{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-3c19aff01dc2cef3", "name": "Possibly dead Python function: is_expired", "shortDescription": {"text": "Possibly dead Python function: is_expired"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-628c6d2b3a0dfcb8", "name": "Possibly dead Python function: is_not_yet_valid", "shortDescription": {"text": "Possibly dead Python function: is_not_yet_valid"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4594c398c478ded9", "name": "Stray `console.log` in TS/JS \u2014 scripts/ping-search-engines.ts:13", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/ping-search-engines.ts:13"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-af5190bf59170504", "name": "`truncate` class without `title=` for hover reveal \u2014 components/ui/blog-reader.tsx:490", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 components/ui/blog-reader.tsx:490"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f58219ffde32eceb", "name": "`truncate` class without `title=` for hover reveal \u2014 components/ui/navbar.tsx:302", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 components/ui/navbar.tsx:302"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d8b8c86bad46ada3", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 app/page.tsx:163", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/page.tsx:163"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-18ea7eb2aafe5412", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 app/layout.tsx:290", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/layout.tsx:290"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4fe0dd2a1dcea86a", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 app/about/page.tsx:126", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/about/page.tsx:126"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ee8c9fe133e80d93", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 app/blog/page.tsx:213", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/blog/page.tsx:213"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3c5ba3b56f568254", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 app/blog/tag/[tag]/page.tsx:115", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/blog/tag/[tag]/page.tsx:115"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0d049d35478400a1", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 app/blog/[slug]/page.tsx:239", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/blog/[slug]/page.tsx:239"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ed2f2d6fc92c239c", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 app/blog/[slug]/blog-post-client.tsx:279", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/blog/[slug]/blog-post-client.tsx:279"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ccb19bfc4fa4072b", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 app/qauth/page.tsx:47", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/qauth/page.tsx:47"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-108fc8256b026e05", "name": "`truncate` class without `title=` for hover reveal \u2014 app/qauth/demo/demo-client.tsx:373", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/qauth/demo/demo-client.tsx:373"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-27033afea07fb547", "name": "Stray `console.log` in TS/JS \u2014 app/qauth/docs/docs-client.tsx:32", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 app/qauth/docs/docs-client.tsx:32"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9df9bfed5eac38cc", "name": "Stray `console.log` in TS/JS \u2014 app/qauth/docs/api/api-client.tsx:88", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 app/qauth/docs/api/api-client.tsx:88"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-44e113036141637e", "name": "Stray `console.log` in TS/JS \u2014 app/qauth/docs/full-auth/full-auth-client.tsx:498", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 app/qauth/docs/full-auth/full-auth-client.tsx:498"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2ee1cddb3d456a4d", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 app/quantum-shield/page.tsx:47", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/quantum-shield/page.tsx:47"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d4af12d377a339a4", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 app/privacy/page.tsx:31", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/privacy/page.tsx:31"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-297d3251e43c2ac5", "name": "Insecure pattern 'node_child_process' in scripts/generate-audio.mjs:25", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/generate-audio.mjs:25"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cc412e5ed0e42557", "name": "Insecure pattern 'dangerous_innerhtml' in app/page.tsx:163", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in app/page.tsx:163"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0a81753c2ff46da3", "name": "Insecure pattern 'dangerous_innerhtml' in app/layout.tsx:290", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in app/layout.tsx:290"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fad7887e53c18bd2", "name": "Insecure pattern 'dangerous_innerhtml' in app/about/page.tsx:126", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in app/about/page.tsx:126"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7f5ef1e8b3943daf", "name": "Insecure pattern 'dangerous_innerhtml' in app/blog/page.tsx:213", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in app/blog/page.tsx:213"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c0e3946a722580d5", "name": "Insecure pattern 'dangerous_innerhtml' in app/blog/tag/[tag]/page.tsx:115", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in app/blog/tag/[tag]/page.tsx:115"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-14b84a00126278b5", "name": "Insecure pattern 'dangerous_innerhtml' in app/blog/[slug]/page.tsx:239", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in app/blog/[slug]/page.tsx:239"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d502f3ee27d3c323", "name": "Insecure pattern 'dangerous_innerhtml' in app/blog/[slug]/blog-post-client.tsx:279", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in app/blog/[slug]/blog-post-client.tsx:279"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-360fa96d2cab56d0", "name": "Insecure pattern 'local_storage_auth_token' in app/admin/page.tsx:32", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in app/admin/page.tsx:32"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d34f5750a0ab3d3a", "name": "Insecure pattern 'dangerous_innerhtml' in app/qauth/page.tsx:47", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in app/qauth/page.tsx:47"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-124eeb7b8ff44597", "name": "Insecure pattern 'dangerous_innerhtml' in app/quantum-shield/page.tsx:47", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in app/quantum-shield/page.tsx:47"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0a5b6db3baacbf97", "name": "Insecure pattern 'dangerous_innerhtml' in app/privacy/page.tsx:31", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in app/privacy/page.tsx:31"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5df87d9fdf996f64", "name": "Insecure pattern 'local_storage_auth_token' in lib/api.ts:81", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in lib/api.ts:81"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cb4b50a395369ed3", "name": "Insecure pattern 'new_function_used' in public/wasm/quantum_shield_demo.js:1519", "shortDescription": {"text": "Insecure pattern 'new_function_used' in public/wasm/quantum_shield_demo.js:1519"}, "fullDescription": {"text": "Found a known-risky pattern (new_function_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-90da0338b5c1b7fa", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e046e53a8d17f316", "name": "GitHub Action tracks a moving branch", "shortDescription": {"text": "GitHub Action tracks a moving branch"}, "fullDescription": {"text": "dtolnay/rust-toolchain@master can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a7923ddf028a9310", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/cache@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dc2662262a95566e", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ad40b1e0a5584947", "name": "Very large file: app/qauth/qauth-client.tsx (1040 lines)", "shortDescription": {"text": "Very large file: app/qauth/qauth-client.tsx (1040 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c4a1d16d00a0ff20", "name": "Very large file: app/quantum-shield/quantum-shield-client.tsx (1001 lines)", "shortDescription": {"text": "Very large file: app/quantum-shield/quantum-shield-client.tsx (1001 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8b6921f8780d2396", "name": "Very large file: quantum-shield/wasm/src/lib.rs (1400 lines)", "shortDescription": {"text": "Very large file: quantum-shield/wasm/src/lib.rs (1400 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-70051a2f819ddbc2", "name": "Very large file: public/wasm/quantum_shield_demo.js (1871 lines)", "shortDescription": {"text": "Very large file: public/wasm/quantum_shield_demo.js (1871 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "15 test file(s) for 163 source file(s) (ratio 0.09). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6f648f9041b618c5", "name": "Node manifest has dependencies but no lockfile: quantum-shield/wasm/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: quantum-shield/wasm/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 83 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 25 placeholder/mock markers across 9 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-093c1859cae5d417", "name": "Commented-code block (5 lines) in next.config.ts:79", "shortDescription": {"text": "Commented-code block (5 lines) in next.config.ts:79"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-acc2aead94e6fae2", "name": "`fetch()` without try/.catch or AbortSignal \u2014 app/api/indexnow/route.ts:42", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 app/api/indexnow/route.ts:42"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a5550b15a6bc9f0f", "name": "Commented-code block (5 lines) in app/qauth/docs/policy/policy-client.tsx:148", "shortDescription": {"text": "Commented-code block (5 lines) in app/qauth/docs/policy/policy-client.tsx:148"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5f0c029aa86da0eb", "name": "`fetch()` without try/.catch or AbortSignal \u2014 app/qauth/docs/api/api-client.tsx:128", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 app/qauth/docs/api/api-client.tsx:128"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f722f3d1f65dd996", "name": "Commented-code block (5 lines) in quantum-shield/examples/key_exchange.py:140", "shortDescription": {"text": "Commented-code block (5 lines) in quantum-shield/examples/key_exchange.py:140"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4ed5eef2b195381f", "name": "`fetch()` without try/.catch or AbortSignal \u2014 public/wasm/quantum_shield_demo.js:1863", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/wasm/quantum_shield_demo.js:1863"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3c96ce36d7c8975b", "name": "Network/subprocess call without timeout or try/except \u2014 backend/create_blogs.py:12", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 backend/create_blogs.py:12"}, "fullDescription": {"text": "`requests.post(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-be46ea126aa5d8dc", "name": "Near-duplicate function bodies in 3 places", "shortDescription": {"text": "Near-duplicate function bodies in 3 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nquantum-shield/qauth/sdks/python/qauth/__init__.py:validate_token, quantum-shield/qauth/sdks/python/qauth/__init__.py:validate, quantum-shield/qauth/sdks/python/qauth/__init__.py:validate\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5773a11475834e56", "name": "FastAPI POST `create_comment` without auth dependency \u2014 backend/routers/blog_router.py:179", "shortDescription": {"text": "FastAPI POST `create_comment` without auth dependency \u2014 backend/routers/blog_router.py:179"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7359cdbd1c94abb5", "name": "Dangling fetch: POST https://www.bing.com/indexnow (scripts/ping-search-engines.ts:52)", "shortDescription": {"text": "Dangling fetch: POST https://www.bing.com/indexnow (scripts/ping-search-engines.ts:52)"}, "fullDescription": {"text": "`scripts/ping-search-engines.ts:52` calls `POST https://www.bing.com/indexnow` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/www.bing.com/indexnow`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f6e9ce5b290cfe71", "name": "Dangling fetch: POST https://api.indexnow.org/indexnow (scripts/ping-search-engines.ts:64)", "shortDescription": {"text": "Dangling fetch: POST https://api.indexnow.org/indexnow (scripts/ping-search-engines.ts:64)"}, "fullDescription": {"text": "`scripts/ping-search-engines.ts:64` calls `POST https://api.indexnow.org/indexnow` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.indexnow.org/indexnow`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-01c73fe50b0aa933", "name": "Dangling fetch: POST /api/chat (components/ui/ai-chat-panel.tsx:148)", "shortDescription": {"text": "Dangling fetch: POST /api/chat (components/ui/ai-chat-panel.tsx:148)"}, "fullDescription": {"text": "`components/ui/ai-chat-panel.tsx:148` calls `POST /api/chat` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/chat`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a4faa220aad4a453", "name": "Dangling fetch: POST /api/waitlist (components/quantum-shield/WaitlistForm.tsx:37)", "shortDescription": {"text": "Dangling fetch: POST /api/waitlist (components/quantum-shield/WaitlistForm.tsx:37)"}, "fullDescription": {"text": "`components/quantum-shield/WaitlistForm.tsx:37` calls `POST /api/waitlist` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/waitlist`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3a53b67c77cee85b", "name": "Dangling fetch: GET /api/waitlist (components/quantum-shield/StatsCounter.tsx:13)", "shortDescription": {"text": "Dangling fetch: GET /api/waitlist (components/quantum-shield/StatsCounter.tsx:13)"}, "fullDescription": {"text": "`components/quantum-shield/StatsCounter.tsx:13` calls `GET /api/waitlist` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/waitlist`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-253178b7ce22d036", "name": "Dangling fetch: GET /api/users/me (app/qauth/docs/api/api-client.tsx:128)", "shortDescription": {"text": "Dangling fetch: GET /api/users/me (app/qauth/docs/api/api-client.tsx:128)"}, "fullDescription": {"text": "`app/qauth/docs/api/api-client.tsx:128` calls `GET /api/users/me` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/users/me`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5c126b98a8fda670", "name": "Dangling fetch: GET /wasm/quantum_shield_demo.js (app/quantum-shield/demo/demo-client.tsx:128)", "shortDescription": {"text": "Dangling fetch: GET /wasm/quantum_shield_demo.js (app/quantum-shield/demo/demo-client.tsx:128)"}, "fullDescription": {"text": "`app/quantum-shield/demo/demo-client.tsx:128` calls `GET /wasm/quantum_shield_demo.js` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/wasm/quantum_shield_demo.js`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c65ade85d9075630", "name": "Dangling fetch: GET /api/blogs (lib/api.ts:49)", "shortDescription": {"text": "Dangling fetch: GET /api/blogs (lib/api.ts:49)"}, "fullDescription": {"text": "`lib/api.ts:49` calls `GET /api/blogs` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/blogs`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9e06e22e5e20feb9", "name": "Dangling fetch: GET /api/blogs/slug/${slug} (lib/api.ts:53)", "shortDescription": {"text": "Dangling fetch: GET /api/blogs/slug/${slug} (lib/api.ts:53)"}, "fullDescription": {"text": "`lib/api.ts:53` calls `GET /api/blogs/slug/${slug}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/blogs/slug/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c3bb2efbc00d4497", "name": "Dangling fetch: GET /api/blogs/search?q=${encodedQuery} (lib/api.ts:58)", "shortDescription": {"text": "Dangling fetch: GET /api/blogs/search?q=${encodedQuery} (lib/api.ts:58)"}, "fullDescription": {"text": "`lib/api.ts:58` calls `GET /api/blogs/search?q=${encodedQuery}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/blogs/search`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5f11ba133c55dfa4", "name": "Dangling fetch: GET /api/blogs/${blogId}/comments (lib/api.ts:62)", "shortDescription": {"text": "Dangling fetch: GET /api/blogs/${blogId}/comments (lib/api.ts:62)"}, "fullDescription": {"text": "`lib/api.ts:62` calls `GET /api/blogs/${blogId}/comments` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/blogs/<p>/comments`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-772c3387cf14c644", "name": "Dangling fetch: POST /api/blogs/comments (lib/api.ts:66)", "shortDescription": {"text": "Dangling fetch: POST /api/blogs/comments (lib/api.ts:66)"}, "fullDescription": {"text": "`lib/api.ts:66` calls `POST /api/blogs/comments` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/blogs/comments`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5a5192c48756fedc", "name": "Dangling fetch: POST /api/blogs (lib/api.ts:95)", "shortDescription": {"text": "Dangling fetch: POST /api/blogs (lib/api.ts:95)"}, "fullDescription": {"text": "`lib/api.ts:95` calls `POST /api/blogs` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/blogs`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-82e3b5f7e63552ef", "name": "Dangling fetch: PUT /api/blogs/${id} (lib/api.ts:103)", "shortDescription": {"text": "Dangling fetch: PUT /api/blogs/${id} (lib/api.ts:103)"}, "fullDescription": {"text": "`lib/api.ts:103` calls `PUT /api/blogs/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/blogs/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-36031199ecd5eff8", "name": "Dangling fetch: DELETE /api/blogs/${id} (lib/api.ts:111)", "shortDescription": {"text": "Dangling fetch: DELETE /api/blogs/${id} (lib/api.ts:111)"}, "fullDescription": {"text": "`lib/api.ts:111` calls `DELETE /api/blogs/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/blogs/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-16cb8910a1b775d1", "name": "Dangling fetch: GET /api/blogs/${id} (lib/api.ts:118)", "shortDescription": {"text": "Dangling fetch: GET /api/blogs/${id} (lib/api.ts:118)"}, "fullDescription": {"text": "`lib/api.ts:118` calls `GET /api/blogs/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/blogs/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6032b0ec0dca42e1", "name": "Dangling fetch: PATCH /api/blogs/comments/${id}/approve (lib/api.ts:125)", "shortDescription": {"text": "Dangling fetch: PATCH /api/blogs/comments/${id}/approve (lib/api.ts:125)"}, "fullDescription": {"text": "`lib/api.ts:125` calls `PATCH /api/blogs/comments/${id}/approve` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/blogs/comments/<p>/approve`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-aea376d23590940d", "name": "Dangling fetch: DELETE /api/blogs/comments/${id} (lib/api.ts:132)", "shortDescription": {"text": "Dangling fetch: DELETE /api/blogs/comments/${id} (lib/api.ts:132)"}, "fullDescription": {"text": "`lib/api.ts:132` calls `DELETE /api/blogs/comments/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/blogs/comments/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`backend/main.py` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7b7ecdd35e1b1d84", "name": "Unused endpoint: GET /slug/{slug}", "shortDescription": {"text": "Unused endpoint: GET /slug/{slug}"}, "fullDescription": {"text": "`backend/routers/blog_router.py` declares `GET /slug/{slug}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d16e4fa529c520e9", "name": "Unused endpoint: GET /search", "shortDescription": {"text": "Unused endpoint: GET /search"}, "fullDescription": {"text": "`backend/routers/blog_router.py` declares `GET /search` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a009b1a56794f45", "name": "Unused endpoint: POST /", "shortDescription": {"text": "Unused endpoint: POST /"}, "fullDescription": {"text": "`backend/routers/blog_router.py` declares `POST /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8acef98448417765", "name": "Unused endpoint: GET /{blog_id}", "shortDescription": {"text": "Unused endpoint: GET /{blog_id}"}, "fullDescription": {"text": "`backend/routers/blog_router.py` declares `GET /{blog_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-065442e8bfd352c6", "name": "Unused endpoint: PUT /{blog_id}", "shortDescription": {"text": "Unused endpoint: PUT /{blog_id}"}, "fullDescription": {"text": "`backend/routers/blog_router.py` declares `PUT /{blog_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a264091f4e3d47be", "name": "Unused endpoint: DELETE /{blog_id}", "shortDescription": {"text": "Unused endpoint: DELETE /{blog_id}"}, "fullDescription": {"text": "`backend/routers/blog_router.py` declares `DELETE /{blog_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2f45a153048d9870", "name": "Unused endpoint: POST /comments", "shortDescription": {"text": "Unused endpoint: POST /comments"}, "fullDescription": {"text": "`backend/routers/blog_router.py` declares `POST /comments` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b24605857807c293", "name": "Unused endpoint: GET /{blog_id}/comments", "shortDescription": {"text": "Unused endpoint: GET /{blog_id}/comments"}, "fullDescription": {"text": "`backend/routers/blog_router.py` declares `GET /{blog_id}/comments` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-974f7e95c1541d74", "name": "Unused endpoint: PATCH /comments/{comment_id}/approve", "shortDescription": {"text": "Unused endpoint: PATCH /comments/{comment_id}/approve"}, "fullDescription": {"text": "`backend/routers/blog_router.py` declares `PATCH /comments/{comment_id}/approve` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-855ced39c3f8d63b", "name": "Unused endpoint: DELETE /comments/{comment_id}", "shortDescription": {"text": "Unused endpoint: DELETE /comments/{comment_id}"}, "fullDescription": {"text": "`backend/routers/blog_router.py` declares `DELETE /comments/{comment_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-618721b912bad1c2", "name": "Unused endpoint: POST /login", "shortDescription": {"text": "Unused endpoint: POST /login"}, "fullDescription": {"text": "`backend/routers/auth_router.py` declares `POST /login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d5a39262ac205120", "name": "Unused endpoint: POST /api/auth/logout", "shortDescription": {"text": "Unused endpoint: POST /api/auth/logout"}, "fullDescription": {"text": "`app/qauth/docs/full-auth/full-auth-client.tsx` declares `POST /api/auth/logout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4a12d5ed34c864c6", "name": "Unused endpoint: POST /auth/signup", "shortDescription": {"text": "Unused endpoint: POST /auth/signup"}, "fullDescription": {"text": "`app/qauth/docs/full-auth/full-auth-client.tsx` declares `POST /auth/signup` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5c1545494ab6166c", "name": "Unused endpoint: GET /api/me", "shortDescription": {"text": "Unused endpoint: GET /api/me"}, "fullDescription": {"text": "`app/qauth/docs/full-auth/full-auth-client.tsx` declares `GET /api/me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/21731"}, "properties": {"repository": "Tushar010402/Tushar-Agrawal-Website", "repoUrl": "https://github.com/Tushar010402/Tushar-Agrawal-Website", "branch": "main"}, "results": [{"ruleId": "scanner-3c19aff01dc2cef3", "level": "note", "message": {"text": "Possibly dead Python function: is_expired"}, "properties": {"repobilityId": "43d05883fea1f364", "scanner": "scanner-primary", "fingerprint": "3c19aff01dc2cef3", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "quantum-shield/qauth/sdks/python/qauth/__init__.py:72"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-628c6d2b3a0dfcb8", "level": "note", "message": {"text": "Possibly dead Python function: is_not_yet_valid"}, "properties": {"repobilityId": "2facfbe8eabf5fa4", "scanner": "scanner-primary", "fingerprint": "628c6d2b3a0dfcb8", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "quantum-shield/qauth/sdks/python/qauth/__init__.py:76"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4594c398c478ded9", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/ping-search-engines.ts:13"}, "properties": {"repobilityId": "c205545e17cf71ea", "scanner": "scanner-primary", "fingerprint": "4594c398c478ded9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-af5190bf59170504", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 components/ui/blog-reader.tsx:490"}, "properties": {"repobilityId": "04c3a811888a6d56", "scanner": "scanner-primary", "fingerprint": "af5190bf59170504", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-f58219ffde32eceb", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 components/ui/navbar.tsx:302"}, "properties": {"repobilityId": "4e00310c17402355", "scanner": "scanner-primary", "fingerprint": "f58219ffde32eceb", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-d8b8c86bad46ada3", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/page.tsx:163"}, "properties": {"repobilityId": "6779a4843a9d41ee", "scanner": "scanner-primary", "fingerprint": "d8b8c86bad46ada3", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-18ea7eb2aafe5412", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/layout.tsx:290"}, "properties": {"repobilityId": "6f16eb9b82a2dcd6", "scanner": "scanner-primary", "fingerprint": "18ea7eb2aafe5412", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-4fe0dd2a1dcea86a", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/about/page.tsx:126"}, "properties": {"repobilityId": "6d20b1460170584a", "scanner": "scanner-primary", "fingerprint": "4fe0dd2a1dcea86a", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-ee8c9fe133e80d93", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/blog/page.tsx:213"}, "properties": {"repobilityId": "1f238bbf17f33cc8", "scanner": "scanner-primary", "fingerprint": "ee8c9fe133e80d93", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-3c5ba3b56f568254", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/blog/tag/[tag]/page.tsx:115"}, "properties": {"repobilityId": "dc16ec51352b6884", "scanner": "scanner-primary", "fingerprint": "3c5ba3b56f568254", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-0d049d35478400a1", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/blog/[slug]/page.tsx:239"}, "properties": {"repobilityId": "c21e1247bf006285", "scanner": "scanner-primary", "fingerprint": "0d049d35478400a1", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-ed2f2d6fc92c239c", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/blog/[slug]/blog-post-client.tsx:279"}, "properties": {"repobilityId": "5a723e04afc377c6", "scanner": "scanner-primary", "fingerprint": "ed2f2d6fc92c239c", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-ccb19bfc4fa4072b", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/qauth/page.tsx:47"}, "properties": {"repobilityId": "140dd607053d9439", "scanner": "scanner-primary", "fingerprint": "ccb19bfc4fa4072b", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-108fc8256b026e05", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/qauth/demo/demo-client.tsx:373"}, "properties": {"repobilityId": "185e86539be60a76", "scanner": "scanner-primary", "fingerprint": "108fc8256b026e05", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-27033afea07fb547", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 app/qauth/docs/docs-client.tsx:32"}, "properties": {"repobilityId": "9939068724ddeb86", "scanner": "scanner-primary", "fingerprint": "27033afea07fb547", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9df9bfed5eac38cc", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 app/qauth/docs/api/api-client.tsx:88"}, "properties": {"repobilityId": "b4ea8efbc44da7b3", "scanner": "scanner-primary", "fingerprint": "9df9bfed5eac38cc", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-44e113036141637e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 app/qauth/docs/full-auth/full-auth-client.tsx:498"}, "properties": {"repobilityId": "ff41d0b35622b278", "scanner": "scanner-primary", "fingerprint": "44e113036141637e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2ee1cddb3d456a4d", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/quantum-shield/page.tsx:47"}, "properties": {"repobilityId": "bc2b7785dbd5992c", "scanner": "scanner-primary", "fingerprint": "2ee1cddb3d456a4d", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-d4af12d377a339a4", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/privacy/page.tsx:31"}, "properties": {"repobilityId": "66ca60bff35ad72c", "scanner": "scanner-primary", "fingerprint": "d4af12d377a339a4", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-297d3251e43c2ac5", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/generate-audio.mjs:25"}, "properties": {"repobilityId": "4b86e93f5dd3e2f3", "scanner": "scanner-primary", "fingerprint": "297d3251e43c2ac5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/generate-audio.mjs"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-cc412e5ed0e42557", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in app/page.tsx:163"}, "properties": {"repobilityId": "cfec9d1837258177", "scanner": "scanner-primary", "fingerprint": "cc412e5ed0e42557", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/page.tsx"}, "region": {"startLine": 163}}}]}, {"ruleId": "scanner-0a81753c2ff46da3", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in app/layout.tsx:290"}, "properties": {"repobilityId": "69d4743587f721a0", "scanner": "scanner-primary", "fingerprint": "0a81753c2ff46da3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/layout.tsx"}, "region": {"startLine": 290}}}]}, {"ruleId": "scanner-fad7887e53c18bd2", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in app/about/page.tsx:126"}, "properties": {"repobilityId": "dd88c92d39901aad", "scanner": "scanner-primary", "fingerprint": "fad7887e53c18bd2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/about/page.tsx"}, "region": {"startLine": 126}}}]}, {"ruleId": "scanner-7f5ef1e8b3943daf", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in app/blog/page.tsx:213"}, "properties": {"repobilityId": "4b5bb7451f415d1c", "scanner": "scanner-primary", "fingerprint": "7f5ef1e8b3943daf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/blog/page.tsx"}, "region": {"startLine": 213}}}]}, {"ruleId": "scanner-c0e3946a722580d5", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in app/blog/tag/[tag]/page.tsx:115"}, "properties": {"repobilityId": "5931e81eda39573e", "scanner": "scanner-primary", "fingerprint": "c0e3946a722580d5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/blog/tag/[tag]/page.tsx"}, "region": {"startLine": 115}}}]}, {"ruleId": "scanner-14b84a00126278b5", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in app/blog/[slug]/page.tsx:239"}, "properties": {"repobilityId": "9c6991e1f0c5c6d8", "scanner": "scanner-primary", "fingerprint": "14b84a00126278b5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/blog/[slug]/page.tsx"}, "region": {"startLine": 239}}}]}, {"ruleId": "scanner-d502f3ee27d3c323", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in app/blog/[slug]/blog-post-client.tsx:279"}, "properties": {"repobilityId": "8a57f85be138be7a", "scanner": "scanner-primary", "fingerprint": "d502f3ee27d3c323", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/blog/[slug]/blog-post-client.tsx"}, "region": {"startLine": 279}}}]}, {"ruleId": "scanner-360fa96d2cab56d0", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in app/admin/page.tsx:32"}, "properties": {"repobilityId": "bf45e5211d9f02bf", "scanner": "scanner-primary", "fingerprint": "360fa96d2cab56d0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/admin/page.tsx"}, "region": {"startLine": 32}}}]}, {"ruleId": "scanner-d34f5750a0ab3d3a", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in app/qauth/page.tsx:47"}, "properties": {"repobilityId": "c8f729f931ebeb1e", "scanner": "scanner-primary", "fingerprint": "d34f5750a0ab3d3a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/qauth/page.tsx"}, "region": {"startLine": 47}}}]}, {"ruleId": "scanner-124eeb7b8ff44597", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in app/quantum-shield/page.tsx:47"}, "properties": {"repobilityId": "17f5b1e8274e111d", "scanner": "scanner-primary", "fingerprint": "124eeb7b8ff44597", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/quantum-shield/page.tsx"}, "region": {"startLine": 47}}}]}, {"ruleId": "scanner-0a5b6db3baacbf97", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in app/privacy/page.tsx:31"}, "properties": {"repobilityId": "2de92323a4743f70", "scanner": "scanner-primary", "fingerprint": "0a5b6db3baacbf97", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/privacy/page.tsx"}, "region": {"startLine": 31}}}]}, {"ruleId": "scanner-5df87d9fdf996f64", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in lib/api.ts:81"}, "properties": {"repobilityId": "9046f3185ba041be", "scanner": "scanner-primary", "fingerprint": "5df87d9fdf996f64", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "lib/api.ts"}, "region": {"startLine": 81}}}]}, {"ruleId": "scanner-cb4b50a395369ed3", "level": "error", "message": {"text": "Insecure pattern 'new_function_used' in public/wasm/quantum_shield_demo.js:1519"}, "properties": {"repobilityId": "315a413a58201f12", "scanner": "scanner-primary", "fingerprint": "cb4b50a395369ed3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "new_function_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/wasm/quantum_shield_demo.js"}, "region": {"startLine": 1519}}}]}, {"ruleId": "scanner-90da0338b5c1b7fa", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "892e630f269527d4", "scanner": "scanner-primary", "fingerprint": "90da0338b5c1b7fa", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/indexnow.yml"}, "region": {"startLine": 39}}}]}, {"ruleId": "scanner-e046e53a8d17f316", "level": "error", "message": {"text": "GitHub Action tracks a moving branch"}, "properties": {"repobilityId": "73215ab8407f79cb", "scanner": "scanner-primary", "fingerprint": "e046e53a8d17f316", "layer": "cicd", "severity": "high", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/qauth-ci.yml"}, "region": {"startLine": 37}}}]}, {"ruleId": "scanner-a7923ddf028a9310", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "e10978bd6e0748c1", "scanner": "scanner-primary", "fingerprint": "a7923ddf028a9310", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/qauth-ci.yml"}, "region": {"startLine": 43}}}]}, {"ruleId": "scanner-a7923ddf028a9310", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ba816e60f8a12874", "scanner": "scanner-primary", "fingerprint": "a7923ddf028a9310", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/qauth-ci.yml"}, "region": {"startLine": 81}}}]}, {"ruleId": "scanner-a7923ddf028a9310", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "097232be9f44714c", "scanner": "scanner-primary", "fingerprint": "a7923ddf028a9310", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/qauth-ci.yml"}, "region": {"startLine": 93}}}]}, {"ruleId": "scanner-a7923ddf028a9310", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ba816e60f8a12874", "scanner": "scanner-primary", "fingerprint": "a7923ddf028a9310", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/qauth-ci.yml"}, "region": {"startLine": 107}}}]}, {"ruleId": "scanner-a7923ddf028a9310", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ba816e60f8a12874", "scanner": "scanner-primary", "fingerprint": "a7923ddf028a9310", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/qauth-ci.yml"}, "region": {"startLine": 125}}}]}, {"ruleId": "scanner-a7923ddf028a9310", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "75fd8ccfdcbdb52c", "scanner": "scanner-primary", "fingerprint": "a7923ddf028a9310", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/qauth-ci.yml"}, "region": {"startLine": 132}}}]}, {"ruleId": "scanner-a7923ddf028a9310", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ee7a237dbba89c0d", "scanner": "scanner-primary", "fingerprint": "a7923ddf028a9310", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/qauth-ci.yml"}, "region": {"startLine": 154}}}]}, {"ruleId": "scanner-a7923ddf028a9310", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "097232be9f44714c", "scanner": "scanner-primary", "fingerprint": "a7923ddf028a9310", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/qauth-ci.yml"}, "region": {"startLine": 181}}}]}, {"ruleId": "scanner-a7923ddf028a9310", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "2d8e5e79163424ad", "scanner": "scanner-primary", "fingerprint": "a7923ddf028a9310", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/qauth-ci.yml"}, "region": {"startLine": 204}}}]}, {"ruleId": "scanner-a7923ddf028a9310", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "097232be9f44714c", "scanner": "scanner-primary", "fingerprint": "a7923ddf028a9310", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/qauth-ci.yml"}, "region": {"startLine": 235}}}]}, {"ruleId": "scanner-a7923ddf028a9310", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "a31634fe87b026e9", "scanner": "scanner-primary", "fingerprint": "a7923ddf028a9310", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/qauth-ci.yml"}, "region": {"startLine": 258}}}]}, {"ruleId": "scanner-a7923ddf028a9310", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ba816e60f8a12874", "scanner": "scanner-primary", "fingerprint": "a7923ddf028a9310", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/qauth-ci.yml"}, "region": {"startLine": 289}}}]}, {"ruleId": "scanner-a7923ddf028a9310", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "75fd8ccfdcbdb52c", "scanner": "scanner-primary", "fingerprint": "a7923ddf028a9310", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/qauth-ci.yml"}, "region": {"startLine": 296}}}]}, {"ruleId": "scanner-a7923ddf028a9310", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ba816e60f8a12874", "scanner": "scanner-primary", "fingerprint": "a7923ddf028a9310", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/qauth-ci.yml"}, "region": {"startLine": 313}}}]}, {"ruleId": "scanner-a7923ddf028a9310", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ee7a237dbba89c0d", "scanner": "scanner-primary", "fingerprint": "a7923ddf028a9310", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/qauth-ci.yml"}, "region": {"startLine": 332}}}]}, {"ruleId": "scanner-a7923ddf028a9310", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "74e7e7dd06c6209d", "scanner": "scanner-primary", "fingerprint": "a7923ddf028a9310", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/qauth-ci.yml"}, "region": {"startLine": 344}}}]}, {"ruleId": "scanner-a7923ddf028a9310", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "a31634fe87b026e9", "scanner": "scanner-primary", "fingerprint": "a7923ddf028a9310", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/qauth-ci.yml"}, "region": {"startLine": 357}}}]}, {"ruleId": "scanner-dc2662262a95566e", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "1e6adff29e917cf7", "scanner": "scanner-primary", "fingerprint": "dc2662262a95566e", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/qauth-ci.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ad40b1e0a5584947", "level": "note", "message": {"text": "Very large file: app/qauth/qauth-client.tsx (1040 lines)"}, "properties": {"repobilityId": "2bc25b1e58e62a40", "scanner": "scanner-primary", "fingerprint": "ad40b1e0a5584947", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-c4a1d16d00a0ff20", "level": "note", "message": {"text": "Very large file: app/quantum-shield/quantum-shield-client.tsx (1001 lines)"}, "properties": {"repobilityId": "4183f80a9851639f", "scanner": "scanner-primary", "fingerprint": "c4a1d16d00a0ff20", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-8b6921f8780d2396", "level": "note", "message": {"text": "Very large file: quantum-shield/wasm/src/lib.rs (1400 lines)"}, "properties": {"repobilityId": "aa66ab910893fd61", "scanner": "scanner-primary", "fingerprint": "8b6921f8780d2396", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-70051a2f819ddbc2", "level": "note", "message": {"text": "Very large file: public/wasm/quantum_shield_demo.js (1871 lines)"}, "properties": {"repobilityId": "607bfad9cdde047f", "scanner": "scanner-primary", "fingerprint": "70051a2f819ddbc2", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-6f648f9041b618c5", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: quantum-shield/wasm/package.json"}, "properties": {"repobilityId": "9f02060b29e91c9e", "scanner": "scanner-primary", "fingerprint": "6f648f9041b618c5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "quantum-shield/wasm/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "4717aab3f6ffec0a", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "49972bb0ecf7ff1a", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "ae8a755c7c0d0a7e", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "5f084ab894267795", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "92a842379bb32325", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-093c1859cae5d417", "level": "none", "message": {"text": "Commented-code block (5 lines) in next.config.ts:79"}, "properties": {"repobilityId": "4b1424e31da69038", "scanner": "scanner-primary", "fingerprint": "093c1859cae5d417", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-acc2aead94e6fae2", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 app/api/indexnow/route.ts:42"}, "properties": {"repobilityId": "42963cd316200963", "scanner": "scanner-primary", "fingerprint": "acc2aead94e6fae2", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-a5550b15a6bc9f0f", "level": "none", "message": {"text": "Commented-code block (5 lines) in app/qauth/docs/policy/policy-client.tsx:148"}, "properties": {"repobilityId": "b7ee55fcb74f4e1a", "scanner": "scanner-primary", "fingerprint": "a5550b15a6bc9f0f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5f0c029aa86da0eb", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 app/qauth/docs/api/api-client.tsx:128"}, "properties": {"repobilityId": "987f0c8b1a2e7321", "scanner": "scanner-primary", "fingerprint": "5f0c029aa86da0eb", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-f722f3d1f65dd996", "level": "none", "message": {"text": "Commented-code block (5 lines) in quantum-shield/examples/key_exchange.py:140"}, "properties": {"repobilityId": "d14b11ba51ee51aa", "scanner": "scanner-primary", "fingerprint": "f722f3d1f65dd996", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4ed5eef2b195381f", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/wasm/quantum_shield_demo.js:1863"}, "properties": {"repobilityId": "785ee3106bfd381f", "scanner": "scanner-primary", "fingerprint": "4ed5eef2b195381f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-3c96ce36d7c8975b", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 backend/create_blogs.py:12"}, "properties": {"repobilityId": "7d1e0719b7063dfc", "scanner": "scanner-primary", "fingerprint": "3c96ce36d7c8975b", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "cabc3bfc9a15395d", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "e37ef94d3fa1fa35", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "339e404aef3ad170", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "ab957d3465144af9", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "30d952c8ce7ccfa8", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-5773a11475834e56", "level": "error", "message": {"text": "FastAPI POST `create_comment` without auth dependency \u2014 backend/routers/blog_router.py:179"}, "properties": {"repobilityId": "0306fa216cef83c3", "scanner": "scanner-primary", "fingerprint": "5773a11475834e56", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routers/blog_router.py"}, "region": {"startLine": 179}}}]}, {"ruleId": "scanner-7359cdbd1c94abb5", "level": "error", "message": {"text": "Dangling fetch: POST https://www.bing.com/indexnow (scripts/ping-search-engines.ts:52)"}, "properties": {"repobilityId": "e044173ecc060542", "scanner": "scanner-primary", "fingerprint": "7359cdbd1c94abb5", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-f6e9ce5b290cfe71", "level": "error", "message": {"text": "Dangling fetch: POST https://api.indexnow.org/indexnow (scripts/ping-search-engines.ts:64)"}, "properties": {"repobilityId": "5c087a0ff1464c9a", "scanner": "scanner-primary", "fingerprint": "f6e9ce5b290cfe71", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-01c73fe50b0aa933", "level": "error", "message": {"text": "Dangling fetch: POST /api/chat (components/ui/ai-chat-panel.tsx:148)"}, "properties": {"repobilityId": "582f8b7b1d8bc49d", "scanner": "scanner-primary", "fingerprint": "01c73fe50b0aa933", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-a4faa220aad4a453", "level": "error", "message": {"text": "Dangling fetch: POST /api/waitlist (components/quantum-shield/WaitlistForm.tsx:37)"}, "properties": {"repobilityId": "4672c8d899b5deff", "scanner": "scanner-primary", "fingerprint": "a4faa220aad4a453", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-3a53b67c77cee85b", "level": "error", "message": {"text": "Dangling fetch: GET /api/waitlist (components/quantum-shield/StatsCounter.tsx:13)"}, "properties": {"repobilityId": "62c282499a4d88a3", "scanner": "scanner-primary", "fingerprint": "3a53b67c77cee85b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-253178b7ce22d036", "level": "error", "message": {"text": "Dangling fetch: GET /api/users/me (app/qauth/docs/api/api-client.tsx:128)"}, "properties": {"repobilityId": "b27a19f82f7cb943", "scanner": "scanner-primary", "fingerprint": "253178b7ce22d036", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-5c126b98a8fda670", "level": "error", "message": {"text": "Dangling fetch: GET /wasm/quantum_shield_demo.js (app/quantum-shield/demo/demo-client.tsx:128)"}, "properties": {"repobilityId": "a50e991deb0d1be6", "scanner": "scanner-primary", "fingerprint": "5c126b98a8fda670", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-c65ade85d9075630", "level": "error", "message": {"text": "Dangling fetch: GET /api/blogs (lib/api.ts:49)"}, "properties": {"repobilityId": "f714b06317dbe01a", "scanner": "scanner-primary", "fingerprint": "c65ade85d9075630", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-9e06e22e5e20feb9", "level": "error", "message": {"text": "Dangling fetch: GET /api/blogs/slug/${slug} (lib/api.ts:53)"}, "properties": {"repobilityId": "c511e4e6e6f0e22c", "scanner": "scanner-primary", "fingerprint": "9e06e22e5e20feb9", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-c3bb2efbc00d4497", "level": "error", "message": {"text": "Dangling fetch: GET /api/blogs/search?q=${encodedQuery} (lib/api.ts:58)"}, "properties": {"repobilityId": "d0e0d25d1576db3c", "scanner": "scanner-primary", "fingerprint": "c3bb2efbc00d4497", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-5f11ba133c55dfa4", "level": "error", "message": {"text": "Dangling fetch: GET /api/blogs/${blogId}/comments (lib/api.ts:62)"}, "properties": {"repobilityId": "7735fdb7026e4f1b", "scanner": "scanner-primary", "fingerprint": "5f11ba133c55dfa4", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-772c3387cf14c644", "level": "error", "message": {"text": "Dangling fetch: POST /api/blogs/comments (lib/api.ts:66)"}, "properties": {"repobilityId": "0ffea997bf438457", "scanner": "scanner-primary", "fingerprint": "772c3387cf14c644", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-5a5192c48756fedc", "level": "error", "message": {"text": "Dangling fetch: POST /api/blogs (lib/api.ts:95)"}, "properties": {"repobilityId": "4d64c2828f0a16a7", "scanner": "scanner-primary", "fingerprint": "5a5192c48756fedc", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-82e3b5f7e63552ef", "level": "error", "message": {"text": "Dangling fetch: PUT /api/blogs/${id} (lib/api.ts:103)"}, "properties": {"repobilityId": "5898ac74c1d320f0", "scanner": "scanner-primary", "fingerprint": "82e3b5f7e63552ef", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-36031199ecd5eff8", "level": "error", "message": {"text": "Dangling fetch: DELETE /api/blogs/${id} (lib/api.ts:111)"}, "properties": {"repobilityId": "1244cc6ae5513fdb", "scanner": "scanner-primary", "fingerprint": "36031199ecd5eff8", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-16cb8910a1b775d1", "level": "error", "message": {"text": "Dangling fetch: GET /api/blogs/${id} (lib/api.ts:118)"}, "properties": {"repobilityId": "973008cdb2bb40a8", "scanner": "scanner-primary", "fingerprint": "16cb8910a1b775d1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-6032b0ec0dca42e1", "level": "error", "message": {"text": "Dangling fetch: PATCH /api/blogs/comments/${id}/approve (lib/api.ts:125)"}, "properties": {"repobilityId": "b82189574b4b1753", "scanner": "scanner-primary", "fingerprint": "6032b0ec0dca42e1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-aea376d23590940d", "level": "error", "message": {"text": "Dangling fetch: DELETE /api/blogs/comments/${id} (lib/api.ts:132)"}, "properties": {"repobilityId": "a025848f02041541", "scanner": "scanner-primary", "fingerprint": "aea376d23590940d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "9266ee3970fba636", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7b7ecdd35e1b1d84", "level": "note", "message": {"text": "Unused endpoint: GET /slug/{slug}"}, "properties": {"repobilityId": "395d6365688c04ce", "scanner": "scanner-primary", "fingerprint": "7b7ecdd35e1b1d84", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d16e4fa529c520e9", "level": "note", "message": {"text": "Unused endpoint: GET /search"}, "properties": {"repobilityId": "eb5857c65c8d4c80", "scanner": "scanner-primary", "fingerprint": "d16e4fa529c520e9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a009b1a56794f45", "level": "note", "message": {"text": "Unused endpoint: POST /"}, "properties": {"repobilityId": "919cae4454d8a4d1", "scanner": "scanner-primary", "fingerprint": "7a009b1a56794f45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8acef98448417765", "level": "note", "message": {"text": "Unused endpoint: GET /{blog_id}"}, "properties": {"repobilityId": "901b7ba649b261e2", "scanner": "scanner-primary", "fingerprint": "8acef98448417765", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-065442e8bfd352c6", "level": "note", "message": {"text": "Unused endpoint: PUT /{blog_id}"}, "properties": {"repobilityId": "78de2175fd740bfc", "scanner": "scanner-primary", "fingerprint": "065442e8bfd352c6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a264091f4e3d47be", "level": "note", "message": {"text": "Unused endpoint: DELETE /{blog_id}"}, "properties": {"repobilityId": "e669c9b50fd5bab4", "scanner": "scanner-primary", "fingerprint": "a264091f4e3d47be", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2f45a153048d9870", "level": "note", "message": {"text": "Unused endpoint: POST /comments"}, "properties": {"repobilityId": "050dbc458b8cd7b7", "scanner": "scanner-primary", "fingerprint": "2f45a153048d9870", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b24605857807c293", "level": "note", "message": {"text": "Unused endpoint: GET /{blog_id}/comments"}, "properties": {"repobilityId": "fd3824fcfeb1353c", "scanner": "scanner-primary", "fingerprint": "b24605857807c293", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-974f7e95c1541d74", "level": "note", "message": {"text": "Unused endpoint: PATCH /comments/{comment_id}/approve"}, "properties": {"repobilityId": "e5cf773f0f88f8bd", "scanner": "scanner-primary", "fingerprint": "974f7e95c1541d74", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-855ced39c3f8d63b", "level": "note", "message": {"text": "Unused endpoint: DELETE /comments/{comment_id}"}, "properties": {"repobilityId": "28bd0ddc9c7999d3", "scanner": "scanner-primary", "fingerprint": "855ced39c3f8d63b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-618721b912bad1c2", "level": "note", "message": {"text": "Unused endpoint: POST /login"}, "properties": {"repobilityId": "cd175e7b4125c5a0", "scanner": "scanner-primary", "fingerprint": "618721b912bad1c2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d5a39262ac205120", "level": "note", "message": {"text": "Unused endpoint: POST /api/auth/logout"}, "properties": {"repobilityId": "a1cc84419bb26992", "scanner": "scanner-primary", "fingerprint": "d5a39262ac205120", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4a12d5ed34c864c6", "level": "note", "message": {"text": "Unused endpoint: POST /auth/signup"}, "properties": {"repobilityId": "d1703de37936c0e8", "scanner": "scanner-primary", "fingerprint": "4a12d5ed34c864c6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5c1545494ab6166c", "level": "note", "message": {"text": "Unused endpoint: GET /api/me"}, "properties": {"repobilityId": "d28bdf78fe493efb", "scanner": "scanner-primary", "fingerprint": "5c1545494ab6166c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}