{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "foundry_blueprint_gap", "name": "Foundry mined blueprint gap alignment: TheAxiomFoundation/axiom-microsim", "shortDescription": {"text": "Foundry mined blueprint gap alignment: TheAxiomFoundation/axiom-microsim"}, "fullDescription": {"text": "Graph query export: Human feedback aligned with blueprint or architecture gaps\nQuery id: blueprint_gap_alignment\nQuery type: motif_query\nIntent: Curriculum-gap examples connecting issue threads to helicopter-view gaps.\nMotif: blueprint_gap_alignment\nTraining usage: curriculum_gap\nGraph gold label: weak_supervision_needs_review\nRepo: TheAxiomFoundation/axiom-microsim\nThread: TheAxiomFoundation/axiom-microsim#1\nEvidence:\nGraph motif: Human feedback aligns with blueprint or architecture gaps\nMotif id: blueprint_gap_alignment\nPolarity: mixed\nTraining usage: curriculum_gap\nSeverity: medium\nRepo: TheAxiomFoundation/axiom-microsim\nThread: TheAxiomFoundation/axiom-microsim#1\nGraph gold label: weak_supervision_needs_review\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: TheAxiomFoundation/axiom-microsim#1\nRepo: TheAxiomFoundation/axiom-microsim\nIssue/PR number: 1\nGraph consistency label: weak_supervision_needs_review\nNodes: 16\nEdges: 21\nNode types: {'link_quality': 4, 'commit':"}, "properties": {"scanner": "foundry_dataset", "category": "tech_debt", "severity": "medium", "confidence": 0.7, "cwe": "", "owasp": ""}}, {"id": "foundry_assumption_check", "name": "Foundry mined assumption checks: TheAxiomFoundation/axiom-microsim", "shortDescription": {"text": "Foundry mined assumption checks: TheAxiomFoundation/axiom-microsim"}, "fullDescription": {"text": "Comment chain pattern product: assumption_checks\nRepo: TheAxiomFoundation/axiom-microsim\nThread: TheAxiomFoundation/axiom-microsim#2\nOutcome: ambiguous_needs_more_evidence\nThread label: thread_has_human_issue_and_fix_context\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, link_quality_high_confidence, high_risk_human_feedback_label\nChain evidence:\nIssue/PR evidence chain: TheAxiomFoundation/axiom-microsim#2\nRepo: TheAxiomFoundation/axiom-microsim\nThread label: thread_has_human_issue_and_fix_context\nOutcome: ambiguous_needs_more_evidence\nComment count: 1\nLinked commit count: 1\nLinked CI commit count: 1\nLinked CI labels: {'ci_pending_or_incomplete': 1}\nChanged file count: 11\nLabels: {'runtime_failure': 1}\nPolarities: {'bad': 1}\nChanged file labels: {'test_or_ci': 2, 'source_or_other': 8, 'api_or_backend': 1}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-ca8695744c270d1c\",\n    \"kind\": \"pull_reques"}, "properties": {"scanner": "foundry_dataset", "category": "practices", "severity": "medium", "confidence": 0.62, "cwe": "", "owasp": ""}}, {"id": "foundry_test_ci_gap", "name": "Foundry mined test ci gap after feedback: TheAxiomFoundation/axiom-microsim", "shortDescription": {"text": "Foundry mined test ci gap after feedback: TheAxiomFoundation/axiom-microsim"}, "fullDescription": {"text": "Graph query export: Feedback exposes missing tests or CI\nQuery id: test_ci_gap_after_feedback\nQuery type: motif_query\nIntent: Hard negatives for feedback/fix chains without adequate guardrails.\nMotif: test_ci_gap_after_feedback\nTraining usage: hard_negative\nGraph gold label: weak_supervision_needs_review\nRepo: TheAxiomFoundation/axiom-microsim\nThread: TheAxiomFoundation/axiom-microsim#1\nEvidence:\nGraph motif: Feedback or fix context exposes missing test/CI guardrails\nMotif id: test_ci_gap_after_feedback\nPolarity: bad\nTraining usage: hard_negative\nSeverity: high\nRepo: TheAxiomFoundation/axiom-microsim\nThread: TheAxiomFoundation/axiom-microsim#1\nGraph gold label: weak_supervision_needs_review\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: TheAxiomFoundation/axiom-microsim#1\nRepo: TheAxiomFoundation/axiom-microsim\nIssue/PR number: 1\nGraph consistency label: weak_supervision_needs_review\nNodes: 16\nEdges: 21\nNode types: {'link_quality': 4, 'commit': 2, 'thread': 1, 'repo':"}, "properties": {"scanner": "foundry_dataset", "category": "testing", "severity": "high", "confidence": 0.78, "cwe": "", "owasp": ""}}, {"id": "scanner-7950d58feaa9185b", "name": "Possibly dead Python function: profile_co_snap", "shortDescription": {"text": "Possibly dead Python function: profile_co_snap"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3d7bf99e7bccfacf", "name": "Possibly dead Python function: profile_federal_income_tax", "shortDescription": {"text": "Possibly dead Python function: profile_federal_income_tax"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-68be99e417dfba7a", "name": "Possibly dead Python function: profile_federal_ctc", "shortDescription": {"text": "Possibly dead Python function: profile_federal_ctc"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bc92316686e1bccd", "name": "Possibly dead Python function: compare", "shortDescription": {"text": "Possibly dead Python function: compare"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d8dc1b23e0feae8e", "name": "Possibly dead Python function: aggregate", "shortDescription": {"text": "Possibly dead Python function: aggregate"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ced12e412cb8757a", "name": "Insecure pattern 'cors_wildcard' in axiom_microsim/server.py:131", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in axiom_microsim/server.py:131"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "3 test file(s) for 37 source file(s) (ratio 0.08). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 7 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4a631806a3667896", "name": "Commented-code block (5 lines) in modal_app.py:45", "shortDescription": {"text": "Commented-code block (5 lines) in modal_app.py:45"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-fe12aa905f673e4f", "name": "Network/subprocess call without timeout or try/except \u2014 scripts/profile_run.py:179", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/profile_run.py:179"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8c0d15d70fa4e8a7", "name": "`fetch()` without try/.catch or AbortSignal \u2014 web/src/app/api/microsim/route.ts:13", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 web/src/app/api/microsim/route.ts:13"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-611d2b5aa812483e", "name": "`fetch()` without try/.catch or AbortSignal \u2014 web/src/app/api/ecps-stats/route.ts:15", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 web/src/app/api/ecps-stats/route.ts:15"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d4d4f2bc0e08befe", "name": "Network/subprocess call without timeout or try/except \u2014 axiom_microsim/run/microsim.py:558", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 axiom_microsim/run/microsim.py:558"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e7c11381b84e43d8", "name": "Commented-code block (5 lines) in axiom_microsim/project/co_snap.py:74", "shortDescription": {"text": "Commented-code block (5 lines) in axiom_microsim/project/co_snap.py:74"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d0b17c8c07a7421d", "name": "8 env vars used in code but missing from .env.example", "shortDescription": {"text": "8 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `AXIOM_ARTIFACTS_DIR`, `AXIOM_ECPS_PATH`, `AXIOM_PE_ECPS_PATH`, `AXIOM_PE_PYTHON`, `AXIOM_PE_SCRIPT`, `AXIOM_RULES_ENGINE_BINARY`, `AXIOM_RULES_US_CO_DIR`, `AXIOM_RULES_US_DIR`. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-61e42f740b5d1e07", "name": "FastAPI POST `compare` without auth dependency \u2014 axiom_microsim/server.py:293", "shortDescription": {"text": "FastAPI POST `compare` without auth dependency \u2014 axiom_microsim/server.py:293"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8420f56aa450f720", "name": "FastAPI POST `microsim` without auth dependency \u2014 axiom_microsim/server.py:349", "shortDescription": {"text": "FastAPI POST `microsim` without auth dependency \u2014 axiom_microsim/server.py:349"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/21077"}, "properties": {"repository": "TheAxiomFoundation/axiom-microsim", "repoUrl": "https://github.com/TheAxiomFoundation/axiom-microsim", "branch": "main"}, "results": [{"ruleId": "foundry_blueprint_gap", "level": "warning", "message": {"text": "Foundry mined blueprint gap alignment: TheAxiomFoundation/axiom-microsim"}, "properties": {"repobilityId": 345429, "scanner": "foundry_dataset", "fingerprint": "0f32da643a7468dbca0dc9c140d5b7db50e281059e48ca27e947382dc4891487", "category": "tech_debt", "severity": "medium", "confidence": 0.7, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Human feedback aligned with blueprint or architecture gaps", "intent": "Curriculum-gap examples connecting issue threads to helicopter-view gaps.", "labels": {"test_ci_gap": 1, "commit_general": 1, "source_or_other": 1, "verification_or_tests": 1, "ci_pending_or_incomplete": 1, "mostly follows blueprint": 1, "issue_or_pull_request_thread": 1, "ambiguous_needs_more_evidence": 3, "blueprint_human_gap_disagreement": 1, "comment_has_related_commit_context": 1, "thread_has_human_issue_and_fix_context": 2}, "source": "graph_query_export", "motif_id": "blueprint_gap_alignment", "outcomes": {"ambiguous_needs_more_evidence": 6}, "polarity": "mixed", "query_id": "blueprint_gap_alignment", "severity": "medium", "ci_labels": {"ci_pending_or_incomplete": 2}, "synthetic": false, "edge_count": 21, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "thread_touches_file": 1, "comment_chain_has_ci": 1, "alignment_uses_comment": 1, "alignment_uses_finding": 1, "chain_has_link_quality": 4, "comment_aligns_finding": 1, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 1, "thread_has_comment_chain": 1, "comment_chain_links_commit": 2, "comment_chain_touches_file": 1, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 16, "node_types": {"repo": 1, "commit": 2, "thread": 1, "comment": 1, "pr_file": 1, "alignment": 1, "ci_summary": 1, "fix_outcome": 1, "issue_chain": 1, "link_quality": 4, "comment_chain": 1, "blueprint_finding": 1}, "query_type": "motif_query", "thread_key": "TheAxiomFoundation/axiom-microsim#1", "issue_number": "1", "quality_tiers": {"assumption_check": 1, "weak_supervision": 3}, "repo_full_name": "TheAxiomFoundation/axiom-microsim", "training_usage": "curriculum_gap", "source_motif_id": "graph-pattern-motif-thread-363a49551eac8df8", "graph_gold_label": "weak_supervision_needs_review", "changed_file_labels": {"source_or_other": 4}}, "text": "Graph query export: Human feedback aligned with blueprint or architecture gaps\nQuery id: blueprint_gap_alignment\nQuery type: motif_query\nIntent: Curriculum-gap examples connecting issue threads to helicopter-view gaps.\nMotif: blueprint_gap_alignment\nTraining usage: curriculum_gap\nGraph gold label: weak_supervision_needs_review\nRepo: TheAxiomFoundation/axiom-microsim\nThread: TheAxiomFoundation/axiom-microsim#1\nEvidence:\nGraph motif: Human feedback aligns with blueprint or architecture gaps\nMotif id: blueprint_gap_alignment\nPolarity: mixed\nTraining usage: curriculum_gap\nSeverity: medium\nRepo: TheAxiomFoundation/axiom-microsim\nThread: TheAxiomFoundation/axiom-microsim#1\nGraph gold label: weak_supervision_needs_review\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: TheAxiomFoundation/axiom-microsim#1\nRepo: TheAxiomFoundation/axiom-microsim\nIssue/PR number: 1\nGraph consistency label: weak_supervision_needs_review\nNodes: 16\nEdges: 21\nNode types: {'link_quality': 4, 'commit': 2, 'thread': 1, 'repo': 1, 'comment': 1, 'pr_file': 1, 'comment_chain': 1, 'ci_summary': 1, 'issue_chain': 1, 'fix_outcome': 1, 'alignment': 1, 'blueprint_finding': 1}\nEdge types: {'chain_has_link_quality': 4, 'comment_chain_links_commit': 2, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_touches_file': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'comment_chain_has_ci': 1, 'comment_chain_touches_file': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'issue_chain_touches_file': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1, 'alignment_uses_comment': 1, 'alignment_uses_finding': 1}\nLabels: {'ambiguous_needs_more_evidence': 3, 'thread_has_human_issue_and_fix_context': 2, 'issue_or_pull_request_thread': 1, 'test_ci_gap': 1, 'source_or_other': 1, 'comment_has_related_commit_context': 1, 'commit_general': 1, 'verification_or_tests': 1, 'ci_pending_or_incomplete': 1, 'blueprint_human_gap_disagreement': 1, 'mostly follows blueprint': 1}\nOutcomes: {'ambiguous_needs_more_evidence': 6}\nQuality tiers: {'weak_supervision': 3, 'assumption_check': 1}\nCI labels: {'ci_pending_or_incomplete': 2}\nCurriculum targets:\n- Use helicopter-view architecture/schema/design evidence beside issue threads.\n- Teach models to compare requested product class against implementation layers.\nAssumption checks:\n- Which blueprint layer is absent: frontend, API, data, auth, tests, or deployment?\n- Does human feedback confirm the same architectural gap?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/TheAxiomFoundation/axiom-microsim", "source_id": "graph-query-motif_query-df967dc9f7256dda", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/blueprint_gap_alignment/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "TheAxiomFoundation/axiom-microsim", "source_dataset": "graph_queries/blueprint_gap_alignment", "training_usage": "curriculum_gap"}}}, {"ruleId": "foundry_assumption_check", "level": "warning", "message": {"text": "Foundry mined assumption checks: TheAxiomFoundation/axiom-microsim"}, "properties": {"repobilityId": 301078, "scanner": "foundry_dataset", "fingerprint": "3e866672afefa57e2fd93ecce20a10d8f3d5441a2b022373b45c55bda6fc7fa5", "category": "practices", "severity": "medium", "confidence": 0.62, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "comment_chain_pattern_product", "source": "comment_chain_pattern_miner", "product": "assumption_checks", "synthetic": false, "thread_key": "TheAxiomFoundation/axiom-microsim#2", "human_labels": ["api_or_backend", "runtime_failure", "source_or_other", "test_or_ci"], "issue_number": "2", "thread_label": "thread_has_human_issue_and_fix_context", "outcome_label": "ambiguous_needs_more_evidence", "source_backed": true, "max_confidence": 0.92, "repo_full_name": "TheAxiomFoundation/axiom-microsim", "training_usage": "gold_candidate", "confidence_tier": "high_confidence", "source_chain_id": "evidence-chain-issue_chain-990baea073be6aff", "helicopter_views": {}, "artifact_families": {"ci": 2, "docs": 1}, "source_chain_kind": "issue_chain", "changed_file_count": 11, "source_graph_label": "source_backed_multi_signal_graph", "changed_file_labels": {"test_or_ci": 2, "api_or_backend": 1, "source_or_other": 8}, "linked_commit_count": 1, "helicopter_view_count": 0, "source_artifact_count": 3, "classification_reasons": ["source_graph_has_real_artifacts", "source_graph_has_verification_artifacts", "link_quality_high_confidence", "high_risk_human_feedback_label"], "linked_ci_commit_count": 1, "verification_artifact_count": 2, "design_schema_api_artifact_count": 0}, "text": "Comment chain pattern product: assumption_checks\nRepo: TheAxiomFoundation/axiom-microsim\nThread: TheAxiomFoundation/axiom-microsim#2\nOutcome: ambiguous_needs_more_evidence\nThread label: thread_has_human_issue_and_fix_context\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, link_quality_high_confidence, high_risk_human_feedback_label\nChain evidence:\nIssue/PR evidence chain: TheAxiomFoundation/axiom-microsim#2\nRepo: TheAxiomFoundation/axiom-microsim\nThread label: thread_has_human_issue_and_fix_context\nOutcome: ambiguous_needs_more_evidence\nComment count: 1\nLinked commit count: 1\nLinked CI commit count: 1\nLinked CI labels: {'ci_pending_or_incomplete': 1}\nChanged file count: 11\nLabels: {'runtime_failure': 1}\nPolarities: {'bad': 1}\nChanged file labels: {'test_or_ci': 2, 'source_or_other': 8, 'api_or_backend': 1}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-ca8695744c270d1c\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"runtime_failure\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.com/TheAxiomFoundation/axiom-microsim/pull/2\",\n    \"text\": \"GitHub feedback: runtime_failure\\nPolarity: bad\\nKind: pull_request_body\\nRepo: TheAxiomFoundation/axiom-microsim\\nAuthor: MaxGhenis (User)\\nURL: https://github.com/TheAxiomFoundation/axiom-microsim/pull/2\\nTitle: Add CI (ruff + pytest); make the package pass its own lint config\\nBody:\\naxiom-microsim had no CI. Two commits:\\n\\n**1. Make the package pass its own ruff config** \u2014 it didn't: 8 `ruff check` errors and 10 files drifted from `ruff format`. Fixes are mechanical: the relative imports in `run/microsim.py` and the `/compare` section imports in `server.py` move to the top of their modules (E402 \u2014 verified no circular-import risk: `data/` and `project/` never import `run/`), one unused `tax_unit_ids` h5 read removed (F841), formatter applied.\\n\\n**2. Add the workflow** \u2014 ruff check + format + pytest, with `axiom-rules-engine`'s Python package installed from a sibling checkout (no Rust build). Engine- and ECPS-dependent tests already self-skip; the remaining tests gate imports, projections, and the FastAPI surface, so a broken import or schema regression now fails at merge time instead of at the next Modal deploy.\\n\\nLocal verification: `ruff check` clean, `ruff format --check` clean, `pytes\"\n  }\n]\nChanged files:\n[\n  {\n    \"id\": \"github-pr-file-file-eaedeb6347235c60\",\n    \"filename\": \".github/workflows/ci.yml\",\n    \"label\": \"test_or_ci\",\n    \"status\": \"added\",\n    \"additions\": 25,\n    \"deletions\": 0,\n    \"changes\": 25,\n    \"blob_url\": \"https://github.com/TheAxiomFoundation/axiom-microsim/blob/24cf37b5ba38a131b7ef0245d9bdc1b190e297ab/.github%2Fworkflows%2Fci.yml\"\n  },\n  {\n    \"id\": \"github-pr-file-file-c264765b7c39f482\",\n    \"filename\": \"axiom_microsim/aggregate/cost.py\",\n    \"label\": \"source_or_other\",\n    \"status\": \"modified\",\n    \"additions\": 7,\n    \"deletions\": 4,\n    \"changes\":\n[truncated by importer]", "source": "foundry_mined_dataset", "repo_url": "https://github.com/TheAxiomFoundation/axiom-microsim", "source_id": "comment-chain-pattern-assumption_checks-8608f07a588b9635", "synthetic": false, "gold_label": "", "graph_label": "source_backed_multi_signal_graph", "source_path": "/data/distillate/foundry_data/comment_chain_patterns/assumption_checks/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "TheAxiomFoundation/axiom-microsim", "source_dataset": "comment_chain_patterns/assumption_checks", "training_usage": "gold_candidate"}}}, {"ruleId": "foundry_assumption_check", "level": "warning", "message": {"text": "Foundry mined assumption checks: TheAxiomFoundation/axiom-microsim"}, "properties": {"repobilityId": 301077, "scanner": "foundry_dataset", "fingerprint": "ede37985887761fcd68999fa6184a3f995616b320a95a8aa577d8f61d84391bd", "category": "practices", "severity": "medium", "confidence": 0.62, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "comment_chain_pattern_product", "source": "comment_chain_pattern_miner", "product": "assumption_checks", "synthetic": false, "thread_key": "TheAxiomFoundation/axiom-microsim#1", "human_labels": ["source_or_other", "test_ci_gap"], "issue_number": "1", "thread_label": "thread_has_human_issue_and_fix_context", "outcome_label": "ambiguous_needs_more_evidence", "source_backed": true, "max_confidence": 0.708, "repo_full_name": "TheAxiomFoundation/axiom-microsim", "training_usage": "weak_supervision", "confidence_tier": "weak_supervision", "source_chain_id": "evidence-chain-issue_chain-f6ca5720586617fa", "helicopter_views": {}, "artifact_families": {"ci": 2, "docs": 1}, "source_chain_kind": "issue_chain", "changed_file_count": 1, "source_graph_label": "source_backed_multi_signal_graph", "changed_file_labels": {"source_or_other": 1}, "linked_commit_count": 2, "helicopter_view_count": 0, "source_artifact_count": 3, "classification_reasons": ["source_graph_has_real_artifacts", "source_graph_has_verification_artifacts", "link_quality_weak_supervision", "high_risk_human_feedback_label"], "linked_ci_commit_count": 1, "verification_artifact_count": 2, "design_schema_api_artifact_count": 0}, "text": "Comment chain pattern product: assumption_checks\nRepo: TheAxiomFoundation/axiom-microsim\nThread: TheAxiomFoundation/axiom-microsim#1\nOutcome: ambiguous_needs_more_evidence\nThread label: thread_has_human_issue_and_fix_context\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, link_quality_weak_supervision, high_risk_human_feedback_label\nChain evidence:\nIssue/PR evidence chain: TheAxiomFoundation/axiom-microsim#1\nRepo: TheAxiomFoundation/axiom-microsim\nThread label: thread_has_human_issue_and_fix_context\nOutcome: ambiguous_needs_more_evidence\nComment count: 1\nLinked commit count: 2\nLinked CI commit count: 1\nLinked CI labels: {'ci_pending_or_incomplete': 1}\nChanged file count: 1\nLabels: {'test_ci_gap': 1}\nPolarities: {'bad': 1}\nChanged file labels: {'source_or_other': 1}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-405780ee9d283cbc\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"test_ci_gap\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.com/TheAxiomFoundation/axiom-microsim/pull/1\",\n    \"text\": \"GitHub feedback: test_ci_gap\\nPolarity: bad\\nKind: pull_request_body\\nRepo: TheAxiomFoundation/axiom-microsim\\nAuthor: MaxGhenis (User)\\nURL: https://github.com/TheAxiomFoundation/axiom-microsim/pull/1\\nTitle: Require Python 3.14\\nBody:\\n## Summary\\n- require the Python 3.14 series explicitly\\n- update Ruff target to py314\\n\\n## Verification\\n- `env -u UV_FROZEN uv run --python 3.14 --extra dev pytest -q` (1 passed, 4 skipped)\\n\\nNote: `ruff check .` still reports existing unrelated lint failures in this repo; this PR does not broaden into that cleanup.\"\n  }\n]\nChanged files:\n[\n  {\n    \"id\": \"github-pr-file-file-7a95d65ea2f2c305\",\n    \"filename\": \"pyproject.toml\",\n    \"label\": \"source_or_other\",\n    \"status\": \"modified\",\n    \"additions\": 2,\n    \"deletions\": 2,\n    \"changes\": 4,\n    \"blob_url\": \"https://github.com/TheAxiomFoundation/axiom-microsim/blob/39e4e65bcb442e58cf0fc416555d094892bd0927/pyproject.toml\"\n  }\n]\nLinked chain ids:\n[\"evidence-chain-comment_to_commit-02fe8e6122912d00\"]\nSource graph evidence:\nSource evidence repo graph summary\nRepo: TheAxiomFoundation/axiom-microsim\nGraph label: source_backed_multi_signal_graph\nNodes: 7\nEdges: 10\nNode types: {\"cooccurrence_profile\": 1, \"github_repo_summary\": 1, \"repo\": 1, \"source_artifact\": 3, \"source_bundle\": 1}\nEdge types: {\"artifact_needs_claim_verification\": 1, \"artifact_supports_verification\": 2, \"repo_has_cooccurrence_profile\": 1, \"repo_has_github_evidence_summary\": 1, \"repo_has_source_artifact\": 3, \"repo_has_source_bundle\": 1, \"source_bundle_uses_cooccurrence_profile\": 1}\nArtifact families: {\"ci\": 2, \"docs\": 1}\nHelicopter views: {}\nBundle labels: {\"source_backed_graph_pattern_bundle\": 1}\nCo-occurrence labels: {\"mixed_good_bad_repo_profile\": 1}", "source": "foundry_mined_dataset", "repo_url": "https://github.com/TheAxiomFoundation/axiom-microsim", "source_id": "comment-chain-pattern-assumption_checks-1f1f153beebafa53", "synthetic": false, "gold_label": "", "graph_label": "source_backed_multi_signal_graph", "source_path": "/data/distillate/foundry_data/comment_chain_patterns/assumption_checks/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "TheAxiomFoundation/axiom-microsim", "source_dataset": "comment_chain_patterns/assumption_checks", "training_usage": "weak_supervision"}}}, {"ruleId": "foundry_test_ci_gap", "level": "error", "message": {"text": "Foundry mined test ci gap after feedback: TheAxiomFoundation/axiom-microsim"}, "properties": {"repobilityId": 336783, "scanner": "foundry_dataset", "fingerprint": "8243c5f0fa2b2817be859aee57ddb43972052644e71f0f1b3fb6da5e8166ee36", "category": "testing", "severity": "high", "confidence": 0.78, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Feedback exposes missing tests or CI", "intent": "Hard negatives for feedback/fix chains without adequate guardrails.", "labels": {"test_ci_gap": 1, "commit_general": 1, "source_or_other": 1, "verification_or_tests": 1, "ci_pending_or_incomplete": 1, "mostly follows blueprint": 1, "issue_or_pull_request_thread": 1, "ambiguous_needs_more_evidence": 3, "blueprint_human_gap_disagreement": 1, "comment_has_related_commit_context": 1, "thread_has_human_issue_and_fix_context": 2}, "source": "graph_query_export", "motif_id": "test_ci_gap_after_feedback", "outcomes": {"ambiguous_needs_more_evidence": 6}, "polarity": "bad", "query_id": "test_ci_gap_after_feedback", "severity": "high", "ci_labels": {"ci_pending_or_incomplete": 2}, "synthetic": false, "edge_count": 21, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "thread_touches_file": 1, "comment_chain_has_ci": 1, "alignment_uses_comment": 1, "alignment_uses_finding": 1, "chain_has_link_quality": 4, "comment_aligns_finding": 1, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 1, "thread_has_comment_chain": 1, "comment_chain_links_commit": 2, "comment_chain_touches_file": 1, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 16, "node_types": {"repo": 1, "commit": 2, "thread": 1, "comment": 1, "pr_file": 1, "alignment": 1, "ci_summary": 1, "fix_outcome": 1, "issue_chain": 1, "link_quality": 4, "comment_chain": 1, "blueprint_finding": 1}, "query_type": "motif_query", "thread_key": "TheAxiomFoundation/axiom-microsim#1", "issue_number": "1", "quality_tiers": {"assumption_check": 1, "weak_supervision": 3}, "repo_full_name": "TheAxiomFoundation/axiom-microsim", "training_usage": "hard_negative", "source_motif_id": "graph-pattern-motif-thread-283d9b4101733a99", "graph_gold_label": "weak_supervision_needs_review", "changed_file_labels": {"source_or_other": 4}}, "text": "Graph query export: Feedback exposes missing tests or CI\nQuery id: test_ci_gap_after_feedback\nQuery type: motif_query\nIntent: Hard negatives for feedback/fix chains without adequate guardrails.\nMotif: test_ci_gap_after_feedback\nTraining usage: hard_negative\nGraph gold label: weak_supervision_needs_review\nRepo: TheAxiomFoundation/axiom-microsim\nThread: TheAxiomFoundation/axiom-microsim#1\nEvidence:\nGraph motif: Feedback or fix context exposes missing test/CI guardrails\nMotif id: test_ci_gap_after_feedback\nPolarity: bad\nTraining usage: hard_negative\nSeverity: high\nRepo: TheAxiomFoundation/axiom-microsim\nThread: TheAxiomFoundation/axiom-microsim#1\nGraph gold label: weak_supervision_needs_review\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: TheAxiomFoundation/axiom-microsim#1\nRepo: TheAxiomFoundation/axiom-microsim\nIssue/PR number: 1\nGraph consistency label: weak_supervision_needs_review\nNodes: 16\nEdges: 21\nNode types: {'link_quality': 4, 'commit': 2, 'thread': 1, 'repo': 1, 'comment': 1, 'pr_file': 1, 'comment_chain': 1, 'ci_summary': 1, 'issue_chain': 1, 'fix_outcome': 1, 'alignment': 1, 'blueprint_finding': 1}\nEdge types: {'chain_has_link_quality': 4, 'comment_chain_links_commit': 2, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_touches_file': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'comment_chain_has_ci': 1, 'comment_chain_touches_file': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'issue_chain_touches_file': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1, 'alignment_uses_comment': 1, 'alignment_uses_finding': 1}\nLabels: {'ambiguous_needs_more_evidence': 3, 'thread_has_human_issue_and_fix_context': 2, 'issue_or_pull_request_thread': 1, 'test_ci_gap': 1, 'source_or_other': 1, 'comment_has_related_commit_context': 1, 'commit_general': 1, 'verification_or_tests': 1, 'ci_pending_or_incomplete': 1, 'blueprint_human_gap_disagreement': 1, 'mostly follows blueprint': 1}\nOutcomes: {'ambiguous_needs_more_evidence': 6}\nQuality tiers: {'weak_supervision': 3, 'assumption_check': 1}\nCI labels: {'ci_pending_or_incomplete': 2}\nCurriculum targets:\n- Turn human feedback into regression tests and CI gates.\n- Penalize fixes that do not add or exercise verification for affected workflows.\nAssumption checks:\n- Did the fix add tests for the exact complaint?\n- Does CI run those tests, or is verification only implied?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/TheAxiomFoundation/axiom-microsim", "source_id": "graph-query-motif_query-5268640cd8783ceb", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/test_ci_gap_after_feedback/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "TheAxiomFoundation/axiom-microsim", "source_dataset": "graph_queries/test_ci_gap_after_feedback", "training_usage": "hard_negative"}}}, {"ruleId": "scanner-7950d58feaa9185b", "level": "note", "message": {"text": "Possibly dead Python function: profile_co_snap"}, "properties": {"repobilityId": "88a8c733edef84be", "scanner": "scanner-primary", "fingerprint": "7950d58feaa9185b", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/profile_run.py:82"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3d7bf99e7bccfacf", "level": "note", "message": {"text": "Possibly dead Python function: profile_federal_income_tax"}, "properties": {"repobilityId": "4b75a19d0c9946f8", "scanner": "scanner-primary", "fingerprint": "3d7bf99e7bccfacf", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/profile_run.py:216"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-68be99e417dfba7a", "level": "note", "message": {"text": "Possibly dead Python function: profile_federal_ctc"}, "properties": {"repobilityId": "40e238ef0a2b3f06", "scanner": "scanner-primary", "fingerprint": "68be99e417dfba7a", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/profile_run.py:311"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bc92316686e1bccd", "level": "note", "message": {"text": "Possibly dead Python function: compare"}, "properties": {"repobilityId": "0bd493b14cb9748f", "scanner": "scanner-primary", "fingerprint": "bc92316686e1bccd", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "axiom_microsim/aggregate/reform.py:36"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d8dc1b23e0feae8e", "level": "note", "message": {"text": "Possibly dead Python function: aggregate"}, "properties": {"repobilityId": "e8497ef77751657c", "scanner": "scanner-primary", "fingerprint": "d8dc1b23e0feae8e", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "axiom_microsim/aggregate/cost.py:32"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ced12e412cb8757a", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in axiom_microsim/server.py:131"}, "properties": {"repobilityId": "b47fb07df31b3e15", "scanner": "scanner-primary", "fingerprint": "ced12e412cb8757a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "axiom_microsim/server.py"}, "region": {"startLine": 131}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "4d3c089e135b162b", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "6b8b092c95f67ce8", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "d378b3bb92c18841", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "a2cb27d8a52f63ff", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-4a631806a3667896", "level": "none", "message": {"text": "Commented-code block (5 lines) in modal_app.py:45"}, "properties": {"repobilityId": "e370e16a85c06dda", "scanner": "scanner-primary", "fingerprint": "4a631806a3667896", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-fe12aa905f673e4f", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/profile_run.py:179"}, "properties": {"repobilityId": "d0cb8f8818f6114c", "scanner": "scanner-primary", "fingerprint": "fe12aa905f673e4f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-8c0d15d70fa4e8a7", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 web/src/app/api/microsim/route.ts:13"}, "properties": {"repobilityId": "61b01fa56a06cca2", "scanner": "scanner-primary", "fingerprint": "8c0d15d70fa4e8a7", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-611d2b5aa812483e", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 web/src/app/api/ecps-stats/route.ts:15"}, "properties": {"repobilityId": "0f30d90864cfcc1d", "scanner": "scanner-primary", "fingerprint": "611d2b5aa812483e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-d4d4f2bc0e08befe", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 axiom_microsim/run/microsim.py:558"}, "properties": {"repobilityId": "e74f2098a566def4", "scanner": "scanner-primary", "fingerprint": "d4d4f2bc0e08befe", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-e7c11381b84e43d8", "level": "none", "message": {"text": "Commented-code block (5 lines) in axiom_microsim/project/co_snap.py:74"}, "properties": {"repobilityId": "baf891de83b4a776", "scanner": "scanner-primary", "fingerprint": "e7c11381b84e43d8", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d0b17c8c07a7421d", "level": "note", "message": {"text": "8 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "17fe720e8247f9df", "scanner": "scanner-primary", "fingerprint": "d0b17c8c07a7421d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-61e42f740b5d1e07", "level": "error", "message": {"text": "FastAPI POST `compare` without auth dependency \u2014 axiom_microsim/server.py:293"}, "properties": {"repobilityId": "31ad7faad1f13f1c", "scanner": "scanner-primary", "fingerprint": "61e42f740b5d1e07", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "axiom_microsim/server.py"}, "region": {"startLine": 293}}}]}, {"ruleId": "scanner-8420f56aa450f720", "level": "error", "message": {"text": "FastAPI POST `microsim` without auth dependency \u2014 axiom_microsim/server.py:349"}, "properties": {"repobilityId": "bb9a960fd870fed6", "scanner": "scanner-primary", "fingerprint": "8420f56aa450f720", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "axiom_microsim/server.py"}, "region": {"startLine": 349}}}]}]}]}