name": "CVE-2026-31812: quinn-proto 0.11.13 \u2014 tauri/src-tauri/Cargo.lock", "shortDescription": {"text": "CVE-2026-31812: quinn-proto 0.11.13 \u2014 tauri/src-tauri/Cargo.lock"}, "fullDescription": {"text": "quinn-proto: quinn-proto: Denial of Service via crafted QUIC Initial packet\n\nQuinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable quinn versions by sending a crafted QUIC Initial packet containing malformed quic_transport_parameters. In quinn-proto parsing logic, attacker-controlled varints are decoded with unwrap(), so truncated encodings cause Err(UnexpectedEnd) and panic. This is reachable over the network with a s\n\nPackage: quinn-proto\nInstalled: 0.11.13\nFixed in: 0.11.14\nSeverity: HIGH\nFix: Upgrade quinn-proto to 0.11.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4883291790d52ea3", "name": "GHSA-cq8v-f236-94qc: rand 0.7.3 \u2014 tauri/src-tauri/Cargo.lock", "shortDescription": {"text": "GHSA-cq8v-f236-94qc: rand 0.7.3 \u2014 tauri/src-tauri/Cargo.lock"}, "fullDescription": {"text": "Rand is unsound with a custom logger using rand::rng()\n\nIt has been reported (by @lopopolo) that the `rand` library is [unsound](https://rust-lang.github.io/unsafe-code-guidelines/glossary.html#soundness-of-code--of-a-library) (i.e. that safe code using the public API can cause Undefined Behaviour) when all the following conditions are met:\n\n- The `log` and `thread_rng` features are enabled\n- A [custom logger](https://docs.rs/log/latest/log/#implementing-a-logger) is defined\n- The custom logger accesses `rand::rng()` (previously `rand::thread_rng()`)\n\nPackage: rand\nInstalled: 0.7.3\nFixed in: 0.9.3, 0.10.1, 0.8.6\nSeverity: LOW\nFix: Upgrade rand to 0.9.3, 0.10.1, 0.8.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-07a4765356e134f7", "name": "GHSA-cq8v-f236-94qc: rand 0.8.5 \u2014 tauri/src-tauri/Cargo.lock", "shortDescription": {"text": "GHSA-cq8v-f236-94qc: rand 0.8.5 \u2014 tauri/src-tauri/Cargo.lock"}, "fullDescription": {"text": "Rand is unsound with a custom logger using rand::rng()\n\nIt has been reported (by @lopopolo) that the `rand` library is [unsound](https://rust-lang.github.io/unsafe-code-guidelines/glossary.html#soundness-of-code--of-a-library) (i.e. that safe code using the public API can cause Undefined Behaviour) when all the following conditions are met:\n\n- The `log` and `thread_rng` features are enabled\n- A [custom logger](https://docs.rs/log/latest/log/#implementing-a-logger) is defined\n- The custom logger accesses `rand::rng()` (previously `rand::thread_rng()`)\n\nPackage: rand\nInstalled: 0.8.5\nFixed in: 0.9.3, 0.10.1, 0.8.6\nSeverity: LOW\nFix: Upgrade rand to 0.9.3, 0.10.1, 0.8.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0079332a161d9171", "name": "GHSA-cq8v-f236-94qc: rand 0.9.2 \u2014 tauri/src-tauri/Cargo.lock", "shortDescription": {"text": "GHSA-cq8v-f236-94qc: rand 0.9.2 \u2014 tauri/src-tauri/Cargo.lock"}, "fullDescription": {"text": "Rand is unsound with a custom logger using rand::rng()\n\nIt has been reported (by @lopopolo) that the `rand` library is [unsound](https://rust-lang.github.io/unsafe-code-guidelines/glossary.html#soundness-of-code--of-a-library) (i.e. that safe code using the public API can cause Undefined Behaviour) when all the following conditions are met:\n\n- The `log` and `thread_rng` features are enabled\n- A [custom logger](https://docs.rs/log/latest/log/#implementing-a-logger) is defined\n- The custom logger accesses `rand::rng()` (previously `rand::thread_rng()`)\n\nPackage: rand\nInstalled: 0.9.2\nFixed in: 0.9.3, 0.10.1, 0.8.6\nSeverity: LOW\nFix: Upgrade rand to 0.9.3, 0.10.1, 0.8.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1237f25c5d5cd203", "name": "GHSA-82j2-j2ch-gfr8: rustls-webpki 0.103.9 \u2014 tauri/src-tauri/Cargo.lock", "shortDescription": {"text": "GHSA-82j2-j2ch-gfr8: rustls-webpki 0.103.9 \u2014 tauri/src-tauri/Cargo.lock"}, "fullDescription": {"text": "rustls-webpki: Denial of service via panic on malformed CRL BIT STRING\n\n### Summary\n\n`bit_string_flags()` in `src/der.rs` panics with an index-out-of-bounds when given a BIT STRING whose content is exactly `[0x00]` (one byte: zero padding bits, zero data bytes). This is reachable through the public API `BorrowedCertRevocationList::from_der()` via the `issuingDistributionPoint` CRL extension.\n\n**Precondition**: CRL checking is opt-in in rustls-webpki. This vulnerability affects only applications that explicitly pass `RevocationOptions` to `verify_for_usage()` and loa\n\nPackage: rustls-webpki\nInstalled: 0.103.9\nFixed in: 0.103.13, 0.104.0-alpha.7\nSeverity: HIGH\nFix: Upgrade rustls-webpki to 0.103.13, 0.104.0-alpha.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b389ad36a927d4d4", "name": "GHSA-pwjx-qhcg-rvj4: rustls-webpki 0.103.9 \u2014 tauri/src-tauri/Cargo.lock", "shortDescription": {"text": "GHSA-pwjx-qhcg-rvj4: rustls-webpki 0.103.9 \u2014 tauri/src-tauri/Cargo.lock"}, "fullDescription": {"text": "webpki: CRLs not considered authoritative by Distribution Point due to faulty matching logic\n\nIf a certificate had more than one `distributionPoint`, then only the first `distributionPoint` would be considered against each CRL's `IssuingDistributionPoint` `distributionPoint`, and then the certificate's subsequent `distributionPoint`s would be ignored.\n\nThe impact was that correct provided CRLs would not be consulted to check revocation. With `UnknownStatusPolicy::Deny` (the default) this would lead to incorrect but safe `Error::UnknownRevocationStatus`. With `UnknownStatusPolicy::Allow` \n\nPackage: rustls-webpki\nInstalled: 0.103.9\nFixed in: 0.103.10, 0.104.0-alpha.5\nSeverity: MEDIUM\nFix: Upgrade rustls-webpki to 0.103.10, 0.104.0-alpha.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2741ad652f9d2f9b", "name": "GHSA-965h-392x-2mh5: rustls-webpki 0.103.9 \u2014 tauri/src-tauri/Cargo.lock", "shortDescription": {"text": "GHSA-965h-392x-2mh5: rustls-webpki 0.103.9 \u2014 tauri/src-tauri/Cargo.lock"}, "fullDescription": {"text": "webpki: Name constraints for URI names were incorrectly accepted\n\nName constraints for URI names were ignored and therefore accepted.\n\nNote this library does not provide an API for asserting URI names, and URI name constraints are otherwise not implemented.  URI name constraints are now rejected unconditionally.\n\nSince name constraints are restrictions on otherwise properly-issued certificates, this bug is reachable only after signature verification and requires misissuance to exploit.\n\nPackage: rustls-webpki\nInstalled: 0.103.9\nFixed in: 0.103.12, 0.104.0-alpha.6\nSeverity: LOW\nFix: Upgrade rustls-webpki to 0.103.12, 0.104.0-alpha.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1458d24bc28906c5", "name": "GHSA-xgp8-3hg3-c2mh: rustls-webpki 0.103.9 \u2014 tauri/src-tauri/Cargo.lock", "shortDescription": {"text": "GHSA-xgp8-3hg3-c2mh: rustls-webpki 0.103.9 \u2014 tauri/src-tauri/Cargo.lock"}, "fullDescription": {"text": "webpki: Name constraints were accepted for certificates asserting a wildcard name\n\nPermitted subtree name constraints for DNS names were accepted for certificates asserting a wildcard name.\n\nThis was incorrect because, given a name constraint of `accept.example.com`, `*.example.com` could feasibly allow a name of `reject.example.com` which is outside the constraint.\nThis is very similar to [CVE-2025-61727](https://go.dev/issue/76442).\n\nSince name constraints are restrictions on otherwise properly-issued certificates, this bug is reachable only after signature verification and \n\nPackage: rustls-webpki\nInstalled: 0.103.9\nFixed in: 0.103.12, 0.104.0-alpha.6\nSeverity: LOW\nFix: Upgrade rustls-webpki to 0.103.12, 0.104.0-alpha.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-535010bab8b79458", "name": "GHSA-7gcf-g7xr-8hxj: serde_with 3.16.1 \u2014 tauri/src-tauri/Cargo.lock", "shortDescription": {"text": "GHSA-7gcf-g7xr-8hxj: serde_with 3.16.1 \u2014 tauri/src-tauri/Cargo.lock"}, "fullDescription": {"text": "serde_with: KeyValueMap serialization panics on empty sequence or map entries\n\n### Summary\n\nThe public `KeyValueMap` serializer assumes that each mapped element has at least one field or item to use as the map key, but it subtracts `1` from the caller-visible length before validating that assumption. An application that serializes attacker-controlled data through `#[serde_as(as = \"KeyValueMap<_>\")]` can be crashed by an empty inner sequence or map entry.\n\n### Details\n\nThe affected public surface includes:\n\n- Serialization of `#[serde_as(as = \"KeyValueMap<_>\")]` values thro\n\nPackage: serde_with\nInstalled: 3.16.1\nFixed in: 3.21.0\nSeverity: MEDIUM\nFix: Upgrade serde_with to 3.21.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dab96fdc836548fa", "name": "CVE-2026-33055: tar 0.4.44 \u2014 tauri/src-tauri/Cargo.lock", "shortDescription": {"text": "CVE-2026-33055: tar 0.4.44 \u2014 tauri/src-tauri/Cargo.lock"}, "fullDescription": {"text": "tar-rs is a tar archive reading/writing library for Rust. Versions 0.4 ...\n\ntar-rs is a tar archive reading/writing library for Rust. Versions 0.4.44 and below have conditional logic that skips the PAX size header in cases where the base header size is nonzero. As part of CVE-2025-62518, the astral-tokio-tar project was changed to correctly honor PAX size headers in the case where it was different from the base header. This is almost the inverse of the astral-tokio-tar issue. Any discrepancy in how tar parsers honor file size can be used to create archives that appear d\n\nPackage: tar\nInstalled: 0.4.44\nFixed in: 0.4.45\nSeverity: MEDIUM\nFix: Upgrade tar to 0.4.45"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ef72d38bd94d27ab", "name": "CVE-2026-33056: tar 0.4.44 \u2014 tauri/src-tauri/Cargo.lock", "shortDescription": {"text": "CVE-2026-33056: tar 0.4.44 \u2014 tauri/src-tauri/Cargo.lock"}, "fullDescription": {"text": "tar-rs: tar-rs: Arbitrary directory permission modification via crafted tar archive\n\ntar-rs is a tar archive reading/writing library for Rust. In versions 0.4.44 and below, when unpacking a tar archive, the tar crate's unpack_dir function uses fs::metadata() to check whether a path that already exists is a directory. Because fs::metadata() follows symbolic links, a crafted tarball containing a symlink entry followed by a directory entry with the same name causes the crate to treat the symlink target as a valid existing directory \u2014 and subsequently apply chmod to it. This allows \n\nPackage: tar\nInstalled: 0.4.44\nFixed in: 0.4.45\nSeverity: MEDIUM\nFix: Upgrade tar to 0.4.45"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b2de7aab73811f4b", "name": "GHSA-3pv8-6f4r-ffg2: tar 0.4.44 \u2014 tauri/src-tauri/Cargo.lock", "shortDescription": {"text": "GHSA-3pv8-6f4r-ffg2: tar 0.4.44 \u2014 tauri/src-tauri/Cargo.lock"}, "fullDescription": {"text": "tar has a PAX header desynchronization issue\n\n### Summary\n\nWhen a tar stream contains multiple \"header\" entries prior to a file entry, tar-rs applies the PAX header (`x`) to the _next_ entry in the stream, regardless of type. For example, a stream of `x -> L -> file` (PAX, GNU longname, file) would result in `x`'s extensions being applied to `L` rather than to `file`.\n\n[Per POSIX pax](https://pubs.opengroup.org/onlinepubs/9799919799/utilities/pax.html), this is incorrect: a PAX header always applies to a file entry, not any intermediary ent\n\nPackage: tar\nInstalled: 0.4.44\nFixed in: 0.4.46\nSeverity: MEDIUM\nFix: Upgrade tar to 0.4.46"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9225e2cf4f5c7436", "name": "CVE-2026-42184: tauri 2.9.5 \u2014 tauri/src-tauri/Cargo.lock", "shortDescription": {"text": "CVE-2026-42184: tauri 2.9.5 \u2014 tauri/src-tauri/Cargo.lock"}, "fullDescription": {"text": "Tauri has an Origin Confusion Issue that Allows Remote Pages to Invoke Local-Only IPC Commands\n\nTauri is a framework for building binaries for all major desktop platforms. From 2.0 to 2.11.0, a flaw in Tauri's is_local_url() function causes it to incorrectly classify remote URLs as trusted local origins on Windows and Android. On these systems, Tauri maps custom URI scheme protocols to http://<scheme>.localhost/ because those platforms' WebView implementations cannot serve custom URI schemes directly. The issue is that Tauri's check to see if the origin is local, only checks the first subd\n\nPackage: tauri\nInstalled: 2.9.5\nFixed in: 2.11.1\nSeverity: MEDIUM\nFix: Upgrade tauri to 2.11.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-37dcb81539586f3f", "name": "CVE-2026-25727: time 0.3.46 \u2014 tauri/src-tauri/Cargo.lock", "shortDescription": {"text": "CVE-2026-25727: time 0.3.46 \u2014 tauri/src-tauri/Cargo.lock"}, "fullDescription": {"text": "time: time affected by a stack exhaustion denial of service attack\n\ntime provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any type that parses with the RFC 2822 format, a denial of service attack via stack exhaustion is possible. The attack relies on formally deprecated and rarely-used features that are part of the RFC 2822 format used in a malicious manner. Ordinary, non-malicious input will never encounter this scenario. A limit to the depth of recursion was added in v0.3.47. From this version, an er\n\nPackage: time\nInstalled: 0.3.46\nFixed in: 0.3.47\nSeverity: MEDIUM\nFix: Upgrade time to 0.3.47"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3a3527e70129fb18", "name": "DS-0002: Image user should not be 'root' \u2014 Dockerfile", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 Dockerfile"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-72ff79e0f8219b60", "name": "DS-0013: 'RUN cd ...' to change directory \u2014 Dockerfile", "shortDescription": {"text": "DS-0013: 'RUN cd ...' to change directory \u2014 Dockerfile"}, "fullDescription": {"text": "'RUN cd ...' to change directory\n\nRUN should not be used to change directory: 'cd web && bunx --bun vite build'. Use 'WORKDIR' statement instead.\n\nRule: DS-0013\nSeverity: MEDIUM\nTarget: Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d63da3583b14afc0", "name": "Dockerfile runs as root: Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9fff85edbbb8c52b", "name": "Docker base image is tag-pinned but not digest-pinned: oven/bun:1", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: oven/bun:1"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e066691601852931", "name": "Docker base image is tag-pinned but not digest-pinned: python:3.11-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.11-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8e8313aee9ea8527", "name": "Insecure pattern 'node_child_process' in scripts/setup-dev-sidecar.js:13", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/setup-dev-sidecar.js:13"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.9}}, {"id": "scanner-9ab26d43bebb357d", "name": "Insecure pattern 'direct_innerhtml_assignment' in app/src/components/Generation/ParalinguisticInput.tsx:159", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in app/src/components/Generation/ParalinguisticInput.tsx:159"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-67d7c60b3a8fcae8", "name": "Insecure pattern 'dangerous_innerhtml' in landing/src/app/blog/[slug]/page.tsx:85", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in landing/src/app/blog/[slug]/page.tsx:85"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-fb08cd342b72fec8", "name": "Insecure pattern 'exec_used' in backend/pyi_rth_torch_compiler_disable.py:335", "shortDescription": {"text": "Insecure pattern 'exec_used' in backend/pyi_rth_torch_compiler_disable.py:335"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-27924aa79fa4a517", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "oven-sh/setup-bun@v2 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-46c644c6227e4d4a", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/setup-python@v5 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1838a141491ce38c", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-360cb263256aacfa", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/setup-python@v5 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6e61fb60af308a45", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-529d9f2b5dd1170d", "name": "package.json defines install-time lifecycle scripts", "shortDescription": {"text": "package.json defines install-time lifecycle scripts"}, "fullDescription": {"text": "preinstall/install/postinstall/prepare scripts execute during dependency installation. Review them carefully for network calls, obfuscation, shell execution, or credential access."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a760f6b31da81a8c", "name": "Very large file: app/src/components/StoriesTab/StoryTrackEditor.tsx (1531 lines)", "shortDescription": {"text": "Very large file: app/src/components/StoriesTab/StoryTrackEditor.tsx (1531 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4cc6da301727b928", "name": "Very large file: app/src/components/VoiceProfiles/ProfileForm.tsx (1317 lines)", "shortDescription": {"text": "Very large file: app/src/components/VoiceProfiles/ProfileForm.tsx (1317 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ab76ba206f803807", "name": "Very large file: tauri/src-tauri/src/main.rs (1659 lines)", "shortDescription": {"text": "Very large file: tauri/src-tauri/src/main.rs (1659 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "31 test file(s) for 376 source file(s) (ratio 0.08). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fbb5fa8bc006353f", "name": "Node manifest has dependencies but no lockfile: app/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: app/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b8d99132ab8d1975", "name": "Node manifest has dependencies but no lockfile: web/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: web/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b93c6a558b425596", "name": "Node manifest has dependencies but no lockfile: landing/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: landing/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-589d00c93cc7357e", "name": "Node manifest has dependencies but no lockfile: tauri/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: tauri/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 88 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 95 placeholder/mock markers across 31 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea6060b55f9ebd0c", "name": "Legacy-named symbol `t3_mtl23ls_v2` in scripts/test_download_progress.py:41", "shortDescription": {"text": "Legacy-named symbol `t3_mtl23ls_v2` in scripts/test_download_progress.py:41"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6ae73aeb92d23df6", "name": "Commented-code block (6 lines) in scripts/package_cuda.py:22", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/package_cuda.py:22"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-715bc2d9f1a5de20", "name": "Commented-code block (6 lines) in app/src/components/CapturesTab/CapturesTab.tsx:198", "shortDescription": {"text": "Commented-code block (6 lines) in app/src/components/CapturesTab/CapturesTab.tsx:198"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-dffaea76e8ce16ec", "name": "`fetch()` without try/.catch or AbortSignal \u2014 app/src/components/CapturesTab/CapturesTab.tsx:344", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 app/src/components/CapturesTab/CapturesTab.tsx:344"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bdbb3df93ef42189", "name": "Commented-code block (6 lines) in app/src/components/StoriesTab/StoryTrackEditor.tsx:85", "shortDescription": {"text": "Commented-code block (6 lines) in app/src/components/StoriesTab/StoryTrackEditor.tsx:85"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9d3ea9349790c2e1", "name": "`fetch()` without try/.catch or AbortSignal \u2014 app/src/components/AudioPlayer/AudioPlayer.tsx:444", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 app/src/components/AudioPlayer/AudioPlayer.tsx:444"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e4d14d51e7f76e5a", "name": "`fetch()` without try/.catch or AbortSignal \u2014 app/src/components/ServerSettings/ModelManagement.tsx:50", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 app/src/components/ServerSettings/ModelManagement.tsx:50"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b1357b98b6e3a533", "name": "Commented-code block (5 lines) in app/src/components/DictateWindow/DictateWindow.tsx:184", "shortDescription": {"text": "Commented-code block (5 lines) in app/src/components/DictateWindow/DictateWindow.tsx:184"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ff07ab509cf73e8e", "name": "`fetch()` without try/.catch or AbortSignal \u2014 app/src/lib/api/core/request.ts:230", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 app/src/lib/api/core/request.ts:230"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0c70530e8ebbd43f", "name": "Commented-code block (5 lines) in app/src/lib/hooks/useCaptureRecordingSession.ts:46", "shortDescription": {"text": "Commented-code block (5 lines) in app/src/lib/hooks/useCaptureRecordingSession.ts:46"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-528cd605cbeaa453", "name": "`fetch()` without try/.catch or AbortSignal \u2014 app/src/lib/hooks/useStoryPlayback.ts:128", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 app/src/lib/hooks/useStoryPlayback.ts:128"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b3981244412e24fe", "name": "Commented-code block (6 lines) in app/src/lib/hooks/useGenerationProgress.ts:110", "shortDescription": {"text": "Commented-code block (6 lines) in app/src/lib/hooks/useGenerationProgress.ts:110"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7f739fcc633d0023", "name": "Commented-code block (5 lines) in landing/src/app/download/[platform]/route.ts:5", "shortDescription": {"text": "Commented-code block (5 lines) in landing/src/app/download/[platform]/route.ts:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6d313d613f4bc48c", "name": "Commented-code block (5 lines) in landing/src/lib/constants.ts:19", "shortDescription": {"text": "Commented-code block (5 lines) in landing/src/lib/constants.ts:19"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d3f0188c7f87e326", "name": "Commented-code block (7 lines) in landing/src/lib/token-stats.ts:3", "shortDescription": {"text": "Commented-code block (7 lines) in landing/src/lib/token-stats.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-775e0e66ac5cc36e", "name": "`fetch()` without try/.catch or AbortSignal \u2014 landing/src/lib/token-stats.ts:263", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 landing/src/lib/token-stats.ts:263"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2c886461907ea9a0", "name": "Commented-code block (5 lines) in backend/pyi_rth_torch_compiler_disable.py:435", "shortDescription": {"text": "Commented-code block (5 lines) in backend/pyi_rth_torch_compiler_disable.py:435"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a235c419771368fe", "name": "Commented-code block (6 lines) in backend/app.py:152", "shortDescription": {"text": "Commented-code block (6 lines) in backend/app.py:152"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-fc1925a07700ca4a", "name": "Commented-code block (5 lines) in backend/models.py:392", "shortDescription": {"text": "Commented-code block (5 lines) in backend/models.py:392"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1cadcb3fae457a56", "name": "Commented-code block (5 lines) in backend/server.py:184", "shortDescription": {"text": "Commented-code block (5 lines) in backend/server.py:184"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a6b7f6856673f215", "name": "Commented-code block (6 lines) in backend/build_binary.py:46", "shortDescription": {"text": "Commented-code block (6 lines) in backend/build_binary.py:46"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-85cf3966d8887d65", "name": "Network/subprocess call without timeout or try/except \u2014 backend/build_binary.py:499", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 backend/build_binary.py:499"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b990d84c05289a0d", "name": "Commented-code block (8 lines) in backend/utils/hf_offline_patch.py:17", "shortDescription": {"text": "Commented-code block (8 lines) in backend/utils/hf_offline_patch.py:17"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a062fd427653365a", "name": "Commented-code block (8 lines) in backend/database/migrations.py:272", "shortDescription": {"text": "Commented-code block (8 lines) in backend/database/migrations.py:272"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ba7da2604396d0dc", "name": "Commented-code block (6 lines) in backend/routes/profiles.py:366", "shortDescription": {"text": "Commented-code block (6 lines) in backend/routes/profiles.py:366"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-43ff5efa3a973ce7", "name": "Commented-code block (5 lines) in backend/backends/hume_backend.py:136", "shortDescription": {"text": "Commented-code block (5 lines) in backend/backends/hume_backend.py:136"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-72f6e02f9879f925", "name": "Commented-code block (5 lines) in backend/backends/__init__.py:8", "shortDescription": {"text": "Commented-code block (5 lines) in backend/backends/__init__.py:8"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-40338b8767a382f7", "name": "Commented-code block (5 lines) in backend/backends/qwen_llm_backend.py:105", "shortDescription": {"text": "Commented-code block (5 lines) in backend/backends/qwen_llm_backend.py:105"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bf754c8223d72a60", "name": "Commented-code block (5 lines) in backend/backends/mlx_backend.py:219", "shortDescription": {"text": "Commented-code block (5 lines) in backend/backends/mlx_backend.py:219"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-001857db7c8fc793", "name": "Commented-code block (5 lines) in backend/backends/pytorch_backend.py:341", "shortDescription": {"text": "Commented-code block (5 lines) in backend/backends/pytorch_backend.py:341"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d4f502cd77565c80", "name": "Legacy-named symbol `t3_turbo_v1` in backend/backends/chatterbox_turbo_backend.py:34", "shortDescription": {"text": "Legacy-named symbol `t3_turbo_v1` in backend/backends/chatterbox_turbo_backend.py:34"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3a74c524759d841f", "name": "Legacy-named symbol `t3_mtl23ls_v2` in backend/backends/chatterbox_backend.py:34", "shortDescription": {"text": "Legacy-named symbol `t3_mtl23ls_v2` in backend/backends/chatterbox_backend.py:34"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-db17d70cf8b3a347", "name": "Commented-code block (6 lines) in backend/services/rocm.py:293", "shortDescription": {"text": "Commented-code block (6 lines) in backend/services/rocm.py:293"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-098add0da946363e", "name": "Commented-code block (8 lines) in backend/services/refinement.py:17", "shortDescription": {"text": "Commented-code block (8 lines) in backend/services/refinement.py:17"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-58eaa2d5ae0dfe1f", "name": "Commented-code block (6 lines) in backend/mcp_server/context.py:57", "shortDescription": {"text": "Commented-code block (6 lines) in backend/mcp_server/context.py:57"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nscripts/package_cuda.py:sha256_file, scripts/package_rocm.py:sha256_file\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-49c98f7cedd9c977", "name": "Near-duplicate function bodies in 4 places", "shortDescription": {"text": "Near-duplicate function bodies in 4 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nbackend/pyi_rth_torch_compiler_disable.py:create_module, backend/pyi_rth_torch_compiler_disable.py:create_module, backend/pyi_rth_torch_compiler_disable.py:create_module, backend/pyi_rth_torch_compiler_disable.py:create_module\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0027e313ade46c8f", "name": "Near-duplicate function bodies in 7 places", "shortDescription": {"text": "Near-duplicate function bodies in 7 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nbackend/backends/luxtts_backend.py:create_voice_prompt, backend/backends/hume_backend.py:create_voice_prompt, backend/backends/__init__.py:create_voice_prompt, backend/backends/mlx_backend.py:create_voice_prompt\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9dad557909b86499", "name": "Near-duplicate function bodies in 10 places", "shortDescription": {"text": "Near-duplicate function bodies in 10 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nbackend/backends/luxtts_backend.py:generate, backend/backends/hume_backend.py:generate, backend/backends/kokoro_backend.py:generate, backend/backends/__init__.py:generate\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be46ea126aa5d8dc", "name": "Near-duplicate function bodies in 3 places", "shortDescription": {"text": "Near-duplicate function bodies in 3 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nbackend/backends/__init__.py:load_model, backend/backends/__init__.py:load_model, backend/backends/__init__.py:load_model\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8860d40de2a0db15", "name": "FastAPI POST `generate_speech` without auth dependency \u2014 backend/routes/generations.py:56", "shortDescription": {"text": "FastAPI POST `generate_speech` without auth dependency \u2014 backend/routes/generations.py:56"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2c45def40361df74", "name": "FastAPI POST `retry_generation` without auth dependency \u2014 backend/routes/generations.py:148", "shortDescription": {"text": "FastAPI POST `retry_generation` without auth dependency \u2014 backend/routes/generations.py:148"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1bae075cd6d333ad", "name": "FastAPI POST `regenerate_generation` without auth dependency \u2014 backend/routes/generations.py:190", "shortDescription": {"text": "FastAPI POST `regenerate_generation` without auth dependency \u2014 backend/routes/generations.py:190"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-66fcbaef20e82d86", "name": "FastAPI POST `cancel_generation` without auth dependency \u2014 backend/routes/generations.py:235", "shortDescription": {"text": "FastAPI POST `cancel_generation` without auth dependency \u2014 backend/routes/generations.py:235"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-aa8aac1e82ba846a", "name": "FastAPI POST `stream_speech` without auth dependency \u2014 backend/routes/generations.py:318", "shortDescription": {"text": "FastAPI POST `stream_speech` without auth dependency \u2014 backend/routes/generations.py:318"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dd4f31376ac9a094", "name": "FastAPI POST `import_audio` without auth dependency \u2014 backend/routes/generations.py:405", "shortDescription": {"text": "FastAPI POST `import_audio` without auth dependency \u2014 backend/routes/generations.py:405"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0fa7d72a9712af55", "name": "FastAPI POST `import_generation` without auth dependency \u2014 backend/routes/history.py:41", "shortDescription": {"text": "FastAPI POST `import_generation` without auth dependency \u2014 backend/routes/history.py:41"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b5272aadea6c2cd9", "name": "FastAPI DELETE `clear_failed_generations` without auth dependency \u2014 backend/routes/history.py:65", "shortDescription": {"text": "FastAPI DELETE `clear_failed_generations` without auth dependency \u2014 backend/routes/history.py:65"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-009f85c6af39cf79", "name": "FastAPI POST `toggle_favorite` without auth dependency \u2014 backend/routes/history.py:108", "shortDescription": {"text": "FastAPI POST `toggle_favorite` without auth dependency \u2014 backend/routes/history.py:108"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-01b61842fe660ce3", "name": "FastAPI DELETE `delete_generation` without auth dependency \u2014 backend/routes/history.py:122", "shortDescription": {"text": "FastAPI DELETE `delete_generation` without auth dependency \u2014 backend/routes/history.py:122"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-edfccf74319a800c", "name": "FastAPI PUT `upsert_mcp_binding` without auth dependency \u2014 backend/routes/mcp_bindings.py:37", "shortDescription": {"text": "FastAPI PUT `upsert_mcp_binding` without auth dependency \u2014 backend/routes/mcp_bindings.py:37"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c1bfecdba27d7b58", "name": "FastAPI DELETE `delete_mcp_binding` without auth dependency \u2014 backend/routes/mcp_bindings.py:65", "shortDescription": {"text": "FastAPI DELETE `delete_mcp_binding` without auth dependency \u2014 backend/routes/mcp_bindings.py:65"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-978cbed9a589d037", "name": "FastAPI POST `shutdown` without auth dependency \u2014 backend/routes/health.py:35", "shortDescription": {"text": "FastAPI POST `shutdown` without auth dependency \u2014 backend/routes/health.py:35"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-07d748c9158de095", "name": "FastAPI POST `watchdog_disable` without auth dependency \u2014 backend/routes/health.py:47", "shortDescription": {"text": "FastAPI POST `watchdog_disable` without auth dependency \u2014 backend/routes/health.py:47"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a12227ce9cf1cf3d", "name": "FastAPI POST `create_story` without auth dependency \u2014 backend/routes/stories.py:23", "shortDescription": {"text": "FastAPI POST `create_story` without auth dependency \u2014 backend/routes/stories.py:23"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a3b6ee09767a0da9", "name": "FastAPI PUT `update_story` without auth dependency \u2014 backend/routes/stories.py:47", "shortDescription": {"text": "FastAPI PUT `update_story` without auth dependency \u2014 backend/routes/stories.py:47"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4d60c9d5608c7373", "name": "FastAPI DELETE `delete_story` without auth dependency \u2014 backend/routes/stories.py:60", "shortDescription": {"text": "FastAPI DELETE `delete_story` without auth dependency \u2014 backend/routes/stories.py:60"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-53371b96ac4b2184", "name": "FastAPI POST `add_story_item` without auth dependency \u2014 backend/routes/stories.py:72", "shortDescription": {"text": "FastAPI POST `add_story_item` without auth dependency \u2014 backend/routes/stories.py:72"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7addece6f86a9949", "name": "FastAPI DELETE `remove_story_item` without auth dependency \u2014 backend/routes/stories.py:85", "shortDescription": {"text": "FastAPI DELETE `remove_story_item` without auth dependency \u2014 backend/routes/stories.py:85"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0fdb0e39fa29bdb9", "name": "FastAPI PUT `update_story_item_times` without auth dependency \u2014 backend/routes/stories.py:98", "shortDescription": {"text": "FastAPI PUT `update_story_item_times` without auth dependency \u2014 backend/routes/stories.py:98"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-08268d8c4fda2428", "name": "FastAPI PUT `reorder_story_items` without auth dependency \u2014 backend/routes/stories.py:111", "shortDescription": {"text": "FastAPI PUT `reorder_story_items` without auth dependency \u2014 backend/routes/stories.py:111"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4c255950a34e628d", "name": "FastAPI PUT `move_story_item` without auth dependency \u2014 backend/routes/stories.py:126", "shortDescription": {"text": "FastAPI PUT `move_story_item` without auth dependency \u2014 backend/routes/stories.py:126"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3bf78d9dad1ea603", "name": "FastAPI PUT `trim_story_item` without auth dependency \u2014 backend/routes/stories.py:140", "shortDescription": {"text": "FastAPI PUT `trim_story_item` without auth dependency \u2014 backend/routes/stories.py:140"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2f3e9401f826e8a9", "name": "FastAPI PUT `update_story_item_volume` without auth dependency \u2014 backend/routes/stories.py:154", "shortDescription": {"text": "FastAPI PUT `update_story_item_volume` without auth dependency \u2014 backend/routes/stories.py:154"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-60659af2153b28a1", "name": "FastAPI POST `split_story_item` without auth dependency \u2014 backend/routes/stories.py:168", "shortDescription": {"text": "FastAPI POST `split_story_item` without auth dependency \u2014 backend/routes/stories.py:168"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6f4b4f1cdcd448f5", "name": "FastAPI POST `duplicate_story_item` without auth dependency \u2014 backend/routes/stories.py:182", "shortDescription": {"text": "FastAPI POST `duplicate_story_item` without auth dependency \u2014 backend/routes/stories.py:182"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-38b55463ed8c0781", "name": "FastAPI PUT `set_story_item_version` without auth dependency \u2014 backend/routes/stories.py:195", "shortDescription": {"text": "FastAPI PUT `set_story_item_version` without auth dependency \u2014 backend/routes/stories.py:195"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a7f59a844c127c31", "name": "FastAPI POST `transcribe_audio` without auth dependency \u2014 backend/routes/transcription.py:23", "shortDescription": {"text": "FastAPI POST `transcribe_audio` without auth dependency \u2014 backend/routes/transcription.py:23"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5919052e89115baa", "name": "FastAPI POST `download_cuda_backend` without auth dependency \u2014 backend/routes/cuda.py:24", "shortDescription": {"text": "FastAPI POST `download_cuda_backend` without auth dependency \u2014 backend/routes/cuda.py:24"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2fc6a7ae045187a7", "name": "FastAPI DELETE `delete_cuda_backend` without auth dependency \u2014 backend/routes/cuda.py:51", "shortDescription": {"text": "FastAPI DELETE `delete_cuda_backend` without auth dependency \u2014 backend/routes/cuda.py:51"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a24f755d23389866", "name": "FastAPI POST `llm_generate` without auth dependency \u2014 backend/routes/llm.py:19", "shortDescription": {"text": "FastAPI POST `llm_generate` without auth dependency \u2014 backend/routes/llm.py:19"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-58672eb3e0ac2037", "name": "FastAPI POST `download_rocm_backend` without auth dependency \u2014 backend/routes/rocm.py:24", "shortDescription": {"text": "FastAPI POST `download_rocm_backend` without auth dependency \u2014 backend/routes/rocm.py:24"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-28593f4ef17a0990", "name": "FastAPI DELETE `delete_rocm_backend` without auth dependency \u2014 backend/routes/rocm.py:44", "shortDescription": {"text": "FastAPI DELETE `delete_rocm_backend` without auth dependency \u2014 backend/routes/rocm.py:44"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-de2aae427f5bc803", "name": "FastAPI POST `clear_all_tasks` without auth dependency \u2014 backend/routes/tasks.py:16", "shortDescription": {"text": "FastAPI POST `clear_all_tasks` without auth dependency \u2014 backend/routes/tasks.py:16"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-03b045e219983a81", "name": "FastAPI POST `clear_cache` without auth dependency \u2014 backend/routes/tasks.py:32", "shortDescription": {"text": "FastAPI POST `clear_cache` without auth dependency \u2014 backend/routes/tasks.py:32"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5a263ec8f65d6630", "name": "FastAPI POST `preview_effects` without auth dependency \u2014 backend/routes/effects.py:18", "shortDescription": {"text": "FastAPI POST `preview_effects` without auth dependency \u2014 backend/routes/effects.py:18"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-feac42403173c37d", "name": "FastAPI POST `create_effect_preset` without auth dependency \u2014 backend/routes/effects.py:93", "shortDescription": {"text": "FastAPI POST `create_effect_preset` without auth dependency \u2014 backend/routes/effects.py:93"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a836aff24c83a028", "name": "FastAPI PUT `update_effect_preset` without auth dependency \u2014 backend/routes/effects.py:107", "shortDescription": {"text": "FastAPI PUT `update_effect_preset` without auth dependency \u2014 backend/routes/effects.py:107"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6cf9722da928e37b", "name": "FastAPI DELETE `delete_effect_preset` without auth dependency \u2014 backend/routes/effects.py:125", "shortDescription": {"text": "FastAPI DELETE `delete_effect_preset` without auth dependency \u2014 backend/routes/effects.py:125"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-23a1acdec92e1a06", "name": "FastAPI POST `apply_effects_to_generation` without auth dependency \u2014 backend/routes/effects.py:156", "shortDescription": {"text": "FastAPI POST `apply_effects_to_generation` without auth dependency \u2014 backend/routes/effects.py:156"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-23dece215aff53b1", "name": "FastAPI PUT `set_default_version` without auth dependency \u2014 backend/routes/effects.py:222", "shortDescription": {"text": "FastAPI PUT `set_default_version` without auth dependency \u2014 backend/routes/effects.py:222"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1ec9b0f4e9286c8d", "name": "FastAPI DELETE `delete_generation_version` without auth dependency \u2014 backend/routes/effects.py:244", "shortDescription": {"text": "FastAPI DELETE `delete_generation_version` without auth dependency \u2014 backend/routes/effects.py:244"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ff01553fa0610299", "name": "FastAPI POST `load_model` without auth dependency \u2014 backend/routes/models.py:50", "shortDescription": {"text": "FastAPI POST `load_model` without auth dependency \u2014 backend/routes/models.py:50"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d23b924b765458aa", "name": "FastAPI POST `unload_model` without auth dependency \u2014 backend/routes/models.py:63", "shortDescription": {"text": "FastAPI POST `unload_model` without auth dependency \u2014 backend/routes/models.py:63"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c1e9a25ad80d6ee2", "name": "FastAPI POST `unload_model_by_name` without auth dependency \u2014 backend/routes/models.py:75", "shortDescription": {"text": "FastAPI POST `unload_model_by_name` without auth dependency \u2014 backend/routes/models.py:75"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0149eb1d06bfa93d", "name": "FastAPI POST `migrate_models` without auth dependency \u2014 backend/routes/models.py:121", "shortDescription": {"text": "FastAPI POST `migrate_models` without auth dependency \u2014 backend/routes/models.py:121"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-80699c3e6cc5bc84", "name": "FastAPI POST `trigger_model_download` without auth dependency \u2014 backend/routes/models.py:390", "shortDescription": {"text": "FastAPI POST `trigger_model_download` without auth dependency \u2014 backend/routes/models.py:390"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-55fb3cc8897740a7", "name": "FastAPI POST `cancel_model_download` without auth dependency \u2014 backend/routes/models.py:428", "shortDescription": {"text": "FastAPI POST `cancel_model_download` without auth dependency \u2014 backend/routes/models.py:428"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a4f14e97eaf2a2ae", "name": "FastAPI DELETE `delete_model` without auth dependency \u2014 backend/routes/models.py:447", "shortDescription": {"text": "FastAPI DELETE `delete_model` without auth dependency \u2014 backend/routes/models.py:447"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-21da453f5ea90af6", "name": "FastAPI POST `start_cloud_login` without auth dependency \u2014 backend/routes/cloud.py:30", "shortDescription": {"text": "FastAPI POST `start_cloud_login` without auth dependency \u2014 backend/routes/cloud.py:30"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-438c925496a5c318", "name": "FastAPI POST `cloud_disconnect` without auth dependency \u2014 backend/routes/cloud.py:72", "shortDescription": {"text": "FastAPI POST `cloud_disconnect` without auth dependency \u2014 backend/routes/cloud.py:72"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8e71522ca07644d5", "name": "FastAPI POST `create_profile` without auth dependency \u2014 backend/routes/profiles.py:25", "shortDescription": {"text": "FastAPI POST `create_profile` without auth dependency \u2014 backend/routes/profiles.py:25"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ba17a2cb068f6ffa", "name": "FastAPI POST `import_profile` without auth dependency \u2014 backend/routes/profiles.py:45", "shortDescription": {"text": "FastAPI POST `import_profile` without auth dependency \u2014 backend/routes/profiles.py:45"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0e83a18e1160ff31", "name": "FastAPI PUT `update_profile` without auth dependency \u2014 backend/routes/profiles.py:121", "shortDescription": {"text": "FastAPI PUT `update_profile` without auth dependency \u2014 backend/routes/profiles.py:121"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-04c75b4263aecf3a", "name": "FastAPI DELETE `delete_profile` without auth dependency \u2014 backend/routes/profiles.py:137", "shortDescription": {"text": "FastAPI DELETE `delete_profile` without auth dependency \u2014 backend/routes/profiles.py:137"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3ae4de2c13cc5b61", "name": "FastAPI POST `add_profile_sample` without auth dependency \u2014 backend/routes/profiles.py:153", "shortDescription": {"text": "FastAPI POST `add_profile_sample` without auth dependency \u2014 backend/routes/profiles.py:153"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6d4bf72c3d3dd68e", "name": "FastAPI DELETE `delete_profile_sample` without auth dependency \u2014 backend/routes/profiles.py:203", "shortDescription": {"text": "FastAPI DELETE `delete_profile_sample` without auth dependency \u2014 backend/routes/profiles.py:203"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9bc9fd03ad4eb507", "name": "FastAPI PUT `update_profile_sample` without auth dependency \u2014 backend/routes/profiles.py:215", "shortDescription": {"text": "FastAPI PUT `update_profile_sample` without auth dependency \u2014 backend/routes/profiles.py:215"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-913b3a065b854006", "name": "FastAPI POST `upload_profile_avatar` without auth dependency \u2014 backend/routes/profiles.py:228", "shortDescription": {"text": "FastAPI POST `upload_profile_avatar` without auth dependency \u2014 backend/routes/profiles.py:228"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d3bd294ef25a8b1b", "name": "FastAPI DELETE `delete_profile_avatar` without auth dependency \u2014 backend/routes/profiles.py:269", "shortDescription": {"text": "FastAPI DELETE `delete_profile_avatar` without auth dependency \u2014 backend/routes/profiles.py:269"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9b1397c5fc1a2fdb", "name": "FastAPI PUT `set_profile_channels` without auth dependency \u2014 backend/routes/profiles.py:323", "shortDescription": {"text": "FastAPI PUT `set_profile_channels` without auth dependency \u2014 backend/routes/profiles.py:323"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b7b426361d188b82", "name": "FastAPI PUT `update_profile_effects` without auth dependency \u2014 backend/routes/profiles.py:337", "shortDescription": {"text": "FastAPI PUT `update_profile_effects` without auth dependency \u2014 backend/routes/profiles.py:337"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7cd9d15bff28d8c7", "name": "FastAPI POST `compose_in_character` without auth dependency \u2014 backend/routes/profiles.py:374", "shortDescription": {"text": "FastAPI POST `compose_in_character` without auth dependency \u2014 backend/routes/profiles.py:374"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-64a1c99b1c809887", "name": "FastAPI PUT `update_capture_settings_endpoint` without auth dependency \u2014 backend/routes/settings.py:18", "shortDescription": {"text": "FastAPI PUT `update_capture_settings_endpoint` without auth dependency \u2014 backend/routes/settings.py:18"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-27fca6d1511b5994", "name": "FastAPI PUT `update_generation_settings_endpoint` without auth dependency \u2014 backend/routes/settings.py:31", "shortDescription": {"text": "FastAPI PUT `update_generation_settings_endpoint` without auth dependency \u2014 backend/routes/settings.py:31"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-13b1681ae96b9970", "name": "FastAPI POST `speak` without auth dependency \u2014 backend/routes/speak.py:27", "shortDescription": {"text": "FastAPI POST `speak` without auth dependency \u2014 backend/routes/speak.py:27"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4286bd9baa34828e", "name": "FastAPI POST `create_capture_endpoint` without auth dependency \u2014 backend/routes/captures.py:24", "shortDescription": {"text": "FastAPI POST `create_capture_endpoint` without auth dependency \u2014 backend/routes/captures.py:24"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4942a1390362ac2b", "name": "FastAPI DELETE `delete_capture_endpoint` without auth dependency \u2014 backend/routes/captures.py:111", "shortDescription": {"text": "FastAPI DELETE `delete_capture_endpoint` without auth dependency \u2014 backend/routes/captures.py:111"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dcc3f072d344e1c5", "name": "FastAPI POST `refine_capture_endpoint` without auth dependency \u2014 backend/routes/captures.py:119", "shortDescription": {"text": "FastAPI POST `refine_capture_endpoint` without auth dependency \u2014 backend/routes/captures.py:119"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-583b6f17e82530f4", "name": "FastAPI POST `retranscribe_capture_endpoint` without auth dependency \u2014 backend/routes/captures.py:203", "shortDescription": {"text": "FastAPI POST `retranscribe_capture_endpoint` without auth dependency \u2014 backend/routes/captures.py:203"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b6ee92e8d558ed40", "name": "FastAPI POST `create_channel` without auth dependency \u2014 backend/routes/channels.py:19", "shortDescription": {"text": "FastAPI POST `create_channel` without auth dependency \u2014 backend/routes/channels.py:19"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-be9a27aa838c4f3c", "name": "FastAPI PUT `update_channel` without auth dependency \u2014 backend/routes/channels.py:43", "shortDescription": {"text": "FastAPI PUT `update_channel` without auth dependency \u2014 backend/routes/channels.py:43"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-09bc78c46651c97c", "name": "FastAPI DELETE `delete_channel` without auth dependency \u2014 backend/routes/channels.py:59", "shortDescription": {"text": "FastAPI DELETE `delete_channel` without auth dependency \u2014 backend/routes/channels.py:59"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-faf62112b6f93f1c", "name": "FastAPI PUT `set_channel_voices` without auth dependency \u2014 backend/routes/channels.py:87", "shortDescription": {"text": "FastAPI PUT `set_channel_voices` without auth dependency \u2014 backend/routes/channels.py:87"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a37c4d83833bb650", "name": "Vulnerable dependency next 16.1.4: GHSA-267c-6grr-h53f", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-267c-6grr-h53f"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-267c-6grr-h53f (aka CVE-2026-44575).\n\nNext.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes\n\nAliases: CVE-2026-44575\nAdvisory: https://osv.dev/vulnerability/GHSA-267c-6grr-h53f\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fa8943c715790d91", "name": "Vulnerable dependency next 16.1.4: GHSA-26hh-7cqf-hhc6", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-26hh-7cqf-hhc6"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-26hh-7cqf-hhc6 (aka CVE-2026-45109).\n\nNext.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up\n\nAliases: CVE-2026-45109\nAdvisory: https://osv.dev/vulnerability/GHSA-26hh-7cqf-hhc6\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a29d1b99d94d1eba", "name": "Vulnerable dependency next 16.1.4: GHSA-36qx-fr4f-26g5", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-36qx-fr4f-26g5"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-36qx-fr4f-26g5 (aka CVE-2026-44573).\n\nNext.js has a Middleware / Proxy bypass in Pages Router applications using i18n\n\nAliases: CVE-2026-44573\nAdvisory: https://osv.dev/vulnerability/GHSA-36qx-fr4f-26g5\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3f0c1b4061872109", "name": "Vulnerable dependency next 16.1.4: GHSA-3g8h-86w9-wvmq", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-3g8h-86w9-wvmq"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-3g8h-86w9-wvmq (aka CVE-2026-44572).\n\nNext.js's Middleware / Proxy redirects can be cache-poisoned\n\nAliases: CVE-2026-44572\nAdvisory: https://osv.dev/vulnerability/GHSA-3g8h-86w9-wvmq\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d31e98fb2b12e2ee", "name": "Vulnerable dependency next 16.1.4: GHSA-3x4c-7xq6-9pq8", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-3x4c-7xq6-9pq8"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-3x4c-7xq6-9pq8 (aka CVE-2026-27980).\n\nNext.js: Unbounded next/image disk cache growth can exhaust storage\n\nAliases: CVE-2026-27980\nAdvisory: https://osv.dev/vulnerability/GHSA-3x4c-7xq6-9pq8\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-569055332c227fd2", "name": "Vulnerable dependency next 16.1.4: GHSA-4633-3j49-mh5q", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-4633-3j49-mh5q"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-4633-3j49-mh5q (aka CVE-2026-64647).\n\nNext.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\nAliases: CVE-2026-64647\nAdvisory: https://osv.dev/vulnerability/GHSA-4633-3j49-mh5q\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c59eb2a8de09122f", "name": "Vulnerable dependency next 16.1.4: GHSA-492v-c6pp-mqqv", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-492v-c6pp-mqqv"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-492v-c6pp-mqqv (aka CVE-2026-44574).\n\nNext.js has a Middleware / Proxy bypass through dynamic route parameter injection\n\nAliases: CVE-2026-44574\nAdvisory: https://osv.dev/vulnerability/GHSA-492v-c6pp-mqqv\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-13b37bca9debbf55", "name": "Vulnerable dependency next 16.1.4: GHSA-4c39-4ccg-62r3", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-4c39-4ccg-62r3"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-4c39-4ccg-62r3 (aka CVE-2026-64646).\n\nNext.js: Unbounded Server Action payload in Edge runtime\n\nAliases: CVE-2026-64646\nAdvisory: https://osv.dev/vulnerability/GHSA-4c39-4ccg-62r3\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a8543e5fbb96a19e", "name": "Vulnerable dependency next 16.1.4: GHSA-5f7q-jpqc-wp7h", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-5f7q-jpqc-wp7h"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-5f7q-jpqc-wp7h.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-5f7q-jpqc-wp7h\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5bcb62695d0c2fea", "name": "Vulnerable dependency next 16.1.4: GHSA-68g3-v927-f742", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-68g3-v927-f742"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-68g3-v927-f742 (aka CVE-2026-64648).\n\nNext.js: Cache confusion of response bodies for requests with bodies\n\nAliases: CVE-2026-64648\nAdvisory: https://osv.dev/vulnerability/GHSA-68g3-v927-f742\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c5fca1883fe47925", "name": "Vulnerable dependency next 16.1.4: GHSA-6gpp-xcg3-4w24", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-6gpp-xcg3-4w24"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-6gpp-xcg3-4w24 (aka CVE-2026-64642).\n\nNext.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale\n\nAliases: CVE-2026-64642\nAdvisory: https://osv.dev/vulnerability/GHSA-6gpp-xcg3-4w24\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-353eaee5a024a709", "name": "Vulnerable dependency next 16.1.4: GHSA-89xv-2m56-2m9x", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-89xv-2m56-2m9x"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-89xv-2m56-2m9x (aka CVE-2026-64649).\n\nNext.js: Server-Side Request Forgery in Server Actions on custom servers\n\nAliases: CVE-2026-64649\nAdvisory: https://osv.dev/vulnerability/GHSA-89xv-2m56-2m9x\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c552bc16148b9d15", "name": "Vulnerable dependency next 16.1.4: GHSA-8h8q-6873-q5fj", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-8h8q-6873-q5fj"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-8h8q-6873-q5fj.\n\nNext.js Vulnerable to Denial of Service with Server Components\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8h8q-6873-q5fj\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5f3645b622d518df", "name": "Vulnerable dependency next 16.1.4: GHSA-955p-x3mx-jcvp", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-955p-x3mx-jcvp"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-955p-x3mx-jcvp (aka CVE-2026-64643).\n\nNext.js: Unauthenticated disclosure of internal Server Function endpoints\n\nAliases: CVE-2026-64643\nAdvisory: https://osv.dev/vulnerability/GHSA-955p-x3mx-jcvp\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fcb316d03947cae4", "name": "Vulnerable dependency next 16.1.4: GHSA-9g9p-9gw9-jx7f", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-9g9p-9gw9-jx7f"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-9g9p-9gw9-jx7f.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9g9p-9gw9-jx7f\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f260c60044c81eee", "name": "Vulnerable dependency next 16.1.4: GHSA-c4j6-fc7j-m34r", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-c4j6-fc7j-m34r"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-c4j6-fc7j-m34r (aka CVE-2026-44578).\n\nNext.js vulnerable to server-side request forgery in applications using WebSocket upgrades\n\nAliases: CVE-2026-44578\nAdvisory: https://osv.dev/vulnerability/GHSA-c4j6-fc7j-m34r\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1c62fc5abf12694c", "name": "Vulnerable dependency next 16.1.4: GHSA-ffhc-5mcf-pf4q", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-ffhc-5mcf-pf4q"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-ffhc-5mcf-pf4q (aka CVE-2026-44581).\n\nNext.js vulnerable to cross-site scripting in App Router applications using CSP nonces\n\nAliases: CVE-2026-44581\nAdvisory: https://osv.dev/vulnerability/GHSA-ffhc-5mcf-pf4q\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6e857fcc46f4c0c9", "name": "Vulnerable dependency next 16.1.4: GHSA-ggv3-7p47-pfv8", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-ggv3-7p47-pfv8"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-ggv3-7p47-pfv8 (aka CVE-2026-29057).\n\nNext.js: HTTP request smuggling in rewrites\n\nAliases: CVE-2026-29057\nAdvisory: https://osv.dev/vulnerability/GHSA-ggv3-7p47-pfv8\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cfdabd1e3d18ef1b", "name": "Vulnerable dependency next 16.1.4: GHSA-gx5p-jg67-6x7h", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-gx5p-jg67-6x7h"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-gx5p-jg67-6x7h.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-gx5p-jg67-6x7h\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1e0fcc111a113248", "name": "Vulnerable dependency next 16.1.4: GHSA-h25m-26qc-wcjf", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-h25m-26qc-wcjf"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-h25m-26qc-wcjf.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-h25m-26qc-wcjf\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-28e5ba9ae8a7ed42", "name": "Vulnerable dependency next 16.1.4: GHSA-h27x-g6w4-24gq", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-h27x-g6w4-24gq"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-h27x-g6w4-24gq.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-h27x-g6w4-24gq\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5e1751938e62bd56", "name": "Vulnerable dependency next 16.1.4: GHSA-h64f-5h5j-jqjh", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-h64f-5h5j-jqjh"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-h64f-5h5j-jqjh.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-h64f-5h5j-jqjh\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f4fe304a48ccf3e8", "name": "Vulnerable dependency next 16.1.4: GHSA-jcc7-9wpm-mj36", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-jcc7-9wpm-mj36"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-jcc7-9wpm-mj36.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jcc7-9wpm-mj36\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a176eb42e6f9763e", "name": "Vulnerable dependency next 16.1.4: GHSA-m99w-x7hq-7vfj", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-m99w-x7hq-7vfj"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-m99w-x7hq-7vfj.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-m99w-x7hq-7vfj\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4001153c43ee5a2f", "name": "Vulnerable dependency next 16.1.4: GHSA-mg66-mrh9-m8jx", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-mg66-mrh9-m8jx"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-mg66-mrh9-m8jx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mg66-mrh9-m8jx\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5e183bfc44a9a1e9", "name": "Vulnerable dependency next 16.1.4: GHSA-mq59-m269-xvcx", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-mq59-m269-xvcx"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-mq59-m269-xvcx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mq59-m269-xvcx\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ede9477cae92fb48", "name": "Vulnerable dependency next 16.1.4: GHSA-p9j2-gv94-2wf4", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-p9j2-gv94-2wf4"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-p9j2-gv94-2wf4.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-p9j2-gv94-2wf4\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0abe7770a163bbd6", "name": "Vulnerable dependency next 16.1.4: GHSA-q4gf-8mx6-v5v3", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-q4gf-8mx6-v5v3"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-q4gf-8mx6-v5v3.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q4gf-8mx6-v5v3\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e5f0dd8902c24c4f", "name": "Vulnerable dependency next 16.1.4: GHSA-q8wf-6r8g-63ch", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-q8wf-6r8g-63ch"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-q8wf-6r8g-63ch.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q8wf-6r8g-63ch\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-92688f1ab4d7683a", "name": "Vulnerable dependency next 16.1.4: GHSA-vfv6-92ff-j949", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-vfv6-92ff-j949"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-vfv6-92ff-j949.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vfv6-92ff-j949\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9b4df8310b3b804c", "name": "Vulnerable dependency next 16.1.4: GHSA-wfc6-r584-vfw7", "shortDescription": {"text": "Vulnerable dependency next 16.1.4: GHSA-wfc6-r584-vfw7"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.4` (resolved in `bun.lock`) is affected by GHSA-wfc6-r584-vfw7.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wfc6-r584-vfw7\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1ef4e36137af8a94", "name": "Vulnerable dependency postcss 8.5.6: GHSA-qx2v-qp2m-jg93", "shortDescription": {"text": "Vulnerable dependency postcss 8.5.6: GHSA-qx2v-qp2m-jg93"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.5.6` (resolved in `bun.lock`) is affected by GHSA-qx2v-qp2m-jg93.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-qx2v-qp2m-jg93\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-20c5c9da0b7b62f6", "name": "Vulnerable dependency vite 5.4.21: GHSA-4w7w-66w2-5vf9", "shortDescription": {"text": "Vulnerable dependency vite 5.4.21: GHSA-4w7w-66w2-5vf9"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `5.4.21` (resolved in `bun.lock`) is affected by GHSA-4w7w-66w2-5vf9.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-4w7w-66w2-5vf9\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-2a4a6231445f45c5", "name": "Vulnerable dependency vite 5.4.21: GHSA-fx2h-pf6j-xcff", "shortDescription": {"text": "Vulnerable dependency vite 5.4.21: GHSA-fx2h-pf6j-xcff"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `5.4.21` (resolved in `bun.lock`) is affected by GHSA-fx2h-pf6j-xcff.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-fx2h-pf6j-xcff\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-ba50ebe54f9ed9c3", "name": "Vulnerable dependency vite 5.4.21: GHSA-v6wh-96g9-6wx3", "shortDescription": {"text": "Vulnerable dependency vite 5.4.21: GHSA-v6wh-96g9-6wx3"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `5.4.21` (resolved in `bun.lock`) is affected by GHSA-v6wh-96g9-6wx3.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-v6wh-96g9-6wx3\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-f00a3f05020518bc", "name": "Vulnerable dependency postcss 8.4.31: GHSA-qx2v-qp2m-jg93", "shortDescription": {"text": "Vulnerable dependency postcss 8.4.31: GHSA-qx2v-qp2m-jg93"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.4.31` (resolved in `bun.lock`) is affected by GHSA-qx2v-qp2m-jg93.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-qx2v-qp2m-jg93\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-461ffb132c915370", "name": "Vulnerable dependency next 16.1.6: GHSA-267c-6grr-h53f", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-267c-6grr-h53f"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-267c-6grr-h53f (aka CVE-2026-44575).\n\nNext.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes\n\nAliases: CVE-2026-44575\nAdvisory: https://osv.dev/vulnerability/GHSA-267c-6grr-h53f\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bed66d8a00ed89d5", "name": "Vulnerable dependency next 16.1.6: GHSA-26hh-7cqf-hhc6", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-26hh-7cqf-hhc6"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-26hh-7cqf-hhc6 (aka CVE-2026-45109).\n\nNext.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up\n\nAliases: CVE-2026-45109\nAdvisory: https://osv.dev/vulnerability/GHSA-26hh-7cqf-hhc6\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-550cc5f5a1955f67", "name": "Vulnerable dependency next 16.1.6: GHSA-36qx-fr4f-26g5", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-36qx-fr4f-26g5"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-36qx-fr4f-26g5 (aka CVE-2026-44573).\n\nNext.js has a Middleware / Proxy bypass in Pages Router applications using i18n\n\nAliases: CVE-2026-44573\nAdvisory: https://osv.dev/vulnerability/GHSA-36qx-fr4f-26g5\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a077cb8b3191de0a", "name": "Vulnerable dependency next 16.1.6: GHSA-3g8h-86w9-wvmq", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-3g8h-86w9-wvmq"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-3g8h-86w9-wvmq (aka CVE-2026-44572).\n\nNext.js's Middleware / Proxy redirects can be cache-poisoned\n\nAliases: CVE-2026-44572\nAdvisory: https://osv.dev/vulnerability/GHSA-3g8h-86w9-wvmq\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-97540d8fe4c932bc", "name": "Vulnerable dependency next 16.1.6: GHSA-3x4c-7xq6-9pq8", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-3x4c-7xq6-9pq8"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-3x4c-7xq6-9pq8 (aka CVE-2026-27980).\n\nNext.js: Unbounded next/image disk cache growth can exhaust storage\n\nAliases: CVE-2026-27980\nAdvisory: https://osv.dev/vulnerability/GHSA-3x4c-7xq6-9pq8\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6e6355d5ff6077b8", "name": "Vulnerable dependency next 16.1.6: GHSA-4633-3j49-mh5q", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-4633-3j49-mh5q"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-4633-3j49-mh5q (aka CVE-2026-64647).\n\nNext.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\nAliases: CVE-2026-64647\nAdvisory: https://osv.dev/vulnerability/GHSA-4633-3j49-mh5q\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4292688685a013bc", "name": "Vulnerable dependency next 16.1.6: GHSA-492v-c6pp-mqqv", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-492v-c6pp-mqqv"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-492v-c6pp-mqqv (aka CVE-2026-44574).\n\nNext.js has a Middleware / Proxy bypass through dynamic route parameter injection\n\nAliases: CVE-2026-44574\nAdvisory: https://osv.dev/vulnerability/GHSA-492v-c6pp-mqqv\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-986db914802d3d9e", "name": "Vulnerable dependency next 16.1.6: GHSA-4c39-4ccg-62r3", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-4c39-4ccg-62r3"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-4c39-4ccg-62r3 (aka CVE-2026-64646).\n\nNext.js: Unbounded Server Action payload in Edge runtime\n\nAliases: CVE-2026-64646\nAdvisory: https://osv.dev/vulnerability/GHSA-4c39-4ccg-62r3\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-006fb1b9c1308cde", "name": "Vulnerable dependency next 16.1.6: GHSA-68g3-v927-f742", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-68g3-v927-f742"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-68g3-v927-f742 (aka CVE-2026-64648).\n\nNext.js: Cache confusion of response bodies for requests with bodies\n\nAliases: CVE-2026-64648\nAdvisory: https://osv.dev/vulnerability/GHSA-68g3-v927-f742\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f612c8d0f250ef2c", "name": "Vulnerable dependency next 16.1.6: GHSA-6gpp-xcg3-4w24", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-6gpp-xcg3-4w24"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-6gpp-xcg3-4w24 (aka CVE-2026-64642).\n\nNext.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale\n\nAliases: CVE-2026-64642\nAdvisory: https://osv.dev/vulnerability/GHSA-6gpp-xcg3-4w24\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-59b2a87d7314313d", "name": "Vulnerable dependency next 16.1.6: GHSA-89xv-2m56-2m9x", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-89xv-2m56-2m9x"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-89xv-2m56-2m9x (aka CVE-2026-64649).\n\nNext.js: Server-Side Request Forgery in Server Actions on custom servers\n\nAliases: CVE-2026-64649\nAdvisory: https://osv.dev/vulnerability/GHSA-89xv-2m56-2m9x\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b4d5641d201f6910", "name": "Vulnerable dependency next 16.1.6: GHSA-8h8q-6873-q5fj", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-8h8q-6873-q5fj"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-8h8q-6873-q5fj.\n\nNext.js Vulnerable to Denial of Service with Server Components\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8h8q-6873-q5fj\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-061dd8b61418afe1", "name": "Vulnerable dependency next 16.1.6: GHSA-955p-x3mx-jcvp", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-955p-x3mx-jcvp"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-955p-x3mx-jcvp (aka CVE-2026-64643).\n\nNext.js: Unauthenticated disclosure of internal Server Function endpoints\n\nAliases: CVE-2026-64643\nAdvisory: https://osv.dev/vulnerability/GHSA-955p-x3mx-jcvp\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0df5a06192b4be15", "name": "Vulnerable dependency next 16.1.6: GHSA-c4j6-fc7j-m34r", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-c4j6-fc7j-m34r"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-c4j6-fc7j-m34r (aka CVE-2026-44578).\n\nNext.js vulnerable to server-side request forgery in applications using WebSocket upgrades\n\nAliases: CVE-2026-44578\nAdvisory: https://osv.dev/vulnerability/GHSA-c4j6-fc7j-m34r\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4a3fcbeef416eb87", "name": "Vulnerable dependency next 16.1.6: GHSA-ffhc-5mcf-pf4q", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-ffhc-5mcf-pf4q"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-ffhc-5mcf-pf4q (aka CVE-2026-44581).\n\nNext.js vulnerable to cross-site scripting in App Router applications using CSP nonces\n\nAliases: CVE-2026-44581\nAdvisory: https://osv.dev/vulnerability/GHSA-ffhc-5mcf-pf4q\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3db72d49b35269fc", "name": "Vulnerable dependency next 16.1.6: GHSA-ggv3-7p47-pfv8", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-ggv3-7p47-pfv8"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-ggv3-7p47-pfv8 (aka CVE-2026-29057).\n\nNext.js: HTTP request smuggling in rewrites\n\nAliases: CVE-2026-29057\nAdvisory: https://osv.dev/vulnerability/GHSA-ggv3-7p47-pfv8\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-17040fea84ec05bf", "name": "Vulnerable dependency next 16.1.6: GHSA-gx5p-jg67-6x7h", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-gx5p-jg67-6x7h"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-gx5p-jg67-6x7h.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-gx5p-jg67-6x7h\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0a1b84b4e0409e40", "name": "Vulnerable dependency next 16.1.6: GHSA-h27x-g6w4-24gq", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-h27x-g6w4-24gq"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-h27x-g6w4-24gq.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-h27x-g6w4-24gq\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b100d1fbfca2abca", "name": "Vulnerable dependency next 16.1.6: GHSA-h64f-5h5j-jqjh", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-h64f-5h5j-jqjh"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-h64f-5h5j-jqjh.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-h64f-5h5j-jqjh\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dd49bef8cb4761bb", "name": "Vulnerable dependency next 16.1.6: GHSA-jcc7-9wpm-mj36", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-jcc7-9wpm-mj36"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-jcc7-9wpm-mj36.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jcc7-9wpm-mj36\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6c922a0b4918f4da", "name": "Vulnerable dependency next 16.1.6: GHSA-m99w-x7hq-7vfj", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-m99w-x7hq-7vfj"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-m99w-x7hq-7vfj.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-m99w-x7hq-7vfj\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-157931d78ae4314e", "name": "Vulnerable dependency next 16.1.6: GHSA-mg66-mrh9-m8jx", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-mg66-mrh9-m8jx"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-mg66-mrh9-m8jx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mg66-mrh9-m8jx\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cba11b5b6d2484f0", "name": "Vulnerable dependency next 16.1.6: GHSA-mq59-m269-xvcx", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-mq59-m269-xvcx"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-mq59-m269-xvcx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mq59-m269-xvcx\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-66cd8fd0ce0d648d", "name": "Vulnerable dependency next 16.1.6: GHSA-p9j2-gv94-2wf4", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-p9j2-gv94-2wf4"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-p9j2-gv94-2wf4.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-p9j2-gv94-2wf4\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bf4f1976a9b7144c", "name": "Vulnerable dependency next 16.1.6: GHSA-q4gf-8mx6-v5v3", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-q4gf-8mx6-v5v3"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-q4gf-8mx6-v5v3.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q4gf-8mx6-v5v3\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-510d8b300cc39bd4", "name": "Vulnerable dependency next 16.1.6: GHSA-q8wf-6r8g-63ch", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-q8wf-6r8g-63ch"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-q8wf-6r8g-63ch.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q8wf-6r8g-63ch\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5ebdccf480a2f5e2", "name": "Vulnerable dependency next 16.1.6: GHSA-vfv6-92ff-j949", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-vfv6-92ff-j949"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-vfv6-92ff-j949.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vfv6-92ff-j949\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e0b43734a07787cf", "name": "Vulnerable dependency next 16.1.6: GHSA-wfc6-r584-vfw7", "shortDescription": {"text": "Vulnerable dependency next 16.1.6: GHSA-wfc6-r584-vfw7"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.1.6` (resolved in `docs/bun.lock`) is affected by GHSA-wfc6-r584-vfw7.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wfc6-r584-vfw7\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-de53f21ca886215e", "name": "Vulnerable dependency tauri 2.9.5: GHSA-7gmj-67g7-phm9", "shortDescription": {"text": "Vulnerable dependency tauri 2.9.5: GHSA-7gmj-67g7-phm9"}, "fullDescription": {"text": "OSV.dev reports `tauri` at version `2.9.5` (resolved in `tauri/src-tauri/Cargo.lock`) is affected by GHSA-7gmj-67g7-phm9 (aka CVE-2026-42184).\n\nTauri has an Origin Confusion Issue that Allows Remote Pages to Invoke Local-Only IPC Commands\n\nAliases: CVE-2026-42184\nAdvisory: https://osv.dev/vulnerability/GHSA-7gmj-67g7-phm9\nFix: upgrade `tauri` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-889fe40b3def0d43", "name": "Vulnerable dependency tauri 2.0: GHSA-7gmj-67g7-phm9", "shortDescription": {"text": "Vulnerable dependency tauri 2.0: GHSA-7gmj-67g7-phm9"}, "fullDescription": {"text": "OSV.dev reports `tauri` at version `2.0` (declared in `tauri/src-tauri/Cargo.toml`) is affected by GHSA-7gmj-67g7-phm9 (aka CVE-2026-42184).\nNote: `2.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nTauri has an Origin Confusion Issue that Allows Remote Pages to Invoke Local-Only IPC Commands\n\nAliases: CVE-2026-42184\nAdvisory: https://osv.dev/vulnerability/GHSA-7gmj-67g7-phm9\nFix: upgrade `tauri` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.7}}, {"id": "scanner-c6b499f795883422", "name": "Vulnerable dependency tauri-plugin-shell 2.0: GHSA-c9pr-q8gx-3mgp", "shortDescription": {"text": "Vulnerable dependency tauri-plugin-shell 2.0: GHSA-c9pr-q8gx-3mgp"}, "fullDescription": {"text": "OSV.dev reports `tauri-plugin-shell` at version `2.0` (declared in `tauri/src-tauri/Cargo.toml`) is affected by GHSA-c9pr-q8gx-3mgp.\nNote: `2.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-c9pr-q8gx-3mgp\nFix: upgrade `tauri-plugin-shell` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-07ce9957955118f9", "name": "Vulnerable dependency @babel/core 7.28.6: GHSA-4x5r-pxfx-6jf8", "shortDescription": {"text": "Vulnerable dependency @babel/core 7.28.6: GHSA-4x5r-pxfx-6jf8"}, "fullDescription": {"text": "OSV.dev reports `@babel/core` at version `7.28.6` (resolved in `bun.lock`) is affected by GHSA-4x5r-pxfx-6jf8.\nNote: `@babel/core` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-4x5r-pxfx-6jf8\nFix: upgrade `@babel/core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-f228235887a9a3b4", "name": "Vulnerable dependency ajv 6.12.6: GHSA-2g4f-4pwh-qvx6", "shortDescription": {"text": "Vulnerable dependency ajv 6.12.6: GHSA-2g4f-4pwh-qvx6"}, "fullDescription": {"text": "OSV.dev reports `ajv` at version `6.12.6` (resolved in `bun.lock`) is affected by GHSA-2g4f-4pwh-qvx6.\nNote: `ajv` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-2g4f-4pwh-qvx6\nFix: upgrade `ajv` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-0fecd96894f7839e", "name": "Vulnerable dependency brace-expansion 1.1.12: GHSA-3jxr-9vmj-r5cp", "shortDescription": {"text": "Vulnerable dependency brace-expansion 1.1.12: GHSA-3jxr-9vmj-r5cp"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `1.1.12` (resolved in `bun.lock`) is affected by GHSA-3jxr-9vmj-r5cp.\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-3jxr-9vmj-r5cp\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-f8baa36b152a15a9", "name": "Vulnerable dependency brace-expansion 1.1.12: GHSA-f886-m6hf-6m8v", "shortDescription": {"text": "Vulnerable dependency brace-expansion 1.1.12: GHSA-f886-m6hf-6m8v"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `1.1.12` (resolved in `bun.lock`) is affected by GHSA-f886-m6hf-6m8v.\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-f886-m6hf-6m8v\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-5c243a2e5b9ef05f", "name": "Vulnerable dependency esbuild 0.21.5: GHSA-67mh-4wv8-2f99", "shortDescription": {"text": "Vulnerable dependency esbuild 0.21.5: GHSA-67mh-4wv8-2f99"}, "fullDescription": {"text": "OSV.dev reports `esbuild` at version `0.21.5` (resolved in `bun.lock`) is affected by GHSA-67mh-4wv8-2f99.\nNote: `esbuild` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-67mh-4wv8-2f99\nFix: upgrade `esbuild` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-b5b354a1b900569a", "name": "Vulnerable dependency flatted 3.3.3: GHSA-25h7-pfq9-p65f", "shortDescription": {"text": "Vulnerable dependency flatted 3.3.3: GHSA-25h7-pfq9-p65f"}, "fullDescription": {"text": "OSV.dev reports `flatted` at version `3.3.3` (resolved in `bun.lock`) is affected by GHSA-25h7-pfq9-p65f.\nNote: `flatted` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-25h7-pfq9-p65f\nFix: upgrade `flatted` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-b933c9da3b8a9d65", "name": "Vulnerable dependency flatted 3.3.3: GHSA-rf6f-7fwh-wjgh", "shortDescription": {"text": "Vulnerable dependency flatted 3.3.3: GHSA-rf6f-7fwh-wjgh"}, "fullDescription": {"text": "OSV.dev reports `flatted` at version `3.3.3` (resolved in `bun.lock`) is affected by GHSA-rf6f-7fwh-wjgh.\nNote: `flatted` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-rf6f-7fwh-wjgh\nFix: upgrade `flatted` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-40b7862aa8000461", "name": "Vulnerable dependency minimatch 3.1.2: GHSA-23c5-xmqv-rm74", "shortDescription": {"text": "Vulnerable dependency minimatch 3.1.2: GHSA-23c5-xmqv-rm74"}, "fullDescription": {"text": "OSV.dev reports `minimatch` at version `3.1.2` (resolved in `bun.lock`) is affected by GHSA-23c5-xmqv-rm74.\nNote: `minimatch` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-23c5-xmqv-rm74\nFix: upgrade `minimatch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-69f5380a5b975224", "name": "Vulnerable dependency minimatch 3.1.2: GHSA-3ppc-4f35-3m26", "shortDescription": {"text": "Vulnerable dependency minimatch 3.1.2: GHSA-3ppc-4f35-3m26"}, "fullDescription": {"text": "OSV.dev reports `minimatch` at version `3.1.2` (resolved in `bun.lock`) is affected by GHSA-3ppc-4f35-3m26.\nNote: `minimatch` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-3ppc-4f35-3m26\nFix: upgrade `minimatch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-d2d5ce7c6cb9e82a", "name": "Vulnerable dependency minimatch 3.1.2: GHSA-7r86-cg39-jmmj", "shortDescription": {"text": "Vulnerable dependency minimatch 3.1.2: GHSA-7r86-cg39-jmmj"}, "fullDescription": {"text": "OSV.dev reports `minimatch` at version `3.1.2` (resolved in `bun.lock`) is affected by GHSA-7r86-cg39-jmmj.\nNote: `minimatch` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-7r86-cg39-jmmj\nFix: upgrade `minimatch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-eb6230694a1cc79e", "name": "Vulnerable dependency picomatch 2.3.1: GHSA-3v7f-55p6-f55p", "shortDescription": {"text": "Vulnerable dependency picomatch 2.3.1: GHSA-3v7f-55p6-f55p"}, "fullDescription": {"text": "OSV.dev reports `picomatch` at version `2.3.1` (resolved in `bun.lock`) is affected by GHSA-3v7f-55p6-f55p.\nNote: `picomatch` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-3v7f-55p6-f55p\nFix: upgrade `picomatch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-390d73d0cd2fe4d5", "name": "Vulnerable dependency picomatch 2.3.1: GHSA-c2c7-rcm5-vvqj", "shortDescription": {"text": "Vulnerable dependency picomatch 2.3.1: GHSA-c2c7-rcm5-vvqj"}, "fullDescription": {"text": "OSV.dev reports `picomatch` at version `2.3.1` (resolved in `bun.lock`) is affected by GHSA-c2c7-rcm5-vvqj.\nNote: `picomatch` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-c2c7-rcm5-vvqj\nFix: upgrade `picomatch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-96722930b13d8666", "name": "Dependency screencapturekit is two or more major versions behind", "shortDescription": {"text": "Dependency screencapturekit is two or more major versions behind"}, "fullDescription": {"text": "`screencapturekit` is pinned at `1` in `tauri/src-tauri/Cargo.toml` while the latest release on the cargo registry is `8.0.1` \u2014 7 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `screencapturekit` to `8.0.1`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-7c573ef14eaaa9d4", "name": "Dependency @hookform/resolvers is two or more major versions behind", "shortDescription": {"text": "Dependency @hookform/resolvers is two or more major versions behind"}, "fullDescription": {"text": "`@hookform/resolvers` is pinned at `3.9.0` in `app/package.json` while the latest release on the npm registry is `5.4.0` \u2014 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@hookform/resolvers` to `5.4.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-0f063172efc884e7", "name": "Dangling fetch: GET https://huggingface.co/api/models/${repoId} (app/src/components/ServerSettings/ModelManagement.tsx:5", "shortDescription": {"text": "Dangling fetch: GET https://huggingface.co/api/models/${repoId} (app/src/components/ServerSettings/ModelManagement.tsx:50)"}, "fullDescription": {"text": "`app/src/components/ServerSettings/ModelManagement.tsx:50` calls `GET https://huggingface.co/api/models/${repoId}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/huggingface.co/api/models/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b682dd2e23466611", "name": "Dangling fetch: GET /settings/captures (app/src/lib/api/client.ts:496)", "shortDescription": {"text": "Dangling fetch: GET /settings/captures (app/src/lib/api/client.ts:496)"}, "fullDescription": {"text": "`app/src/lib/api/client.ts:496` calls `GET /settings/captures` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/settings/captures`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2e4f6a4eba75f373", "name": "Dangling fetch: PUT /settings/captures (app/src/lib/api/client.ts:504)", "shortDescription": {"text": "Dangling fetch: PUT /settings/captures (app/src/lib/api/client.ts:504)"}, "fullDescription": {"text": "`app/src/lib/api/client.ts:504` calls `PUT /settings/captures` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/settings/captures`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-28b1e042936fe283", "name": "Dangling fetch: GET /settings/generation (app/src/lib/api/client.ts:511)", "shortDescription": {"text": "Dangling fetch: GET /settings/generation (app/src/lib/api/client.ts:511)"}, "fullDescription": {"text": "`app/src/lib/api/client.ts:511` calls `GET /settings/generation` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/settings/generation`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bdf30718ce4ab331", "name": "Dangling fetch: PUT /settings/generation (app/src/lib/api/client.ts:517)", "shortDescription": {"text": "Dangling fetch: PUT /settings/generation (app/src/lib/api/client.ts:517)"}, "fullDescription": {"text": "`app/src/lib/api/client.ts:517` calls `PUT /settings/generation` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/settings/generation`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3173c00365087339", "name": "Dangling fetch: GET /cloud/status (app/src/lib/api/client.ts:948)", "shortDescription": {"text": "Dangling fetch: GET /cloud/status (app/src/lib/api/client.ts:948)"}, "fullDescription": {"text": "`app/src/lib/api/client.ts:948` calls `GET /cloud/status` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/cloud/status`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d37457a58febbc20", "name": "Dangling fetch: POST /cloud/login/start (app/src/lib/api/client.ts:952)", "shortDescription": {"text": "Dangling fetch: POST /cloud/login/start (app/src/lib/api/client.ts:952)"}, "fullDescription": {"text": "`app/src/lib/api/client.ts:952` calls `POST /cloud/login/start` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/cloud/login/start`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9107573f5ed4a754", "name": "Dangling fetch: POST /cloud/disconnect (app/src/lib/api/client.ts:956)", "shortDescription": {"text": "Dangling fetch: POST /cloud/disconnect (app/src/lib/api/client.ts:956)"}, "fullDescription": {"text": "`app/src/lib/api/client.ts:956` calls `POST /cloud/disconnect` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/cloud/disconnect`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0414130e1e911ead", "name": "Dangling fetch: GET /api/stars (landing/src/components/Navbar.tsx:20)", "shortDescription": {"text": "Dangling fetch: GET /api/stars (landing/src/components/Navbar.tsx:20)"}, "fullDescription": {"text": "`landing/src/components/Navbar.tsx:20` calls `GET /api/stars` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/stars`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dd74c75380116414", "name": "Dangling fetch: GET /api/releases (landing/src/app/page.tsx:26)", "shortDescription": {"text": "Dangling fetch: GET /api/releases (landing/src/app/page.tsx:26)"}, "fullDescription": {"text": "`landing/src/app/page.tsx:26` calls `GET /api/releases` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/releases`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4bfbd32383b34fca", "name": "Dangling fetch: GET /api/releases (landing/src/app/capture/page.tsx:18)", "shortDescription": {"text": "Dangling fetch: GET /api/releases (landing/src/app/capture/page.tsx:18)"}, "fullDescription": {"text": "`landing/src/app/capture/page.tsx:18` calls `GET /api/releases` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/releases`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4e3044a1353f0fcc", "name": "Dangling fetch: GET /api/releases (landing/src/app/download/page.tsx:83)", "shortDescription": {"text": "Dangling fetch: GET /api/releases (landing/src/app/download/page.tsx:83)"}, "fullDescription": {"text": "`landing/src/app/download/page.tsx:83` calls `GET /api/releases` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/releases`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-074cd7938df999f9", "name": "Dangling fetch: GET https://lite-api.jup.ag/price/v3?ids=${mint} (landing/src/lib/token-stats.ts:387)", "shortDescription": {"text": "Dangling fetch: GET https://lite-api.jup.ag/price/v3?ids=${mint} (landing/src/lib/token-stats.ts:387)"}, "fullDescription": {"text": "`landing/src/lib/token-stats.ts:387` calls `GET https://lite-api.jup.ag/price/v3?ids=${mint}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/lite-api.jup.ag/price/v3`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1b1d5926fda286fa", "name": "Unused endpoint: GET /{full_path:path}", "shortDescription": {"text": "Unused endpoint: GET /{full_path:path}"}, "fullDescription": {"text": "`backend/app.py` declares `GET /{full_path:path}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e76bfd3f7d716be3", "name": "Unused endpoint: GET /generate/{generation_id}/status", "shortDescription": {"text": "Unused endpoint: GET /generate/{generation_id}/status"}, "fullDescription": {"text": "`backend/routes/generations.py` declares `GET /generate/{generation_id}/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-76e7b0bc9cf34275", "name": "Unused endpoint: POST /generate/stream", "shortDescription": {"text": "Unused endpoint: POST /generate/stream"}, "fullDescription": {"text": "`backend/routes/generations.py` declares `POST /generate/stream` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6b28608f033f2a3e", "name": "Unused endpoint: POST /generate/import", "shortDescription": {"text": "Unused endpoint: POST /generate/import"}, "fullDescription": {"text": "`backend/routes/generations.py` declares `POST /generate/import` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-afc064028ae39ea9", "name": "Unused endpoint: GET /history", "shortDescription": {"text": "Unused endpoint: GET /history"}, "fullDescription": {"text": "`backend/routes/history.py` declares `GET /history` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8b2c1b29e535b939", "name": "Unused endpoint: GET /history/stats", "shortDescription": {"text": "Unused endpoint: GET /history/stats"}, "fullDescription": {"text": "`backend/routes/history.py` declares `GET /history/stats` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d5832f8b2dc83bb4", "name": "Unused endpoint: POST /history/import", "shortDescription": {"text": "Unused endpoint: POST /history/import"}, "fullDescription": {"text": "`backend/routes/history.py` declares `POST /history/import` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-703630a2f1ca9b52", "name": "Unused endpoint: GET /history/{generation_id}/export", "shortDescription": {"text": "Unused endpoint: GET /history/{generation_id}/export"}, "fullDescription": {"text": "`backend/routes/history.py` declares `GET /history/{generation_id}/export` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c32437e94dcaf435", "name": "Unused endpoint: GET /history/{generation_id}/export-audio", "shortDescription": {"text": "Unused endpoint: GET /history/{generation_id}/export-audio"}, "fullDescription": {"text": "`backend/routes/history.py` declares `GET /history/{generation_id}/export-audio` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`backend/routes/health.py` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c9537c842ba93d4c", "name": "Unused endpoint: POST /shutdown", "shortDescription": {"text": "Unused endpoint: POST /shutdown"}, "fullDescription": {"text": "`backend/routes/health.py` declares `POST /shutdown` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2250d1a2f9cf281a", "name": "Unused endpoint: POST /watchdog/disable", "shortDescription": {"text": "Unused endpoint: POST /watchdog/disable"}, "fullDescription": {"text": "`backend/routes/health.py` declares `POST /watchdog/disable` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6dd25d1f862f4e09", "name": "Unused endpoint: GET /stories/{story_id}/export-audio", "shortDescription": {"text": "Unused endpoint: GET /stories/{story_id}/export-audio"}, "fullDescription": {"text": "`backend/routes/stories.py` declares `GET /stories/{story_id}/export-audio` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7de4e88d608e05fe", "name": "Unused endpoint: POST /transcribe", "shortDescription": {"text": "Unused endpoint: POST /transcribe"}, "fullDescription": {"text": "`backend/routes/transcription.py` declares `POST /transcribe` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5dccf4cc0b07424e", "name": "Unused endpoint: GET /backend/cuda-progress", "shortDescription": {"text": "Unused endpoint: GET /backend/cuda-progress"}, "fullDescription": {"text": "`backend/routes/cuda.py` declares `GET /backend/cuda-progress` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-712752d3766e651f", "name": "Unused endpoint: POST /llm/generate", "shortDescription": {"text": "Unused endpoint: POST /llm/generate"}, "fullDescription": {"text": "`backend/routes/llm.py` declares `POST /llm/generate` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-38af776f9f8d12af", "name": "Unused endpoint: GET /backend/rocm-progress", "shortDescription": {"text": "Unused endpoint: GET /backend/rocm-progress"}, "fullDescription": {"text": "`backend/routes/rocm.py` declares `GET /backend/rocm-progress` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7f2a75404375395f", "name": "Unused endpoint: GET /audio/version/{version_id}", "shortDescription": {"text": "Unused endpoint: GET /audio/version/{version_id}"}, "fullDescription": {"text": "`backend/routes/audio.py` declares `GET /audio/version/{version_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-31b7e2f6ad7a9aeb", "name": "Unused endpoint: GET /audio/{generation_id}", "shortDescription": {"text": "Unused endpoint: GET /audio/{generation_id}"}, "fullDescription": {"text": "`backend/routes/audio.py` declares `GET /audio/{generation_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-da4f0c1059da1408", "name": "Unused endpoint: GET /samples/{sample_id}", "shortDescription": {"text": "Unused endpoint: GET /samples/{sample_id}"}, "fullDescription": {"text": "`backend/routes/audio.py` declares `GET /samples/{sample_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ad68c06f5b5283a", "name": "Unused endpoint: POST /cache/clear", "shortDescription": {"text": "Unused endpoint: POST /cache/clear"}, "fullDescription": {"text": "`backend/routes/tasks.py` declares `POST /cache/clear` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e1f8b42c544c5338", "name": "Unused endpoint: GET /events/speak", "shortDescription": {"text": "Unused endpoint: GET /events/speak"}, "fullDescription": {"text": "`backend/routes/events.py` declares `GET /events/speak` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-81b5bae47b244a56", "name": "Unused endpoint: POST /effects/preview/{generation_id}", "shortDescription": {"text": "Unused endpoint: POST /effects/preview/{generation_id}"}, "fullDescription": {"text": "`backend/routes/effects.py` declares `POST /effects/preview/{generation_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bbae4bd1684cc7a0", "name": "Unused endpoint: GET /effects/presets/{preset_id}", "shortDescription": {"text": "Unused endpoint: GET /effects/presets/{preset_id}"}, "fullDescription": {"text": "`backend/routes/effects.py` declares `GET /effects/presets/{preset_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-61470bf3b08c0c19", "name": "Unused endpoint: PUT /generations/{generation_id}/versions/{version_id}/set-default", "shortDescription": {"text": "Unused endpoint: PUT /generations/{generation_id}/versions/{version_id}/set-default"}, "fullDescription": {"text": "`backend/routes/effects.py` declares `PUT /generations/{generation_id}/versions/{version_id}/set-default` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a888fd77df02110a", "name": "Unused endpoint: DELETE /generations/{generation_id}/versions/{version_id}", "shortDescription": {"text": "Unused endpoint: DELETE /generations/{generation_id}/versions/{version_id}"}, "fullDescription": {"text": "`backend/routes/effects.py` declares `DELETE /generations/{generation_id}/versions/{version_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-21f7fd061acae43c", "name": "Unused endpoint: POST /models/load", "shortDescription": {"text": "Unused endpoint: POST /models/load"}, "fullDescription": {"text": "`backend/routes/models.py` declares `POST /models/load` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0b8f7c9e642c1208", "name": "Unused endpoint: POST /models/unload", "shortDescription": {"text": "Unused endpoint: POST /models/unload"}, "fullDescription": {"text": "`backend/routes/models.py` declares `POST /models/unload` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a56cf3cdc52215b4", "name": "Unused endpoint: GET /models/progress/{model_name}", "shortDescription": {"text": "Unused endpoint: GET /models/progress/{model_name}"}, "fullDescription": {"text": "`backend/routes/models.py` declares `GET /models/progress/{model_name}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4e4ba55bc6bb23e5", "name": "Unused endpoint: GET /models/cache-dir", "shortDescription": {"text": "Unused endpoint: GET /models/cache-dir"}, "fullDescription": {"text": "`backend/routes/models.py` declares `GET /models/cache-dir` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6d9ea566be206a24", "name": "Unused endpoint: POST /models/migrate", "shortDescription": {"text": "Unused endpoint: POST /models/migrate"}, "fullDescription": {"text": "`backend/routes/models.py` declares `POST /models/migrate` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5d9fbf9a1e9e9656", "name": "Unused endpoint: GET /models/migrate/progress", "shortDescription": {"text": "Unused endpoint: GET /models/migrate/progress"}, "fullDescription": {"text": "`backend/routes/models.py` declares `GET /models/migrate/progress` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-73c936e1e1498315", "name": "Unused endpoint: GET /models/status", "shortDescription": {"text": "Unused endpoint: GET /models/status"}, "fullDescription": {"text": "`backend/routes/models.py` declares `GET /models/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-846858242a61dac5", "name": "Unused endpoint: POST /login/start", "shortDescription": {"text": "Unused endpoint: POST /login/start"}, "fullDescription": {"text": "`backend/routes/cloud.py` declares `POST /login/start` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cdfb578618cf2542", "name": "Unused endpoint: GET /callback", "shortDescription": {"text": "Unused endpoint: GET /callback"}, "fullDescription": {"text": "`backend/routes/cloud.py` declares `GET /callback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-540ebf4772ccf420", "name": "Unused endpoint: POST /disconnect", "shortDescription": {"text": "Unused endpoint: POST /disconnect"}, "fullDescription": {"text": "`backend/routes/cloud.py` declares `POST /disconnect` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ee27d839f5b50a27", "name": "Unused endpoint: POST /profiles/import", "shortDescription": {"text": "Unused endpoint: POST /profiles/import"}, "fullDescription": {"text": "`backend/routes/profiles.py` declares `POST /profiles/import` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-75c7174c800f27c8", "name": "Unused endpoint: POST /profiles/{profile_id}/samples", "shortDescription": {"text": "Unused endpoint: POST /profiles/{profile_id}/samples"}, "fullDescription": {"text": "`backend/routes/profiles.py` declares `POST /profiles/{profile_id}/samples` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8df76da407751a3c", "name": "Unused endpoint: POST /profiles/{profile_id}/avatar", "shortDescription": {"text": "Unused endpoint: POST /profiles/{profile_id}/avatar"}, "fullDescription": {"text": "`backend/routes/profiles.py` declares `POST /profiles/{profile_id}/avatar` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b10658800b98c034", "name": "Unused endpoint: GET /profiles/{profile_id}/avatar", "shortDescription": {"text": "Unused endpoint: GET /profiles/{profile_id}/avatar"}, "fullDescription": {"text": "`backend/routes/profiles.py` declares `GET /profiles/{profile_id}/avatar` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dd1d8e4b66983778", "name": "Unused endpoint: GET /profiles/{profile_id}/export", "shortDescription": {"text": "Unused endpoint: GET /profiles/{profile_id}/export"}, "fullDescription": {"text": "`backend/routes/profiles.py` declares `GET /profiles/{profile_id}/export` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9465831cb9b3daa4", "name": "Unused endpoint: GET /captures", "shortDescription": {"text": "Unused endpoint: GET /captures"}, "fullDescription": {"text": "`backend/routes/settings.py` declares `GET /captures` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-565ea87c275e06eb", "name": "Unused endpoint: PUT /captures", "shortDescription": {"text": "Unused endpoint: PUT /captures"}, "fullDescription": {"text": "`backend/routes/settings.py` declares `PUT /captures` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6bfc8d2e383629df", "name": "Unused endpoint: GET /generation", "shortDescription": {"text": "Unused endpoint: GET /generation"}, "fullDescription": {"text": "`backend/routes/settings.py` declares `GET /generation` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4fab57e3ac145061", "name": "Unused endpoint: PUT /generation", "shortDescription": {"text": "Unused endpoint: PUT /generation"}, "fullDescription": {"text": "`backend/routes/settings.py` declares `PUT /generation` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cc05e2496e726a3a", "name": "Unused endpoint: POST /speak", "shortDescription": {"text": "Unused endpoint: POST /speak"}, "fullDescription": {"text": "`backend/routes/speak.py` declares `POST /speak` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1524429992899d20", "name": "Unused endpoint: POST /captures", "shortDescription": {"text": "Unused endpoint: POST /captures"}, "fullDescription": {"text": "`backend/routes/captures.py` declares `POST /captures` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4d9c103838a297b0", "name": "Unused endpoint: GET /captures/{capture_id}/audio", "shortDescription": {"text": "Unused endpoint: GET /captures/{capture_id}/audio"}, "fullDescription": {"text": "`backend/routes/captures.py` declares `GET /captures/{capture_id}/audio` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f908028f8c139837", "name": "Unused endpoint: GET /channels/{channel_id}", "shortDescription": {"text": "Unused endpoint: GET /channels/{channel_id}"}, "fullDescription": {"text": "`backend/routes/channels.py` declares `GET /channels/{channel_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/30745"}, "properties": {"repository": "jamiepine/voicebox", "repoUrl": "https://github.com/jamiepine/voicebox", "branch": "main"}, "results": [{"ruleId": "scanner-27ed1c156f6bf844", "level": "note", "message": {"text": "Possibly dead Python function: find_libraries"}, "properties": {"repobilityId": "0d03fe9739917a1c", "scanner": "scanner-primary", "fingerprint": "27ed1c156f6bf844", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/pyi_rth_rocm_sdk.py:32"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-32b7915f6db8afe6", "level": "note", "message": {"text": "Possibly dead Python function: safe_patch_mistral_regex"}, "properties": {"repobilityId": "3021ae15173b2ae6", "scanner": "scanner-primary", "fingerprint": "32b7915f6db8afe6", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/utils/hf_offline_patch.py:180"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1a3423063a962d2a", "level": "note", "message": {"text": "Possibly dead Python function: forward"}, "properties": {"repobilityId": "ea414cce7f8e5874", "scanner": "scanner-primary", "fingerprint": "1a3423063a962d2a", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/utils/dac_shim.py:43"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a323e2fb100f702b", "level": "note", "message": {"text": "Possibly dead Python function: trim_tts_output"}, "properties": {"repobilityId": "32243e0eaa76f9fe", "scanner": "scanner-primary", "fingerprint": "a323e2fb100f702b", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/utils/audio.py:113"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0704823b8c36377a", "level": "note", "message": {"text": "Possibly dead Python function: validate_reference_audio"}, "properties": {"repobilityId": "c4ac8ed1de3ed1a5", "scanner": "scanner-primary", "fingerprint": "0704823b8c36377a", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/utils/audio.py:262"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6955c954477e6da4", "level": "note", "message": {"text": "Possibly dead Python function: patched_update"}, "properties": {"repobilityId": "5c444d55640968af", "scanner": "scanner-primary", "fingerprint": "6955c954477e6da4", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/utils/hf_progress.py:291"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9d659e53a09addc7", "level": "note", "message": {"text": "Possibly dead Python function: callback"}, "properties": {"repobilityId": "d86912f8937c65c2", "scanner": "scanner-primary", "fingerprint": "9d659e53a09addc7", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/utils/hf_progress.py:368"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5f910336353cfa51", "level": "note", "message": {"text": "Possibly dead Python function: create_progress_callback"}, "properties": {"repobilityId": "55d0fea199aa2d6e", "scanner": "scanner-primary", "fingerprint": "5f910336353cfa51", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/utils/progress.py:162"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5079b151c4b95cf0", "level": "note", "message": {"text": "Possibly dead Python function: callback"}, "properties": {"repobilityId": "d86912f8937c65c2", "scanner": "scanner-primary", "fingerprint": "5079b151c4b95cf0", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/utils/progress.py:173"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8a959a3981988ad6", "level": "note", "message": {"text": "Possibly dead Python function: reset_backends"}, "properties": {"repobilityId": "ef674b4f8c0f71aa", "scanner": "scanner-primary", "fingerprint": "8a959a3981988ad6", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/backends/__init__.py:775"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-181367faff37ca8a", "level": "note", "message": {"text": "Possibly dead Python function: generate_audio_sync"}, "properties": {"repobilityId": "73eb6f960195e847", "scanner": "scanner-primary", "fingerprint": "181367faff37ca8a", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/services/generation.py:245"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-afd3ef6534f99acd", "level": "note", "message": {"text": "Possibly dead Python function: delete_generations_by_profile"}, "properties": {"repobilityId": "86cbf6064d80d241", "scanner": "scanner-primary", "fingerprint": "afd3ef6534f99acd", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/services/history.py:310"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2f0bf93190596070", "level": "note", "message": {"text": "Possibly dead Python function: with_db"}, "properties": {"repobilityId": "ac6041cde633e2b3", "scanner": "scanner-primary", "fingerprint": "2f0bf93190596070", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/mcp_server/resolve.py:55"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c1679ad755d6aef2", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 docs/scripts/generate-openapi.ts:10"}, "properties": {"repobilityId": "ea1d9a9b464db575", "scanner": "scanner-primary", "fingerprint": "c1679ad755d6aef2", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a117d57ea177636a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/setup-dev-sidecar.js:62"}, "properties": {"repobilityId": "acb603d658c386e7", "scanner": "scanner-primary", "fingerprint": "a117d57ea177636a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a5c4e25b39206921", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 app/src/App.tsx:155"}, "properties": {"repobilityId": "9544bc6232f90c79", "scanner": "scanner-primary", "fingerprint": "a5c4e25b39206921", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-51b98179e5258de1", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 app/src/stores/storyStore.ts:72"}, "properties": {"repobilityId": "d5cc6a77757a5f62", "scanner": "scanner-primary", "fingerprint": "51b98179e5258de1", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e2e1879109d4b044", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/Effects/GenerationPicker.tsx:46"}, "properties": {"repobilityId": "64408c0ca2f882b4", "scanner": "scanner-primary", "fingerprint": "e2e1879109d4b044", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-5570ba48a02d0e47", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/CapturePill/CapturePill.tsx:194"}, "properties": {"repobilityId": "5fea52bdb3df09df", "scanner": "scanner-primary", "fingerprint": "5570ba48a02d0e47", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-5ae645cd8e18275f", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/History/HistoryTable.tsx:729"}, "properties": {"repobilityId": "0834fdc764aaf85f", "scanner": "scanner-primary", "fingerprint": "5ae645cd8e18275f", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-486650debea17b4b", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/CapturesTab/CapturesTab.tsx:757"}, "properties": {"repobilityId": "43148cd4afba2b1a", "scanner": "scanner-primary", "fingerprint": "486650debea17b4b", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-563aeeebf4f96b72", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/StoriesTab/StoryContent.tsx:439"}, "properties": {"repobilityId": "75935f2a7e3c78ac", "scanner": "scanner-primary", "fingerprint": "563aeeebf4f96b72", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-dfada1d726e6613f", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/StoriesTab/StoryTrackEditor.tsx:1209"}, "properties": {"repobilityId": "26b92328d3c0bae3", "scanner": "scanner-primary", "fingerprint": "dfada1d726e6613f", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-6fb65d0b4117e4c0", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/StoriesTab/StoryChatItem.tsx:109"}, "properties": {"repobilityId": "86653431e38b583d", "scanner": "scanner-primary", "fingerprint": "6fb65d0b4117e4c0", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-f52808a9be7268b9", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/AudioTab/AudioTab.tsx:190"}, "properties": {"repobilityId": "18e41358875ca15f", "scanner": "scanner-primary", "fingerprint": "f52808a9be7268b9", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-c51a80f81714a876", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/ServerSettings/ModelManagement.tsx:575"}, "properties": {"repobilityId": "289618a551c7274e", "scanner": "scanner-primary", "fingerprint": "c51a80f81714a876", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-82b8eebfc32c6154", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 app/src/components/ServerSettings/ModelProgress.tsx:31"}, "properties": {"repobilityId": "9cb51ddbd4ec7653", "scanner": "scanner-primary", "fingerprint": "82b8eebfc32c6154", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a8195375f6050029", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/ServerTab/MCPPage.tsx:168"}, "properties": {"repobilityId": "12a959597931094c", "scanner": "scanner-primary", "fingerprint": "a8195375f6050029", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-0d7001d638a3810f", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/ServerTab/CapturesPage.tsx:476"}, "properties": {"repobilityId": "e8fcaae41cd238bf", "scanner": "scanner-primary", "fingerprint": "0d7001d638a3810f", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-203d17054876fbc7", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/EffectsTab/EffectsList.tsx:160"}, "properties": {"repobilityId": "be7c88111a520c33", "scanner": "scanner-primary", "fingerprint": "203d17054876fbc7", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-475f689b6b4cda7e", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/src/components/VoicesTab/VoicesTab.tsx:227"}, "properties": {"repobilityId": "7581015a248aa29f", "scanner": "scanner-primary", "fingerprint": "475f689b6b4cda7e", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-5f58314cb093bf6e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 app/src/lib/api/client.ts:567"}, "properties": {"repobilityId": "40567c427f37163d", "scanner": "scanner-primary", "fingerprint": "5f58314cb093bf6e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-300b9702abb62396", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 app/src/lib/utils/debug.ts:6"}, "properties": {"repobilityId": "c1873d4dd4e6910d", "scanner": "scanner-primary", "fingerprint": "300b9702abb62396", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-dde9a742c298aea4", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 app/src/lib/hooks/useModelDownloadToast.tsx:43"}, "properties": {"repobilityId": "c75c2445fec73fe4", "scanner": "scanner-primary", "fingerprint": "dde9a742c298aea4", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-efbbd5cfdd9c88d4", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 app/src/lib/hooks/useStoryPlayback.ts:42"}, "properties": {"repobilityId": "248f2ca7b8e3f3ca", "scanner": "scanner-primary", "fingerprint": "efbbd5cfdd9c88d4", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-96ed4b03127334cb", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 landing/src/components/CaptureSection.tsx:196"}, "properties": {"repobilityId": "787ee08dcdf6bcf2", "scanner": "scanner-primary", "fingerprint": "96ed4b03127334cb", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-a265bb5781d332a9", "level": "note", "message": {"text": "\"active\" state uses light bg in a dark theme \u2014 landing/src/components/CapturesMockup.tsx:64"}, "properties": {"repobilityId": "f12df261aa7edd4e", "scanner": "scanner-primary", "fingerprint": "a265bb5781d332a9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.active-light-bg"]}}, {"ruleId": "scanner-26638f51f2919403", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 landing/src/components/ControlUI.tsx:389"}, "properties": {"repobilityId": "e70e7fcf75c7e2f7", "scanner": "scanner-primary", "fingerprint": "26638f51f2919403", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-34000899e86ce09a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 landing/src/components/ControlUI.tsx:601"}, "properties": {"repobilityId": "51d883df9e67294e", "scanner": "scanner-primary", "fingerprint": "34000899e86ce09a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-786a7b7a646c0ffd", "level": "note", "message": {"text": "\"active\" state uses light bg in a dark theme \u2014 landing/src/components/ControlUI.tsx:759"}, "properties": {"repobilityId": "ff06fc32ba111ecf", "scanner": "scanner-primary", "fingerprint": "786a7b7a646c0ffd", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.active-light-bg"]}}, {"ruleId": "scanner-3896f19672966d09", "level": "note", "message": {"text": "\"active\" state uses light bg in a dark theme \u2014 landing/src/components/Personalities.tsx:84"}, "properties": {"repobilityId": "b14e43ab1490788e", "scanner": "scanner-primary", "fingerprint": "3896f19672966d09", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.active-light-bg"]}}, {"ruleId": "scanner-d52a6d760113e6be", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 landing/src/components/TokenSection.tsx:74"}, "properties": {"repobilityId": "8cd70ef6b16ce8f1", "scanner": "scanner-primary", "fingerprint": "d52a6d760113e6be", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-30bd41517e3ee2e6", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 landing/src/components/SupportedModels.tsx:160"}, "properties": {"repobilityId": "d820440234e87f7f", "scanner": "scanner-primary", "fingerprint": "30bd41517e3ee2e6", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-0cc57baeae5b6401", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 landing/src/components/LandingAudioPlayer.tsx:258"}, "properties": {"repobilityId": "2b27930add16a544", "scanner": "scanner-primary", "fingerprint": "0cc57baeae5b6401", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-ee84ada160ffdd8d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 landing/src/components/LandingAudioPlayer.tsx:135"}, "properties": {"repobilityId": "cfd30aa20218a481", "scanner": "scanner-primary", "fingerprint": "ee84ada160ffdd8d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-97761e105d4b5989", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 landing/src/app/blog/[slug]/page.tsx:85"}, "properties": {"repobilityId": "4b43a18c560a95f5", "scanner": "scanner-primary", "fingerprint": "97761e105d4b5989", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-e973be083d678275", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 landing/src/lib/constants.ts:142"}, "properties": {"repobilityId": "f45aebc8430772c4", "scanner": "scanner-primary", "fingerprint": "e973be083d678275", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-16a52601481598cd", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tauri/src/platform/lifecycle.ts:14"}, "properties": {"repobilityId": "11dafd37c4065f7f", "scanner": "scanner-primary", "fingerprint": "16a52601481598cd", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-476013846b8600a4", "level": "warning", "message": {"text": "exec detected \u2014 backend/pyi_rth_torch_compiler_disable.py:335"}, "properties": {"repobilityId": "7b73c209eb7a4f8f", "scanner": "scanner-primary", "fingerprint": "476013846b8600a4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-9aabd74304a56dea", "level": "warning", "message": {"text": "exec detected \u2014 backend/pyi_rth_torch_compiler_disable.py:461"}, "properties": {"repobilityId": "f99114f174db68c0", "scanner": "scanner-primary", "fingerprint": "9aabd74304a56dea", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-9d99b96de9e13c92", "level": "error", "message": {"text": "CVE-2026-44573: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "47e514f63bc515d5", "scanner": "scanner-primary", "fingerprint": "9d99b96de9e13c92", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44573"]}}, {"ruleId": "scanner-903d6275bc097612", "level": "error", "message": {"text": "CVE-2026-44574: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "be1de9eea6a2fcbb", "scanner": "scanner-primary", "fingerprint": "903d6275bc097612", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44574"]}}, {"ruleId": "scanner-d5b29c11c3c406a5", "level": "error", "message": {"text": "CVE-2026-44575: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "a888ce9d40932918", "scanner": "scanner-primary", "fingerprint": "d5b29c11c3c406a5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44575"]}}, {"ruleId": "scanner-92dbe0b7b2a67144", "level": "error", "message": {"text": "CVE-2026-44578: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "0390d45d6098fc30", "scanner": "scanner-primary", "fingerprint": "92dbe0b7b2a67144", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44578"]}}, {"ruleId": "scanner-4b87f99bf2dd4847", "level": "error", "message": {"text": "CVE-2026-44579: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "0132e62dc2f4d745", "scanner": "scanner-primary", "fingerprint": "4b87f99bf2dd4847", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44579"]}}, {"ruleId": "scanner-30a58c47ed74df81", "level": "error", "message": {"text": "CVE-2026-45109: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "8b04ebac69226e55", "scanner": "scanner-primary", "fingerprint": "30a58c47ed74df81", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45109"]}}, {"ruleId": "scanner-372563b284b7c724", "level": "error", "message": {"text": "CVE-2026-64641: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "abb877e81c59ccfe", "scanner": "scanner-primary", "fingerprint": "372563b284b7c724", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64641"]}}, {"ruleId": "scanner-9fb0ba5ab85a3c63", "level": "error", "message": {"text": "CVE-2026-64642: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "19c6bb00b17cea32", "scanner": "scanner-primary", "fingerprint": "9fb0ba5ab85a3c63", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64642"]}}, {"ruleId": "scanner-65686f8cd76fb656", "level": "error", "message": {"text": "CVE-2026-64645: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "ee5a1cfe9fed695e", "scanner": "scanner-primary", "fingerprint": "65686f8cd76fb656", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64645"]}}, {"ruleId": "scanner-020b28bcdaa5c695", "level": "error", "message": {"text": "CVE-2026-64649: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "89a38baa4779f486", "scanner": "scanner-primary", "fingerprint": "020b28bcdaa5c695", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64649"]}}, {"ruleId": "scanner-de98e22d9c14f9dc", "level": "error", "message": {"text": "GHSA-8h8q-6873-q5fj: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "d9dc6154cd71d407", "scanner": "scanner-primary", "fingerprint": "de98e22d9c14f9dc", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-8h8q-6873-q5fj"]}}, {"ruleId": "scanner-b1ff9ca01e92400a", "level": "error", "message": {"text": "GHSA-h25m-26qc-wcjf: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "2affa3123246b75b", "scanner": "scanner-primary", "fingerprint": "b1ff9ca01e92400a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-h25m-26qc-wcjf"]}}, {"ruleId": "scanner-b29f0e12ea37393d", "level": "error", "message": {"text": "GHSA-q4gf-8mx6-v5v3: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "9e573f56ab2ccafa", "scanner": "scanner-primary", "fingerprint": "b29f0e12ea37393d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-q4gf-8mx6-v5v3"]}}, {"ruleId": "scanner-cd090f806c60bbe3", "level": "warning", "message": {"text": "CVE-2025-59471: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "1243ac8f68c91e87", "scanner": "scanner-primary", "fingerprint": "cd090f806c60bbe3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-59471"]}}, {"ruleId": "scanner-8f7e97a20dd6a8a2", "level": "warning", "message": {"text": "CVE-2025-59472: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "3411bd940df7a93f", "scanner": "scanner-primary", "fingerprint": "8f7e97a20dd6a8a2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-59472"]}}, {"ruleId": "scanner-85b2bda42b124149", "level": "warning", "message": {"text": "CVE-2026-27978: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "6103f3f646a15dd1", "scanner": "scanner-primary", "fingerprint": "85b2bda42b124149", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27978"]}}, {"ruleId": "scanner-6b8f685bbc40fed4", "level": "warning", "message": {"text": "CVE-2026-27979: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "e33f578a61385a26", "scanner": "scanner-primary", "fingerprint": "6b8f685bbc40fed4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27979"]}}, {"ruleId": "scanner-3d94421d17535df7", "level": "warning", "message": {"text": "CVE-2026-27980: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "9c768febea35bef4", "scanner": "scanner-primary", "fingerprint": "3d94421d17535df7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27980"]}}, {"ruleId": "scanner-877ae5426df8bdde", "level": "warning", "message": {"text": "CVE-2026-29057: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "291620b005bebb0f", "scanner": "scanner-primary", "fingerprint": "877ae5426df8bdde", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29057"]}}, {"ruleId": "scanner-6ce9b8c9342c54bc", "level": "warning", "message": {"text": "CVE-2026-44576: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "9707bda89adffbc5", "scanner": "scanner-primary", "fingerprint": "6ce9b8c9342c54bc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44576"]}}, {"ruleId": "scanner-bc0a9dcc8ff3d201", "level": "warning", "message": {"text": "CVE-2026-44577: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "b80421e7e1423fd8", "scanner": "scanner-primary", "fingerprint": "bc0a9dcc8ff3d201", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44577"]}}, {"ruleId": "scanner-1867d5abea9f61db", "level": "warning", "message": {"text": "CVE-2026-44580: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "9a172c7088418aab", "scanner": "scanner-primary", "fingerprint": "1867d5abea9f61db", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44580"]}}, {"ruleId": "scanner-1bb0b9a130740958", "level": "warning", "message": {"text": "CVE-2026-44581: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "50e05f9b2c37b8e0", "scanner": "scanner-primary", "fingerprint": "1bb0b9a130740958", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44581"]}}, {"ruleId": "scanner-3da289591305ca33", "level": "warning", "message": {"text": "CVE-2026-64643: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "4c04e607bd96e016", "scanner": "scanner-primary", "fingerprint": "3da289591305ca33", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64643"]}}, {"ruleId": "scanner-a4cba77015a32b49", "level": "warning", "message": {"text": "CVE-2026-64644: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "906492d2b5a9dcfb", "scanner": "scanner-primary", "fingerprint": "a4cba77015a32b49", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64644"]}}, {"ruleId": "scanner-75463bc9ee6a2e34", "level": "warning", "message": {"text": "CVE-2026-64646: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "2ef3022a308d3ded", "scanner": "scanner-primary", "fingerprint": "75463bc9ee6a2e34", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64646"]}}, {"ruleId": "scanner-10ee0918abcec617", "level": "warning", "message": {"text": "CVE-2026-64647: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "ce92d86982a6b329", "scanner": "scanner-primary", "fingerprint": "10ee0918abcec617", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64647"]}}, {"ruleId": "scanner-78e3aa3a78a677e5", "level": "warning", "message": {"text": "CVE-2026-64648: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "61d69d1d5135b65e", "scanner": "scanner-primary", "fingerprint": "78e3aa3a78a677e5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64648"]}}, {"ruleId": "scanner-254de043012da6e5", "level": "note", "message": {"text": "CVE-2026-27977: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "82fa0b8d6b2ec96f", "scanner": "scanner-primary", "fingerprint": "254de043012da6e5", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27977"]}}, {"ruleId": "scanner-b67d8f4b96d27893", "level": "note", "message": {"text": "CVE-2026-44572: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "91b2415accf80712", "scanner": "scanner-primary", "fingerprint": "b67d8f4b96d27893", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44572"]}}, {"ruleId": "scanner-166a578a055b7098", "level": "note", "message": {"text": "CVE-2026-44582: next 16.1.4 \u2014 bun.lock"}, "properties": {"repobilityId": "0c4614bff8529a3c", "scanner": "scanner-primary", "fingerprint": "166a578a055b7098", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44582"]}}, {"ruleId": "scanner-81bf70461c6d53dc", "level": "warning", "message": {"text": "CVE-2026-41305: postcss 8.5.6 \u2014 bun.lock"}, "properties": {"repobilityId": "426f7364ac3866ee", "scanner": "scanner-primary", "fingerprint": "81bf70461c6d53dc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41305"]}}, {"ruleId": "scanner-d81c376d5ca53406", "level": "warning", "message": {"text": "CVE-2025-69873: ajv 8.17.1 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "960c8606a1106dfc", "scanner": "scanner-primary", "fingerprint": "d81c376d5ca53406", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69873"]}}, {"ruleId": "scanner-03154cb2c15c61bd", "level": "error", "message": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "6b8e24df52a9a82c", "scanner": "scanner-primary", "fingerprint": "03154cb2c15c61bd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13676"]}}, {"ruleId": "scanner-63ab716201c59b73", "level": "error", "message": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "7230d63d8b55642a", "scanner": "scanner-primary", "fingerprint": "63ab716201c59b73", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-16221"]}}, {"ruleId": "scanner-bbf9eccdbeab3c3e", "level": "error", "message": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "6e61b583f142c0c7", "scanner": "scanner-primary", "fingerprint": "bbf9eccdbeab3c3e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6321"]}}, {"ruleId": "scanner-eb2652f9be2f53ea", "level": "error", "message": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "594787846153caa2", "scanner": "scanner-primary", "fingerprint": "eb2652f9be2f53ea", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6322"]}}, {"ruleId": "scanner-83c8de6d82803a43", "level": "error", "message": {"text": "CVE-2026-25896: fast-xml-parser 4.5.3 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "ff1ba40fc1f755a2", "scanner": "scanner-primary", "fingerprint": "83c8de6d82803a43", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25896"]}}, {"ruleId": "scanner-da27e12999ff1145", "level": "error", "message": {"text": "CVE-2026-26278: fast-xml-parser 4.5.3 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "ce1f5c0e1ba3a6db", "scanner": "scanner-primary", "fingerprint": "da27e12999ff1145", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-26278"]}}, {"ruleId": "scanner-c93f51df02714707", "level": "error", "message": {"text": "CVE-2026-33036: fast-xml-parser 4.5.3 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "88be11b2fd0f1237", "scanner": "scanner-primary", "fingerprint": "c93f51df02714707", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33036"]}}, {"ruleId": "scanner-f413ea4e707d61ef", "level": "warning", "message": {"text": "CVE-2026-33349: fast-xml-parser 4.5.3 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "637d2c36356a855d", "scanner": "scanner-primary", "fingerprint": "f413ea4e707d61ef", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33349"]}}, {"ruleId": "scanner-55eb60fb3c721e88", "level": "warning", "message": {"text": "CVE-2026-41650: fast-xml-parser 4.5.3 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "76e0c2f80318a397", "scanner": "scanner-primary", "fingerprint": "55eb60fb3c721e88", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41650"]}}, {"ruleId": "scanner-55adbede539c82ac", "level": "note", "message": {"text": "CVE-2026-27942: fast-xml-parser 4.5.3 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "dfea0861b639e8da", "scanner": "scanner-primary", "fingerprint": "55adbede539c82ac", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27942"]}}, {"ruleId": "scanner-d7a137dad00d2cd1", "level": "error", "message": {"text": "CVE-2026-59869: js-yaml 4.1.1 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "5ff46fbf5d0f99e7", "scanner": "scanner-primary", "fingerprint": "d7a137dad00d2cd1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59869"]}}, {"ruleId": "scanner-d9ed915553a2487a", "level": "warning", "message": {"text": "CVE-2026-53550: js-yaml 4.1.1 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "08c04efc4eecde92", "scanner": "scanner-primary", "fingerprint": "d9ed915553a2487a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53550"]}}, {"ruleId": "scanner-d7d76fdba7b1ae58", "level": "error", "message": {"text": "CVE-2026-44573: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "cff306714b9e2076", "scanner": "scanner-primary", "fingerprint": "d7d76fdba7b1ae58", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44573"]}}, {"ruleId": "scanner-a35e220c9ec50445", "level": "error", "message": {"text": "CVE-2026-44574: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "3b18ee16c385e663", "scanner": "scanner-primary", "fingerprint": "a35e220c9ec50445", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44574"]}}, {"ruleId": "scanner-082ab13dc17e4aaa", "level": "error", "message": {"text": "CVE-2026-44575: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "c9bf4c3c6a1393fc", "scanner": "scanner-primary", "fingerprint": "082ab13dc17e4aaa", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44575"]}}, {"ruleId": "scanner-66cd0097f30ada8d", "level": "error", "message": {"text": "CVE-2026-44578: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "cf04e4404929f48b", "scanner": "scanner-primary", "fingerprint": "66cd0097f30ada8d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44578"]}}, {"ruleId": "scanner-87b71bb3b5cdc721", "level": "error", "message": {"text": "CVE-2026-44579: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "d7c30e108b34495f", "scanner": "scanner-primary", "fingerprint": "87b71bb3b5cdc721", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44579"]}}, {"ruleId": "scanner-fb8130085eff3cf3", "level": "error", "message": {"text": "CVE-2026-45109: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "dcf19e70cd96e8ac", "scanner": "scanner-primary", "fingerprint": "fb8130085eff3cf3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45109"]}}, {"ruleId": "scanner-c6f5d93fe1aacdc4", "level": "error", "message": {"text": "CVE-2026-64641: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "4e31d114b079b0eb", "scanner": "scanner-primary", "fingerprint": "c6f5d93fe1aacdc4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64641"]}}, {"ruleId": "scanner-c17c8a311e05e168", "level": "error", "message": {"text": "CVE-2026-64642: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "afb4d00aa8258906", "scanner": "scanner-primary", "fingerprint": "c17c8a311e05e168", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64642"]}}, {"ruleId": "scanner-1fd524df056c2a0f", "level": "error", "message": {"text": "CVE-2026-64645: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "d4d2016abd6777fc", "scanner": "scanner-primary", "fingerprint": "1fd524df056c2a0f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64645"]}}, {"ruleId": "scanner-f989ed8f1261f106", "level": "error", "message": {"text": "CVE-2026-64649: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "2bc77cbfa4135f6b", "scanner": "scanner-primary", "fingerprint": "f989ed8f1261f106", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64649"]}}, {"ruleId": "scanner-7ad2be1d591ba333", "level": "error", "message": {"text": "GHSA-8h8q-6873-q5fj: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "8b0c564374539006", "scanner": "scanner-primary", "fingerprint": "7ad2be1d591ba333", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-8h8q-6873-q5fj"]}}, {"ruleId": "scanner-e78b32d2ef33a97e", "level": "error", "message": {"text": "GHSA-q4gf-8mx6-v5v3: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "e50f2a3573517b2d", "scanner": "scanner-primary", "fingerprint": "e78b32d2ef33a97e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-q4gf-8mx6-v5v3"]}}, {"ruleId": "scanner-2004fa5544ead5f4", "level": "warning", "message": {"text": "CVE-2026-27978: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "61c704747d456c7f", "scanner": "scanner-primary", "fingerprint": "2004fa5544ead5f4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27978"]}}, {"ruleId": "scanner-28825b276f4f9b22", "level": "warning", "message": {"text": "CVE-2026-27979: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "85700112122c0766", "scanner": "scanner-primary", "fingerprint": "28825b276f4f9b22", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27979"]}}, {"ruleId": "scanner-1f81aec5ff7d0c58", "level": "warning", "message": {"text": "CVE-2026-27980: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "441bef12e73a4d38", "scanner": "scanner-primary", "fingerprint": "1f81aec5ff7d0c58", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27980"]}}, {"ruleId": "scanner-62e3b17ea55f357e", "level": "warning", "message": {"text": "CVE-2026-29057: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "c5f6d8fc71c2339c", "scanner": "scanner-primary", "fingerprint": "62e3b17ea55f357e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29057"]}}, {"ruleId": "scanner-b66b19a684566e34", "level": "warning", "message": {"text": "CVE-2026-44576: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "e1b7b2a354e56d7c", "scanner": "scanner-primary", "fingerprint": "b66b19a684566e34", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44576"]}}, {"ruleId": "scanner-15e542e78d9adfcd", "level": "warning", "message": {"text": "CVE-2026-44577: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "5b15e51b5ab32ddc", "scanner": "scanner-primary", "fingerprint": "15e542e78d9adfcd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44577"]}}, {"ruleId": "scanner-3678eb107805df4e", "level": "warning", "message": {"text": "CVE-2026-44580: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "0b74017dd720cee7", "scanner": "scanner-primary", "fingerprint": "3678eb107805df4e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44580"]}}, {"ruleId": "scanner-d7a104ed827f4cbe", "level": "warning", "message": {"text": "CVE-2026-44581: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "528ef834ad7d1c7b", "scanner": "scanner-primary", "fingerprint": "d7a104ed827f4cbe", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44581"]}}, {"ruleId": "scanner-75a3e95ce2417ab9", "level": "warning", "message": {"text": "CVE-2026-64643: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "b0f448830de3bd2f", "scanner": "scanner-primary", "fingerprint": "75a3e95ce2417ab9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64643"]}}, {"ruleId": "scanner-c5ad68df4c8178a0", "level": "warning", "message": {"text": "CVE-2026-64644: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "40bfa01887d50dc6", "scanner": "scanner-primary", "fingerprint": "c5ad68df4c8178a0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64644"]}}, {"ruleId": "scanner-164f175176c41ac0", "level": "warning", "message": {"text": "CVE-2026-64646: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "b0849b19b0f72968", "scanner": "scanner-primary", "fingerprint": "164f175176c41ac0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64646"]}}, {"ruleId": "scanner-add3cd6b9238017c", "level": "warning", "message": {"text": "CVE-2026-64647: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "d2382d45ef67719a", "scanner": "scanner-primary", "fingerprint": "add3cd6b9238017c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64647"]}}, {"ruleId": "scanner-d6bacd205a993ccc", "level": "warning", "message": {"text": "CVE-2026-64648: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "7273d5d3b4a2703e", "scanner": "scanner-primary", "fingerprint": "d6bacd205a993ccc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64648"]}}, {"ruleId": "scanner-8ee073ae0873b632", "level": "note", "message": {"text": "CVE-2026-27977: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "8815368f2e83366c", "scanner": "scanner-primary", "fingerprint": "8ee073ae0873b632", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27977"]}}, {"ruleId": "scanner-a00cb6457eb5b4bb", "level": "note", "message": {"text": "CVE-2026-44572: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "60cbab4f701c6d77", "scanner": "scanner-primary", "fingerprint": "a00cb6457eb5b4bb", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44572"]}}, {"ruleId": "scanner-66457d9490129b53", "level": "note", "message": {"text": "CVE-2026-44582: next 16.1.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "0bddeebc3a89ca1f", "scanner": "scanner-primary", "fingerprint": "66457d9490129b53", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44582"]}}, {"ruleId": "scanner-db527dd683e48b97", "level": "error", "message": {"text": "CVE-2026-4926: path-to-regexp 8.3.0 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "153c18417ba03b77", "scanner": "scanner-primary", "fingerprint": "db527dd683e48b97", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4926"]}}, {"ruleId": "scanner-956212369e0753bf", "level": "warning", "message": {"text": "CVE-2026-4923: path-to-regexp 8.3.0 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "5a95974a289844c3", "scanner": "scanner-primary", "fingerprint": "956212369e0753bf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4923"]}}, {"ruleId": "scanner-723b768ad3916852", "level": "error", "message": {"text": "CVE-2026-33671: picomatch 4.0.3 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "8987857f64b17966", "scanner": "scanner-primary", "fingerprint": "723b768ad3916852", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33671"]}}, {"ruleId": "scanner-31580320c5cc187e", "level": "warning", "message": {"text": "CVE-2026-33672: picomatch 4.0.3 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "123aa1e9ce458e54", "scanner": "scanner-primary", "fingerprint": "31580320c5cc187e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33672"]}}, {"ruleId": "scanner-9be1b8d645950ec0", "level": "warning", "message": {"text": "CVE-2026-41305: postcss 8.5.6 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "8719390ebc61ad97", "scanner": "scanner-primary", "fingerprint": "9be1b8d645950ec0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41305"]}}, {"ruleId": "scanner-362157786fedd921", "level": "warning", "message": {"text": "CVE-2026-33532: yaml 2.8.2 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "c1d70d83089d7eea", "scanner": "scanner-primary", "fingerprint": "362157786fedd921", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33532"]}}, {"ruleId": "scanner-eaa4814067c69709", "level": "warning", "message": {"text": "CVE-2026-25541: bytes 1.11.0 \u2014 tauri/src-tauri/Cargo.lock"}, "properties": {"repobilityId": "a55839e5ea99419f", "scanner": "scanner-primary", "fingerprint": "eaa4814067c69709", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25541"]}}, {"ruleId": "scanner-00fbe39e74c730e4", "level": "warning", "message": {"text": "GHSA-wrw7-89jp-8q8g: glib 0.18.5 \u2014 tauri/src-tauri/Cargo.lock"}, "properties": {"repobilityId": "7689d6643ce4756d", "scanner": "scanner-primary", "fingerprint": "00fbe39e74c730e4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-wrw7-89jp-8q8g"]}}, {"ruleId": "scanner-0248d32f8446f478", "level": "error", "message": {"text": "CVE-2026-41676: openssl 0.10.75 \u2014 tauri/src-tauri/Cargo.lock"}, "properties": {"repobilityId": "f46dd2ed7f11faa7", "scanner": "scanner-primary", "fingerprint": "0248d32f8446f478", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41676"]}}, {"ruleId": "scanner-54d03506de399ab2", "level": "error", "message": {"text": "CVE-2026-41678: openssl 0.10.75 \u2014 tauri/src-tauri/Cargo.lock"}, "properties": {"repobilityId": "a409952a92bc0bc6", "scanner": "scanner-primary", "fingerprint": "54d03506de399ab2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41678"]}}, {"ruleId": "scanner-55be30ff9b3840ea", "level": "error", "message": {"text": "CVE-2026-41681: openssl 0.10.75 \u2014 tauri/src-tauri/Cargo.lock"}, "properties": {"repobilityId": "83d4b00c62dcf158", "scanner": "scanner-primary", "fingerprint": "55be30ff9b3840ea", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41681"]}}, {"ruleId": "scanner-8096ed4b4b177540", "level": "error", "message": {"text": "CVE-2026-41898: openssl 0.10.75 \u2014 tauri/src-tauri/Cargo.lock"}, "properties": {"repobilityId": "06439ccc2d3c796d", "scanner": "scanner-primary", "fingerprint": "8096ed4b4b177540", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41898"]}}, {"ruleId": "scanner-b3468ce3e64eb535", "level": "error", "message": {"text": "CVE-2026-42327: openssl 0.10.75 \u2014 tauri/src-tauri/Cargo.lock"}, "properties": {"repobilityId": "0c63ec0188642b0c", "scanner": "scanner-primary", "fingerprint": "b3468ce3e64eb535", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42327"]}}, {"ruleId": "scanner-efbef695bec7533e", "level": "warning", "message": {"text": "CVE-2026-44662: openssl 0.10.75 \u2014 tauri/src-tauri/Cargo.lock"}, "properties": {"repobilityId": "05fa47bb256e51a2", "scanner": "scanner-primary", "fingerprint": "efbef695bec7533e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44662"]}}, {"ruleId": "scanner-8260af519bd7792b", "level": "warning", "message": {"text": "CVE-2026-45784: openssl 0.10.75 \u2014 tauri/src-tauri/Cargo.lock"}, "properties": {"repobilityId": "c53b6d42934a0fd8", "scanner": "scanner-primary", "fingerprint": "8260af519bd7792b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45784"]}}, {"ruleId": "scanner-8e769a07375eca21", "level": "note", "message": {"text": "CVE-2026-41677: openssl 0.10.75 \u2014 tauri/src-tauri/Cargo.lock"}, "properties": {"repobilityId": "701de0adff89b598", "scanner": "scanner-primary", "fingerprint": "8e769a07375eca21", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41677"]}}, {"ruleId": "scanner-6afab34c2fdab321", "level": "error", "message": {"text": "CVE-2026-31812: quinn-proto 0.11.13 \u2014 tauri/src-tauri/Cargo.lock"}, "properties": {"repobilityId": "aaaf61a14d827778", "scanner": "scanner-primary", "fingerprint": "6afab34c2fdab321", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31812"]}}, {"ruleId": "scanner-4883291790d52ea3", "level": "note", "message": {"text": "GHSA-cq8v-f236-94qc: rand 0.7.3 \u2014 tauri/src-tauri/Cargo.lock"}, "properties": {"repobilityId": "e728a078bc7642cd", "scanner": "scanner-primary", "fingerprint": "4883291790d52ea3", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-cq8v-f236-94qc"]}}, {"ruleId": "scanner-07a4765356e134f7", "level": "note", "message": {"text": "GHSA-cq8v-f236-94qc: rand 0.8.5 \u2014 tauri/src-tauri/Cargo.lock"}, "properties": {"repobilityId": "e728a078bc7642cd", "scanner": "scanner-primary", "fingerprint": "07a4765356e134f7", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-cq8v-f236-94qc"]}}, {"ruleId": "scanner-0079332a161d9171", "level": "note", "message": {"text": "GHSA-cq8v-f236-94qc: rand 0.9.2 \u2014 tauri/src-tauri/Cargo.lock"}, "properties": {"repobilityId": "e728a078bc7642cd", "scanner": "scanner-primary", "fingerprint": "0079332a161d9171", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-cq8v-f236-94qc"]}}, {"ruleId": "scanner-1237f25c5d5cd203", "level": "error", "message": {"text": "GHSA-82j2-j2ch-gfr8: rustls-webpki 0.103.9 \u2014 tauri/src-tauri/Cargo.lock"}, "properties": {"repobilityId": "6de174007fcc5971", "scanner": "scanner-primary", "fingerprint": "1237f25c5d5cd203", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-82j2-j2ch-gfr8"]}}, {"ruleId": "scanner-b389ad36a927d4d4", "level": "warning", "message": {"text": "GHSA-pwjx-qhcg-rvj4: rustls-webpki 0.103.9 \u2014 tauri/src-tauri/Cargo.lock"}, "properties": {"repobilityId": "9e5cec4a2d4a1834", "scanner": "scanner-primary", "fingerprint": "b389ad36a927d4d4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-pwjx-qhcg-rvj4"]}}, {"ruleId": "scanner-2741ad652f9d2f9b", "level": "note", "message": {"text": "GHSA-965h-392x-2mh5: rustls-webpki 0.103.9 \u2014 tauri/src-tauri/Cargo.lock"}, "properties": {"repobilityId": "eb9f3a4483f8982c", "scanner": "scanner-primary", "fingerprint": "2741ad652f9d2f9b", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-965h-392x-2mh5"]}}, {"ruleId": "scanner-1458d24bc28906c5", "level": "note", "message": {"text": "GHSA-xgp8-3hg3-c2mh: rustls-webpki 0.103.9 \u2014 tauri/src-tauri/Cargo.lock"}, "properties": {"repobilityId": "9cc76c70f3f7f75e", "scanner": "scanner-primary", "fingerprint": "1458d24bc28906c5", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-xgp8-3hg3-c2mh"]}}, {"ruleId": "scanner-535010bab8b79458", "level": "warning", "message": {"text": "GHSA-7gcf-g7xr-8hxj: serde_with 3.16.1 \u2014 tauri/src-tauri/Cargo.lock"}, "properties": {"repobilityId": "fd32c6960cd7f82d", "scanner": "scanner-primary", "fingerprint": "535010bab8b79458", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-7gcf-g7xr-8hxj"]}}, {"ruleId": "scanner-dab96fdc836548fa", "level": "warning", "message": {"text": "CVE-2026-33055: tar 0.4.44 \u2014 tauri/src-tauri/Cargo.lock"}, "properties": {"repobilityId": "d03baf4c4da31423", "scanner": "scanner-primary", "fingerprint": "dab96fdc836548fa", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33055"]}}, {"ruleId": "scanner-ef72d38bd94d27ab", "level": "warning", "message": {"text": "CVE-2026-33056: tar 0.4.44 \u2014 tauri/src-tauri/Cargo.lock"}, "properties": {"repobilityId": "af929da298a1e181", "scanner": "scanner-primary", "fingerprint": "ef72d38bd94d27ab", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33056"]}}, {"ruleId": "scanner-b2de7aab73811f4b", "level": "warning", "message": {"text": "GHSA-3pv8-6f4r-ffg2: tar 0.4.44 \u2014 tauri/src-tauri/Cargo.lock"}, "properties": {"repobilityId": "dd0cb96a0ea27c8e", "scanner": "scanner-primary", "fingerprint": "b2de7aab73811f4b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-3pv8-6f4r-ffg2"]}}, {"ruleId": "scanner-9225e2cf4f5c7436", "level": "warning", "message": {"text": "CVE-2026-42184: tauri 2.9.5 \u2014 tauri/src-tauri/Cargo.lock"}, "properties": {"repobilityId": "509fe2b2ae63be46", "scanner": "scanner-primary", "fingerprint": "9225e2cf4f5c7436", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42184"]}}, {"ruleId": "scanner-37dcb81539586f3f", "level": "warning", "message": {"text": "CVE-2026-25727: time 0.3.46 \u2014 tauri/src-tauri/Cargo.lock"}, "properties": {"repobilityId": "30ee459ad0812192", "scanner": "scanner-primary", "fingerprint": "37dcb81539586f3f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25727"]}}, {"ruleId": "scanner-3a3527e70129fb18", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 Dockerfile"}, "properties": {"repobilityId": "691787f6b20605df", "scanner": "scanner-primary", "fingerprint": "3a3527e70129fb18", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-72ff79e0f8219b60", "level": "warning", "message": {"text": "DS-0013: 'RUN cd ...' to change directory \u2014 Dockerfile"}, "properties": {"repobilityId": "975852f52ce6eb22", "scanner": "scanner-primary", "fingerprint": "72ff79e0f8219b60", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-d63da3583b14afc0", "level": "warning", "message": {"text": "Dockerfile runs as root: Dockerfile"}, "properties": {"repobilityId": "a2ed1bd120e507db", "scanner": "scanner-primary", "fingerprint": "d63da3583b14afc0", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-9fff85edbbb8c52b", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: oven/bun:1"}, "properties": {"repobilityId": "7efe032c714ddb63", "scanner": "scanner-primary", "fingerprint": "9fff85edbbb8c52b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 14}}}]}, {"ruleId": "scanner-e066691601852931", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.11-slim"}, "properties": {"repobilityId": "411adf68f468672b", "scanner": "scanner-primary", "fingerprint": "e066691601852931", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 32}}}]}, {"ruleId": "scanner-8e8313aee9ea8527", "level": "error", "message": {"text": "Insecure pattern 'node_child_process' in scripts/setup-dev-sidecar.js:13"}, "properties": {"repobilityId": "7bbb57b487c609c3", "scanner": "scanner-primary", "fingerprint": "8e8313aee9ea8527", "layer": "security", "severity": "high", "confidence": 0.9, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/setup-dev-sidecar.js"}, "region": {"startLine": 13}}}]}, {"ruleId": "scanner-9ab26d43bebb357d", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in app/src/components/Generation/ParalinguisticInput.tsx:159"}, "properties": {"repobilityId": "1385c554f8929911", "scanner": "scanner-primary", "fingerprint": "9ab26d43bebb357d", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/src/components/Generation/ParalinguisticInput.tsx"}, "region": {"startLine": 159}}}]}, {"ruleId": "scanner-67d7c60b3a8fcae8", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in landing/src/app/blog/[slug]/page.tsx:85"}, "properties": {"repobilityId": "55a59d426344953e", "scanner": "scanner-primary", "fingerprint": "67d7c60b3a8fcae8", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/src/app/blog/[slug]/page.tsx"}, "region": {"startLine": 85}}}]}, {"ruleId": "scanner-fb08cd342b72fec8", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in backend/pyi_rth_torch_compiler_disable.py:335"}, "properties": {"repobilityId": "c58bae79fdeab578", "scanner": "scanner-primary", "fingerprint": "fb08cd342b72fec8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/pyi_rth_torch_compiler_disable.py"}, "region": {"startLine": 335}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-27924aa79fa4a517", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "dcb6504096fc20e7", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-46c644c6227e4d4a", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "0ad86557a2848db6", "scanner": "scanner-primary", "fingerprint": "46c644c6227e4d4a", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yml"}, "region": {"startLine": 71}}}]}, {"ruleId": "scanner-1838a141491ce38c", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "b8fd4f5048f96576", "scanner": "scanner-primary", "fingerprint": "1838a141491ce38c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-360cb263256aacfa", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "631a17107eb4bd00", "scanner": "scanner-primary", "fingerprint": "360cb263256aacfa", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/build-windows.yml"}, "region": {"startLine": 16}}}]}, {"ruleId": "scanner-6e61fb60af308a45", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "25ed9c052ad5a584", "scanner": "scanner-primary", "fingerprint": "6e61fb60af308a45", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/build-windows.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-529d9f2b5dd1170d", "level": "note", "message": {"text": "package.json defines install-time lifecycle scripts"}, "properties": {"repobilityId": "2439334d3cfe9a0e", "scanner": "scanner-primary", "fingerprint": "529d9f2b5dd1170d", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "npm", "install-scripts"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a760f6b31da81a8c", "level": "note", "message": {"text": "Very large file: app/src/components/StoriesTab/StoryTrackEditor.tsx (1531 lines)"}, "properties": {"repobilityId": "8a4aadaaef6d2a67", "scanner": "scanner-primary", "fingerprint": "a760f6b31da81a8c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-4cc6da301727b928", "level": "note", "message": {"text": "Very large file: app/src/components/VoiceProfiles/ProfileForm.tsx (1317 lines)"}, "properties": {"repobilityId": "ca41a87b4d606efa", "scanner": "scanner-primary", "fingerprint": "4cc6da301727b928", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ab76ba206f803807", "level": "note", "message": {"text": "Very large file: tauri/src-tauri/src/main.rs (1659 lines)"}, "properties": {"repobilityId": "3851c405d983631d", "scanner": "scanner-primary", "fingerprint": "ab76ba206f803807", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-fbb5fa8bc006353f", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: app/package.json"}, "properties": {"repobilityId": "e096f2af09cd2b28", "scanner": "scanner-primary", "fingerprint": "fbb5fa8bc006353f", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b8d99132ab8d1975", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: web/package.json"}, "properties": {"repobilityId": "dd661d63588916a7", "scanner": "scanner-primary", "fingerprint": "b8d99132ab8d1975", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b93c6a558b425596", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: landing/package.json"}, "properties": {"repobilityId": "675d394143475933", "scanner": "scanner-primary", "fingerprint": "b93c6a558b425596", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-589d00c93cc7357e", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: tauri/package.json"}, "properties": {"repobilityId": "8736c45c5cf9fbd5", "scanner": "scanner-primary", "fingerprint": "589d00c93cc7357e", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tauri/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "74776e5b89c8e3e2", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "dcd6610b9adbacb8", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "0c85775c88f42fac", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea6060b55f9ebd0c", "level": "note", "message": {"text": "Legacy-named symbol `t3_mtl23ls_v2` in scripts/test_download_progress.py:41"}, "properties": {"repobilityId": "38283ef41de34ee6", "scanner": "scanner-primary", "fingerprint": "ea6060b55f9ebd0c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-6ae73aeb92d23df6", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/package_cuda.py:22"}, "properties": {"repobilityId": "a7f389b7242fbf3b", "scanner": "scanner-primary", "fingerprint": "6ae73aeb92d23df6", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-715bc2d9f1a5de20", "level": "none", "message": {"text": "Commented-code block (6 lines) in app/src/components/CapturesTab/CapturesTab.tsx:198"}, "properties": {"repobilityId": "6e288e766ef47771", "scanner": "scanner-primary", "fingerprint": "715bc2d9f1a5de20", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-dffaea76e8ce16ec", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 app/src/components/CapturesTab/CapturesTab.tsx:344"}, "properties": {"repobilityId": "e7f475cd50819c05", "scanner": "scanner-primary", "fingerprint": "dffaea76e8ce16ec", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-bdbb3df93ef42189", "level": "none", "message": {"text": "Commented-code block (6 lines) in app/src/components/StoriesTab/StoryTrackEditor.tsx:85"}, "properties": {"repobilityId": "2a5317dd8dff3649", "scanner": "scanner-primary", "fingerprint": "bdbb3df93ef42189", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-9d3ea9349790c2e1", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 app/src/components/AudioPlayer/AudioPlayer.tsx:444"}, "properties": {"repobilityId": "6ef2a915ef05ead7", "scanner": "scanner-primary", "fingerprint": "9d3ea9349790c2e1", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-e4d14d51e7f76e5a", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 app/src/components/ServerSettings/ModelManagement.tsx:50"}, "properties": {"repobilityId": "778fe71318918897", "scanner": "scanner-primary", "fingerprint": "e4d14d51e7f76e5a", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-b1357b98b6e3a533", "level": "none", "message": {"text": "Commented-code block (5 lines) in app/src/components/DictateWindow/DictateWindow.tsx:184"}, "properties": {"repobilityId": "1a306b7595c485dd", "scanner": "scanner-primary", "fingerprint": "b1357b98b6e3a533", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ff07ab509cf73e8e", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 app/src/lib/api/core/request.ts:230"}, "properties": {"repobilityId": "a1e9955a0697db63", "scanner": "scanner-primary", "fingerprint": "ff07ab509cf73e8e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-0c70530e8ebbd43f", "level": "none", "message": {"text": "Commented-code block (5 lines) in app/src/lib/hooks/useCaptureRecordingSession.ts:46"}, "properties": {"repobilityId": "6b3122d21829a969", "scanner": "scanner-primary", "fingerprint": "0c70530e8ebbd43f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-528cd605cbeaa453", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 app/src/lib/hooks/useStoryPlayback.ts:128"}, "properties": {"repobilityId": "4fd6e0c6e338e487", "scanner": "scanner-primary", "fingerprint": "528cd605cbeaa453", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-b3981244412e24fe", "level": "none", "message": {"text": "Commented-code block (6 lines) in app/src/lib/hooks/useGenerationProgress.ts:110"}, "properties": {"repobilityId": "da26719429a1ea6b", "scanner": "scanner-primary", "fingerprint": "b3981244412e24fe", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7f739fcc633d0023", "level": "none", "message": {"text": "Commented-code block (5 lines) in landing/src/app/download/[platform]/route.ts:5"}, "properties": {"repobilityId": "c3791815c05bf73e", "scanner": "scanner-primary", "fingerprint": "7f739fcc633d0023", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6d313d613f4bc48c", "level": "none", "message": {"text": "Commented-code block (5 lines) in landing/src/lib/constants.ts:19"}, "properties": {"repobilityId": "aa4b65a40ddca7ba", "scanner": "scanner-primary", "fingerprint": "6d313d613f4bc48c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d3f0188c7f87e326", "level": "none", "message": {"text": "Commented-code block (7 lines) in landing/src/lib/token-stats.ts:3"}, "properties": {"repobilityId": "8ccdb3b6ada7d53b", "scanner": "scanner-primary", "fingerprint": "d3f0188c7f87e326", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-775e0e66ac5cc36e", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 landing/src/lib/token-stats.ts:263"}, "properties": {"repobilityId": "f8a0e5d3183663bb", "scanner": "scanner-primary", "fingerprint": "775e0e66ac5cc36e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-2c886461907ea9a0", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/pyi_rth_torch_compiler_disable.py:435"}, "properties": {"repobilityId": "e58fb033d928a7a2", "scanner": "scanner-primary", "fingerprint": "2c886461907ea9a0", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a235c419771368fe", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend/app.py:152"}, "properties": {"repobilityId": "98416d9fa5db7ed6", "scanner": "scanner-primary", "fingerprint": "a235c419771368fe", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-fc1925a07700ca4a", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/models.py:392"}, "properties": {"repobilityId": "9e828a08b8477e20", "scanner": "scanner-primary", "fingerprint": "fc1925a07700ca4a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1cadcb3fae457a56", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/server.py:184"}, "properties": {"repobilityId": "8bdb2d9eca174312", "scanner": "scanner-primary", "fingerprint": "1cadcb3fae457a56", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a6b7f6856673f215", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend/build_binary.py:46"}, "properties": {"repobilityId": "1b598a8a217ee6cc", "scanner": "scanner-primary", "fingerprint": "a6b7f6856673f215", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-85cf3966d8887d65", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 backend/build_binary.py:499"}, "properties": {"repobilityId": "0e03679143757cef", "scanner": "scanner-primary", "fingerprint": "85cf3966d8887d65", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-b990d84c05289a0d", "level": "none", "message": {"text": "Commented-code block (8 lines) in backend/utils/hf_offline_patch.py:17"}, "properties": {"repobilityId": "88c051b69a80001a", "scanner": "scanner-primary", "fingerprint": "b990d84c05289a0d", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a062fd427653365a", "level": "none", "message": {"text": "Commented-code block (8 lines) in backend/database/migrations.py:272"}, "properties": {"repobilityId": "05fd95217350f11d", "scanner": "scanner-primary", "fingerprint": "a062fd427653365a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ba7da2604396d0dc", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend/routes/profiles.py:366"}, "properties": {"repobilityId": "0c9ba3c2fee82112", "scanner": "scanner-primary", "fingerprint": "ba7da2604396d0dc", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-43ff5efa3a973ce7", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/backends/hume_backend.py:136"}, "properties": {"repobilityId": "be3b526d9122c2d6", "scanner": "scanner-primary", "fingerprint": "43ff5efa3a973ce7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-72f6e02f9879f925", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/backends/__init__.py:8"}, "properties": {"repobilityId": "a81e0d9f01a1b912", "scanner": "scanner-primary", "fingerprint": "72f6e02f9879f925", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-40338b8767a382f7", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/backends/qwen_llm_backend.py:105"}, "properties": {"repobilityId": "d23e6c8f3e314cf8", "scanner": "scanner-primary", "fingerprint": "40338b8767a382f7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-bf754c8223d72a60", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/backends/mlx_backend.py:219"}, "properties": {"repobilityId": "9675c64325850590", "scanner": "scanner-primary", "fingerprint": "bf754c8223d72a60", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-001857db7c8fc793", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/backends/pytorch_backend.py:341"}, "properties": {"repobilityId": "a12135a2b63f9a26", "scanner": "scanner-primary", "fingerprint": "001857db7c8fc793", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d4f502cd77565c80", "level": "note", "message": {"text": "Legacy-named symbol `t3_turbo_v1` in backend/backends/chatterbox_turbo_backend.py:34"}, "properties": {"repobilityId": "ab592998baf14b9f", "scanner": "scanner-primary", "fingerprint": "d4f502cd77565c80", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-3a74c524759d841f", "level": "note", "message": {"text": "Legacy-named symbol `t3_mtl23ls_v2` in backend/backends/chatterbox_backend.py:34"}, "properties": {"repobilityId": "afb8403022a3bc08", "scanner": "scanner-primary", "fingerprint": "3a74c524759d841f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-db17d70cf8b3a347", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend/services/rocm.py:293"}, "properties": {"repobilityId": "d15c23066418b862", "scanner": "scanner-primary", "fingerprint": "db17d70cf8b3a347", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-098add0da946363e", "level": "none", "message": {"text": "Commented-code block (8 lines) in backend/services/refinement.py:17"}, "properties": {"repobilityId": "4e26c51e41a04a7f", "scanner": "scanner-primary", "fingerprint": "098add0da946363e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-58eaa2d5ae0dfe1f", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend/mcp_server/context.py:57"}, "properties": {"repobilityId": "d39a5ab1672148c5", "scanner": "scanner-primary", "fingerprint": "58eaa2d5ae0dfe1f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "02b036a08e3533d9", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "4e3023d59872e58a", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-0027e313ade46c8f", "level": "note", "message": {"text": "Near-duplicate function bodies in 7 places"}, "properties": {"repobilityId": "22be26b9cf5ae4cc", "scanner": "scanner-primary", "fingerprint": "0027e313ade46c8f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-9dad557909b86499", "level": "note", "message": {"text": "Near-duplicate function bodies in 10 places"}, "properties": {"repobilityId": "54f4c187fe016a98", "scanner": "scanner-primary", "fingerprint": "9dad557909b86499", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "a7fb8711de9b3f14", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-8860d40de2a0db15", "level": "error", "message": {"text": "FastAPI POST `generate_speech` without auth dependency \u2014 backend/routes/generations.py:56"}, "properties": {"repobilityId": "72dbacde379cf3d9", "scanner": "scanner-primary", "fingerprint": "8860d40de2a0db15", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/generations.py"}, "region": {"startLine": 56}}}]}, {"ruleId": "scanner-2c45def40361df74", "level": "error", "message": {"text": "FastAPI POST `retry_generation` without auth dependency \u2014 backend/routes/generations.py:148"}, "properties": {"repobilityId": "e77bf0bab332204a", "scanner": "scanner-primary", "fingerprint": "2c45def40361df74", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/generations.py"}, "region": {"startLine": 148}}}]}, {"ruleId": "scanner-1bae075cd6d333ad", "level": "error", "message": {"text": "FastAPI POST `regenerate_generation` without auth dependency \u2014 backend/routes/generations.py:190"}, "properties": {"repobilityId": "ef920b606359fae4", "scanner": "scanner-primary", "fingerprint": "1bae075cd6d333ad", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/generations.py"}, "region": {"startLine": 190}}}]}, {"ruleId": "scanner-66fcbaef20e82d86", "level": "error", "message": {"text": "FastAPI POST `cancel_generation` without auth dependency \u2014 backend/routes/generations.py:235"}, "properties": {"repobilityId": "8e08bab7fa6c9501", "scanner": "scanner-primary", "fingerprint": "66fcbaef20e82d86", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/generations.py"}, "region": {"startLine": 235}}}]}, {"ruleId": "scanner-aa8aac1e82ba846a", "level": "error", "message": {"text": "FastAPI POST `stream_speech` without auth dependency \u2014 backend/routes/generations.py:318"}, "properties": {"repobilityId": "8736c8d9c6f07fe8", "scanner": "scanner-primary", "fingerprint": "aa8aac1e82ba846a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/generations.py"}, "region": {"startLine": 318}}}]}, {"ruleId": "scanner-dd4f31376ac9a094", "level": "error", "message": {"text": "FastAPI POST `import_audio` without auth dependency \u2014 backend/routes/generations.py:405"}, "properties": {"repobilityId": "b44224538eef8498", "scanner": "scanner-primary", "fingerprint": "dd4f31376ac9a094", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/generations.py"}, "region": {"startLine": 405}}}]}, {"ruleId": "scanner-0fa7d72a9712af55", "level": "error", "message": {"text": "FastAPI POST `import_generation` without auth dependency \u2014 backend/routes/history.py:41"}, "properties": {"repobilityId": "6b0814ef9e89e53f", "scanner": "scanner-primary", "fingerprint": "0fa7d72a9712af55", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/history.py"}, "region": {"startLine": 41}}}]}, {"ruleId": "scanner-b5272aadea6c2cd9", "level": "error", "message": {"text": "FastAPI DELETE `clear_failed_generations` without auth dependency \u2014 backend/routes/history.py:65"}, "properties": {"repobilityId": "2093fef0093a82f3", "scanner": "scanner-primary", "fingerprint": "b5272aadea6c2cd9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/history.py"}, "region": {"startLine": 65}}}]}, {"ruleId": "scanner-009f85c6af39cf79", "level": "error", "message": {"text": "FastAPI POST `toggle_favorite` without auth dependency \u2014 backend/routes/history.py:108"}, "properties": {"repobilityId": "253ec6379c49a935", "scanner": "scanner-primary", "fingerprint": "009f85c6af39cf79", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/history.py"}, "region": {"startLine": 108}}}]}, {"ruleId": "scanner-01b61842fe660ce3", "level": "error", "message": {"text": "FastAPI DELETE `delete_generation` without auth dependency \u2014 backend/routes/history.py:122"}, "properties": {"repobilityId": "716dea8aac8221fe", "scanner": "scanner-primary", "fingerprint": "01b61842fe660ce3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/history.py"}, "region": {"startLine": 122}}}]}, {"ruleId": "scanner-edfccf74319a800c", "level": "error", "message": {"text": "FastAPI PUT `upsert_mcp_binding` without auth dependency \u2014 backend/routes/mcp_bindings.py:37"}, "properties": {"repobilityId": "8f7ca127625a1ecf", "scanner": "scanner-primary", "fingerprint": "edfccf74319a800c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/mcp_bindings.py"}, "region": {"startLine": 37}}}]}, {"ruleId": "scanner-c1bfecdba27d7b58", "level": "error", "message": {"text": "FastAPI DELETE `delete_mcp_binding` without auth dependency \u2014 backend/routes/mcp_bindings.py:65"}, "properties": {"repobilityId": "ffbd0acca3e37eb3", "scanner": "scanner-primary", "fingerprint": "c1bfecdba27d7b58", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/mcp_bindings.py"}, "region": {"startLine": 65}}}]}, {"ruleId": "scanner-978cbed9a589d037", "level": "error", "message": {"text": "FastAPI POST `shutdown` without auth dependency \u2014 backend/routes/health.py:35"}, "properties": {"repobilityId": "0f43eaf4b2db7cfc", "scanner": "scanner-primary", "fingerprint": "978cbed9a589d037", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/health.py"}, "region": {"startLine": 35}}}]}, {"ruleId": "scanner-07d748c9158de095", "level": "error", "message": {"text": "FastAPI POST `watchdog_disable` without auth dependency \u2014 backend/routes/health.py:47"}, "properties": {"repobilityId": "7039ea93fdcab2cd", "scanner": "scanner-primary", "fingerprint": "07d748c9158de095", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/health.py"}, "region": {"startLine": 47}}}]}, {"ruleId": "scanner-a12227ce9cf1cf3d", "level": "error", "message": {"text": "FastAPI POST `create_story` without auth dependency \u2014 backend/routes/stories.py:23"}, "properties": {"repobilityId": "82119a06b2a09fae", "scanner": "scanner-primary", "fingerprint": "a12227ce9cf1cf3d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/stories.py"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-a3b6ee09767a0da9", "level": "error", "message": {"text": "FastAPI PUT `update_story` without auth dependency \u2014 backend/routes/stories.py:47"}, "properties": {"repobilityId": "f61455180bfc0463", "scanner": "scanner-primary", "fingerprint": "a3b6ee09767a0da9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/stories.py"}, "region": {"startLine": 47}}}]}, {"ruleId": "scanner-4d60c9d5608c7373", "level": "error", "message": {"text": "FastAPI DELETE `delete_story` without auth dependency \u2014 backend/routes/stories.py:60"}, "properties": {"repobilityId": "12c4eb4a01aa9d55", "scanner": "scanner-primary", "fingerprint": "4d60c9d5608c7373", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/stories.py"}, "region": {"startLine": 60}}}]}, {"ruleId": "scanner-53371b96ac4b2184", "level": "error", "message": {"text": "FastAPI POST `add_story_item` without auth dependency \u2014 backend/routes/stories.py:72"}, "properties": {"repobilityId": "34bce4913c5dff14", "scanner": "scanner-primary", "fingerprint": "53371b96ac4b2184", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/stories.py"}, "region": {"startLine": 72}}}]}, {"ruleId": "scanner-7addece6f86a9949", "level": "error", "message": {"text": "FastAPI DELETE `remove_story_item` without auth dependency \u2014 backend/routes/stories.py:85"}, "properties": {"repobilityId": "0b5330685933198f", "scanner": "scanner-primary", "fingerprint": "7addece6f86a9949", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/stories.py"}, "region": {"startLine": 85}}}]}, {"ruleId": "scanner-0fdb0e39fa29bdb9", "level": "error", "message": {"text": "FastAPI PUT `update_story_item_times` without auth dependency \u2014 backend/routes/stories.py:98"}, "properties": {"repobilityId": "c9ceed21c2a4a8e6", "scanner": "scanner-primary", "fingerprint": "0fdb0e39fa29bdb9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/stories.py"}, "region": {"startLine": 98}}}]}, {"ruleId": "scanner-08268d8c4fda2428", "level": "error", "message": {"text": "FastAPI PUT `reorder_story_items` without auth dependency \u2014 backend/routes/stories.py:111"}, "properties": {"repobilityId": "8020111334c72871", "scanner": "scanner-primary", "fingerprint": "08268d8c4fda2428", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/stories.py"}, "region": {"startLine": 111}}}]}, {"ruleId": "scanner-4c255950a34e628d", "level": "error", "message": {"text": "FastAPI PUT `move_story_item` without auth dependency \u2014 backend/routes/stories.py:126"}, "properties": {"repobilityId": "fb43e97b0e7b431e", "scanner": "scanner-primary", "fingerprint": "4c255950a34e628d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/stories.py"}, "region": {"startLine": 126}}}]}, {"ruleId": "scanner-3bf78d9dad1ea603", "level": "error", "message": {"text": "FastAPI PUT `trim_story_item` without auth dependency \u2014 backend/routes/stories.py:140"}, "properties": {"repobilityId": "ddfab6cc19fca395", "scanner": "scanner-primary", "fingerprint": "3bf78d9dad1ea603", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/stories.py"}, "region": {"startLine": 140}}}]}, {"ruleId": "scanner-2f3e9401f826e8a9", "level": "error", "message": {"text": "FastAPI PUT `update_story_item_volume` without auth dependency \u2014 backend/routes/stories.py:154"}, "properties": {"repobilityId": "02a3ba152d6e91a8", "scanner": "scanner-primary", "fingerprint": "2f3e9401f826e8a9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/stories.py"}, "region": {"startLine": 154}}}]}, {"ruleId": "scanner-60659af2153b28a1", "level": "error", "message": {"text": "FastAPI POST `split_story_item` without auth dependency \u2014 backend/routes/stories.py:168"}, "properties": {"repobilityId": "6d87901c62e89f2f", "scanner": "scanner-primary", "fingerprint": "60659af2153b28a1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/stories.py"}, "region": {"startLine": 168}}}]}, {"ruleId": "scanner-6f4b4f1cdcd448f5", "level": "error", "message": {"text": "FastAPI POST `duplicate_story_item` without auth dependency \u2014 backend/routes/stories.py:182"}, "properties": {"repobilityId": "7b4e9338b5eb0562", "scanner": "scanner-primary", "fingerprint": "6f4b4f1cdcd448f5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/stories.py"}, "region": {"startLine": 182}}}]}, {"ruleId": "scanner-38b55463ed8c0781", "level": "error", "message": {"text": "FastAPI PUT `set_story_item_version` without auth dependency \u2014 backend/routes/stories.py:195"}, "properties": {"repobilityId": "fdaab34be57a4dc5", "scanner": "scanner-primary", "fingerprint": "38b55463ed8c0781", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/stories.py"}, "region": {"startLine": 195}}}]}, {"ruleId": "scanner-a7f59a844c127c31", "level": "error", "message": {"text": "FastAPI POST `transcribe_audio` without auth dependency \u2014 backend/routes/transcription.py:23"}, "properties": {"repobilityId": "0951db597cc6b621", "scanner": "scanner-primary", "fingerprint": "a7f59a844c127c31", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/transcription.py"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-5919052e89115baa", "level": "error", "message": {"text": "FastAPI POST `download_cuda_backend` without auth dependency \u2014 backend/routes/cuda.py:24"}, "properties": {"repobilityId": "bd30790db8c278e7", "scanner": "scanner-primary", "fingerprint": "5919052e89115baa", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/cuda.py"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-2fc6a7ae045187a7", "level": "error", "message": {"text": "FastAPI DELETE `delete_cuda_backend` without auth dependency \u2014 backend/routes/cuda.py:51"}, "properties": {"repobilityId": "02c729c3ba59cef9", "scanner": "scanner-primary", "fingerprint": "2fc6a7ae045187a7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/cuda.py"}, "region": {"startLine": 51}}}]}, {"ruleId": "scanner-a24f755d23389866", "level": "error", "message": {"text": "FastAPI POST `llm_generate` without auth dependency \u2014 backend/routes/llm.py:19"}, "properties": {"repobilityId": "34bd87a0b0bcc1c5", "scanner": "scanner-primary", "fingerprint": "a24f755d23389866", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/llm.py"}, "region": {"startLine": 19}}}]}, {"ruleId": "scanner-58672eb3e0ac2037", "level": "error", "message": {"text": "FastAPI POST `download_rocm_backend` without auth dependency \u2014 backend/routes/rocm.py:24"}, "properties": {"repobilityId": "fe51077eabeb2c75", "scanner": "scanner-primary", "fingerprint": "58672eb3e0ac2037", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/rocm.py"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-28593f4ef17a0990", "level": "error", "message": {"text": "FastAPI DELETE `delete_rocm_backend` without auth dependency \u2014 backend/routes/rocm.py:44"}, "properties": {"repobilityId": "b96e2edce6babefb", "scanner": "scanner-primary", "fingerprint": "28593f4ef17a0990", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/rocm.py"}, "region": {"startLine": 44}}}]}, {"ruleId": "scanner-de2aae427f5bc803", "level": "error", "message": {"text": "FastAPI POST `clear_all_tasks` without auth dependency \u2014 backend/routes/tasks.py:16"}, "properties": {"repobilityId": "b9fd84db473a29e0", "scanner": "scanner-primary", "fingerprint": "de2aae427f5bc803", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/tasks.py"}, "region": {"startLine": 16}}}]}, {"ruleId": "scanner-03b045e219983a81", "level": "error", "message": {"text": "FastAPI POST `clear_cache` without auth dependency \u2014 backend/routes/tasks.py:32"}, "properties": {"repobilityId": "2e270cffc3060f32", "scanner": "scanner-primary", "fingerprint": "03b045e219983a81", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/tasks.py"}, "region": {"startLine": 32}}}]}, {"ruleId": "scanner-5a263ec8f65d6630", "level": "error", "message": {"text": "FastAPI POST `preview_effects` without auth dependency \u2014 backend/routes/effects.py:18"}, "properties": {"repobilityId": "1bb9643e21c59225", "scanner": "scanner-primary", "fingerprint": "5a263ec8f65d6630", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/effects.py"}, "region": {"startLine": 18}}}]}, {"ruleId": "scanner-feac42403173c37d", "level": "error", "message": {"text": "FastAPI POST `create_effect_preset` without auth dependency \u2014 backend/routes/effects.py:93"}, "properties": {"repobilityId": "ec66a679cc33ad38", "scanner": "scanner-primary", "fingerprint": "feac42403173c37d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/effects.py"}, "region": {"startLine": 93}}}]}, {"ruleId": "scanner-a836aff24c83a028", "level": "error", "message": {"text": "FastAPI PUT `update_effect_preset` without auth dependency \u2014 backend/routes/effects.py:107"}, "properties": {"repobilityId": "9cc3d39cd8c21f4b", "scanner": "scanner-primary", "fingerprint": "a836aff24c83a028", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/effects.py"}, "region": {"startLine": 107}}}]}, {"ruleId": "scanner-6cf9722da928e37b", "level": "error", "message": {"text": "FastAPI DELETE `delete_effect_preset` without auth dependency \u2014 backend/routes/effects.py:125"}, "properties": {"repobilityId": "40b400b72090d324", "scanner": "scanner-primary", "fingerprint": "6cf9722da928e37b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/effects.py"}, "region": {"startLine": 125}}}]}, {"ruleId": "scanner-23a1acdec92e1a06", "level": "error", "message": {"text": "FastAPI POST `apply_effects_to_generation` without auth dependency \u2014 backend/routes/effects.py:156"}, "properties": {"repobilityId": "0b32230cdb4bd9bc", "scanner": "scanner-primary", "fingerprint": "23a1acdec92e1a06", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/effects.py"}, "region": {"startLine": 156}}}]}, {"ruleId": "scanner-23dece215aff53b1", "level": "error", "message": {"text": "FastAPI PUT `set_default_version` without auth dependency \u2014 backend/routes/effects.py:222"}, "properties": {"repobilityId": "e3ac8c6195201ae7", "scanner": "scanner-primary", "fingerprint": "23dece215aff53b1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/effects.py"}, "region": {"startLine": 222}}}]}, {"ruleId": "scanner-1ec9b0f4e9286c8d", "level": "error", "message": {"text": "FastAPI DELETE `delete_generation_version` without auth dependency \u2014 backend/routes/effects.py:244"}, "properties": {"repobilityId": "ce54b6e62ad9d7e3", "scanner": "scanner-primary", "fingerprint": "1ec9b0f4e9286c8d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/effects.py"}, "region": {"startLine": 244}}}]}, {"ruleId": "scanner-ff01553fa0610299", "level": "error", "message": {"text": "FastAPI POST `load_model` without auth dependency \u2014 backend/routes/models.py:50"}, "properties": {"repobilityId": "59a129bdf8f9d3d3", "scanner": "scanner-primary", "fingerprint": "ff01553fa0610299", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/models.py"}, "region": {"startLine": 50}}}]}, {"ruleId": "scanner-d23b924b765458aa", "level": "error", "message": {"text": "FastAPI POST `unload_model` without auth dependency \u2014 backend/routes/models.py:63"}, "properties": {"repobilityId": "f7a130800d0eb757", "scanner": "scanner-primary", "fingerprint": "d23b924b765458aa", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/models.py"}, "region": {"startLine": 63}}}]}, {"ruleId": "scanner-c1e9a25ad80d6ee2", "level": "error", "message": {"text": "FastAPI POST `unload_model_by_name` without auth dependency \u2014 backend/routes/models.py:75"}, "properties": {"repobilityId": "d770f826da3f19b2", "scanner": "scanner-primary", "fingerprint": "c1e9a25ad80d6ee2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/models.py"}, "region": {"startLine": 75}}}]}, {"ruleId": "scanner-0149eb1d06bfa93d", "level": "error", "message": {"text": "FastAPI POST `migrate_models` without auth dependency \u2014 backend/routes/models.py:121"}, "properties": {"repobilityId": "e0f7e18e8e709db4", "scanner": "scanner-primary", "fingerprint": "0149eb1d06bfa93d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/models.py"}, "region": {"startLine": 121}}}]}, {"ruleId": "scanner-80699c3e6cc5bc84", "level": "error", "message": {"text": "FastAPI POST `trigger_model_download` without auth dependency \u2014 backend/routes/models.py:390"}, "properties": {"repobilityId": "314b6465f6eb9780", "scanner": "scanner-primary", "fingerprint": "80699c3e6cc5bc84", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/models.py"}, "region": {"startLine": 390}}}]}, {"ruleId": "scanner-55fb3cc8897740a7", "level": "error", "message": {"text": "FastAPI POST `cancel_model_download` without auth dependency \u2014 backend/routes/models.py:428"}, "properties": {"repobilityId": "9abf2f67485e8017", "scanner": "scanner-primary", "fingerprint": "55fb3cc8897740a7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/models.py"}, "region": {"startLine": 428}}}]}, {"ruleId": "scanner-a4f14e97eaf2a2ae", "level": "error", "message": {"text": "FastAPI DELETE `delete_model` without auth dependency \u2014 backend/routes/models.py:447"}, "properties": {"repobilityId": "c9ea86ae99c57858", "scanner": "scanner-primary", "fingerprint": "a4f14e97eaf2a2ae", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/models.py"}, "region": {"startLine": 447}}}]}, {"ruleId": "scanner-21da453f5ea90af6", "level": "error", "message": {"text": "FastAPI POST `start_cloud_login` without auth dependency \u2014 backend/routes/cloud.py:30"}, "properties": {"repobilityId": "2e265e66a25950a5", "scanner": "scanner-primary", "fingerprint": "21da453f5ea90af6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/cloud.py"}, "region": {"startLine": 30}}}]}, {"ruleId": "scanner-438c925496a5c318", "level": "error", "message": {"text": "FastAPI POST `cloud_disconnect` without auth dependency \u2014 backend/routes/cloud.py:72"}, "properties": {"repobilityId": "abf7ba791b7b09bb", "scanner": "scanner-primary", "fingerprint": "438c925496a5c318", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/cloud.py"}, "region": {"startLine": 72}}}]}, {"ruleId": "scanner-8e71522ca07644d5", "level": "error", "message": {"text": "FastAPI POST `create_profile` without auth dependency \u2014 backend/routes/profiles.py:25"}, "properties": {"repobilityId": "20441c4055ef7cbe", "scanner": "scanner-primary", "fingerprint": "8e71522ca07644d5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/profiles.py"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-ba17a2cb068f6ffa", "level": "error", "message": {"text": "FastAPI POST `import_profile` without auth dependency \u2014 backend/routes/profiles.py:45"}, "properties": {"repobilityId": "d8610671bf063fe1", "scanner": "scanner-primary", "fingerprint": "ba17a2cb068f6ffa", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/profiles.py"}, "region": {"startLine": 45}}}]}, {"ruleId": "scanner-0e83a18e1160ff31", "level": "error", "message": {"text": "FastAPI PUT `update_profile` without auth dependency \u2014 backend/routes/profiles.py:121"}, "properties": {"repobilityId": "8a2376c10250c7cd", "scanner": "scanner-primary", "fingerprint": "0e83a18e1160ff31", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/profiles.py"}, "region": {"startLine": 121}}}]}, {"ruleId": "scanner-04c75b4263aecf3a", "level": "error", "message": {"text": "FastAPI DELETE `delete_profile` without auth dependency \u2014 backend/routes/profiles.py:137"}, "properties": {"repobilityId": "54990dcc8f608c87", "scanner": "scanner-primary", "fingerprint": "04c75b4263aecf3a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/profiles.py"}, "region": {"startLine": 137}}}]}, {"ruleId": "scanner-3ae4de2c13cc5b61", "level": "error", "message": {"text": "FastAPI POST `add_profile_sample` without auth dependency \u2014 backend/routes/profiles.py:153"}, "properties": {"repobilityId": "5557c9f903d13dd7", "scanner": "scanner-primary", "fingerprint": "3ae4de2c13cc5b61", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/profiles.py"}, "region": {"startLine": 153}}}]}, {"ruleId": "scanner-6d4bf72c3d3dd68e", "level": "error", "message": {"text": "FastAPI DELETE `delete_profile_sample` without auth dependency \u2014 backend/routes/profiles.py:203"}, "properties": {"repobilityId": "747aac0055f2b5e0", "scanner": "scanner-primary", "fingerprint": "6d4bf72c3d3dd68e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/profiles.py"}, "region": {"startLine": 203}}}]}, {"ruleId": "scanner-9bc9fd03ad4eb507", "level": "error", "message": {"text": "FastAPI PUT `update_profile_sample` without auth dependency \u2014 backend/routes/profiles.py:215"}, "properties": {"repobilityId": "c819039870d25b0b", "scanner": "scanner-primary", "fingerprint": "9bc9fd03ad4eb507", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/profiles.py"}, "region": {"startLine": 215}}}]}, {"ruleId": "scanner-913b3a065b854006", "level": "error", "message": {"text": "FastAPI POST `upload_profile_avatar` without auth dependency \u2014 backend/routes/profiles.py:228"}, "properties": {"repobilityId": "6b590b4266fd928b", "scanner": "scanner-primary", "fingerprint": "913b3a065b854006", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/profiles.py"}, "region": {"startLine": 228}}}]}, {"ruleId": "scanner-d3bd294ef25a8b1b", "level": "error", "message": {"text": "FastAPI DELETE `delete_profile_avatar` without auth dependency \u2014 backend/routes/profiles.py:269"}, "properties": {"repobilityId": "3a6295fc60918c00", "scanner": "scanner-primary", "fingerprint": "d3bd294ef25a8b1b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/profiles.py"}, "region": {"startLine": 269}}}]}, {"ruleId": "scanner-9b1397c5fc1a2fdb", "level": "error", "message": {"text": "FastAPI PUT `set_profile_channels` without auth dependency \u2014 backend/routes/profiles.py:323"}, "properties": {"repobilityId": "8b6ad93dd1386bb2", "scanner": "scanner-primary", "fingerprint": "9b1397c5fc1a2fdb", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/profiles.py"}, "region": {"startLine": 323}}}]}, {"ruleId": "scanner-b7b426361d188b82", "level": "error", "message": {"text": "FastAPI PUT `update_profile_effects` without auth dependency \u2014 backend/routes/profiles.py:337"}, "properties": {"repobilityId": "9614004c9e48afc3", "scanner": "scanner-primary", "fingerprint": "b7b426361d188b82", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/profiles.py"}, "region": {"startLine": 337}}}]}, {"ruleId": "scanner-7cd9d15bff28d8c7", "level": "error", "message": {"text": "FastAPI POST `compose_in_character` without auth dependency \u2014 backend/routes/profiles.py:374"}, "properties": {"repobilityId": "0fa13e4859994e96", "scanner": "scanner-primary", "fingerprint": "7cd9d15bff28d8c7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/profiles.py"}, "region": {"startLine": 374}}}]}, {"ruleId": "scanner-64a1c99b1c809887", "level": "error", "message": {"text": "FastAPI PUT `update_capture_settings_endpoint` without auth dependency \u2014 backend/routes/settings.py:18"}, "properties": {"repobilityId": "f6562b35bbace66d", "scanner": "scanner-primary", "fingerprint": "64a1c99b1c809887", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/settings.py"}, "region": {"startLine": 18}}}]}, {"ruleId": "scanner-27fca6d1511b5994", "level": "error", "message": {"text": "FastAPI PUT `update_generation_settings_endpoint` without auth dependency \u2014 backend/routes/settings.py:31"}, "properties": {"repobilityId": "5bf8840ce7bef328", "scanner": "scanner-primary", "fingerprint": "27fca6d1511b5994", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/settings.py"}, "region": {"startLine": 31}}}]}, {"ruleId": "scanner-13b1681ae96b9970", "level": "error", "message": {"text": "FastAPI POST `speak` without auth dependency \u2014 backend/routes/speak.py:27"}, "properties": {"repobilityId": "da55ffeb616f5b42", "scanner": "scanner-primary", "fingerprint": "13b1681ae96b9970", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/speak.py"}, "region": {"startLine": 27}}}]}, {"ruleId": "scanner-4286bd9baa34828e", "level": "error", "message": {"text": "FastAPI POST `create_capture_endpoint` without auth dependency \u2014 backend/routes/captures.py:24"}, "properties": {"repobilityId": "b15fe4aad7d958c4", "scanner": "scanner-primary", "fingerprint": "4286bd9baa34828e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/captures.py"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-4942a1390362ac2b", "level": "error", "message": {"text": "FastAPI DELETE `delete_capture_endpoint` without auth dependency \u2014 backend/routes/captures.py:111"}, "properties": {"repobilityId": "72f298a294c291ef", "scanner": "scanner-primary", "fingerprint": "4942a1390362ac2b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/captures.py"}, "region": {"startLine": 111}}}]}, {"ruleId": "scanner-dcc3f072d344e1c5", "level": "error", "message": {"text": "FastAPI POST `refine_capture_endpoint` without auth dependency \u2014 backend/routes/captures.py:119"}, "properties": {"repobilityId": "d1cdea3932438b96", "scanner": "scanner-primary", "fingerprint": "dcc3f072d344e1c5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/captures.py"}, "region": {"startLine": 119}}}]}, {"ruleId": "scanner-583b6f17e82530f4", "level": "error", "message": {"text": "FastAPI POST `retranscribe_capture_endpoint` without auth dependency \u2014 backend/routes/captures.py:203"}, "properties": {"repobilityId": "baf519600af1a76d", "scanner": "scanner-primary", "fingerprint": "583b6f17e82530f4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/captures.py"}, "region": {"startLine": 203}}}]}, {"ruleId": "scanner-b6ee92e8d558ed40", "level": "error", "message": {"text": "FastAPI POST `create_channel` without auth dependency \u2014 backend/routes/channels.py:19"}, "properties": {"repobilityId": "7a9590eacfb19c92", "scanner": "scanner-primary", "fingerprint": "b6ee92e8d558ed40", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/channels.py"}, "region": {"startLine": 19}}}]}, {"ruleId": "scanner-be9a27aa838c4f3c", "level": "error", "message": {"text": "FastAPI PUT `update_channel` without auth dependency \u2014 backend/routes/channels.py:43"}, "properties": {"repobilityId": "eef951cda24e8d16", "scanner": "scanner-primary", "fingerprint": "be9a27aa838c4f3c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/channels.py"}, "region": {"startLine": 43}}}]}, {"ruleId": "scanner-09bc78c46651c97c", "level": "error", "message": {"text": "FastAPI DELETE `delete_channel` without auth dependency \u2014 backend/routes/channels.py:59"}, "properties": {"repobilityId": "53cd7751611a5d85", "scanner": "scanner-primary", "fingerprint": "09bc78c46651c97c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/channels.py"}, "region": {"startLine": 59}}}]}, {"ruleId": "scanner-faf62112b6f93f1c", "level": "error", "message": {"text": "FastAPI PUT `set_channel_voices` without auth dependency \u2014 backend/routes/channels.py:87"}, "properties": {"repobilityId": "cc329a0f5eb3a51f", "scanner": "scanner-primary", "fingerprint": "faf62112b6f93f1c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/channels.py"}, "region": {"startLine": 87}}}]}, {"ruleId": "scanner-a37c4d83833bb650", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-267c-6grr-h53f"}, "properties": {"repobilityId": "f2ec5ebf946cf316", "scanner": "scanner-primary", "fingerprint": "a37c4d83833bb650", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-267c-6grr-h53f"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fa8943c715790d91", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-26hh-7cqf-hhc6"}, "properties": {"repobilityId": "380aec364486ea92", "scanner": "scanner-primary", "fingerprint": "fa8943c715790d91", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-26hh-7cqf-hhc6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a29d1b99d94d1eba", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-36qx-fr4f-26g5"}, "properties": {"repobilityId": "431141be2dd9b565", "scanner": "scanner-primary", "fingerprint": "a29d1b99d94d1eba", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-36qx-fr4f-26g5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3f0c1b4061872109", "level": "note", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-3g8h-86w9-wvmq"}, "properties": {"repobilityId": "f6534b96dc54051e", "scanner": "scanner-primary", "fingerprint": "3f0c1b4061872109", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3g8h-86w9-wvmq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d31e98fb2b12e2ee", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-3x4c-7xq6-9pq8"}, "properties": {"repobilityId": "9cc0a96fb9910d18", "scanner": "scanner-primary", "fingerprint": "d31e98fb2b12e2ee", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3x4c-7xq6-9pq8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-569055332c227fd2", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-4633-3j49-mh5q"}, "properties": {"repobilityId": "e9ea86e787812968", "scanner": "scanner-primary", "fingerprint": "569055332c227fd2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4633-3j49-mh5q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c59eb2a8de09122f", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-492v-c6pp-mqqv"}, "properties": {"repobilityId": "773d6faba6fd2f4f", "scanner": "scanner-primary", "fingerprint": "c59eb2a8de09122f", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-492v-c6pp-mqqv"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-13b37bca9debbf55", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-4c39-4ccg-62r3"}, "properties": {"repobilityId": "0a0a1155370474ca", "scanner": "scanner-primary", "fingerprint": "13b37bca9debbf55", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4c39-4ccg-62r3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a8543e5fbb96a19e", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-5f7q-jpqc-wp7h"}, "properties": {"repobilityId": "ed9b1014012c92b6", "scanner": "scanner-primary", "fingerprint": "a8543e5fbb96a19e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-5f7q-jpqc-wp7h"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5bcb62695d0c2fea", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-68g3-v927-f742"}, "properties": {"repobilityId": "a0a9b864ee9edebc", "scanner": "scanner-primary", "fingerprint": "5bcb62695d0c2fea", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-68g3-v927-f742"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c5fca1883fe47925", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-6gpp-xcg3-4w24"}, "properties": {"repobilityId": "29fab30bd0e5f1d4", "scanner": "scanner-primary", "fingerprint": "c5fca1883fe47925", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6gpp-xcg3-4w24"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-353eaee5a024a709", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-89xv-2m56-2m9x"}, "properties": {"repobilityId": "7a89339e08525c49", "scanner": "scanner-primary", "fingerprint": "353eaee5a024a709", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-89xv-2m56-2m9x"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c552bc16148b9d15", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-8h8q-6873-q5fj"}, "properties": {"repobilityId": "342c7895deabff5e", "scanner": "scanner-primary", "fingerprint": "c552bc16148b9d15", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-8h8q-6873-q5fj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5f3645b622d518df", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-955p-x3mx-jcvp"}, "properties": {"repobilityId": "37727fb78e12543e", "scanner": "scanner-primary", "fingerprint": "5f3645b622d518df", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-955p-x3mx-jcvp"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fcb316d03947cae4", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-9g9p-9gw9-jx7f"}, "properties": {"repobilityId": "9a356e0752806506", "scanner": "scanner-primary", "fingerprint": "fcb316d03947cae4", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9g9p-9gw9-jx7f"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f260c60044c81eee", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-c4j6-fc7j-m34r"}, "properties": {"repobilityId": "5a5dc941a80b1afc", "scanner": "scanner-primary", "fingerprint": "f260c60044c81eee", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-c4j6-fc7j-m34r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1c62fc5abf12694c", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-ffhc-5mcf-pf4q"}, "properties": {"repobilityId": "9e3521f34b2f9dc8", "scanner": "scanner-primary", "fingerprint": "1c62fc5abf12694c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-ffhc-5mcf-pf4q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6e857fcc46f4c0c9", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-ggv3-7p47-pfv8"}, "properties": {"repobilityId": "b9b70ccf746c94ba", "scanner": "scanner-primary", "fingerprint": "6e857fcc46f4c0c9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-ggv3-7p47-pfv8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cfdabd1e3d18ef1b", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-gx5p-jg67-6x7h"}, "properties": {"repobilityId": "dbf8aeb682af6160", "scanner": "scanner-primary", "fingerprint": "cfdabd1e3d18ef1b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gx5p-jg67-6x7h"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1e0fcc111a113248", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-h25m-26qc-wcjf"}, "properties": {"repobilityId": "de94e432924a7213", "scanner": "scanner-primary", "fingerprint": "1e0fcc111a113248", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-h25m-26qc-wcjf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-28e5ba9ae8a7ed42", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-h27x-g6w4-24gq"}, "properties": {"repobilityId": "ff8d481152ced40d", "scanner": "scanner-primary", "fingerprint": "28e5ba9ae8a7ed42", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-h27x-g6w4-24gq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5e1751938e62bd56", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-h64f-5h5j-jqjh"}, "properties": {"repobilityId": "67efb4afac8b341b", "scanner": "scanner-primary", "fingerprint": "5e1751938e62bd56", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-h64f-5h5j-jqjh"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f4fe304a48ccf3e8", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-jcc7-9wpm-mj36"}, "properties": {"repobilityId": "300f258d087511dd", "scanner": "scanner-primary", "fingerprint": "f4fe304a48ccf3e8", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jcc7-9wpm-mj36"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a176eb42e6f9763e", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-m99w-x7hq-7vfj"}, "properties": {"repobilityId": "ca2e75c4cec7bf9f", "scanner": "scanner-primary", "fingerprint": "a176eb42e6f9763e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-m99w-x7hq-7vfj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4001153c43ee5a2f", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-mg66-mrh9-m8jx"}, "properties": {"repobilityId": "05610e48e60a6920", "scanner": "scanner-primary", "fingerprint": "4001153c43ee5a2f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mg66-mrh9-m8jx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5e183bfc44a9a1e9", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-mq59-m269-xvcx"}, "properties": {"repobilityId": "713ee09d48cbb5f0", "scanner": "scanner-primary", "fingerprint": "5e183bfc44a9a1e9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mq59-m269-xvcx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ede9477cae92fb48", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-p9j2-gv94-2wf4"}, "properties": {"repobilityId": "f8421141e58fd8e5", "scanner": "scanner-primary", "fingerprint": "ede9477cae92fb48", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p9j2-gv94-2wf4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0abe7770a163bbd6", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-q4gf-8mx6-v5v3"}, "properties": {"repobilityId": "3a7e6924007b873d", "scanner": "scanner-primary", "fingerprint": "0abe7770a163bbd6", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-q4gf-8mx6-v5v3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e5f0dd8902c24c4f", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-q8wf-6r8g-63ch"}, "properties": {"repobilityId": "d48c86376fb8e54d", "scanner": "scanner-primary", "fingerprint": "e5f0dd8902c24c4f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-q8wf-6r8g-63ch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-92688f1ab4d7683a", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-vfv6-92ff-j949"}, "properties": {"repobilityId": "d4dcfad91fb1d51d", "scanner": "scanner-primary", "fingerprint": "92688f1ab4d7683a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vfv6-92ff-j949"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9b4df8310b3b804c", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.4: GHSA-wfc6-r584-vfw7"}, "properties": {"repobilityId": "a003e3c110a7af7c", "scanner": "scanner-primary", "fingerprint": "9b4df8310b3b804c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wfc6-r584-vfw7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1ef4e36137af8a94", "level": "warning", "message": {"text": "Vulnerable dependency postcss 8.5.6: GHSA-qx2v-qp2m-jg93"}, "properties": {"repobilityId": "6c83605d3aa8fcef", "scanner": "scanner-primary", "fingerprint": "1ef4e36137af8a94", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-qx2v-qp2m-jg93"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "landing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-20c5c9da0b7b62f6", "level": "warning", "message": {"text": "Vulnerable dependency vite 5.4.21: GHSA-4w7w-66w2-5vf9"}, "properties": {"repobilityId": "90685dbb72b15019", "scanner": "scanner-primary", "fingerprint": "20c5c9da0b7b62f6", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-4w7w-66w2-5vf9", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2a4a6231445f45c5", "level": "warning", "message": {"text": "Vulnerable dependency vite 5.4.21: GHSA-fx2h-pf6j-xcff"}, "properties": {"repobilityId": "d9b9604813f5ec55", "scanner": "scanner-primary", "fingerprint": "2a4a6231445f45c5", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-fx2h-pf6j-xcff", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ba50ebe54f9ed9c3", "level": "warning", "message": {"text": "Vulnerable dependency vite 5.4.21: GHSA-v6wh-96g9-6wx3"}, "properties": {"repobilityId": "6d8cd9b06e1669ff", "scanner": "scanner-primary", "fingerprint": "ba50ebe54f9ed9c3", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-v6wh-96g9-6wx3", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f00a3f05020518bc", "level": "warning", "message": {"text": "Vulnerable dependency postcss 8.4.31: GHSA-qx2v-qp2m-jg93"}, "properties": {"repobilityId": "00a7666aebb4f6a3", "scanner": "scanner-primary", "fingerprint": "f00a3f05020518bc", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-qx2v-qp2m-jg93"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-461ffb132c915370", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-267c-6grr-h53f"}, "properties": {"repobilityId": "3708940b2ab3dc6b", "scanner": "scanner-primary", "fingerprint": "461ffb132c915370", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-267c-6grr-h53f"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bed66d8a00ed89d5", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-26hh-7cqf-hhc6"}, "properties": {"repobilityId": "a53da63fa7d784b7", "scanner": "scanner-primary", "fingerprint": "bed66d8a00ed89d5", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-26hh-7cqf-hhc6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-550cc5f5a1955f67", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-36qx-fr4f-26g5"}, "properties": {"repobilityId": "fc7744c20ea98806", "scanner": "scanner-primary", "fingerprint": "550cc5f5a1955f67", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-36qx-fr4f-26g5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a077cb8b3191de0a", "level": "note", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-3g8h-86w9-wvmq"}, "properties": {"repobilityId": "900b57d9c1f7e194", "scanner": "scanner-primary", "fingerprint": "a077cb8b3191de0a", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3g8h-86w9-wvmq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-97540d8fe4c932bc", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-3x4c-7xq6-9pq8"}, "properties": {"repobilityId": "51628ef0b365e46b", "scanner": "scanner-primary", "fingerprint": "97540d8fe4c932bc", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3x4c-7xq6-9pq8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6e6355d5ff6077b8", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-4633-3j49-mh5q"}, "properties": {"repobilityId": "2d649e5e57ff6cb6", "scanner": "scanner-primary", "fingerprint": "6e6355d5ff6077b8", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4633-3j49-mh5q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4292688685a013bc", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-492v-c6pp-mqqv"}, "properties": {"repobilityId": "d24a0fa912d1e04a", "scanner": "scanner-primary", "fingerprint": "4292688685a013bc", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-492v-c6pp-mqqv"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-986db914802d3d9e", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-4c39-4ccg-62r3"}, "properties": {"repobilityId": "662a81a94e3a7ebc", "scanner": "scanner-primary", "fingerprint": "986db914802d3d9e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4c39-4ccg-62r3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-006fb1b9c1308cde", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-68g3-v927-f742"}, "properties": {"repobilityId": "b5e7b2382a50577a", "scanner": "scanner-primary", "fingerprint": "006fb1b9c1308cde", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-68g3-v927-f742"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f612c8d0f250ef2c", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-6gpp-xcg3-4w24"}, "properties": {"repobilityId": "d15316045a9b03b6", "scanner": "scanner-primary", "fingerprint": "f612c8d0f250ef2c", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6gpp-xcg3-4w24"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-59b2a87d7314313d", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-89xv-2m56-2m9x"}, "properties": {"repobilityId": "8cbacec70b7c7195", "scanner": "scanner-primary", "fingerprint": "59b2a87d7314313d", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-89xv-2m56-2m9x"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b4d5641d201f6910", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-8h8q-6873-q5fj"}, "properties": {"repobilityId": "c61a0c071ac39d53", "scanner": "scanner-primary", "fingerprint": "b4d5641d201f6910", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-8h8q-6873-q5fj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-061dd8b61418afe1", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-955p-x3mx-jcvp"}, "properties": {"repobilityId": "fb8419cc43ac3ba6", "scanner": "scanner-primary", "fingerprint": "061dd8b61418afe1", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-955p-x3mx-jcvp"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0df5a06192b4be15", "level": "error", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-c4j6-fc7j-m34r"}, "properties": {"repobilityId": "74cdb5616b49a582", "scanner": "scanner-primary", "fingerprint": "0df5a06192b4be15", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-c4j6-fc7j-m34r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4a3fcbeef416eb87", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-ffhc-5mcf-pf4q"}, "properties": {"repobilityId": "0b3cf6bf4e7a0b02", "scanner": "scanner-primary", "fingerprint": "4a3fcbeef416eb87", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-ffhc-5mcf-pf4q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3db72d49b35269fc", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-ggv3-7p47-pfv8"}, "properties": {"repobilityId": "81cbbad60d5fbd4a", "scanner": "scanner-primary", "fingerprint": "3db72d49b35269fc", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-ggv3-7p47-pfv8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-17040fea84ec05bf", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-gx5p-jg67-6x7h"}, "properties": {"repobilityId": "02432a4df744c996", "scanner": "scanner-primary", "fingerprint": "17040fea84ec05bf", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gx5p-jg67-6x7h"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0a1b84b4e0409e40", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-h27x-g6w4-24gq"}, "properties": {"repobilityId": "f51bacfba1218354", "scanner": "scanner-primary", "fingerprint": "0a1b84b4e0409e40", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-h27x-g6w4-24gq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b100d1fbfca2abca", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-h64f-5h5j-jqjh"}, "properties": {"repobilityId": "19955fe845c7cfb2", "scanner": "scanner-primary", "fingerprint": "b100d1fbfca2abca", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-h64f-5h5j-jqjh"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dd49bef8cb4761bb", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-jcc7-9wpm-mj36"}, "properties": {"repobilityId": "0df15800dc50f97d", "scanner": "scanner-primary", "fingerprint": "dd49bef8cb4761bb", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jcc7-9wpm-mj36"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6c922a0b4918f4da", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-m99w-x7hq-7vfj"}, "properties": {"repobilityId": "a3fc9a2bbb41bf1c", "scanner": "scanner-primary", "fingerprint": "6c922a0b4918f4da", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-m99w-x7hq-7vfj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-157931d78ae4314e", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-mg66-mrh9-m8jx"}, "properties": {"repobilityId": "8b4a1aafdda0467a", "scanner": "scanner-primary", "fingerprint": "157931d78ae4314e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mg66-mrh9-m8jx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cba11b5b6d2484f0", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-mq59-m269-xvcx"}, "properties": {"repobilityId": "d3eccf0a013f6e9d", "scanner": "scanner-primary", "fingerprint": "cba11b5b6d2484f0", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mq59-m269-xvcx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-66cd8fd0ce0d648d", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-p9j2-gv94-2wf4"}, "properties": {"repobilityId": "423677b66ed8f9f0", "scanner": "scanner-primary", "fingerprint": "66cd8fd0ce0d648d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p9j2-gv94-2wf4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bf4f1976a9b7144c", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-q4gf-8mx6-v5v3"}, "properties": {"repobilityId": "66e931275063f8bd", "scanner": "scanner-primary", "fingerprint": "bf4f1976a9b7144c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-q4gf-8mx6-v5v3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-510d8b300cc39bd4", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-q8wf-6r8g-63ch"}, "properties": {"repobilityId": "7a28661a22c099a4", "scanner": "scanner-primary", "fingerprint": "510d8b300cc39bd4", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-q8wf-6r8g-63ch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5ebdccf480a2f5e2", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-vfv6-92ff-j949"}, "properties": {"repobilityId": "65c727db5ce72555", "scanner": "scanner-primary", "fingerprint": "5ebdccf480a2f5e2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vfv6-92ff-j949"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e0b43734a07787cf", "level": "warning", "message": {"text": "Vulnerable dependency next 16.1.6: GHSA-wfc6-r584-vfw7"}, "properties": {"repobilityId": "edc5a9e8364ab838", "scanner": "scanner-primary", "fingerprint": "e0b43734a07787cf", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wfc6-r584-vfw7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-de53f21ca886215e", "level": "error", "message": {"text": "Vulnerable dependency tauri 2.9.5: GHSA-7gmj-67g7-phm9"}, "properties": {"repobilityId": "a8098f90c125d8fe", "scanner": "scanner-primary", "fingerprint": "de53f21ca886215e", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-7gmj-67g7-phm9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tauri/src-tauri/Cargo.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-889fe40b3def0d43", "level": "error", "message": {"text": "Vulnerable dependency tauri 2.0: GHSA-7gmj-67g7-phm9"}, "properties": {"repobilityId": "b78b11caa378ddbc", "scanner": "scanner-primary", "fingerprint": "889fe40b3def0d43", "layer": "dependencies", "severity": "high", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-7gmj-67g7-phm9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tauri/src-tauri/Cargo.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c6b499f795883422", "level": "warning", "message": {"text": "Vulnerable dependency tauri-plugin-shell 2.0: GHSA-c9pr-q8gx-3mgp"}, "properties": {"repobilityId": "46f3f310fd840832", "scanner": "scanner-primary", "fingerprint": "c6b499f795883422", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-c9pr-q8gx-3mgp"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tauri/src-tauri/Cargo.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-07ce9957955118f9", "level": "warning", "message": {"text": "Vulnerable dependency @babel/core 7.28.6: GHSA-4x5r-pxfx-6jf8"}, "properties": {"repobilityId": "daea4b773564c44d", "scanner": "scanner-primary", "fingerprint": "07ce9957955118f9", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-4x5r-pxfx-6jf8", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f228235887a9a3b4", "level": "warning", "message": {"text": "Vulnerable dependency ajv 6.12.6: GHSA-2g4f-4pwh-qvx6"}, "properties": {"repobilityId": "cf8ef5d83527dc1c", "scanner": "scanner-primary", "fingerprint": "f228235887a9a3b4", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-2g4f-4pwh-qvx6", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0fecd96894f7839e", "level": "warning", "message": {"text": "Vulnerable dependency brace-expansion 1.1.12: GHSA-3jxr-9vmj-r5cp"}, "properties": {"repobilityId": "5d2ce580505ef5a7", "scanner": "scanner-primary", "fingerprint": "0fecd96894f7839e", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3jxr-9vmj-r5cp", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f8baa36b152a15a9", "level": "warning", "message": {"text": "Vulnerable dependency brace-expansion 1.1.12: GHSA-f886-m6hf-6m8v"}, "properties": {"repobilityId": "c4fa6cea7167ee7e", "scanner": "scanner-primary", "fingerprint": "f8baa36b152a15a9", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-f886-m6hf-6m8v", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5c243a2e5b9ef05f", "level": "warning", "message": {"text": "Vulnerable dependency esbuild 0.21.5: GHSA-67mh-4wv8-2f99"}, "properties": {"repobilityId": "be00f073db852f14", "scanner": "scanner-primary", "fingerprint": "5c243a2e5b9ef05f", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-67mh-4wv8-2f99", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b5b354a1b900569a", "level": "warning", "message": {"text": "Vulnerable dependency flatted 3.3.3: GHSA-25h7-pfq9-p65f"}, "properties": {"repobilityId": "d9983483d98c7b10", "scanner": "scanner-primary", "fingerprint": "b5b354a1b900569a", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-25h7-pfq9-p65f", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b933c9da3b8a9d65", "level": "warning", "message": {"text": "Vulnerable dependency flatted 3.3.3: GHSA-rf6f-7fwh-wjgh"}, "properties": {"repobilityId": "cf3a229f2fddbb99", "scanner": "scanner-primary", "fingerprint": "b933c9da3b8a9d65", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-rf6f-7fwh-wjgh", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-40b7862aa8000461", "level": "warning", "message": {"text": "Vulnerable dependency minimatch 3.1.2: GHSA-23c5-xmqv-rm74"}, "properties": {"repobilityId": "9f7f5897e94c3644", "scanner": "scanner-primary", "fingerprint": "40b7862aa8000461", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-23c5-xmqv-rm74", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-69f5380a5b975224", "level": "warning", "message": {"text": "Vulnerable dependency minimatch 3.1.2: GHSA-3ppc-4f35-3m26"}, "properties": {"repobilityId": "1f348c9c38426ebf", "scanner": "scanner-primary", "fingerprint": "69f5380a5b975224", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3ppc-4f35-3m26", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d2d5ce7c6cb9e82a", "level": "warning", "message": {"text": "Vulnerable dependency minimatch 3.1.2: GHSA-7r86-cg39-jmmj"}, "properties": {"repobilityId": "20c31d31e282c8df", "scanner": "scanner-primary", "fingerprint": "d2d5ce7c6cb9e82a", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-7r86-cg39-jmmj", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-eb6230694a1cc79e", "level": "warning", "message": {"text": "Vulnerable dependency picomatch 2.3.1: GHSA-3v7f-55p6-f55p"}, "properties": {"repobilityId": "a2746cb9d8be4794", "scanner": "scanner-primary", "fingerprint": "eb6230694a1cc79e", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3v7f-55p6-f55p", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-390d73d0cd2fe4d5", "level": "warning", "message": {"text": "Vulnerable dependency picomatch 2.3.1: GHSA-c2c7-rcm5-vvqj"}, "properties": {"repobilityId": "676e59b75389f27b", "scanner": "scanner-primary", "fingerprint": "390d73d0cd2fe4d5", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-c2c7-rcm5-vvqj", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-96722930b13d8666", "level": "warning", "message": {"text": "Dependency screencapturekit is two or more major versions behind"}, "properties": {"repobilityId": "2c70ae3385e9ce2e", "scanner": "scanner-primary", "fingerprint": "96722930b13d8666", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tauri/src-tauri/Cargo.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7c573ef14eaaa9d4", "level": "warning", "message": {"text": "Dependency @hookform/resolvers is two or more major versions behind"}, "properties": {"repobilityId": "52576545617f2ad7", "scanner": "scanner-primary", "fingerprint": "7c573ef14eaaa9d4", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0f063172efc884e7", "level": "error", "message": {"text": "Dangling fetch: GET https://huggingface.co/api/models/${repoId} (app/src/components/ServerSettings/ModelManagement.tsx:50)"}, "properties": {"repobilityId": "94e1f5303d2390b1", "scanner": "scanner-primary", "fingerprint": "0f063172efc884e7", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-b682dd2e23466611", "level": "error", "message": {"text": "Dangling fetch: GET /settings/captures (app/src/lib/api/client.ts:496)"}, "properties": {"repobilityId": "57c1c246bfd2bf52", "scanner": "scanner-primary", "fingerprint": "b682dd2e23466611", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-2e4f6a4eba75f373", "level": "error", "message": {"text": "Dangling fetch: PUT /settings/captures (app/src/lib/api/client.ts:504)"}, "properties": {"repobilityId": "3b57832b4633b711", "scanner": "scanner-primary", "fingerprint": "2e4f6a4eba75f373", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-28b1e042936fe283", "level": "error", "message": {"text": "Dangling fetch: GET /settings/generation (app/src/lib/api/client.ts:511)"}, "properties": {"repobilityId": "836cc71f38b1d378", "scanner": "scanner-primary", "fingerprint": "28b1e042936fe283", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-bdf30718ce4ab331", "level": "error", "message": {"text": "Dangling fetch: PUT /settings/generation (app/src/lib/api/client.ts:517)"}, "properties": {"repobilityId": "f77eb3aae33fd2cc", "scanner": "scanner-primary", "fingerprint": "bdf30718ce4ab331", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-3173c00365087339", "level": "error", "message": {"text": "Dangling fetch: GET /cloud/status (app/src/lib/api/client.ts:948)"}, "properties": {"repobilityId": "23718d6bd9df18b0", "scanner": "scanner-primary", "fingerprint": "3173c00365087339", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-d37457a58febbc20", "level": "error", "message": {"text": "Dangling fetch: POST /cloud/login/start (app/src/lib/api/client.ts:952)"}, "properties": {"repobilityId": "a93f8a23092ac362", "scanner": "scanner-primary", "fingerprint": "d37457a58febbc20", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-9107573f5ed4a754", "level": "error", "message": {"text": "Dangling fetch: POST /cloud/disconnect (app/src/lib/api/client.ts:956)"}, "properties": {"repobilityId": "48b4f924ea873402", "scanner": "scanner-primary", "fingerprint": "9107573f5ed4a754", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-0414130e1e911ead", "level": "error", "message": {"text": "Dangling fetch: GET /api/stars (landing/src/components/Navbar.tsx:20)"}, "properties": {"repobilityId": "148b8b95cb52c360", "scanner": "scanner-primary", "fingerprint": "0414130e1e911ead", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-dd74c75380116414", "level": "error", "message": {"text": "Dangling fetch: GET /api/releases (landing/src/app/page.tsx:26)"}, "properties": {"repobilityId": "3b4d5cf8889ab172", "scanner": "scanner-primary", "fingerprint": "dd74c75380116414", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-4bfbd32383b34fca", "level": "error", "message": {"text": "Dangling fetch: GET /api/releases (landing/src/app/capture/page.tsx:18)"}, "properties": {"repobilityId": "86995373a4e1437d", "scanner": "scanner-primary", "fingerprint": "4bfbd32383b34fca", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-4e3044a1353f0fcc", "level": "error", "message": {"text": "Dangling fetch: GET /api/releases (landing/src/app/download/page.tsx:83)"}, "properties": {"repobilityId": "cd1d6eeb16ee81d8", "scanner": "scanner-primary", "fingerprint": "4e3044a1353f0fcc", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-074cd7938df999f9", "level": "error", "message": {"text": "Dangling fetch: GET https://lite-api.jup.ag/price/v3?ids=${mint} (landing/src/lib/token-stats.ts:387)"}, "properties": {"repobilityId": "84690b552e70d807", "scanner": "scanner-primary", "fingerprint": "074cd7938df999f9", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-1b1d5926fda286fa", "level": "note", "message": {"text": "Unused endpoint: GET /{full_path:path}"}, "properties": {"repobilityId": "80c52da6f17f1918", "scanner": "scanner-primary", "fingerprint": "1b1d5926fda286fa", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e76bfd3f7d716be3", "level": "note", "message": {"text": "Unused endpoint: GET /generate/{generation_id}/status"}, "properties": {"repobilityId": "6b04f0c3ee2d5f37", "scanner": "scanner-primary", "fingerprint": "e76bfd3f7d716be3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-76e7b0bc9cf34275", "level": "note", "message": {"text": "Unused endpoint: POST /generate/stream"}, "properties": {"repobilityId": "af26e8ffbf9cac06", "scanner": "scanner-primary", "fingerprint": "76e7b0bc9cf34275", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6b28608f033f2a3e", "level": "note", "message": {"text": "Unused endpoint: POST /generate/import"}, "properties": {"repobilityId": "18beff1bc19c86b8", "scanner": "scanner-primary", "fingerprint": "6b28608f033f2a3e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-afc064028ae39ea9", "level": "note", "message": {"text": "Unused endpoint: GET /history"}, "properties": {"repobilityId": "69cb94631341530f", "scanner": "scanner-primary", "fingerprint": "afc064028ae39ea9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8b2c1b29e535b939", "level": "note", "message": {"text": "Unused endpoint: GET /history/stats"}, "properties": {"repobilityId": "e43c34c3734ed1d8", "scanner": "scanner-primary", "fingerprint": "8b2c1b29e535b939", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d5832f8b2dc83bb4", "level": "note", "message": {"text": "Unused endpoint: POST /history/import"}, "properties": {"repobilityId": "e15aa137fafd4a95", "scanner": "scanner-primary", "fingerprint": "d5832f8b2dc83bb4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-703630a2f1ca9b52", "level": "note", "message": {"text": "Unused endpoint: GET /history/{generation_id}/export"}, "properties": {"repobilityId": "fae0051626eb4276", "scanner": "scanner-primary", "fingerprint": "703630a2f1ca9b52", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c32437e94dcaf435", "level": "note", "message": {"text": "Unused endpoint: GET /history/{generation_id}/export-audio"}, "properties": {"repobilityId": "279ba368b880a931", "scanner": "scanner-primary", "fingerprint": "c32437e94dcaf435", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "6a3cc005a64bedc7", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c9537c842ba93d4c", "level": "note", "message": {"text": "Unused endpoint: POST /shutdown"}, "properties": {"repobilityId": "f0d23726fa29cae1", "scanner": "scanner-primary", "fingerprint": "c9537c842ba93d4c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2250d1a2f9cf281a", "level": "note", "message": {"text": "Unused endpoint: POST /watchdog/disable"}, "properties": {"repobilityId": "6d68079a42105e3c", "scanner": "scanner-primary", "fingerprint": "2250d1a2f9cf281a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6dd25d1f862f4e09", "level": "note", "message": {"text": "Unused endpoint: GET /stories/{story_id}/export-audio"}, "properties": {"repobilityId": "9cabaab329ced417", "scanner": "scanner-primary", "fingerprint": "6dd25d1f862f4e09", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7de4e88d608e05fe", "level": "note", "message": {"text": "Unused endpoint: POST /transcribe"}, "properties": {"repobilityId": "2a830ebcf17a3e48", "scanner": "scanner-primary", "fingerprint": "7de4e88d608e05fe", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5dccf4cc0b07424e", "level": "note", "message": {"text": "Unused endpoint: GET /backend/cuda-progress"}, "properties": {"repobilityId": "b236c2e3c7cb83e3", "scanner": "scanner-primary", "fingerprint": "5dccf4cc0b07424e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-712752d3766e651f", "level": "note", "message": {"text": "Unused endpoint: POST /llm/generate"}, "properties": {"repobilityId": "fd535aa23139fb88", "scanner": "scanner-primary", "fingerprint": "712752d3766e651f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-38af776f9f8d12af", "level": "note", "message": {"text": "Unused endpoint: GET /backend/rocm-progress"}, "properties": {"repobilityId": "6a1a618fbd3a61dc", "scanner": "scanner-primary", "fingerprint": "38af776f9f8d12af", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7f2a75404375395f", "level": "note", "message": {"text": "Unused endpoint: GET /audio/version/{version_id}"}, "properties": {"repobilityId": "f6f10c5073f20d67", "scanner": "scanner-primary", "fingerprint": "7f2a75404375395f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-31b7e2f6ad7a9aeb", "level": "note", "message": {"text": "Unused endpoint: GET /audio/{generation_id}"}, "properties": {"repobilityId": "619a128e912c6767", "scanner": "scanner-primary", "fingerprint": "31b7e2f6ad7a9aeb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-da4f0c1059da1408", "level": "note", "message": {"text": "Unused endpoint: GET /samples/{sample_id}"}, "properties": {"repobilityId": "c5c979ecf89f5939", "scanner": "scanner-primary", "fingerprint": "da4f0c1059da1408", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3ad68c06f5b5283a", "level": "note", "message": {"text": "Unused endpoint: POST /cache/clear"}, "properties": {"repobilityId": "20dea1f52a3805c8", "scanner": "scanner-primary", "fingerprint": "3ad68c06f5b5283a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e1f8b42c544c5338", "level": "note", "message": {"text": "Unused endpoint: GET /events/speak"}, "properties": {"repobilityId": "093bf89b880c6461", "scanner": "scanner-primary", "fingerprint": "e1f8b42c544c5338", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-81b5bae47b244a56", "level": "note", "message": {"text": "Unused endpoint: POST /effects/preview/{generation_id}"}, "properties": {"repobilityId": "3e43bc5321f46048", "scanner": "scanner-primary", "fingerprint": "81b5bae47b244a56", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bbae4bd1684cc7a0", "level": "note", "message": {"text": "Unused endpoint: GET /effects/presets/{preset_id}"}, "properties": {"repobilityId": "6d228fed060c25cb", "scanner": "scanner-primary", "fingerprint": "bbae4bd1684cc7a0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-61470bf3b08c0c19", "level": "note", "message": {"text": "Unused endpoint: PUT /generations/{generation_id}/versions/{version_id}/set-default"}, "properties": {"repobilityId": "febdc806246010a8", "scanner": "scanner-primary", "fingerprint": "61470bf3b08c0c19", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a888fd77df02110a", "level": "note", "message": {"text": "Unused endpoint: DELETE /generations/{generation_id}/versions/{version_id}"}, "properties": {"repobilityId": "5dd3d7f0b0a3b1f1", "scanner": "scanner-primary", "fingerprint": "a888fd77df02110a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-21f7fd061acae43c", "level": "note", "message": {"text": "Unused endpoint: POST /models/load"}, "properties": {"repobilityId": "16e0858b22832ec9", "scanner": "scanner-primary", "fingerprint": "21f7fd061acae43c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0b8f7c9e642c1208", "level": "note", "message": {"text": "Unused endpoint: POST /models/unload"}, "properties": {"repobilityId": "cf9f8a5215b0a0af", "scanner": "scanner-primary", "fingerprint": "0b8f7c9e642c1208", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a56cf3cdc52215b4", "level": "note", "message": {"text": "Unused endpoint: GET /models/progress/{model_name}"}, "properties": {"repobilityId": "149237ad0b905f14", "scanner": "scanner-primary", "fingerprint": "a56cf3cdc52215b4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4e4ba55bc6bb23e5", "level": "note", "message": {"text": "Unused endpoint: GET /models/cache-dir"}, "properties": {"repobilityId": "9e2145d72ff9f97c", "scanner": "scanner-primary", "fingerprint": "4e4ba55bc6bb23e5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6d9ea566be206a24", "level": "note", "message": {"text": "Unused endpoint: POST /models/migrate"}, "properties": {"repobilityId": "7956dc2ca792c3fa", "scanner": "scanner-primary", "fingerprint": "6d9ea566be206a24", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5d9fbf9a1e9e9656", "level": "note", "message": {"text": "Unused endpoint: GET /models/migrate/progress"}, "properties": {"repobilityId": "9d2e8e641c8cd0d0", "scanner": "scanner-primary", "fingerprint": "5d9fbf9a1e9e9656", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-73c936e1e1498315", "level": "note", "message": {"text": "Unused endpoint: GET /models/status"}, "properties": {"repobilityId": "733d1d6a2b1cfb09", "scanner": "scanner-primary", "fingerprint": "73c936e1e1498315", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-846858242a61dac5", "level": "note", "message": {"text": "Unused endpoint: POST /login/start"}, "properties": {"repobilityId": "e5726140cc2b4088", "scanner": "scanner-primary", "fingerprint": "846858242a61dac5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cdfb578618cf2542", "level": "note", "message": {"text": "Unused endpoint: GET /callback"}, "properties": {"repobilityId": "4569480cc67e5625", "scanner": "scanner-primary", "fingerprint": "cdfb578618cf2542", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-540ebf4772ccf420", "level": "note", "message": {"text": "Unused endpoint: POST /disconnect"}, "properties": {"repobilityId": "bbebfd04570e9f75", "scanner": "scanner-primary", "fingerprint": "540ebf4772ccf420", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ee27d839f5b50a27", "level": "note", "message": {"text": "Unused endpoint: POST /profiles/import"}, "properties": {"repobilityId": "e67d615b0218f34a", "scanner": "scanner-primary", "fingerprint": "ee27d839f5b50a27", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-75c7174c800f27c8", "level": "note", "message": {"text": "Unused endpoint: POST /profiles/{profile_id}/samples"}, "properties": {"repobilityId": "f0ac086ef8fb0eee", "scanner": "scanner-primary", "fingerprint": "75c7174c800f27c8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8df76da407751a3c", "level": "note", "message": {"text": "Unused endpoint: POST /profiles/{profile_id}/avatar"}, "properties": {"repobilityId": "cd06bd0a64f3e422", "scanner": "scanner-primary", "fingerprint": "8df76da407751a3c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b10658800b98c034", "level": "note", "message": {"text": "Unused endpoint: GET /profiles/{profile_id}/avatar"}, "properties": {"repobilityId": "6c8e18db10be004c", "scanner": "scanner-primary", "fingerprint": "b10658800b98c034", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dd1d8e4b66983778", "level": "note", "message": {"text": "Unused endpoint: GET /profiles/{profile_id}/export"}, "properties": {"repobilityId": "d2a5313361d28929", "scanner": "scanner-primary", "fingerprint": "dd1d8e4b66983778", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9465831cb9b3daa4", "level": "note", "message": {"text": "Unused endpoint: GET /captures"}, "properties": {"repobilityId": "4a6c763d546c3547", "scanner": "scanner-primary", "fingerprint": "9465831cb9b3daa4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-565ea87c275e06eb", "level": "note", "message": {"text": "Unused endpoint: PUT /captures"}, "properties": {"repobilityId": "e9359e3030245c00", "scanner": "scanner-primary", "fingerprint": "565ea87c275e06eb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6bfc8d2e383629df", "level": "note", "message": {"text": "Unused endpoint: GET /generation"}, "properties": {"repobilityId": "fdc14e0743f70c97", "scanner": "scanner-primary", "fingerprint": "6bfc8d2e383629df", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4fab57e3ac145061", "level": "note", "message": {"text": "Unused endpoint: PUT /generation"}, "properties": {"repobilityId": "338995517999984c", "scanner": "scanner-primary", "fingerprint": "4fab57e3ac145061", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cc05e2496e726a3a", "level": "note", "message": {"text": "Unused endpoint: POST /speak"}, "properties": {"repobilityId": "1df95cea005ea958", "scanner": "scanner-primary", "fingerprint": "cc05e2496e726a3a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1524429992899d20", "level": "note", "message": {"text": "Unused endpoint: POST /captures"}, "properties": {"repobilityId": "f53d956d6f9f4a5c", "scanner": "scanner-primary", "fingerprint": "1524429992899d20", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4d9c103838a297b0", "level": "note", "message": {"text": "Unused endpoint: GET /captures/{capture_id}/audio"}, "properties": {"repobilityId": "5c8b88edfcbb263b", "scanner": "scanner-primary", "fingerprint": "4d9c103838a297b0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f908028f8c139837", "level": "note", "message": {"text": "Unused endpoint: GET /channels/{channel_id}"}, "properties": {"repobilityId": "52aa1536210375a1", "scanner": "scanner-primary", "fingerprint": "f908028f8c139837", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}