{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-ff03e3e471f7df3c", "name": "`truncate` class without `title=` for hover reveal \u2014 client/src/components/layout/Sidebar.tsx:86", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 client/src/components/layout/Sidebar.tsx:86"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f13a5a87083d170d", "name": "`truncate` class without `title=` for hover reveal \u2014 client/src/pages/JobsPage.tsx:304", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 client/src/pages/JobsPage.tsx:304"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9106d8c5c4fb4652", "name": "`truncate` class without `title=` for hover reveal \u2014 client/src/pages/AdminPage.tsx:68", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 client/src/pages/AdminPage.tsx:68"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4caa75d2b8c81f08", "name": "`truncate` class without `title=` for hover reveal \u2014 client/src/pages/SalaryPage.tsx:198", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 client/src/pages/SalaryPage.tsx:198"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f081989a5e129c72", "name": "`truncate` class without `title=` for hover reveal \u2014 client/src/pages/CommunityPage.tsx:230", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 client/src/pages/CommunityPage.tsx:230"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-978be9fc27a5e290", "name": "`truncate` class without `title=` for hover reveal \u2014 client/src/pages/JobDiscoveryPage.tsx:673", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 client/src/pages/JobDiscoveryPage.tsx:673"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0c0ae03863de1d48", "name": "`truncate` class without `title=` for hover reveal \u2014 client/src/pages/DashboardPage.tsx:252", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 client/src/pages/DashboardPage.tsx:252"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-519a74c278c41a29", "name": "`truncate` class without `title=` for hover reveal \u2014 client/src/pages/NetworkingPage.tsx:189", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 client/src/pages/NetworkingPage.tsx:189"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5d5cc87f49730f54", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 client/src/pages/PracticePage.tsx:328", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 client/src/pages/PracticePage.tsx:328"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9814a26a16a6cb7f", "name": "`truncate` class without `title=` for hover reveal \u2014 client/src/pages/AssistantPage.tsx:117", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 client/src/pages/AssistantPage.tsx:117"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ca50c3a5f3f7bda0", "name": "Stray `console.log` in TS/JS \u2014 server/src/index.ts:12", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 server/src/index.ts:12"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-541ad5988014a2a0", "name": "Stray `console.log` in TS/JS \u2014 server/src/services/scheduler.ts:67", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 server/src/services/scheduler.ts:67"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c1b1ba305b21c9f", "name": "Stray `console.log` in TS/JS \u2014 server/src/db/seed.ts:31", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 server/src/db/seed.ts:31"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-65b7ae5ac9812864", "name": "Stray `console.log` in TS/JS \u2014 server/src/db/store.ts:82", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 server/src/db/store.ts:82"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3b83e442397d76a0", "name": "Stray `console.log` in TS/JS \u2014 server/src/db/migrate.ts:11", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 server/src/db/migrate.ts:11"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b69f45b2dcff8d24", "name": "Dockerfile runs as root: server/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: server/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d7158aa1e38492c6", "name": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8e6af304ca7abc20", "name": "Possible secret in client/src/pages/LandingPage.tsx", "shortDescription": {"text": "Possible secret in client/src/pages/LandingPage.tsx"}, "fullDescription": {"text": "Detected pattern matching password_literal. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-d904226e520b2725", "name": "Insecure pattern 'new_function_used' in client/src/pages/PracticePage.tsx:31", "shortDescription": {"text": "Insecure pattern 'new_function_used' in client/src/pages/PracticePage.tsx:31"}, "fullDescription": {"text": "Found a known-risky pattern (new_function_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e65335aff36f727c", "name": "Insecure pattern 'dangerous_innerhtml' in client/src/pages/PracticePage.tsx:328", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in client/src/pages/PracticePage.tsx:328"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-420d2fb05f1517f2", "name": "Insecure pattern 'exec_used' in server/src/routes/practice.ts:108", "shortDescription": {"text": "Insecure pattern 'exec_used' in server/src/routes/practice.ts:108"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-27924aa79fa4a517", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "appleboy/ssh-action@v1.0.0 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5a91683e7a61ef34", "name": "Very large file: client/src/pages/JobDiscoveryPage.tsx (1179 lines)", "shortDescription": {"text": "Very large file: client/src/pages/JobDiscoveryPage.tsx (1179 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f672f9974244469a", "name": "Very large file: server/src/routes/jobDiscovery.ts (803 lines)", "shortDescription": {"text": "Very large file: server/src/routes/jobDiscovery.ts (803 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "6 test file(s) for 86 source file(s) (ratio 0.07). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1a6aeb84f8544549", "name": "Node manifest has dependencies but no lockfile: client/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: client/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d7101ca1926e3342", "name": "Node manifest has dependencies but no lockfile: server/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: server/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 9 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 42 placeholder/mock markers across 22 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9d79c4077342a7d0", "name": "Runtime service client appears to use placeholder configuration", "shortDescription": {"text": "Runtime service client appears to use placeholder configuration"}, "fullDescription": {"text": "A runtime source file appears to wire Supabase/Firebase/AI/payment-style clients to placeholder URLs, keys, or fallback values. In the Fable corpus this often means the UI/API shape is present while the backend service is not actually configured."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, lockfile. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-dbd5d6435eeeca8e", "name": "`fetch()` without try/.catch or AbortSignal \u2014 client/src/pages/JobDiscoveryPage.tsx:211", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 client/src/pages/JobDiscoveryPage.tsx:211"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6d4fd24ccce854aa", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/src/routes/auth.ts:88", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/src/routes/auth.ts:88"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c6605b54609bf280", "name": "Commented-code block (8 lines) in server/src/routes/jobDiscovery.ts:529", "shortDescription": {"text": "Commented-code block (8 lines) in server/src/routes/jobDiscovery.ts:529"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3482f7e5dd70cd1a", "name": "6 env vars used in code but missing from .env.example", "shortDescription": {"text": "6 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `ADMIN_EMAILS`, `AI_BASE_URL`, `AI_MODEL`, `DATABASE_URL`, `PISTON_URL`, `REDIS_URL`. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5766dc24db809018", "name": "Frontend route `/auth/callback` has no Link/navigate to it \u2014 client/src/App.tsx", "shortDescription": {"text": "Frontend route `/auth/callback` has no Link/navigate to it \u2014 client/src/App.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7d2d565659fb154a", "name": "Frontend route `/analytics` has no Link/navigate to it \u2014 client/src/App.tsx", "shortDescription": {"text": "Frontend route `/analytics` has no Link/navigate to it \u2014 client/src/App.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-94470e34d48279c9", "name": "Frontend route `/salary` has no Link/navigate to it \u2014 client/src/App.tsx", "shortDescription": {"text": "Frontend route `/salary` has no Link/navigate to it \u2014 client/src/App.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-949f18d509bc250d", "name": "Frontend route `/companies` has no Link/navigate to it \u2014 client/src/App.tsx", "shortDescription": {"text": "Frontend route `/companies` has no Link/navigate to it \u2014 client/src/App.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a16eb53a8e4350e7", "name": "Dangling fetch: POST /api/resume/tailor (client/src/pages/ResumePage.tsx:171)", "shortDescription": {"text": "Dangling fetch: POST /api/resume/tailor (client/src/pages/ResumePage.tsx:171)"}, "fullDescription": {"text": "`client/src/pages/ResumePage.tsx:171` calls `POST /api/resume/tailor` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/resume/tailor`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-85efd92cb5db05b4", "name": "Dangling fetch: GET /api/job-discovery/export?${params} (client/src/pages/JobDiscoveryPage.tsx:211)", "shortDescription": {"text": "Dangling fetch: GET /api/job-discovery/export?${params} (client/src/pages/JobDiscoveryPage.tsx:211)"}, "fullDescription": {"text": "`client/src/pages/JobDiscoveryPage.tsx:211` calls `GET /api/job-discovery/export?${params}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/job-discovery/export`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fe064476d69a4333", "name": "Dangling fetch: GET /api/job-discovery/export?${params} (client/src/pages/JobDiscoveryPage.tsx:249)", "shortDescription": {"text": "Dangling fetch: GET /api/job-discovery/export?${params} (client/src/pages/JobDiscoveryPage.tsx:249)"}, "fullDescription": {"text": "`client/src/pages/JobDiscoveryPage.tsx:249` calls `GET /api/job-discovery/export?${params}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/job-discovery/export`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bb008726810fd286", "name": "Dangling fetch: POST /api/practice/run (client/src/pages/PracticePage.tsx:154)", "shortDescription": {"text": "Dangling fetch: POST /api/practice/run (client/src/pages/PracticePage.tsx:154)"}, "fullDescription": {"text": "`client/src/pages/PracticePage.tsx:154` calls `POST /api/practice/run` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/practice/run`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a56a9984d606f03e", "name": "Dangling fetch: POST https://oauth2.googleapis.com/token (server/src/routes/auth.ts:82)", "shortDescription": {"text": "Dangling fetch: POST https://oauth2.googleapis.com/token (server/src/routes/auth.ts:82)"}, "fullDescription": {"text": "`server/src/routes/auth.ts:82` calls `POST https://oauth2.googleapis.com/token` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/oauth2.googleapis.com/token`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b3a2cd2e84fa36b5", "name": "Dangling fetch: GET https://www.googleapis.com/oauth2/v2/userinfo (server/src/routes/auth.ts:88)", "shortDescription": {"text": "Dangling fetch: GET https://www.googleapis.com/oauth2/v2/userinfo (server/src/routes/auth.ts:88)"}, "fullDescription": {"text": "`server/src/routes/auth.ts:88` calls `GET https://www.googleapis.com/oauth2/v2/userinfo` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/www.googleapis.com/oauth2/v2/userinfo`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-df7dbfa43984ca75", "name": "Dangling fetch: GET https://jsearch.p.rapidapi.com/search?${params} (server/src/routes/jobDiscovery.ts:48)", "shortDescription": {"text": "Dangling fetch: GET https://jsearch.p.rapidapi.com/search?${params} (server/src/routes/jobDiscovery.ts:48)"}, "fullDescription": {"text": "`server/src/routes/jobDiscovery.ts:48` calls `GET https://jsearch.p.rapidapi.com/search?${params}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/jsearch.p.rapidapi.com/search`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9d56bbf3b9370eec", "name": "Dangling fetch: POST https://judge0-ce.p.rapidapi.com/submissions?base64_encoded=false&wait=true (server/src/routes/prac", "shortDescription": {"text": "Dangling fetch: POST https://judge0-ce.p.rapidapi.com/submissions?base64_encoded=false&wait=true (server/src/routes/practice.ts:32)"}, "fullDescription": {"text": "`server/src/routes/practice.ts:32` calls `POST https://judge0-ce.p.rapidapi.com/submissions?base64_encoded=false&wait=true` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/judge0-ce.p.rapidapi.com/submissions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fc42d1fbc91b3d7e", "name": "Dangling fetch: POST https://wandbox.org/api/compile.json (server/src/routes/practice.ts:92)", "shortDescription": {"text": "Dangling fetch: POST https://wandbox.org/api/compile.json (server/src/routes/practice.ts:92)"}, "fullDescription": {"text": "`server/src/routes/practice.ts:92` calls `POST https://wandbox.org/api/compile.json` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/wandbox.org/api/compile.json`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ed802b739c77fffe", "name": "Dangling fetch: GET https://leetcode.com/api/problems/all/ (server/src/routes/practice.ts:337)", "shortDescription": {"text": "Dangling fetch: GET https://leetcode.com/api/problems/all/ (server/src/routes/practice.ts:337)"}, "fullDescription": {"text": "`server/src/routes/practice.ts:337` calls `GET https://leetcode.com/api/problems/all/` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/leetcode.com/api/problems/all`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9a2e16fc569c2b1a", "name": "Dangling fetch: POST https://leetcode.com/graphql (server/src/routes/practice.ts:391)", "shortDescription": {"text": "Dangling fetch: POST https://leetcode.com/graphql (server/src/routes/practice.ts:391)"}, "fullDescription": {"text": "`server/src/routes/practice.ts:391` calls `POST https://leetcode.com/graphql` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/leetcode.com/graphql`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-137679e170c7f5bc", "name": "Dangling fetch: POST https://leetcode.com/graphql (server/src/routes/practice.ts:497)", "shortDescription": {"text": "Dangling fetch: POST https://leetcode.com/graphql (server/src/routes/practice.ts:497)"}, "fullDescription": {"text": "`server/src/routes/practice.ts:497` calls `POST https://leetcode.com/graphql` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/leetcode.com/graphql`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fac3ec5b71e756ec", "name": "Unused endpoint: POST /assistant/chat", "shortDescription": {"text": "Unused endpoint: POST /assistant/chat"}, "fullDescription": {"text": "`client/src/components/AssistantWidget.tsx` declares `POST /assistant/chat` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6066e63cf1a3e82a", "name": "Unused endpoint: GET /dashboard/notifications", "shortDescription": {"text": "Unused endpoint: GET /dashboard/notifications"}, "fullDescription": {"text": "`client/src/components/layout/TopBar.tsx` declares `GET /dashboard/notifications` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8e0470eac79d157b", "name": "Unused endpoint: PATCH /dashboard/notifications/read-all", "shortDescription": {"text": "Unused endpoint: PATCH /dashboard/notifications/read-all"}, "fullDescription": {"text": "`client/src/components/layout/TopBar.tsx` declares `PATCH /dashboard/notifications/read-all` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-904e7dedc4c1f0dc", "name": "Unused endpoint: GET /interviews/sessions", "shortDescription": {"text": "Unused endpoint: GET /interviews/sessions"}, "fullDescription": {"text": "`client/src/pages/MockInterviewPage.tsx` declares `GET /interviews/sessions` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-46278aec40fd51f4", "name": "Unused endpoint: POST /interviews/sessions", "shortDescription": {"text": "Unused endpoint: POST /interviews/sessions"}, "fullDescription": {"text": "`client/src/pages/MockInterviewPage.tsx` declares `POST /interviews/sessions` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-803d84878b712404", "name": "Unused endpoint: GET /compliance", "shortDescription": {"text": "Unused endpoint: GET /compliance"}, "fullDescription": {"text": "`client/src/pages/CompliancePage.tsx` declares `GET /compliance` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5e9597b7d0e8276f", "name": "Unused endpoint: POST /compliance", "shortDescription": {"text": "Unused endpoint: POST /compliance"}, "fullDescription": {"text": "`client/src/pages/CompliancePage.tsx` declares `POST /compliance` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e5f2f73e982e17a9", "name": "Unused endpoint: PATCH /compliance/unemployment-days", "shortDescription": {"text": "Unused endpoint: PATCH /compliance/unemployment-days"}, "fullDescription": {"text": "`client/src/pages/CompliancePage.tsx` declares `PATCH /compliance/unemployment-days` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-de2e1f7e3f2e029a", "name": "Unused endpoint: GET /resume/history", "shortDescription": {"text": "Unused endpoint: GET /resume/history"}, "fullDescription": {"text": "`client/src/pages/ResumePage.tsx` declares `GET /resume/history` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e50fe10b22bec1f2", "name": "Unused endpoint: POST /resume/optimize", "shortDescription": {"text": "Unused endpoint: POST /resume/optimize"}, "fullDescription": {"text": "`client/src/pages/ResumePage.tsx` declares `POST /resume/optimize` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8fdbacfe9430a6ed", "name": "Unused endpoint: POST /auth/login", "shortDescription": {"text": "Unused endpoint: POST /auth/login"}, "fullDescription": {"text": "`client/src/pages/LandingPage.tsx` declares `POST /auth/login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-00817d7995e674fb", "name": "Unused endpoint: PATCH /auth/profile", "shortDescription": {"text": "Unused endpoint: PATCH /auth/profile"}, "fullDescription": {"text": "`client/src/pages/ProfilePage.tsx` declares `PATCH /auth/profile` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d8c2194dcb2086df", "name": "Unused endpoint: POST /auth/linkedin-import", "shortDescription": {"text": "Unused endpoint: POST /auth/linkedin-import"}, "fullDescription": {"text": "`client/src/pages/ProfilePage.tsx` declares `POST /auth/linkedin-import` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5a228d9780e42199", "name": "Unused endpoint: POST /jobs/parse-voice", "shortDescription": {"text": "Unused endpoint: POST /jobs/parse-voice"}, "fullDescription": {"text": "`client/src/pages/JobsPage.tsx` declares `POST /jobs/parse-voice` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1008c575819b3d37", "name": "Unused endpoint: GET /jobs", "shortDescription": {"text": "Unused endpoint: GET /jobs"}, "fullDescription": {"text": "`client/src/pages/JobsPage.tsx` declares `GET /jobs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d177f796b0e92b79", "name": "Unused endpoint: GET /jobs/analytics", "shortDescription": {"text": "Unused endpoint: GET /jobs/analytics"}, "fullDescription": {"text": "`client/src/pages/JobsPage.tsx` declares `GET /jobs/analytics` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2b73face5b06aa67", "name": "Unused endpoint: POST /jobs", "shortDescription": {"text": "Unused endpoint: POST /jobs"}, "fullDescription": {"text": "`client/src/pages/JobsPage.tsx` declares `POST /jobs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b518bbfdf15058c8", "name": "Unused endpoint: POST /jobs/assistant", "shortDescription": {"text": "Unused endpoint: POST /jobs/assistant"}, "fullDescription": {"text": "`client/src/pages/JobsPage.tsx` declares `POST /jobs/assistant` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dd159bd05997c05c", "name": "Unused endpoint: GET /admin/stats", "shortDescription": {"text": "Unused endpoint: GET /admin/stats"}, "fullDescription": {"text": "`client/src/pages/AdminPage.tsx` declares `GET /admin/stats` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0aba7f1883cb96f2", "name": "Unused endpoint: GET /admin/users", "shortDescription": {"text": "Unused endpoint: GET /admin/users"}, "fullDescription": {"text": "`client/src/pages/AdminPage.tsx` declares `GET /admin/users` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-09cfebff1cf5669e", "name": "Unused endpoint: POST /salary/assistant", "shortDescription": {"text": "Unused endpoint: POST /salary/assistant"}, "fullDescription": {"text": "`client/src/pages/SalaryPage.tsx` declares `POST /salary/assistant` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3fa047fb5e45b0d1", "name": "Unused endpoint: GET /salary/insights", "shortDescription": {"text": "Unused endpoint: GET /salary/insights"}, "fullDescription": {"text": "`client/src/pages/SalaryPage.tsx` declares `GET /salary/insights` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-19be12423dc53fb3", "name": "Unused endpoint: GET /salary/compare", "shortDescription": {"text": "Unused endpoint: GET /salary/compare"}, "fullDescription": {"text": "`client/src/pages/SalaryPage.tsx` declares `GET /salary/compare` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a35ce3e9c9f59e0a", "name": "Unused endpoint: GET /companies", "shortDescription": {"text": "Unused endpoint: GET /companies"}, "fullDescription": {"text": "`client/src/pages/CompaniesPage.tsx` declares `GET /companies` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c6e3d34a74a121c", "name": "Unused endpoint: GET /community/discover", "shortDescription": {"text": "Unused endpoint: GET /community/discover"}, "fullDescription": {"text": "`client/src/pages/CommunityPage.tsx` declares `GET /community/discover` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-92f7c540cc9dc25e", "name": "Unused endpoint: GET /community/connections", "shortDescription": {"text": "Unused endpoint: GET /community/connections"}, "fullDescription": {"text": "`client/src/pages/CommunityPage.tsx` declares `GET /community/connections` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d7f8d598ed733689", "name": "Unused endpoint: GET /community/pending", "shortDescription": {"text": "Unused endpoint: GET /community/pending"}, "fullDescription": {"text": "`client/src/pages/CommunityPage.tsx` declares `GET /community/pending` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-80b5012653b3ba9e", "name": "Unused endpoint: POST /community/connect", "shortDescription": {"text": "Unused endpoint: POST /community/connect"}, "fullDescription": {"text": "`client/src/pages/CommunityPage.tsx` declares `POST /community/connect` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-deddea033ccbb846", "name": "Unused endpoint: GET /job-discovery/search", "shortDescription": {"text": "Unused endpoint: GET /job-discovery/search"}, "fullDescription": {"text": "`client/src/pages/JobDiscoveryPage.tsx` declares `GET /job-discovery/search` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-06e37f97b1c0ccac", "name": "Unused endpoint: GET /job-discovery/trending", "shortDescription": {"text": "Unused endpoint: GET /job-discovery/trending"}, "fullDescription": {"text": "`client/src/pages/JobDiscoveryPage.tsx` declares `GET /job-discovery/trending` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-493bc441cd6c4e07", "name": "Unused endpoint: GET /referrals", "shortDescription": {"text": "Unused endpoint: GET /referrals"}, "fullDescription": {"text": "`client/src/pages/ReferralsPage.tsx` declares `GET /referrals` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7f4b85af222c2902", "name": "Unused endpoint: GET /referrals/stats", "shortDescription": {"text": "Unused endpoint: GET /referrals/stats"}, "fullDescription": {"text": "`client/src/pages/ReferralsPage.tsx` declares `GET /referrals/stats` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6707b5ad8e4cecc5", "name": "Unused endpoint: POST /referrals/generate", "shortDescription": {"text": "Unused endpoint: POST /referrals/generate"}, "fullDescription": {"text": "`client/src/pages/ReferralsPage.tsx` declares `POST /referrals/generate` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-39769fc22715dac8", "name": "Unused endpoint: POST /referrals", "shortDescription": {"text": "Unused endpoint: POST /referrals"}, "fullDescription": {"text": "`client/src/pages/ReferralsPage.tsx` declares `POST /referrals` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d504b80adc9409ec", "name": "Unused endpoint: GET /dashboard", "shortDescription": {"text": "Unused endpoint: GET /dashboard"}, "fullDescription": {"text": "`client/src/pages/DashboardPage.tsx` declares `GET /dashboard` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f22b2880ee0bfd44", "name": "Unused endpoint: GET /news", "shortDescription": {"text": "Unused endpoint: GET /news"}, "fullDescription": {"text": "`client/src/pages/DashboardPage.tsx` declares `GET /news` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-695b02b863b76467", "name": "Unused endpoint: GET /dashboard/today-plan", "shortDescription": {"text": "Unused endpoint: GET /dashboard/today-plan"}, "fullDescription": {"text": "`client/src/pages/DashboardPage.tsx` declares `GET /dashboard/today-plan` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4170cd9a9b08a23d", "name": "Unused endpoint: POST /networking/recruiter-outreach/generate", "shortDescription": {"text": "Unused endpoint: POST /networking/recruiter-outreach/generate"}, "fullDescription": {"text": "`client/src/pages/NetworkingPage.tsx` declares `POST /networking/recruiter-outreach/generate` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2b9c7b06b7b684bf", "name": "Unused endpoint: POST /networking/recruiter-outreach", "shortDescription": {"text": "Unused endpoint: POST /networking/recruiter-outreach"}, "fullDescription": {"text": "`client/src/pages/NetworkingPage.tsx` declares `POST /networking/recruiter-outreach` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7f91db6c85c54ede", "name": "Unused endpoint: GET /networking/recruiter-outreach", "shortDescription": {"text": "Unused endpoint: GET /networking/recruiter-outreach"}, "fullDescription": {"text": "`client/src/pages/NetworkingPage.tsx` declares `GET /networking/recruiter-outreach` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1e60177584c50039", "name": "Unused endpoint: GET /practice/topics", "shortDescription": {"text": "Unused endpoint: GET /practice/topics"}, "fullDescription": {"text": "`client/src/pages/PracticePage.tsx` declares `GET /practice/topics` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-62417c6ab500c8af", "name": "Unused endpoint: GET /practice/problems", "shortDescription": {"text": "Unused endpoint: GET /practice/problems"}, "fullDescription": {"text": "`client/src/pages/PracticePage.tsx` declares `GET /practice/problems` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bffdd4755bc0ad8b", "name": "Unused endpoint: GET /assistant/conversations", "shortDescription": {"text": "Unused endpoint: GET /assistant/conversations"}, "fullDescription": {"text": "`client/src/pages/AssistantPage.tsx` declares `GET /assistant/conversations` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-60f31fa379ce3a8d", "name": "Unused endpoint: GET /assistant/status", "shortDescription": {"text": "Unused endpoint: GET /assistant/status"}, "fullDescription": {"text": "`client/src/pages/AssistantPage.tsx` declares `GET /assistant/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-832ba7039fcaa3ae", "name": "Unused endpoint: GET /dashboard/analytics", "shortDescription": {"text": "Unused endpoint: GET /dashboard/analytics"}, "fullDescription": {"text": "`client/src/pages/AnalyticsPage.tsx` declares `GET /dashboard/analytics` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6193d4fdbd666ca7", "name": "Unused endpoint: GET /auth/providers", "shortDescription": {"text": "Unused endpoint: GET /auth/providers"}, "fullDescription": {"text": "`client/src/pages/auth/LoginPage.tsx` declares `GET /auth/providers` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ac42422b23e45104", "name": "Unused endpoint: GET /auth/me", "shortDescription": {"text": "Unused endpoint: GET /auth/me"}, "fullDescription": {"text": "`client/src/pages/auth/AuthCallbackPage.tsx` declares `GET /auth/me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8292c0931391749a", "name": "Unused endpoint: POST /auth/register", "shortDescription": {"text": "Unused endpoint: POST /auth/register"}, "fullDescription": {"text": "`client/src/pages/auth/RegisterPage.tsx` declares `POST /auth/register` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dde3adb27bf7eebe", "name": "Unused endpoint: USE /api", "shortDescription": {"text": "Unused endpoint: USE /api"}, "fullDescription": {"text": "`server/src/app.ts` declares `USE /api` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8bf2f7ca3faa1f1b", "name": "Unused endpoint: USE /api/auth/login", "shortDescription": {"text": "Unused endpoint: USE /api/auth/login"}, "fullDescription": {"text": "`server/src/app.ts` declares `USE /api/auth/login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/22220"}, "properties": {"repository": "VIGNESHREDDY25/F1-FORGE", "repoUrl": "https://github.com/VIGNESHREDDY25/F1-FORGE", "branch": "main"}, "results": [{"ruleId": "scanner-ff03e3e471f7df3c", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 client/src/components/layout/Sidebar.tsx:86"}, "properties": {"repobilityId": "0a855d90bdcce40b", "scanner": "scanner-primary", "fingerprint": "ff03e3e471f7df3c", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-f13a5a87083d170d", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 client/src/pages/JobsPage.tsx:304"}, "properties": {"repobilityId": "d12e250a808c7a35", "scanner": "scanner-primary", "fingerprint": "f13a5a87083d170d", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-9106d8c5c4fb4652", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 client/src/pages/AdminPage.tsx:68"}, "properties": {"repobilityId": "3a7827d0ff7efd2b", "scanner": "scanner-primary", "fingerprint": "9106d8c5c4fb4652", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-4caa75d2b8c81f08", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 client/src/pages/SalaryPage.tsx:198"}, "properties": {"repobilityId": "ad7126d9ec909347", "scanner": "scanner-primary", "fingerprint": "4caa75d2b8c81f08", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-f081989a5e129c72", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 client/src/pages/CommunityPage.tsx:230"}, "properties": {"repobilityId": "b3b29b6b3dca4e5c", "scanner": "scanner-primary", "fingerprint": "f081989a5e129c72", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-978be9fc27a5e290", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 client/src/pages/JobDiscoveryPage.tsx:673"}, "properties": {"repobilityId": "11307331018e6880", "scanner": "scanner-primary", "fingerprint": "978be9fc27a5e290", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-0c0ae03863de1d48", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 client/src/pages/DashboardPage.tsx:252"}, "properties": {"repobilityId": "a0af6ecfaf885e8b", "scanner": "scanner-primary", "fingerprint": "0c0ae03863de1d48", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-519a74c278c41a29", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 client/src/pages/NetworkingPage.tsx:189"}, "properties": {"repobilityId": "653d8e58964feed7", "scanner": "scanner-primary", "fingerprint": "519a74c278c41a29", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-5d5cc87f49730f54", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 client/src/pages/PracticePage.tsx:328"}, "properties": {"repobilityId": "6a756f532f93ed7c", "scanner": "scanner-primary", "fingerprint": "5d5cc87f49730f54", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-9814a26a16a6cb7f", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 client/src/pages/AssistantPage.tsx:117"}, "properties": {"repobilityId": "20d7d3a26b310ab0", "scanner": "scanner-primary", "fingerprint": "9814a26a16a6cb7f", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-ca50c3a5f3f7bda0", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 server/src/index.ts:12"}, "properties": {"repobilityId": "966123b8e19cb728", "scanner": "scanner-primary", "fingerprint": "ca50c3a5f3f7bda0", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-541ad5988014a2a0", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 server/src/services/scheduler.ts:67"}, "properties": {"repobilityId": "534cee8bf5667054", "scanner": "scanner-primary", "fingerprint": "541ad5988014a2a0", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2c1b1ba305b21c9f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 server/src/db/seed.ts:31"}, "properties": {"repobilityId": "777f1a7bcffd5332", "scanner": "scanner-primary", "fingerprint": "2c1b1ba305b21c9f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-65b7ae5ac9812864", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 server/src/db/store.ts:82"}, "properties": {"repobilityId": "91a82adbd9a37bb7", "scanner": "scanner-primary", "fingerprint": "65b7ae5ac9812864", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3b83e442397d76a0", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 server/src/db/migrate.ts:11"}, "properties": {"repobilityId": "70f5a999533eb73c", "scanner": "scanner-primary", "fingerprint": "3b83e442397d76a0", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b69f45b2dcff8d24", "level": "warning", "message": {"text": "Dockerfile runs as root: server/Dockerfile"}, "properties": {"repobilityId": "4600ca3b571a3f30", "scanner": "scanner-primary", "fingerprint": "b69f45b2dcff8d24", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-d7158aa1e38492c6", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine"}, "properties": {"repobilityId": "d4a273007cd8368b", "scanner": "scanner-primary", "fingerprint": "d7158aa1e38492c6", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "server/Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-8e6af304ca7abc20", "level": "error", "message": {"text": "Possible secret in client/src/pages/LandingPage.tsx"}, "properties": {"repobilityId": "4c68ad0c4ff60c22", "scanner": "scanner-primary", "fingerprint": "8e6af304ca7abc20", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "client/src/pages/LandingPage.tsx"}, "region": {"startLine": 43}}}]}, {"ruleId": "scanner-d904226e520b2725", "level": "error", "message": {"text": "Insecure pattern 'new_function_used' in client/src/pages/PracticePage.tsx:31"}, "properties": {"repobilityId": "c98b2673874d239c", "scanner": "scanner-primary", "fingerprint": "d904226e520b2725", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "new_function_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "client/src/pages/PracticePage.tsx"}, "region": {"startLine": 31}}}]}, {"ruleId": "scanner-e65335aff36f727c", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in client/src/pages/PracticePage.tsx:328"}, "properties": {"repobilityId": "fd50616050beab36", "scanner": "scanner-primary", "fingerprint": "e65335aff36f727c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "client/src/pages/PracticePage.tsx"}, "region": {"startLine": 328}}}]}, {"ruleId": "scanner-420d2fb05f1517f2", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in server/src/routes/practice.ts:108"}, "properties": {"repobilityId": "31304473dba15c4f", "scanner": "scanner-primary", "fingerprint": "420d2fb05f1517f2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "server/src/routes/practice.ts"}, "region": {"startLine": 108}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "673917c9622f654f", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 58}}}]}, {"ruleId": "scanner-5a91683e7a61ef34", "level": "note", "message": {"text": "Very large file: client/src/pages/JobDiscoveryPage.tsx (1179 lines)"}, "properties": {"repobilityId": "7ec9ec89982f6750", "scanner": "scanner-primary", "fingerprint": "5a91683e7a61ef34", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-f672f9974244469a", "level": "note", "message": {"text": "Very large file: server/src/routes/jobDiscovery.ts (803 lines)"}, "properties": {"repobilityId": "57ce9e5da059fcb1", "scanner": "scanner-primary", "fingerprint": "f672f9974244469a", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "6e8a7255c652f4c1", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-1a6aeb84f8544549", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: client/package.json"}, "properties": {"repobilityId": "289cda4e29a77d84", "scanner": "scanner-primary", "fingerprint": "1a6aeb84f8544549", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "client/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d7101ca1926e3342", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: server/package.json"}, "properties": {"repobilityId": "bbcd0a89809ced91", "scanner": "scanner-primary", "fingerprint": "d7101ca1926e3342", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "a86ccb84f47e1908", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "0d204f1b6507a9d3", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-9d79c4077342a7d0", "level": "warning", "message": {"text": "Runtime service client appears to use placeholder configuration"}, "properties": {"repobilityId": "f3a256d39766344f", "scanner": "scanner-primary", "fingerprint": "9d79c4077342a7d0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "runtime-config", "service-client", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "0fcb090fc761e70b", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "8f39e3961498bae4", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "7ddf5ed49c5b696b", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "3b002ecc4c6c3cd2", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-dbd5d6435eeeca8e", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 client/src/pages/JobDiscoveryPage.tsx:211"}, "properties": {"repobilityId": "304bedc9270040ef", "scanner": "scanner-primary", "fingerprint": "dbd5d6435eeeca8e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-6d4fd24ccce854aa", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/src/routes/auth.ts:88"}, "properties": {"repobilityId": "344f3e6ac8895233", "scanner": "scanner-primary", "fingerprint": "6d4fd24ccce854aa", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-c6605b54609bf280", "level": "none", "message": {"text": "Commented-code block (8 lines) in server/src/routes/jobDiscovery.ts:529"}, "properties": {"repobilityId": "6d255e3a5ecee7fe", "scanner": "scanner-primary", "fingerprint": "c6605b54609bf280", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3482f7e5dd70cd1a", "level": "note", "message": {"text": "6 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "1da70f25aa46f6e9", "scanner": "scanner-primary", "fingerprint": "3482f7e5dd70cd1a", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-5766dc24db809018", "level": "warning", "message": {"text": "Frontend route `/auth/callback` has no Link/navigate to it \u2014 client/src/App.tsx"}, "properties": {"repobilityId": "d4afad919f54f362", "scanner": "scanner-primary", "fingerprint": "5766dc24db809018", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-7d2d565659fb154a", "level": "warning", "message": {"text": "Frontend route `/analytics` has no Link/navigate to it \u2014 client/src/App.tsx"}, "properties": {"repobilityId": "cc9f3ce0b0de89e8", "scanner": "scanner-primary", "fingerprint": "7d2d565659fb154a", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-94470e34d48279c9", "level": "warning", "message": {"text": "Frontend route `/salary` has no Link/navigate to it \u2014 client/src/App.tsx"}, "properties": {"repobilityId": "b4d310ce44cf5ff2", "scanner": "scanner-primary", "fingerprint": "94470e34d48279c9", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-949f18d509bc250d", "level": "warning", "message": {"text": "Frontend route `/companies` has no Link/navigate to it \u2014 client/src/App.tsx"}, "properties": {"repobilityId": "b33f41aeed83c361", "scanner": "scanner-primary", "fingerprint": "949f18d509bc250d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-a16eb53a8e4350e7", "level": "error", "message": {"text": "Dangling fetch: POST /api/resume/tailor (client/src/pages/ResumePage.tsx:171)"}, "properties": {"repobilityId": "44c462ec926e518c", "scanner": "scanner-primary", "fingerprint": "a16eb53a8e4350e7", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-85efd92cb5db05b4", "level": "error", "message": {"text": "Dangling fetch: GET /api/job-discovery/export?${params} (client/src/pages/JobDiscoveryPage.tsx:211)"}, "properties": {"repobilityId": "5784aca360629b96", "scanner": "scanner-primary", "fingerprint": "85efd92cb5db05b4", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-fe064476d69a4333", "level": "error", "message": {"text": "Dangling fetch: GET /api/job-discovery/export?${params} (client/src/pages/JobDiscoveryPage.tsx:249)"}, "properties": {"repobilityId": "a3ac01398722e68d", "scanner": "scanner-primary", "fingerprint": "fe064476d69a4333", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-bb008726810fd286", "level": "error", "message": {"text": "Dangling fetch: POST /api/practice/run (client/src/pages/PracticePage.tsx:154)"}, "properties": {"repobilityId": "b02433ebb82b983b", "scanner": "scanner-primary", "fingerprint": "bb008726810fd286", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-a56a9984d606f03e", "level": "error", "message": {"text": "Dangling fetch: POST https://oauth2.googleapis.com/token (server/src/routes/auth.ts:82)"}, "properties": {"repobilityId": "f36bb044afa6cbae", "scanner": "scanner-primary", "fingerprint": "a56a9984d606f03e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-b3a2cd2e84fa36b5", "level": "error", "message": {"text": "Dangling fetch: GET https://www.googleapis.com/oauth2/v2/userinfo (server/src/routes/auth.ts:88)"}, "properties": {"repobilityId": "4a71a326ad63be1d", "scanner": "scanner-primary", "fingerprint": "b3a2cd2e84fa36b5", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-df7dbfa43984ca75", "level": "error", "message": {"text": "Dangling fetch: GET https://jsearch.p.rapidapi.com/search?${params} (server/src/routes/jobDiscovery.ts:48)"}, "properties": {"repobilityId": "7ab847b17e98565f", "scanner": "scanner-primary", "fingerprint": "df7dbfa43984ca75", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-9d56bbf3b9370eec", "level": "error", "message": {"text": "Dangling fetch: POST https://judge0-ce.p.rapidapi.com/submissions?base64_encoded=false&wait=true (server/src/routes/practice.ts:32)"}, "properties": {"repobilityId": "6c66849407482ba9", "scanner": "scanner-primary", "fingerprint": "9d56bbf3b9370eec", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-fc42d1fbc91b3d7e", "level": "error", "message": {"text": "Dangling fetch: POST https://wandbox.org/api/compile.json (server/src/routes/practice.ts:92)"}, "properties": {"repobilityId": "1ea2935e6b1b244f", "scanner": "scanner-primary", "fingerprint": "fc42d1fbc91b3d7e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-ed802b739c77fffe", "level": "error", "message": {"text": "Dangling fetch: GET https://leetcode.com/api/problems/all/ (server/src/routes/practice.ts:337)"}, "properties": {"repobilityId": "fc9aa2d488df1369", "scanner": "scanner-primary", "fingerprint": "ed802b739c77fffe", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-9a2e16fc569c2b1a", "level": "error", "message": {"text": "Dangling fetch: POST https://leetcode.com/graphql (server/src/routes/practice.ts:391)"}, "properties": {"repobilityId": "e468da06375c4c54", "scanner": "scanner-primary", "fingerprint": "9a2e16fc569c2b1a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-137679e170c7f5bc", "level": "error", "message": {"text": "Dangling fetch: POST https://leetcode.com/graphql (server/src/routes/practice.ts:497)"}, "properties": {"repobilityId": "9c5c2427cb170662", "scanner": "scanner-primary", "fingerprint": "137679e170c7f5bc", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-fac3ec5b71e756ec", "level": "note", "message": {"text": "Unused endpoint: POST /assistant/chat"}, "properties": {"repobilityId": "c41fd67ecead8270", "scanner": "scanner-primary", "fingerprint": "fac3ec5b71e756ec", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6066e63cf1a3e82a", "level": "note", "message": {"text": "Unused endpoint: GET /dashboard/notifications"}, "properties": {"repobilityId": "715964e07e13a112", "scanner": "scanner-primary", "fingerprint": "6066e63cf1a3e82a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8e0470eac79d157b", "level": "note", "message": {"text": "Unused endpoint: PATCH /dashboard/notifications/read-all"}, "properties": {"repobilityId": "9d8efa3adccad0d9", "scanner": "scanner-primary", "fingerprint": "8e0470eac79d157b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-904e7dedc4c1f0dc", "level": "note", "message": {"text": "Unused endpoint: GET /interviews/sessions"}, "properties": {"repobilityId": "1d4d4ee85affedad", "scanner": "scanner-primary", "fingerprint": "904e7dedc4c1f0dc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-46278aec40fd51f4", "level": "note", "message": {"text": "Unused endpoint: POST /interviews/sessions"}, "properties": {"repobilityId": "e842143ffd51cf91", "scanner": "scanner-primary", "fingerprint": "46278aec40fd51f4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-803d84878b712404", "level": "note", "message": {"text": "Unused endpoint: GET /compliance"}, "properties": {"repobilityId": "6fd65da65a720e33", "scanner": "scanner-primary", "fingerprint": "803d84878b712404", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5e9597b7d0e8276f", "level": "note", "message": {"text": "Unused endpoint: POST /compliance"}, "properties": {"repobilityId": "562076123ddf6e41", "scanner": "scanner-primary", "fingerprint": "5e9597b7d0e8276f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e5f2f73e982e17a9", "level": "note", "message": {"text": "Unused endpoint: PATCH /compliance/unemployment-days"}, "properties": {"repobilityId": "e27d43aa8bdce53c", "scanner": "scanner-primary", "fingerprint": "e5f2f73e982e17a9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-de2e1f7e3f2e029a", "level": "note", "message": {"text": "Unused endpoint: GET /resume/history"}, "properties": {"repobilityId": "6a4d27cc63b474c8", "scanner": "scanner-primary", "fingerprint": "de2e1f7e3f2e029a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e50fe10b22bec1f2", "level": "note", "message": {"text": "Unused endpoint: POST /resume/optimize"}, "properties": {"repobilityId": "c8a34d11e98ad619", "scanner": "scanner-primary", "fingerprint": "e50fe10b22bec1f2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8fdbacfe9430a6ed", "level": "note", "message": {"text": "Unused endpoint: POST /auth/login"}, "properties": {"repobilityId": "65dc7bd5edc5168d", "scanner": "scanner-primary", "fingerprint": "8fdbacfe9430a6ed", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-00817d7995e674fb", "level": "note", "message": {"text": "Unused endpoint: PATCH /auth/profile"}, "properties": {"repobilityId": "b9d6210ca129a737", "scanner": "scanner-primary", "fingerprint": "00817d7995e674fb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d8c2194dcb2086df", "level": "note", "message": {"text": "Unused endpoint: POST /auth/linkedin-import"}, "properties": {"repobilityId": "1ef5f08a933b0bb8", "scanner": "scanner-primary", "fingerprint": "d8c2194dcb2086df", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5a228d9780e42199", "level": "note", "message": {"text": "Unused endpoint: POST /jobs/parse-voice"}, "properties": {"repobilityId": "e618a0c39d2e80c4", "scanner": "scanner-primary", "fingerprint": "5a228d9780e42199", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1008c575819b3d37", "level": "note", "message": {"text": "Unused endpoint: GET /jobs"}, "properties": {"repobilityId": "a114cd06bf002511", "scanner": "scanner-primary", "fingerprint": "1008c575819b3d37", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d177f796b0e92b79", "level": "note", "message": {"text": "Unused endpoint: GET /jobs/analytics"}, "properties": {"repobilityId": "b3fe929bf1eca944", "scanner": "scanner-primary", "fingerprint": "d177f796b0e92b79", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2b73face5b06aa67", "level": "note", "message": {"text": "Unused endpoint: POST /jobs"}, "properties": {"repobilityId": "34bcf5d7b9b722ec", "scanner": "scanner-primary", "fingerprint": "2b73face5b06aa67", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b518bbfdf15058c8", "level": "note", "message": {"text": "Unused endpoint: POST /jobs/assistant"}, "properties": {"repobilityId": "cad4024227228c56", "scanner": "scanner-primary", "fingerprint": "b518bbfdf15058c8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dd159bd05997c05c", "level": "note", "message": {"text": "Unused endpoint: GET /admin/stats"}, "properties": {"repobilityId": "e3d614344ec0c249", "scanner": "scanner-primary", "fingerprint": "dd159bd05997c05c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0aba7f1883cb96f2", "level": "note", "message": {"text": "Unused endpoint: GET /admin/users"}, "properties": {"repobilityId": "b5543fc33be0b41a", "scanner": "scanner-primary", "fingerprint": "0aba7f1883cb96f2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-09cfebff1cf5669e", "level": "note", "message": {"text": "Unused endpoint: POST /salary/assistant"}, "properties": {"repobilityId": "70804d8527a0cc54", "scanner": "scanner-primary", "fingerprint": "09cfebff1cf5669e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3fa047fb5e45b0d1", "level": "note", "message": {"text": "Unused endpoint: GET /salary/insights"}, "properties": {"repobilityId": "078ff00551471705", "scanner": "scanner-primary", "fingerprint": "3fa047fb5e45b0d1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-19be12423dc53fb3", "level": "note", "message": {"text": "Unused endpoint: GET /salary/compare"}, "properties": {"repobilityId": "750b11b1c2484a5f", "scanner": "scanner-primary", "fingerprint": "19be12423dc53fb3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a35ce3e9c9f59e0a", "level": "note", "message": {"text": "Unused endpoint: GET /companies"}, "properties": {"repobilityId": "a1ff38d3f60383ec", "scanner": "scanner-primary", "fingerprint": "a35ce3e9c9f59e0a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2c6e3d34a74a121c", "level": "note", "message": {"text": "Unused endpoint: GET /community/discover"}, "properties": {"repobilityId": "dddec02b5f9454c9", "scanner": "scanner-primary", "fingerprint": "2c6e3d34a74a121c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-92f7c540cc9dc25e", "level": "note", "message": {"text": "Unused endpoint: GET /community/connections"}, "properties": {"repobilityId": "e5b8a04ada82b5ec", "scanner": "scanner-primary", "fingerprint": "92f7c540cc9dc25e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d7f8d598ed733689", "level": "note", "message": {"text": "Unused endpoint: GET /community/pending"}, "properties": {"repobilityId": "3ac021c595081d23", "scanner": "scanner-primary", "fingerprint": "d7f8d598ed733689", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-80b5012653b3ba9e", "level": "note", "message": {"text": "Unused endpoint: POST /community/connect"}, "properties": {"repobilityId": "e2712dceb2b1d791", "scanner": "scanner-primary", "fingerprint": "80b5012653b3ba9e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-deddea033ccbb846", "level": "note", "message": {"text": "Unused endpoint: GET /job-discovery/search"}, "properties": {"repobilityId": "d08e6cec4bfa54b1", "scanner": "scanner-primary", "fingerprint": "deddea033ccbb846", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-06e37f97b1c0ccac", "level": "note", "message": {"text": "Unused endpoint: GET /job-discovery/trending"}, "properties": {"repobilityId": "1741ad901bede396", "scanner": "scanner-primary", "fingerprint": "06e37f97b1c0ccac", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-493bc441cd6c4e07", "level": "note", "message": {"text": "Unused endpoint: GET /referrals"}, "properties": {"repobilityId": "1cd81a6882eecdc1", "scanner": "scanner-primary", "fingerprint": "493bc441cd6c4e07", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7f4b85af222c2902", "level": "note", "message": {"text": "Unused endpoint: GET /referrals/stats"}, "properties": {"repobilityId": "fb0cec2ca2437bb1", "scanner": "scanner-primary", "fingerprint": "7f4b85af222c2902", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6707b5ad8e4cecc5", "level": "note", "message": {"text": "Unused endpoint: POST /referrals/generate"}, "properties": {"repobilityId": "e88dd09db7120c88", "scanner": "scanner-primary", "fingerprint": "6707b5ad8e4cecc5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-39769fc22715dac8", "level": "note", "message": {"text": "Unused endpoint: POST /referrals"}, "properties": {"repobilityId": "ee254819d67685a3", "scanner": "scanner-primary", "fingerprint": "39769fc22715dac8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d504b80adc9409ec", "level": "note", "message": {"text": "Unused endpoint: GET /dashboard"}, "properties": {"repobilityId": "b8f3b011f532ae27", "scanner": "scanner-primary", "fingerprint": "d504b80adc9409ec", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f22b2880ee0bfd44", "level": "note", "message": {"text": "Unused endpoint: GET /news"}, "properties": {"repobilityId": "b1995c3e6c6cae1c", "scanner": "scanner-primary", "fingerprint": "f22b2880ee0bfd44", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-695b02b863b76467", "level": "note", "message": {"text": "Unused endpoint: GET /dashboard/today-plan"}, "properties": {"repobilityId": "30d1c0516362e33e", "scanner": "scanner-primary", "fingerprint": "695b02b863b76467", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4170cd9a9b08a23d", "level": "note", "message": {"text": "Unused endpoint: POST /networking/recruiter-outreach/generate"}, "properties": {"repobilityId": "7efdc9a4e8f29f8d", "scanner": "scanner-primary", "fingerprint": "4170cd9a9b08a23d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2b9c7b06b7b684bf", "level": "note", "message": {"text": "Unused endpoint: POST /networking/recruiter-outreach"}, "properties": {"repobilityId": "e6d973aef29399ac", "scanner": "scanner-primary", "fingerprint": "2b9c7b06b7b684bf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7f91db6c85c54ede", "level": "note", "message": {"text": "Unused endpoint: GET /networking/recruiter-outreach"}, "properties": {"repobilityId": "da3017a601c841c8", "scanner": "scanner-primary", "fingerprint": "7f91db6c85c54ede", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1e60177584c50039", "level": "note", "message": {"text": "Unused endpoint: GET /practice/topics"}, "properties": {"repobilityId": "079c2d390736a7b3", "scanner": "scanner-primary", "fingerprint": "1e60177584c50039", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-62417c6ab500c8af", "level": "note", "message": {"text": "Unused endpoint: GET /practice/problems"}, "properties": {"repobilityId": "2c8d56acc3d18153", "scanner": "scanner-primary", "fingerprint": "62417c6ab500c8af", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bffdd4755bc0ad8b", "level": "note", "message": {"text": "Unused endpoint: GET /assistant/conversations"}, "properties": {"repobilityId": "e919f2bde17f9cb0", "scanner": "scanner-primary", "fingerprint": "bffdd4755bc0ad8b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-60f31fa379ce3a8d", "level": "note", "message": {"text": "Unused endpoint: GET /assistant/status"}, "properties": {"repobilityId": "779a173e38343d61", "scanner": "scanner-primary", "fingerprint": "60f31fa379ce3a8d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-832ba7039fcaa3ae", "level": "note", "message": {"text": "Unused endpoint: GET /dashboard/analytics"}, "properties": {"repobilityId": "4e955ac70a06f66f", "scanner": "scanner-primary", "fingerprint": "832ba7039fcaa3ae", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6193d4fdbd666ca7", "level": "note", "message": {"text": "Unused endpoint: GET /auth/providers"}, "properties": {"repobilityId": "ff68162b519d081a", "scanner": "scanner-primary", "fingerprint": "6193d4fdbd666ca7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ac42422b23e45104", "level": "note", "message": {"text": "Unused endpoint: GET /auth/me"}, "properties": {"repobilityId": "0c02ef431f4abf0d", "scanner": "scanner-primary", "fingerprint": "ac42422b23e45104", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8292c0931391749a", "level": "note", "message": {"text": "Unused endpoint: POST /auth/register"}, "properties": {"repobilityId": "a48172c2e0162a6f", "scanner": "scanner-primary", "fingerprint": "8292c0931391749a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dde3adb27bf7eebe", "level": "note", "message": {"text": "Unused endpoint: USE /api"}, "properties": {"repobilityId": "b6c02166ba88fa20", "scanner": "scanner-primary", "fingerprint": "dde3adb27bf7eebe", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8bf2f7ca3faa1f1b", "level": "note", "message": {"text": "Unused endpoint: USE /api/auth/login"}, "properties": {"repobilityId": "ba99051dd3849037", "scanner": "scanner-primary", "fingerprint": "8bf2f7ca3faa1f1b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}