{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-40c6d23baf0082ed", "name": "Stray `console.log` in TS/JS \u2014 tools/extract-descriptions.ts:145", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tools/extract-descriptions.ts:145"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a3f8cc684a46d277", "name": "Stray `console.log` in TS/JS \u2014 tools/convert-bpm-to-bpmn.ts:21", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tools/convert-bpm-to-bpmn.ts:21"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-69e8727fa7271b50", "name": "Stray `console.log` in TS/JS \u2014 apps/api/src/index.ts:106", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/index.ts:106"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f669e127a0f0ca91", "name": "Stray `console.log` in TS/JS \u2014 apps/api/lib/bpm-converter.ts:36", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/lib/bpm-converter.ts:36"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0c01a186a63741ee", "name": "Stray `console.log` in TS/JS \u2014 apps/web/app/api/sync-processos/route.ts:20", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/web/app/api/sync-processos/route.ts:20"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ed76be57418991b6", "name": "Stray `console.log` in TS/JS \u2014 apps/web/app/api/popit/[processo]/[atividade]/route.ts:24", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/web/app/api/popit/[processo]/[atividade]/route.ts:24"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-83304e01158118ba", "name": "Stray `console.log` in TS/JS \u2014 apps/web/app/api/rename-file/route.ts:42", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/web/app/api/rename-file/route.ts:42"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d4ec5f60d2d59af6", "name": "Stray `console.log` in TS/JS \u2014 apps/web/app/api/descriptions/route.ts:9", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/web/app/api/descriptions/route.ts:9"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-08359888b6fea1bd", "name": "Stray `console.log` in TS/JS \u2014 apps/web/app/api/sync-github/route.ts:22", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/web/app/api/sync-github/route.ts:22"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be149f80e5075546", "name": "Stray `console.log` in TS/JS \u2014 apps/web/app/api/documents/[slug]/route.ts:91", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/web/app/api/documents/[slug]/route.ts:91"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-81f7f9bbedd5ab67", "name": "Stray `console.log` in TS/JS \u2014 apps/web/app/processos/inserir/page.tsx:186", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/web/app/processos/inserir/page.tsx:186"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cd1f52f45afdd716", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 apps/web/app/processos/inserir/page.tsx:771", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 apps/web/app/processos/inserir/page.tsx:771"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a281edfdb0392591", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 apps/web/components/Header.tsx:33", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 apps/web/components/Header.tsx:33"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8ead09b07f8aeb0c", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 apps/web/components/BpmnViewer.tsx:596", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 apps/web/components/BpmnViewer.tsx:596"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4db4ee3a963cc5d0", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/components/ProcessOrganizationModal.tsx:565", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/components/ProcessOrganizationModal.tsx:565"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ba592d35689a0c55", "name": "Stray `console.log` in TS/JS \u2014 apps/web/components/Contact.tsx:18", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/web/components/Contact.tsx:18"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f1d77a605e5e3fd7", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/components/ProcessOrganizationContent.tsx:402", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/components/ProcessOrganizationContent.tsx:402"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-99ff278b0fba987a", "name": "Insecure pattern 'dangerous_innerhtml' in apps/web/app/processos/inserir/page.tsx:771", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in apps/web/app/processos/inserir/page.tsx:771"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-da847ff9e648e30c", "name": "Insecure pattern 'dangerous_innerhtml' in apps/web/components/Header.tsx:33", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in apps/web/components/Header.tsx:33"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-916d35ec76b644e3", "name": "Insecure pattern 'dangerous_innerhtml' in apps/web/components/BpmnViewer.tsx:596", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in apps/web/components/BpmnViewer.tsx:596"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-28c4a04bd807da0c", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e22d9cc212094a60", "name": "Very large file: apps/web/app/processos/inserir/page.tsx (1468 lines)", "shortDescription": {"text": "Very large file: apps/web/app/processos/inserir/page.tsx (1468 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "4 test file(s) for 71 source file(s) (ratio 0.06). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b06b8d86f24c77f9", "name": "Node manifest has dependencies but no lockfile: apps/api/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: apps/api/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4a9eb7dc7c6e3880", "name": "Node manifest has dependencies but no lockfile: apps/web/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: apps/web/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 105 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 20 placeholder/mock markers across 8 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9d79c4077342a7d0", "name": "Runtime service client appears to use placeholder configuration", "shortDescription": {"text": "Runtime service client appears to use placeholder configuration"}, "fullDescription": {"text": "A runtime source file appears to wire Supabase/Firebase/AI/payment-style clients to placeholder URLs, keys, or fallback values. In the Fable corpus this often means the UI/API shape is present while the backend service is not actually configured."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, lockfile. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-da102fde5dc9ea22", "name": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/app/api/sync-processos/route.ts:175", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/app/api/sync-processos/route.ts:175"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4fa5672bcd772a63", "name": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/app/api/sync-github/route.ts:277", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/app/api/sync-github/route.ts:277"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1b08f80fa6937ddd", "name": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/components/ProcessOrganizationModal.tsx:278", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/components/ProcessOrganizationModal.tsx:278"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9b082cc9b7803d4c", "name": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/components/ProcessSettingsModal.tsx:137", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/components/ProcessSettingsModal.tsx:137"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ad6dd385e306a22e", "name": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/components/ProcessOrganizationContent.tsx:235", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/components/ProcessOrganizationContent.tsx:235"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-022e6399d1ef2beb", "name": "12 env vars used in code but missing from .env.example", "shortDescription": {"text": "12 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `DATABASE_URL`, `DEPLOY_TOKEN_QUADRRA`, `FORCE_UPLOAD`, `GITHUB_BRANCH`, `GITHUB_OWNER`, `GITHUB_REPO`, `GITHUB_REPO_PROCESSOS`, `GITHUB_REPO_QUADDRA` + 4 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-45debcfc4924aa50", "name": "Dangling fetch: POST /api/upload-processo (apps/web/app/processos/inserir/page.tsx:670)", "shortDescription": {"text": "Dangling fetch: POST /api/upload-processo (apps/web/app/processos/inserir/page.tsx:670)"}, "fullDescription": {"text": "`apps/web/app/processos/inserir/page.tsx:670` calls `POST /api/upload-processo` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/upload-processo`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d9e0fe9d3435aeb9", "name": "Dangling fetch: GET /api/folders?clientType=${clientType} (apps/web/components/ProcessOrganizationModal.tsx:83)", "shortDescription": {"text": "Dangling fetch: GET /api/folders?clientType=${clientType} (apps/web/components/ProcessOrganizationModal.tsx:83)"}, "fullDescription": {"text": "`apps/web/components/ProcessOrganizationModal.tsx:83` calls `GET /api/folders?clientType=${clientType}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/folders`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-de7e870403ccbaae", "name": "Dangling fetch: POST /api/manage-folder (apps/web/components/ProcessOrganizationModal.tsx:278)", "shortDescription": {"text": "Dangling fetch: POST /api/manage-folder (apps/web/components/ProcessOrganizationModal.tsx:278)"}, "fullDescription": {"text": "`apps/web/components/ProcessOrganizationModal.tsx:278` calls `POST /api/manage-folder` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/manage-folder`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4fac313e14fbef13", "name": "Dangling fetch: POST /api/move-processo (apps/web/components/ProcessOrganizationModal.tsx:303)", "shortDescription": {"text": "Dangling fetch: POST /api/move-processo (apps/web/components/ProcessOrganizationModal.tsx:303)"}, "fullDescription": {"text": "`apps/web/components/ProcessOrganizationModal.tsx:303` calls `POST /api/move-processo` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/move-processo`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4323f451c412d4a6", "name": "Dangling fetch: POST /api/manage-folder (apps/web/components/ProcessOrganizationModal.tsx:340)", "shortDescription": {"text": "Dangling fetch: POST /api/manage-folder (apps/web/components/ProcessOrganizationModal.tsx:340)"}, "fullDescription": {"text": "`apps/web/components/ProcessOrganizationModal.tsx:340` calls `POST /api/manage-folder` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/manage-folder`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-665390c76425e91f", "name": "Dangling fetch: POST /api/manage-folder (apps/web/components/ProcessOrganizationModal.tsx:375)", "shortDescription": {"text": "Dangling fetch: POST /api/manage-folder (apps/web/components/ProcessOrganizationModal.tsx:375)"}, "fullDescription": {"text": "`apps/web/components/ProcessOrganizationModal.tsx:375` calls `POST /api/manage-folder` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/manage-folder`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ab24559110b30f05", "name": "Dangling fetch: POST /api/manage-folder (apps/web/components/ProcessOrganizationModal.tsx:407)", "shortDescription": {"text": "Dangling fetch: POST /api/manage-folder (apps/web/components/ProcessOrganizationModal.tsx:407)"}, "fullDescription": {"text": "`apps/web/components/ProcessOrganizationModal.tsx:407` calls `POST /api/manage-folder` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/manage-folder`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-85495822cf67e1fb", "name": "Dangling fetch: POST /api/upload-processo (apps/web/components/ProcessOrganizationModal.tsx:455)", "shortDescription": {"text": "Dangling fetch: POST /api/upload-processo (apps/web/components/ProcessOrganizationModal.tsx:455)"}, "fullDescription": {"text": "`apps/web/components/ProcessOrganizationModal.tsx:455` calls `POST /api/upload-processo` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/upload-processo`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-35900cab4f3a9684", "name": "Dangling fetch: GET /api/documents/${encodeURIComponent(processSlug)} (apps/web/components/ProcessSettingsModal.tsx:83)", "shortDescription": {"text": "Dangling fetch: GET /api/documents/${encodeURIComponent(processSlug)} (apps/web/components/ProcessSettingsModal.tsx:83)"}, "fullDescription": {"text": "`apps/web/components/ProcessSettingsModal.tsx:83` calls `GET /api/documents/${encodeURIComponent(processSlug)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/documents/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-95b3d3cafb3491b3", "name": "Dangling fetch: GET /api/documents/${encodeURIComponent(processSlug)}/folders (apps/web/components/ProcessSettingsModal.", "shortDescription": {"text": "Dangling fetch: GET /api/documents/${encodeURIComponent(processSlug)}/folders (apps/web/components/ProcessSettingsModal.tsx:95)"}, "fullDescription": {"text": "`apps/web/components/ProcessSettingsModal.tsx:95` calls `GET /api/documents/${encodeURIComponent(processSlug)}/folders` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/documents/<p>/folders`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-64d659fdc0922445", "name": "Dangling fetch: POST /api/documents/${encodeURIComponent(processSlug)} (apps/web/components/ProcessSettingsModal.tsx:137", "shortDescription": {"text": "Dangling fetch: POST /api/documents/${encodeURIComponent(processSlug)} (apps/web/components/ProcessSettingsModal.tsx:137)"}, "fullDescription": {"text": "`apps/web/components/ProcessSettingsModal.tsx:137` calls `POST /api/documents/${encodeURIComponent(processSlug)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/documents/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9a1e1df78ccf0e6d", "name": "Dangling fetch: POST /api/rename-file (apps/web/components/ProcessSettingsModal.tsx:224)", "shortDescription": {"text": "Dangling fetch: POST /api/rename-file (apps/web/components/ProcessSettingsModal.tsx:224)"}, "fullDescription": {"text": "`apps/web/components/ProcessSettingsModal.tsx:224` calls `POST /api/rename-file` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/rename-file`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c6e4a95139f0116a", "name": "Dangling fetch: GET /api/folders?clientType=${clientType} (apps/web/components/ProcessOrganizationContent.tsx:69)", "shortDescription": {"text": "Dangling fetch: GET /api/folders?clientType=${clientType} (apps/web/components/ProcessOrganizationContent.tsx:69)"}, "fullDescription": {"text": "`apps/web/components/ProcessOrganizationContent.tsx:69` calls `GET /api/folders?clientType=${clientType}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/folders`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-60ef15718ffcb65c", "name": "Dangling fetch: POST /api/manage-folder (apps/web/components/ProcessOrganizationContent.tsx:235)", "shortDescription": {"text": "Dangling fetch: POST /api/manage-folder (apps/web/components/ProcessOrganizationContent.tsx:235)"}, "fullDescription": {"text": "`apps/web/components/ProcessOrganizationContent.tsx:235` calls `POST /api/manage-folder` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/manage-folder`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e6acd87c8c49f4a1", "name": "Dangling fetch: POST /api/move-processo (apps/web/components/ProcessOrganizationContent.tsx:252)", "shortDescription": {"text": "Dangling fetch: POST /api/move-processo (apps/web/components/ProcessOrganizationContent.tsx:252)"}, "fullDescription": {"text": "`apps/web/components/ProcessOrganizationContent.tsx:252` calls `POST /api/move-processo` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/move-processo`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-71884c7caea4eef6", "name": "Dangling fetch: POST /api/manage-folder (apps/web/components/ProcessOrganizationContent.tsx:277)", "shortDescription": {"text": "Dangling fetch: POST /api/manage-folder (apps/web/components/ProcessOrganizationContent.tsx:277)"}, "fullDescription": {"text": "`apps/web/components/ProcessOrganizationContent.tsx:277` calls `POST /api/manage-folder` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/manage-folder`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-45a3a8c205f0a459", "name": "Dangling fetch: POST /api/manage-folder (apps/web/components/ProcessOrganizationContent.tsx:298)", "shortDescription": {"text": "Dangling fetch: POST /api/manage-folder (apps/web/components/ProcessOrganizationContent.tsx:298)"}, "fullDescription": {"text": "`apps/web/components/ProcessOrganizationContent.tsx:298` calls `POST /api/manage-folder` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/manage-folder`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-71e0c7c863f14cc3", "name": "Dangling fetch: POST /api/manage-folder (apps/web/components/ProcessOrganizationContent.tsx:318)", "shortDescription": {"text": "Dangling fetch: POST /api/manage-folder (apps/web/components/ProcessOrganizationContent.tsx:318)"}, "fullDescription": {"text": "`apps/web/components/ProcessOrganizationContent.tsx:318` calls `POST /api/manage-folder` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/manage-folder`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dad1776fb2e14bb3", "name": "Dangling fetch: POST /api/upload-processo (apps/web/components/ProcessOrganizationContent.tsx:348)", "shortDescription": {"text": "Dangling fetch: POST /api/upload-processo (apps/web/components/ProcessOrganizationContent.tsx:348)"}, "fullDescription": {"text": "`apps/web/components/ProcessOrganizationContent.tsx:348` calls `POST /api/upload-processo` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/upload-processo`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4756b4c4da7d2088", "name": "Unused endpoint: GET /api/health", "shortDescription": {"text": "Unused endpoint: GET /api/health"}, "fullDescription": {"text": "`apps/api/src/index.ts` declares `GET /api/health` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1920efcc06d9792f", "name": "Unused endpoint: GET /api/processes", "shortDescription": {"text": "Unused endpoint: GET /api/processes"}, "fullDescription": {"text": "`apps/api/src/index.ts` declares `GET /api/processes` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-097c9bc230c84572", "name": "Unused endpoint: GET /api/processes/:slug/bpmn", "shortDescription": {"text": "Unused endpoint: GET /api/processes/:slug/bpmn"}, "fullDescription": {"text": "`apps/api/src/index.ts` declares `GET /api/processes/:slug/bpmn` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a55ed85877e98c18", "name": "Unused endpoint: GET /api/processes/:slug/descriptions", "shortDescription": {"text": "Unused endpoint: GET /api/processes/:slug/descriptions"}, "fullDescription": {"text": "`apps/api/src/index.ts` declares `GET /api/processes/:slug/descriptions` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/23805"}, "properties": {"repository": "4isaque4/quaddra", "repoUrl": "https://github.com/4isaque4/quaddra", "branch": "main"}, "results": [{"ruleId": "scanner-40c6d23baf0082ed", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tools/extract-descriptions.ts:145"}, "properties": {"repobilityId": "82dead92bc6a1876", "scanner": "scanner-primary", "fingerprint": "40c6d23baf0082ed", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a3f8cc684a46d277", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tools/convert-bpm-to-bpmn.ts:21"}, "properties": {"repobilityId": "5151bc27a41ca7d7", "scanner": "scanner-primary", "fingerprint": "a3f8cc684a46d277", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-69e8727fa7271b50", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/index.ts:106"}, "properties": {"repobilityId": "a178156af585d748", "scanner": "scanner-primary", "fingerprint": "69e8727fa7271b50", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f669e127a0f0ca91", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/lib/bpm-converter.ts:36"}, "properties": {"repobilityId": "94295a7dea32c44a", "scanner": "scanner-primary", "fingerprint": "f669e127a0f0ca91", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0c01a186a63741ee", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/web/app/api/sync-processos/route.ts:20"}, "properties": {"repobilityId": "e9cbb40782c44a8c", "scanner": "scanner-primary", "fingerprint": "0c01a186a63741ee", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ed76be57418991b6", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/web/app/api/popit/[processo]/[atividade]/route.ts:24"}, "properties": {"repobilityId": "ed90dcc5349cad77", "scanner": "scanner-primary", "fingerprint": "ed76be57418991b6", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-83304e01158118ba", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/web/app/api/rename-file/route.ts:42"}, "properties": {"repobilityId": "ec9ccf4bad7933e0", "scanner": "scanner-primary", "fingerprint": "83304e01158118ba", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d4ec5f60d2d59af6", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/web/app/api/descriptions/route.ts:9"}, "properties": {"repobilityId": "1feb7b9b90330fa3", "scanner": "scanner-primary", "fingerprint": "d4ec5f60d2d59af6", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-08359888b6fea1bd", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/web/app/api/sync-github/route.ts:22"}, "properties": {"repobilityId": "341e312df291fedb", "scanner": "scanner-primary", "fingerprint": "08359888b6fea1bd", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-be149f80e5075546", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/web/app/api/documents/[slug]/route.ts:91"}, "properties": {"repobilityId": "e614368854a67251", "scanner": "scanner-primary", "fingerprint": "be149f80e5075546", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-81f7f9bbedd5ab67", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/web/app/processos/inserir/page.tsx:186"}, "properties": {"repobilityId": "beb3fbca4203ba42", "scanner": "scanner-primary", "fingerprint": "81f7f9bbedd5ab67", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-cd1f52f45afdd716", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 apps/web/app/processos/inserir/page.tsx:771"}, "properties": {"repobilityId": "63d5256527391a76", "scanner": "scanner-primary", "fingerprint": "cd1f52f45afdd716", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-a281edfdb0392591", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 apps/web/components/Header.tsx:33"}, "properties": {"repobilityId": "34e2935f14361a2c", "scanner": "scanner-primary", "fingerprint": "a281edfdb0392591", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-8ead09b07f8aeb0c", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 apps/web/components/BpmnViewer.tsx:596"}, "properties": {"repobilityId": "499dc1de8dd2f102", "scanner": "scanner-primary", "fingerprint": "8ead09b07f8aeb0c", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-4db4ee3a963cc5d0", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/components/ProcessOrganizationModal.tsx:565"}, "properties": {"repobilityId": "391d9da2e60840f8", "scanner": "scanner-primary", "fingerprint": "4db4ee3a963cc5d0", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-ba592d35689a0c55", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/web/components/Contact.tsx:18"}, "properties": {"repobilityId": "f55352c8566ce981", "scanner": "scanner-primary", "fingerprint": "ba592d35689a0c55", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f1d77a605e5e3fd7", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/components/ProcessOrganizationContent.tsx:402"}, "properties": {"repobilityId": "1af36ccc5aa00d06", "scanner": "scanner-primary", "fingerprint": "f1d77a605e5e3fd7", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-99ff278b0fba987a", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in apps/web/app/processos/inserir/page.tsx:771"}, "properties": {"repobilityId": "4d69d745943216e1", "scanner": "scanner-primary", "fingerprint": "99ff278b0fba987a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/app/processos/inserir/page.tsx"}, "region": {"startLine": 771}}}]}, {"ruleId": "scanner-da847ff9e648e30c", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in apps/web/components/Header.tsx:33"}, "properties": {"repobilityId": "db96365a4dd76abd", "scanner": "scanner-primary", "fingerprint": "da847ff9e648e30c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/components/Header.tsx"}, "region": {"startLine": 33}}}]}, {"ruleId": "scanner-916d35ec76b644e3", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in apps/web/components/BpmnViewer.tsx:596"}, "properties": {"repobilityId": "12ab70eef8549911", "scanner": "scanner-primary", "fingerprint": "916d35ec76b644e3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/components/BpmnViewer.tsx"}, "region": {"startLine": 596}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-28c4a04bd807da0c", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "2aee2e2d969c7c6b", "scanner": "scanner-primary", "fingerprint": "28c4a04bd807da0c", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy.yml"}, "region": {"startLine": 18}}}]}, {"ruleId": "scanner-28c4a04bd807da0c", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "bee6b8956e03198c", "scanner": "scanner-primary", "fingerprint": "28c4a04bd807da0c", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy.yml"}, "region": {"startLine": 22}}}]}, {"ruleId": "scanner-28c4a04bd807da0c", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "85be6b43ccc2bf69", "scanner": "scanner-primary", "fingerprint": "28c4a04bd807da0c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy.yml"}, "region": {"startLine": 78}}}]}, {"ruleId": "scanner-e22d9cc212094a60", "level": "note", "message": {"text": "Very large file: apps/web/app/processos/inserir/page.tsx (1468 lines)"}, "properties": {"repobilityId": "73afa505c6c20406", "scanner": "scanner-primary", "fingerprint": "e22d9cc212094a60", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "e10e72181e50d6f3", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-b06b8d86f24c77f9", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: apps/api/package.json"}, "properties": {"repobilityId": "ce77cd34ed0306d4", "scanner": "scanner-primary", "fingerprint": "b06b8d86f24c77f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4a9eb7dc7c6e3880", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: apps/web/package.json"}, "properties": {"repobilityId": "6c1704bf24cf19ac", "scanner": "scanner-primary", "fingerprint": "4a9eb7dc7c6e3880", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "2a3f3f264d89d5f2", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "6927a5bf57ac4497", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-9d79c4077342a7d0", "level": "warning", "message": {"text": "Runtime service client appears to use placeholder configuration"}, "properties": {"repobilityId": "81525cf23b3c12b3", "scanner": "scanner-primary", "fingerprint": "9d79c4077342a7d0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "runtime-config", "service-client", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "c695f8aa609e25dc", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "6a8638e8f1b7195a", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-da102fde5dc9ea22", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/app/api/sync-processos/route.ts:175"}, "properties": {"repobilityId": "536a7c721c0e697f", "scanner": "scanner-primary", "fingerprint": "da102fde5dc9ea22", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-4fa5672bcd772a63", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/app/api/sync-github/route.ts:277"}, "properties": {"repobilityId": "6e12fbfc1e5f38ec", "scanner": "scanner-primary", "fingerprint": "4fa5672bcd772a63", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-1b08f80fa6937ddd", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/components/ProcessOrganizationModal.tsx:278"}, "properties": {"repobilityId": "1b14b259068e0846", "scanner": "scanner-primary", "fingerprint": "1b08f80fa6937ddd", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-9b082cc9b7803d4c", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/components/ProcessSettingsModal.tsx:137"}, "properties": {"repobilityId": "62b1d260cd8ee5b2", "scanner": "scanner-primary", "fingerprint": "9b082cc9b7803d4c", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-ad6dd385e306a22e", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/components/ProcessOrganizationContent.tsx:235"}, "properties": {"repobilityId": "c69cde77b08fc410", "scanner": "scanner-primary", "fingerprint": "ad6dd385e306a22e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-022e6399d1ef2beb", "level": "note", "message": {"text": "12 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "7bf4178327da75a2", "scanner": "scanner-primary", "fingerprint": "022e6399d1ef2beb", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-45debcfc4924aa50", "level": "error", "message": {"text": "Dangling fetch: POST /api/upload-processo (apps/web/app/processos/inserir/page.tsx:670)"}, "properties": {"repobilityId": "4c6b603c4e565f76", "scanner": "scanner-primary", "fingerprint": "45debcfc4924aa50", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-d9e0fe9d3435aeb9", "level": "error", "message": {"text": "Dangling fetch: GET /api/folders?clientType=${clientType} (apps/web/components/ProcessOrganizationModal.tsx:83)"}, "properties": {"repobilityId": "2aa3195c0bae55b2", "scanner": "scanner-primary", "fingerprint": "d9e0fe9d3435aeb9", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-de7e870403ccbaae", "level": "error", "message": {"text": "Dangling fetch: POST /api/manage-folder (apps/web/components/ProcessOrganizationModal.tsx:278)"}, "properties": {"repobilityId": "0367689efab6b9ee", "scanner": "scanner-primary", "fingerprint": "de7e870403ccbaae", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-4fac313e14fbef13", "level": "error", "message": {"text": "Dangling fetch: POST /api/move-processo (apps/web/components/ProcessOrganizationModal.tsx:303)"}, "properties": {"repobilityId": "193db6364b1eb1b1", "scanner": "scanner-primary", "fingerprint": "4fac313e14fbef13", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-4323f451c412d4a6", "level": "error", "message": {"text": "Dangling fetch: POST /api/manage-folder (apps/web/components/ProcessOrganizationModal.tsx:340)"}, "properties": {"repobilityId": "8203a8ed015604af", "scanner": "scanner-primary", "fingerprint": "4323f451c412d4a6", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-665390c76425e91f", "level": "error", "message": {"text": "Dangling fetch: POST /api/manage-folder (apps/web/components/ProcessOrganizationModal.tsx:375)"}, "properties": {"repobilityId": "ac86896fb569cfd1", "scanner": "scanner-primary", "fingerprint": "665390c76425e91f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-ab24559110b30f05", "level": "error", "message": {"text": "Dangling fetch: POST /api/manage-folder (apps/web/components/ProcessOrganizationModal.tsx:407)"}, "properties": {"repobilityId": "b248fdcf13231a50", "scanner": "scanner-primary", "fingerprint": "ab24559110b30f05", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-85495822cf67e1fb", "level": "error", "message": {"text": "Dangling fetch: POST /api/upload-processo (apps/web/components/ProcessOrganizationModal.tsx:455)"}, "properties": {"repobilityId": "bb4f9510047495c1", "scanner": "scanner-primary", "fingerprint": "85495822cf67e1fb", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-35900cab4f3a9684", "level": "error", "message": {"text": "Dangling fetch: GET /api/documents/${encodeURIComponent(processSlug)} (apps/web/components/ProcessSettingsModal.tsx:83)"}, "properties": {"repobilityId": "47f200259b72d935", "scanner": "scanner-primary", "fingerprint": "35900cab4f3a9684", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-95b3d3cafb3491b3", "level": "error", "message": {"text": "Dangling fetch: GET /api/documents/${encodeURIComponent(processSlug)}/folders (apps/web/components/ProcessSettingsModal.tsx:95)"}, "properties": {"repobilityId": "81ff2b7650b84314", "scanner": "scanner-primary", "fingerprint": "95b3d3cafb3491b3", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-64d659fdc0922445", "level": "error", "message": {"text": "Dangling fetch: POST /api/documents/${encodeURIComponent(processSlug)} (apps/web/components/ProcessSettingsModal.tsx:137)"}, "properties": {"repobilityId": "ebe2ea4cd8f05492", "scanner": "scanner-primary", "fingerprint": "64d659fdc0922445", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-9a1e1df78ccf0e6d", "level": "error", "message": {"text": "Dangling fetch: POST /api/rename-file (apps/web/components/ProcessSettingsModal.tsx:224)"}, "properties": {"repobilityId": "8ce7ece01e58c00f", "scanner": "scanner-primary", "fingerprint": "9a1e1df78ccf0e6d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-c6e4a95139f0116a", "level": "error", "message": {"text": "Dangling fetch: GET /api/folders?clientType=${clientType} (apps/web/components/ProcessOrganizationContent.tsx:69)"}, "properties": {"repobilityId": "f6b341733a20f5bc", "scanner": "scanner-primary", "fingerprint": "c6e4a95139f0116a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-60ef15718ffcb65c", "level": "error", "message": {"text": "Dangling fetch: POST /api/manage-folder (apps/web/components/ProcessOrganizationContent.tsx:235)"}, "properties": {"repobilityId": "4ed7ac330aedfea6", "scanner": "scanner-primary", "fingerprint": "60ef15718ffcb65c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-e6acd87c8c49f4a1", "level": "error", "message": {"text": "Dangling fetch: POST /api/move-processo (apps/web/components/ProcessOrganizationContent.tsx:252)"}, "properties": {"repobilityId": "0ac09814d11eeb9e", "scanner": "scanner-primary", "fingerprint": "e6acd87c8c49f4a1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-71884c7caea4eef6", "level": "error", "message": {"text": "Dangling fetch: POST /api/manage-folder (apps/web/components/ProcessOrganizationContent.tsx:277)"}, "properties": {"repobilityId": "e94b0b98ebca2fb3", "scanner": "scanner-primary", "fingerprint": "71884c7caea4eef6", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-45a3a8c205f0a459", "level": "error", "message": {"text": "Dangling fetch: POST /api/manage-folder (apps/web/components/ProcessOrganizationContent.tsx:298)"}, "properties": {"repobilityId": "e8734e35070d49f0", "scanner": "scanner-primary", "fingerprint": "45a3a8c205f0a459", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-71e0c7c863f14cc3", "level": "error", "message": {"text": "Dangling fetch: POST /api/manage-folder (apps/web/components/ProcessOrganizationContent.tsx:318)"}, "properties": {"repobilityId": "a5c5b87efb664792", "scanner": "scanner-primary", "fingerprint": "71e0c7c863f14cc3", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-dad1776fb2e14bb3", "level": "error", "message": {"text": "Dangling fetch: POST /api/upload-processo (apps/web/components/ProcessOrganizationContent.tsx:348)"}, "properties": {"repobilityId": "5e86d0e20426d06f", "scanner": "scanner-primary", "fingerprint": "dad1776fb2e14bb3", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-4756b4c4da7d2088", "level": "note", "message": {"text": "Unused endpoint: GET /api/health"}, "properties": {"repobilityId": "273a9c4a06c02ef2", "scanner": "scanner-primary", "fingerprint": "4756b4c4da7d2088", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1920efcc06d9792f", "level": "note", "message": {"text": "Unused endpoint: GET /api/processes"}, "properties": {"repobilityId": "03448faa5a8e2656", "scanner": "scanner-primary", "fingerprint": "1920efcc06d9792f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-097c9bc230c84572", "level": "note", "message": {"text": "Unused endpoint: GET /api/processes/:slug/bpmn"}, "properties": {"repobilityId": "025919c99fad061a", "scanner": "scanner-primary", "fingerprint": "097c9bc230c84572", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a55ed85877e98c18", "level": "note", "message": {"text": "Unused endpoint: GET /api/processes/:slug/descriptions"}, "properties": {"repobilityId": "f858acc9a670b57e", "scanner": "scanner-primary", "fingerprint": "a55ed85877e98c18", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}