{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "WEB012", "name": "Service worker is present without a web app manifest", "shortDescription": {"text": "Service worker is present without a web app manifest"}, "fullDescription": {"text": "A service worker without a manifest often means the PWA install surface is incomplete or inconsistent across devices."}, "properties": {"scanner": "repobility-web-presence", "category": "quality", "severity": "medium", "confidence": 0.72, "cwe": "", "owasp": ""}}, {"id": "WEB003", "name": "Public web service has no security.txt", "shortDescription": {"text": "Public web service has no security.txt"}, "fullDescription": {"text": "security.txt gives researchers and customers a safe disclosure channel. Public web apps and APIs should publish it under /.well-known/security.txt."}, "properties": {"scanner": "repobility-web-presence", "category": "quality", "severity": "medium", "confidence": 0.78, "cwe": "", "owasp": ""}}, {"id": "JRN005", "name": "Compliance or security claim is near a placeholder link", "shortDescription": {"text": "Compliance or security claim is near a placeholder link"}, "fullDescription": {"text": "Production pages should not pair trust claims such as SOC 2, GDPR, ISO, biometric consent, or encryption with placeholder links."}, "properties": {"scanner": "repobility-journey-contract", "category": "quality", "severity": "medium", "confidence": 0.76, "cwe": "", "owasp": ""}}, {"id": "JRN003", "name": "Frontend API reference is not matched by discovered backend routes", "shortDescription": {"text": "Frontend API reference is not matched by discovered backend routes"}, "fullDescription": {"text": "A frontend string references a same-origin API path that Repobility could not match to backend route inventory. This often causes live 404s in user journeys."}, "properties": {"scanner": "repobility-journey-contract", "category": "quality", "severity": "medium", "confidence": 0.74, "cwe": "", "owasp": ""}}, {"id": "AUC009", "name": "[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears to perform a sensitive function", "shortDescription": {"text": "[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears to perform a sensitive function such as export, invite, role, token, billing, or destructive action without elevated policy evidence. Endpoint: ANY /ap"}, "fullDescription": {"text": "A route appears to perform a sensitive function such as export, invite, role, token, billing, or destructive action without elevated policy evidence. Endpoint: ANY /api/notifications/."}, "properties": {"scanner": "repobility-access-control", "category": "auth", "severity": "medium", "confidence": 0.68, "cwe": "CWE-285", "owasp": "API5:2023 Broken Function Level Authorization"}}, {"id": "AUC004", "name": "[AUC004] Admin route does not show super_admin separation: An administrative route was detected without nearby evidence ", "shortDescription": {"text": "[AUC004] Admin route does not show super_admin separation: An administrative route was detected without nearby evidence that platform super_admin access is separated from tenant/application admin access. Endpoint: ANY /analytics/teacher/."}, "fullDescription": {"text": "An administrative route was detected without nearby evidence that platform super_admin access is separated from tenant/application admin access. Endpoint: ANY /analytics/teacher/."}, "properties": {"scanner": "repobility-access-control", "category": "auth", "severity": "medium", "confidence": 0.66, "cwe": "CWE-285", "owasp": "API5:2023 Broken Function Level Authorization"}}, {"id": "AUC002", "name": "[AUC002] Low visible authorization coverage in route inventory: Only 32.9% of discovered routes show nearby authenticati", "shortDescription": {"text": "[AUC002] Low visible authorization coverage in route inventory: Only 32.9% of discovered routes show nearby authentication, authorization, middleware, or public-route evidence."}, "fullDescription": {"text": "Only 32.9% of discovered routes show nearby authentication, authorization, middleware, or public-route evidence."}, "properties": {"scanner": "repobility-access-control", "category": "auth", "severity": "medium", "confidence": 0.74, "cwe": "CWE-285", "owasp": "WSTG-AUTHZ"}}, {"id": "AUC001", "name": "[AUC001] No Repobility access matrix policy found: The repository uses web/API frameworks but does not define .repobilit", "shortDescription": {"text": "[AUC001] No Repobility access matrix policy found: The repository uses web/API frameworks but does not define .repobility/access.yml or equivalent authorization documentation."}, "fullDescription": {"text": "The repository uses web/API frameworks but does not define .repobility/access.yml or equivalent authorization documentation."}, "properties": {"scanner": "repobility-access-control", "category": "auth", "severity": "medium", "confidence": 0.92, "cwe": "CWE-285", "owasp": "WSTG-AUTHZ"}}, {"id": "GHSA-gc5v-m9x4-r6x2", "name": "requests: GHSA-gc5v-m9x4-r6x2", "shortDescription": {"text": "requests: GHSA-gc5v-m9x4-r6x2"}, "fullDescription": {"text": "Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-mf9w-mj56-hr94", "name": "python-dotenv: GHSA-mf9w-mj56-hr94", "shortDescription": {"text": "python-dotenv: GHSA-mf9w-mj56-hr94"}, "fullDescription": {"text": "python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-x284-j5p8-9c5p", "name": "pypdf: GHSA-x284-j5p8-9c5p", "shortDescription": {"text": "pypdf: GHSA-x284-j5p8-9c5p"}, "fullDescription": {"text": "pypdf: Manipulated FlateDecode image dimensions can exhaust RAM"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-qpxp-75px-xjcp", "name": "pypdf: GHSA-qpxp-75px-xjcp", "shortDescription": {"text": "pypdf: GHSA-qpxp-75px-xjcp"}, "fullDescription": {"text": "pypdf has inefficient decoding of array-based streams"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-jj6c-8h6c-hppx", "name": "pypdf: GHSA-jj6c-8h6c-hppx", "shortDescription": {"text": "pypdf: GHSA-jj6c-8h6c-hppx"}, "fullDescription": {"text": "pypdf has long runtimes for wrong size values in cross-reference and object streams"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-hqmh-ppp3-xvm7", "name": "pypdf: GHSA-hqmh-ppp3-xvm7", "shortDescription": {"text": "pypdf: GHSA-hqmh-ppp3-xvm7"}, "fullDescription": {"text": "pypdf: manipulated stream length values can exhaust RAM"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-cj93-chg6-vgv8", "name": "pypdf: GHSA-cj93-chg6-vgv8", "shortDescription": {"text": "pypdf: GHSA-cj93-chg6-vgv8"}, "fullDescription": {"text": "pypdf: Possible large memory usage for large offsets for layout mode text"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-9m86-7pmv-2852", "name": "pypdf: GHSA-9m86-7pmv-2852", "shortDescription": {"text": "pypdf: GHSA-9m86-7pmv-2852"}, "fullDescription": {"text": "pypdf vulnerable to inefficient decoding of ASCIIHexDecode streams"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-87mj-5ggw-8qc3", "name": "pypdf: GHSA-87mj-5ggw-8qc3", "shortDescription": {"text": "pypdf: GHSA-87mj-5ggw-8qc3"}, "fullDescription": {"text": "pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-7gw9-cf7v-778f", "name": "pypdf: GHSA-7gw9-cf7v-778f", "shortDescription": {"text": "pypdf: GHSA-7gw9-cf7v-778f"}, "fullDescription": {"text": "pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-4pxv-j86v-mhcw", "name": "pypdf: GHSA-4pxv-j86v-mhcw", "shortDescription": {"text": "pypdf: GHSA-4pxv-j86v-mhcw"}, "fullDescription": {"text": "pypdf: Possible long runtimes for wrong size values in incremental mode"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-3crg-w4f6-42mx", "name": "pypdf: GHSA-3crg-w4f6-42mx", "shortDescription": {"text": "pypdf: GHSA-3crg-w4f6-42mx"}, "fullDescription": {"text": "pypdf: Manipulated XMP metadata entity declarations can exhaust RAM"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-248m-82v9-q6g6", "name": "pypdf: GHSA-248m-82v9-q6g6", "shortDescription": {"text": "pypdf: GHSA-248m-82v9-q6g6"}, "fullDescription": {"text": "pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-r73j-pqj5-w3x7", "name": "pillow: GHSA-r73j-pqj5-w3x7", "shortDescription": {"text": "pillow: GHSA-r73j-pqj5-w3x7"}, "fullDescription": {"text": "Pillow has a PDF Parsing Trailer Infinite Loop (DoS)"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-5xmw-vc9v-4wf2", "name": "pillow: GHSA-5xmw-vc9v-4wf2", "shortDescription": {"text": "pillow: GHSA-5xmw-vc9v-4wf2"}, "fullDescription": {"text": "Pillow has a heap buffer overflow with nested list coordinates"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-65pc-fj4g-8rjx", "name": "idna: GHSA-65pc-fj4g-8rjx", "shortDescription": {"text": "idna: GHSA-65pc-fj4g-8rjx"}, "fullDescription": {"text": "Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-993g-76c3-p5m4", "name": "pyjwt: GHSA-993g-76c3-p5m4", "shortDescription": {"text": "pyjwt: GHSA-993g-76c3-p5m4"}, "fullDescription": {"text": "PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-48c2-rrv3-qjmp", "name": "yaml: GHSA-48c2-rrv3-qjmp", "shortDescription": {"text": "yaml: GHSA-48c2-rrv3-qjmp"}, "fullDescription": {"text": "yaml is vulnerable to Stack Overflow via deeply nested YAML collections"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-58qx-3vcg-4xpx", "name": "ws: GHSA-58qx-3vcg-4xpx", "shortDescription": {"text": "ws: GHSA-58qx-3vcg-4xpx"}, "fullDescription": {"text": "ws: Uninitialized memory disclosure"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-w5hq-g745-h8pq", "name": "uuid: GHSA-w5hq-g745-h8pq", "shortDescription": {"text": "uuid: GHSA-w5hq-g745-h8pq"}, "fullDescription": {"text": "uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-qx2v-qp2m-jg93", "name": "postcss: GHSA-qx2v-qp2m-jg93", "shortDescription": {"text": "postcss: GHSA-qx2v-qp2m-jg93"}, "fullDescription": {"text": "PostCSS has XSS via Unescaped </style> in its CSS Stringify Output"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-3v7f-55p6-f55p", "name": "picomatch: GHSA-3v7f-55p6-f55p", "shortDescription": {"text": "picomatch: GHSA-3v7f-55p6-f55p"}, "fullDescription": {"text": "Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-h67p-54hq-rp68", "name": "js-yaml: GHSA-h67p-54hq-rp68", "shortDescription": {"text": "js-yaml: GHSA-h67p-54hq-rp68"}, "fullDescription": {"text": "JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-r4q5-vmmm-2653", "name": "follow-redirects: GHSA-r4q5-vmmm-2653", "shortDescription": {"text": "follow-redirects: GHSA-r4q5-vmmm-2653"}, "fullDescription": {"text": "follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-jxxr-4gwj-5jf2", "name": "brace-expansion: GHSA-jxxr-4gwj-5jf2", "shortDescription": {"text": "brace-expansion: GHSA-jxxr-4gwj-5jf2"}, "fullDescription": {"text": "brace-expansion: Large numeric range defeats documented `max` DoS protection"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-f886-m6hf-6m8v", "name": "brace-expansion: GHSA-f886-m6hf-6m8v", "shortDescription": {"text": "brace-expansion: GHSA-f886-m6hf-6m8v"}, "fullDescription": {"text": "brace-expansion: Zero-step sequence causes process hang and memory exhaustion"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-xx6v-rp6x-q39c", "name": "axios: GHSA-xx6v-rp6x-q39c", "shortDescription": {"text": "axios: GHSA-xx6v-rp6x-q39c"}, "fullDescription": {"text": "Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-w9j2-pvgh-6h63", "name": "axios: GHSA-w9j2-pvgh-6h63", "shortDescription": {"text": "axios: GHSA-w9j2-pvgh-6h63"}, "fullDescription": {"text": "Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-vf2m-468p-8v99", "name": "axios: GHSA-vf2m-468p-8v99", "shortDescription": {"text": "axios: GHSA-vf2m-468p-8v99"}, "fullDescription": {"text": "Axios: HTTP adapter streamed responses bypass maxContentLength"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-m7pr-hjqh-92cm", "name": "axios: GHSA-m7pr-hjqh-92cm", "shortDescription": {"text": "axios: GHSA-m7pr-hjqh-92cm"}, "fullDescription": {"text": "Axios: no_proxy bypass via IP alias allows SSRF"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-fvcv-3m26-pcqx", "name": "axios: GHSA-fvcv-3m26-pcqx", "shortDescription": {"text": "axios: GHSA-fvcv-3m26-pcqx"}, "fullDescription": {"text": "Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-898c-q2cr-xwhg", "name": "axios: GHSA-898c-q2cr-xwhg", "shortDescription": {"text": "axios: GHSA-898c-q2cr-xwhg"}, "fullDescription": {"text": "axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-62hf-57xw-28j9", "name": "axios: GHSA-62hf-57xw-28j9", "shortDescription": {"text": "axios: GHSA-62hf-57xw-28j9"}, "fullDescription": {"text": "Axios: unbounded recursion in toFormData causes DoS via deeply nested request data"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-5c9x-8gcm-mpgx", "name": "axios: GHSA-5c9x-8gcm-mpgx", "shortDescription": {"text": "axios: GHSA-5c9x-8gcm-mpgx"}, "fullDescription": {"text": "Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-445q-vr5w-6q77", "name": "axios: GHSA-445q-vr5w-6q77", "shortDescription": {"text": "axios: GHSA-445q-vr5w-6q77"}, "fullDescription": {"text": "Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-3w6x-2g7m-8v23", "name": "axios: GHSA-3w6x-2g7m-8v23", "shortDescription": {"text": "axios: GHSA-3w6x-2g7m-8v23"}, "fullDescription": {"text": "Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-4943-9vgg-gr5r", "name": "quill: GHSA-4943-9vgg-gr5r", "shortDescription": {"text": "quill: GHSA-4943-9vgg-gr5r"}, "fullDescription": {"text": "Cross-site Scripting in quill"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-8988-4f7v-96qf", "name": "@opentelemetry/core: GHSA-8988-4f7v-96qf", "shortDescription": {"text": "@opentelemetry/core: GHSA-8988-4f7v-96qf"}, "fullDescription": {"text": "OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "DKR007", "name": "Docker build context has no .dockerignore", "shortDescription": {"text": "Docker build context has no .dockerignore"}, "fullDescription": {"text": "Without .dockerignore, build context can include source history, local env files, dependencies, and generated artifacts."}, "properties": {"scanner": "repobility-docker", "category": "docker", "severity": "medium", "confidence": 0.9, "cwe": "", "owasp": ""}}, {"id": "DKR018", "name": "Database dump or local database file is included in Docker build context", "shortDescription": {"text": "Database dump or local database file is included in Docker build context"}, "fullDescription": {"text": "Database exports and local database files can contain production data, credentials, or large binary payloads that slow Docker builds and can be copied into images by broad COPY instructions."}, "properties": {"scanner": "repobility-docker", "category": "docker", "severity": "medium", "confidence": 0.86, "cwe": "", "owasp": ""}}, {"id": "SEC046", "name": "[SEC046] Client-side open redirect \u2014 window.location = server-supplied URL: Assigning window.location from a server-supp", "shortDescription": {"text": "[SEC046] Client-side open redirect \u2014 window.location = server-supplied URL: Assigning window.location from a server-supplied URL trusts the server endpoint to never return a hostile destination. If that endpoint is ever subverted (compromis"}, "fullDescription": {"text": "Validate the URL is same-origin or on an explicit allowlist before assignment:\n  const u = new URL(serverUrl, location.href);\n  if (u.origin !== location.origin && !ALLOWED.includes(u.host)) return;\n  location.assign(u);\nEven better: have the server return a path (/checkout/done) instead of a full URL, and only allow same-origin navigation."}, "properties": {"scanner": "repobility-threat-engine", "category": "open_redirect", "severity": "medium", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "SEC041", "name": "[SEC041] Tabnabbing \u2014 target=\"_blank\" without rel=\"noopener noreferrer\": <a target=\"_blank\"> without rel=\"noopener noref", "shortDescription": {"text": "[SEC041] Tabnabbing \u2014 target=\"_blank\" without rel=\"noopener noreferrer\": <a target=\"_blank\"> without rel=\"noopener noreferrer\" leaks window.opener to the opened page. The opened page can then run window.opener.location = 'phishing-site' and"}, "fullDescription": {"text": "Add rel=\"noopener noreferrer\" to every <a target=\"_blank\">:\n  <a href=\"...\" target=\"_blank\" rel=\"noopener noreferrer\">link</a>\nFor dynamically generated links from JS, set rel on the element before appending. Even safe-looking subdomains should harden \u2014 costs nothing."}, "properties": {"scanner": "repobility-threat-engine", "category": "security", "severity": "medium", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "SEC134", "name": "[SEC134] AI scaffold leftover \u2014 Lorem ipsum / example.com / John Doe in code: Lorem ipsum / John Doe / example.com left ", "shortDescription": {"text": "[SEC134] AI scaffold leftover \u2014 Lorem ipsum / example.com / John Doe in code: Lorem ipsum / John Doe / example.com left in non-test code. AI agents emit these as 'reasonable defaults' when they don't know real values; the human then forgets"}, "fullDescription": {"text": "Move dummy values to fixtures / seed files. In application code, require these to come from config or fail closed. Add a CI grep that rejects 'lorem ipsum' and 'example.com' outside test files."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "medium", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "SEC015", "name": "[SEC015] Insecure Randomness for Security: Weak PRNG used in security-sensitive context. Output is predictable.", "shortDescription": {"text": "[SEC015] Insecure Randomness for Security: Weak PRNG used in security-sensitive context. Output is predictable."}, "fullDescription": {"text": "Use secrets module (Python) or crypto.getRandomValues() (JS) for security-sensitive randomness."}, "properties": {"scanner": "repobility-threat-engine", "category": "crypto", "severity": "medium", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "SEC042", "name": "[SEC042] SQL identifier injection via f-string in cursor execute: f-string SQL normalizes an unsafe pattern. Currently s", "shortDescription": {"text": "[SEC042] SQL identifier injection via f-string in cursor execute: f-string SQL normalizes an unsafe pattern. Currently safe when only trusted internal values are interpolated (e.g. self._table in Odoo), but a future contributor can extend t"}, "fullDescription": {"text": "Use psycopg2.sql.SQL() + sql.Identifier() for identifiers:\n  from psycopg2 import sql\n  cr.execute(sql.SQL('UPDATE {} SET x=%s').format(sql.Identifier(table)), (value,))\nNever use f-string in cr.execute(). Values go through %s parameters."}, "properties": {"scanner": "repobility-threat-engine", "category": "injection", "severity": "medium", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "SEC003", "name": "[SEC003] Hardcoded Secret: Hardcoded secret key found in source code.", "shortDescription": {"text": "[SEC003] Hardcoded Secret: Hardcoded secret key found in source code."}, "fullDescription": {"text": "Never commit secrets. Use .env files with .gitignore."}, "properties": {"scanner": "repobility-threat-engine", "category": "credential_exposure", "severity": "medium", "confidence": 0.3, "cwe": "", "owasp": ""}}, {"id": "SEC123", "name": "[SEC123] Production stack trace / debug output exposed: Debug mode left on in production exposes stack traces, environme", "shortDescription": {"text": "[SEC123] Production stack trace / debug output exposed: Debug mode left on in production exposes stack traces, environment variables, framework internals \u2014 sometimes triggers RCE (Django debug page with arbitrary template eval)."}, "fullDescription": {"text": "Set DEBUG=False / APP_DEBUG=false in production. Provide a generic 500 handler that logs to backend but returns a sanitized page to clients."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "medium", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "SEC136", "name": "[SEC136] AI-typical over-broad exception handler swallowing all errors: Catch-all exception block that silently returns ", "shortDescription": {"text": "[SEC136] AI-typical over-broad exception handler swallowing all errors: Catch-all exception block that silently returns success or no-ops. AI agents reach for this pattern when a flaky test or an unfamiliar API throws \u2014 wrap, swallow, retur"}, "fullDescription": {"text": "Catch the specific exception type, log at error level with full exception info, and return a failure-shaped result. If the operation is genuinely best-effort, log at warning and document why in a comment so the next reader (or scanner) knows."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "medium", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "ERR001", "name": "[ERR001] Silent Exception Swallowing: Silently swallowing all exceptions hides bugs. Even in cleanup code, log at DEBUG ", "shortDescription": {"text": "[ERR001] Silent Exception Swallowing: Silently swallowing all exceptions hides bugs. Even in cleanup code, log at DEBUG level."}, "fullDescription": {"text": "Log the error: `except Exception: logger.debug('cleanup failed', exc_info=True)`. Or handle specific exception types."}, "properties": {"scanner": "repobility-threat-engine", "category": "error_handling", "severity": "medium", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "COMP001", "name": "[COMP001] High cognitive complexity: Function `handle` has cognitive complexity 22 (SonarSource scale). Cognitive comple", "shortDescription": {"text": "[COMP001] High cognitive complexity: Function `handle` has cognitive complexity 22 (SonarSource scale). Cognitive complexity measures how hard the function is for a human to understand \u2014 nested branches, boolean chains, and recursion all we"}, "fullDescription": {"text": "Extract nested branches into named helper functions; flatten early-return / guard clauses; replace long if/elif chains with dispatch dicts or polymorphism. SonarQube's threshold for 'should refactor' is 15 \u2014 yours is 22."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "medium", "confidence": 0.95, "cwe": "", "owasp": ""}}, {"id": "DEPCUR-NPM", "name": "npm package `react-native-gesture-handler` is 1 major version(s) behind (2.30.0 -> 3.0.1)", "shortDescription": {"text": "npm package `react-native-gesture-handler` is 1 major version(s) behind (2.30.0 -> 3.0.1)"}, "fullDescription": {"text": "`react-native-gesture-handler` is pinned/resolved at 2.30.0 but the latest stable release on the npm registry is 3.0.1 (1 major version(s) behind). Outdated dependencies accumulate unpatched bugs and make future security upgrades harder. This is the version-currency signal Dependabot version-update PRs raise."}, "properties": {"scanner": "repobility-dependency-currency", "category": "dependency", "severity": "medium", "confidence": 0.9, "cwe": "", "owasp": ""}}, {"id": "DEPCUR-PY", "name": "Python package `psutil` is 1 major version(s) behind (6.1.0 -> 7.2.2)", "shortDescription": {"text": "Python package `psutil` is 1 major version(s) behind (6.1.0 -> 7.2.2)"}, "fullDescription": {"text": "`psutil==6.1.0` is 1 major version(s) behind the latest stable release on PyPI (7.2.2). Pinned-but-stale Python dependencies drift away from upstream security and bugfix releases. This is the version-currency signal Dependabot raises."}, "properties": {"scanner": "repobility-dependency-currency", "category": "dependency", "severity": "medium", "confidence": 0.9, "cwe": "", "owasp": ""}}, {"id": "MINED115", "name": "Action `amondnet/vercel-action` pinned to mutable ref `@v25`", "shortDescription": {"text": "Action `amondnet/vercel-action` pinned to mutable ref `@v25`"}, "fullDescription": {"text": "`uses: amondnet/vercel-action@v25` resolves at workflow-run time. Tags and branches can be re-pushed by the action owner; that made the tj-actions/changed-files compromise (2025) instantly affect many repos. Treat official first-party action tags as lower risk, but pin security-sensitive third-party actions to a 40-char commit SHA + lock with Dependabot or renovate."}, "properties": {"scanner": "repobility-supply-chain", "category": "dependency", "severity": "medium", "confidence": 0.9, "cwe": "", "owasp": ""}}, {"id": "MINED111", "name": "Bare except continues silently", "shortDescription": {"text": "Bare except continues silently"}, "fullDescription": {"text": "Bare `except:` (or `except Exception:`) that runs code without re-raising or logging the exception. Hides real failures and makes bugs hard to diagnose."}, "properties": {"scanner": "repobility-ast-engine", "category": "quality", "severity": "medium", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "AIC004", "name": "Suspicious implementation file appears unreferenced", "shortDescription": {"text": "Suspicious implementation file appears unreferenced"}, "fullDescription": {"text": "A file created as a fixed/new/final/copy variant is not referenced by imports or path-like strings in the rest of the repository. This is a strong sign that an agent produced code beside the active application path."}, "properties": {"scanner": "repobility-ai-code-hygiene", "category": "quality", "severity": "medium", "confidence": 0.78, "cwe": "", "owasp": ""}}, {"id": "AIC001", "name": "Parallel implementation file sits beside a canonical file", "shortDescription": {"text": "Parallel implementation file sits beside a canonical file"}, "fullDescription": {"text": "AI-assisted edits often create a new sibling file instead of integrating the change into the existing module. That leaves two paths for future maintainers to understand and can hide the code that is actually wired into the app."}, "properties": {"scanner": "repobility-ai-code-hygiene", "category": "quality", "severity": "medium", "confidence": 0.82, "cwe": "", "owasp": ""}}, {"id": "WEB011", "name": "Public web app has no humans.txt", "shortDescription": {"text": "Public web app has no humans.txt"}, "fullDescription": {"text": "humans.txt is optional, but it gives operators and reviewers a simple place to find ownership, contact, and important public documentation links."}, "properties": {"scanner": "repobility-web-presence", "category": "quality", "severity": "low", "confidence": 0.5, "cwe": "", "owasp": ""}}, {"id": "WEB008", "name": "Public docs site has no llms.txt", "shortDescription": {"text": "Public docs site has no llms.txt"}, "fullDescription": {"text": "AI coding agents increasingly read llms.txt to find canonical docs and API workflows. Without it, agents are more likely to browse pages repeatedly or use stale instructions."}, "properties": {"scanner": "repobility-web-presence", "category": "quality", "severity": "low", "confidence": 0.64, "cwe": "", "owasp": ""}}, {"id": "WEB002", "name": "Public web app has no sitemap", "shortDescription": {"text": "Public web app has no sitemap"}, "fullDescription": {"text": "A sitemap gives search engines, docs crawlers, and AI agents a structured list of public pages. Without one, important docs and product pages are easy to miss."}, "properties": {"scanner": "repobility-web-presence", "category": "quality", "severity": "low", "confidence": 0.72, "cwe": "", "owasp": ""}}, {"id": "WEB001", "name": "Public web app has no robots.txt", "shortDescription": {"text": "Public web app has no robots.txt"}, "fullDescription": {"text": "Public websites should publish a robots.txt file so crawlers and AI agents can discover crawl rules and sitemap locations without guessing."}, "properties": {"scanner": "repobility-web-presence", "category": "quality", "severity": "low", "confidence": 0.74, "cwe": "", "owasp": ""}}, {"id": "GHSA-5239-wwwm-4pmq", "name": "pygments: GHSA-5239-wwwm-4pmq", "shortDescription": {"text": "pygments: GHSA-5239-wwwm-4pmq"}, "fullDescription": {"text": "Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-mjgh-79qc-68w3", "name": "django: GHSA-mjgh-79qc-68w3", "shortDescription": {"text": "django: GHSA-mjgh-79qc-68w3"}, "fullDescription": {"text": "Django has a Race Condition vulnerability"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-xhjh-pmcv-23jw", "name": "axios: GHSA-xhjh-pmcv-23jw", "shortDescription": {"text": "axios: GHSA-xhjh-pmcv-23jw"}, "fullDescription": {"text": "Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-4x5r-pxfx-6jf8", "name": "@babel/core: GHSA-4x5r-pxfx-6jf8", "shortDescription": {"text": "@babel/core: GHSA-4x5r-pxfx-6jf8"}, "fullDescription": {"text": "@babel/core: Arbitrary File Read via sourceMappingURL Comment"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "DKC015", "name": "Database service has no healthcheck", "shortDescription": {"text": "Database service has no healthcheck"}, "fullDescription": {"text": "Compose starts dependent containers in dependency order, but it does not wait for a database to be ready unless a healthcheck is defined and dependents use service_healthy."}, "properties": {"scanner": "repobility-docker", "category": "docker", "severity": "low", "confidence": 0.72, "cwe": "", "owasp": ""}}, {"id": "DKC010", "name": "Compose service lacks no-new-privileges hardening", "shortDescription": {"text": "Compose service lacks no-new-privileges hardening"}, "fullDescription": {"text": "no-new-privileges prevents processes from gaining additional privileges through setuid binaries or file capabilities."}, "properties": {"scanner": "repobility-docker", "category": "docker", "severity": "low", "confidence": 0.62, "cwe": "", "owasp": ""}}, {"id": "DKC006", "name": "Compose service does not declare a runtime user", "shortDescription": {"text": "Compose service does not declare a runtime user"}, "fullDescription": {"text": "If the image does not define USER internally, this service may run as root."}, "properties": {"scanner": "repobility-docker", "category": "docker", "severity": "low", "confidence": 0.56, "cwe": "", "owasp": ""}}, {"id": "DKC016", "name": "App service does not wait for database health", "shortDescription": {"text": "App service does not wait for database health"}, "fullDescription": {"text": "depends_on controls startup order, but without condition: service_healthy an app can start while the database is still initializing and fail intermittently."}, "properties": {"scanner": "repobility-docker", "category": "docker", "severity": "low", "confidence": 0.68, "cwe": "", "owasp": ""}}, {"id": "DKR012", "name": "Dockerfile keeps pip download cache", "shortDescription": {"text": "Dockerfile keeps pip download cache"}, "fullDescription": {"text": "Pip's package cache increases image size and can preserve unnecessary artifacts."}, "properties": {"scanner": "repobility-docker", "category": "docker", "severity": "low", "confidence": 0.72, "cwe": "", "owasp": ""}}, {"id": "SEC006", "name": "[SEC006] XSS Risk: Direct HTML injection without sanitization.", "shortDescription": {"text": "[SEC006] XSS Risk: Direct HTML injection without sanitization."}, "fullDescription": {"text": "Use textContent instead of innerHTML. Sanitize with DOMPurify."}, "properties": {"scanner": "repobility-threat-engine", "category": "injection", "severity": "low", "confidence": 0.4, "cwe": "", "owasp": ""}}, {"id": "SEC124", "name": "[SEC124] TOCTOU file access (os.access then open): Check-then-use file pattern (access/exists then open) lets an attacke", "shortDescription": {"text": "[SEC124] TOCTOU file access (os.access then open): Check-then-use file pattern (access/exists then open) lets an attacker swap the file between check and use (symlink attack). `mktemp` is deprecated for the same reason."}, "fullDescription": {"text": "Use `os.open(path, os.O_CREAT | os.O_EXCL | os.O_WRONLY)` for atomic create-only. Use `tempfile.NamedTemporaryFile()` (not `mktemp`). For locking, use `fcntl.flock`."}, "properties": {"scanner": "repobility-threat-engine", "category": "race_condition", "severity": "low", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "MINED116", "name": "Workflow references `secrets.SLACK_WEBHOOK` in a `pull_request` workflow", "shortDescription": {"text": "Workflow references `secrets.SLACK_WEBHOOK` in a `pull_request` workflow"}, "fullDescription": {"text": "`pull_request` workflows from forks do not receive normal repository secrets, so `${ secrets.SLACK_WEBHOOK }` is usually empty for untrusted fork PRs. This is a reliability/intent signal, not direct fork-secret exfiltration. Keep high severity for pull_request_target or trusted-context jobs that run untrusted PR code with secrets."}, "properties": {"scanner": "repobility-supply-chain", "category": "dependency", "severity": "low", "confidence": 0.9, "cwe": "", "owasp": ""}}, {"id": "AIC005", "name": "Duplicate top-level symbol appears in a patch-style file", "shortDescription": {"text": "Duplicate top-level symbol appears in a patch-style file"}, "fullDescription": {"text": "A generated replacement file defining the same public function or class name as another module can mean the new logic is not actually wired into the running code."}, "properties": {"scanner": "repobility-ai-code-hygiene", "category": "quality", "severity": "low", "confidence": 0.64, "cwe": "", "owasp": ""}}, {"id": "AIC003", "name": "Duplicated implementation block across source files", "shortDescription": {"text": "Duplicated implementation block across source files"}, "fullDescription": {"text": "Duplicated blocks are a common artifact when generated code is pasted or recreated instead of reused. They increase maintenance cost because every future bug fix must be found in multiple locations."}, "properties": {"scanner": "repobility-ai-code-hygiene", "category": "quality", "severity": "low", "confidence": 0.86, "cwe": "", "owasp": ""}}, {"id": "AIC002", "name": "Source file name looks like an AI patch artifact", "shortDescription": {"text": "Source file name looks like an AI patch artifact"}, "fullDescription": {"text": "Files named as final, fixed, copy, new, or backup are often temporary patch artifacts. They may be legitimate, but they deserve review before becoming production surface area."}, "properties": {"scanner": "repobility-ai-code-hygiene", "category": "quality", "severity": "low", "confidence": 0.62, "cwe": "", "owasp": ""}}, {"id": "MINED055", "name": "[MINED055] Npm Install No Lockfile: Production image runs npm install (resolves new versions on every build) instead of ", "shortDescription": {"text": "[MINED055] Npm Install No Lockfile: Production image runs npm install (resolves new versions on every build) instead of npm ci."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-1357 / A06:2021 for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "MINED058", "name": "[MINED058] React Dangerously Set Html: dangerouslySetInnerHTML bypasses Reacts JSX escaping. Pair with DOMPurify or neve", "shortDescription": {"text": "[MINED058] React Dangerously Set Html: dangerouslySetInnerHTML bypasses Reacts JSX escaping. Pair with DOMPurify or never use with user data."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-79 / A03:2021 for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "MINED045", "name": "[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError if wrong.", "shortDescription": {"text": "[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError if wrong."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-476 /  for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "MINED056", "name": "[MINED056] React Key As Index (and 30 more): Same pattern found in 30 additional files. Review if needed.", "shortDescription": {"text": "[MINED056] React Key As Index (and 30 more): Same pattern found in 30 additional files. Review if needed."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-682 /  for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 0.2, "cwe": "", "owasp": ""}}, {"id": "MINED054", "name": "[MINED054] Ts As Any (and 17 more): Same pattern found in 17 additional files. Review if needed.", "shortDescription": {"text": "[MINED054] Ts As Any (and 17 more): Same pattern found in 17 additional files. Review if needed."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-704 /  for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 0.2, "cwe": "", "owasp": ""}}, {"id": "MINED052", "name": "[MINED052] Ts Any Typed (and 29 more): Same pattern found in 29 additional files. Review if needed.", "shortDescription": {"text": "[MINED052] Ts Any Typed (and 29 more): Same pattern found in 29 additional files. Review if needed."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-704 /  for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 0.2, "cwe": "", "owasp": ""}}, {"id": "MINED044", "name": "[MINED044] Js Console Log Prod (and 65 more): Same pattern found in 65 additional files. Review if needed.", "shortDescription": {"text": "[MINED044] Js Console Log Prod (and 65 more): Same pattern found in 65 additional files. Review if needed."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-532 /  for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 0.2, "cwe": "", "owasp": ""}}, {"id": "MINED077", "name": "[MINED077] Python Open No Context: fp = open(path) outside with-block leaks file handles.", "shortDescription": {"text": "[MINED077] Python Open No Context: fp = open(path) outside with-block leaks file handles."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-772 /  for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "MINED064", "name": "[MINED064] Python Input Call: input() blocks for stdin. Inappropriate in services.", "shortDescription": {"text": "[MINED064] Python Input Call: input() blocks for stdin. Inappropriate in services."}, "fullDescription": {"text": "Review and fix per the pattern semantics."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "MINED007", "name": "[MINED007] Sql String Concat (and 1 more): Same pattern found in 1 additional files. Review if needed.", "shortDescription": {"text": "[MINED007] Sql String Concat (and 1 more): Same pattern found in 1 additional files. Review if needed."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-89 / A03:2021 for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 0.2, "cwe": "", "owasp": ""}}, {"id": "SEC004", "name": "[SEC004] SQL Injection Risk (and 1 more): Same pattern found in 1 additional files. Review if needed.", "shortDescription": {"text": "[SEC004] SQL Injection Risk (and 1 more): Same pattern found in 1 additional files. Review if needed."}, "fullDescription": {"text": "Use parameterized queries: cursor.execute('SELECT * FROM t WHERE id = ?', [id]). For dynamic table or column names, choose identifiers from a hard-coded allowlist and keep values in parameters."}, "properties": {"scanner": "repobility-threat-engine", "category": "injection", "severity": "info", "confidence": 0.2, "cwe": "", "owasp": ""}}, {"id": "MINED049", "name": "[MINED049] Print Pii (and 12 more): Same pattern found in 12 additional files. Review if needed.", "shortDescription": {"text": "[MINED049] Print Pii (and 12 more): Same pattern found in 12 additional files. Review if needed."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-532 / A09:2021 for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 0.2, "cwe": "", "owasp": ""}}, {"id": "MINED053", "name": "[MINED053] Placeholder Default Username (and 7 more): Same pattern found in 7 additional files. Review if needed.", "shortDescription": {"text": "[MINED053] Placeholder Default Username (and 7 more): Same pattern found in 7 additional files. Review if needed."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-1392,CWE-798 /  for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 0.2, "cwe": "", "owasp": ""}}, {"id": "MINED065", "name": "[MINED065] Cors Wildcard: Access-Control-Allow-Origin: * exposes the API to any browser origin. Acceptable for public re", "shortDescription": {"text": "[MINED065] Cors Wildcard: Access-Control-Allow-Origin: * exposes the API to any browser origin. Acceptable for public read-only endpoints; dangerous when paired with credentials or write endpoints."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-942,CWE-346 / A05:2021 for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "MINED069", "name": "[MINED069] Debug True Prod: Django/Flask DEBUG=True or app.debug=True in non-test files.", "shortDescription": {"text": "[MINED069] Debug True Prod: Django/Flask DEBUG=True or app.debug=True in non-test files."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-489 / A05:2021 for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "MINED067", "name": "[MINED067] Python Requests No Timeout (and 17 more): Same pattern found in 17 additional files. Review if needed.", "shortDescription": {"text": "[MINED067] Python Requests No Timeout (and 17 more): Same pattern found in 17 additional files. Review if needed."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-400 /  for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 0.2, "cwe": "", "owasp": ""}}, {"id": "SEC078", "name": "[SEC078] Python: requests without timeout (and 17 more): Same pattern found in 17 additional files. Review if needed.", "shortDescription": {"text": "[SEC078] Python: requests without timeout (and 17 more): Same pattern found in 17 additional files. Review if needed."}, "fullDescription": {"text": "Add `timeout=10` (or appropriate value) to every requests call."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 0.2, "cwe": "", "owasp": ""}}, {"id": "MINED072", "name": "[MINED072] Python Pass Only Class: class Foo: pass \u2014 stub waiting to be filled in.", "shortDescription": {"text": "[MINED072] Python Pass Only Class: class Foo: pass \u2014 stub waiting to be filled in."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-1188 /  for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "SEC029", "name": "[SEC029] Server-Side Request Forgery (SSRF) \u2014 outbound HTTP from user input (and 7 more): Same pattern found in 7 additi", "shortDescription": {"text": "[SEC029] Server-Side Request Forgery (SSRF) \u2014 outbound HTTP from user input (and 7 more): Same pattern found in 7 additional files. Review if needed."}, "fullDescription": {"text": "Validate the URL against an allowlist BEFORE fetching:\n  ALLOWED = {'images.example.com', 'cdn.example.com'}\n  host = urlparse(url).hostname\n  if host not in ALLOWED: abort(400)\nOr use a server-side proxy (Imgproxy / serve-files-only-from-S3) that isolates outbound network access from the request handler.\nBlock private CIDRs explicitly: 10/8, 172.16/12, 192.168/16, 169.254/16."}, "properties": {"scanner": "repobility-threat-engine", "category": "ssrf", "severity": "info", "confidence": 0.2, "cwe": "", "owasp": ""}}, {"id": "SEC020", "name": "[SEC020] Secret Printed to Logs (and 16 more): Same pattern found in 16 additional files. Review if needed.", "shortDescription": {"text": "[SEC020] Secret Printed to Logs (and 16 more): Same pattern found in 16 additional files. Review if needed."}, "fullDescription": {"text": "Log only redacted, hashed, or last-four-style metadata. Rotate any secret that may have reached logs."}, "properties": {"scanner": "repobility-threat-engine", "category": "credential_exposure", "severity": "info", "confidence": 0.2, "cwe": "", "owasp": ""}}, {"id": "MINED043", "name": "[MINED043] Http Not Https (and 2 more): Same pattern found in 2 additional files. Review if needed.", "shortDescription": {"text": "[MINED043] Http Not Https (and 2 more): Same pattern found in 2 additional files. Review if needed."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-319 / A02:2021 for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 0.2, "cwe": "", "owasp": ""}}, {"id": "MINED076", "name": "[MINED076] Catch And Reraise Noop: except X: raise X \u2014 adds no value, hides traceback if AI accidentally changes message", "shortDescription": {"text": "[MINED076] Catch And Reraise Noop: except X: raise X \u2014 adds no value, hides traceback if AI accidentally changes message."}, "fullDescription": {"text": "Review and fix per the pattern semantics."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "SEC001", "name": "[SEC001] Hardcoded Password (and 42 more): Same pattern found in 42 additional files. Review if needed.", "shortDescription": {"text": "[SEC001] Hardcoded Password (and 42 more): Same pattern found in 42 additional files. Review if needed."}, "fullDescription": {"text": "Use environment variables or a secrets manager."}, "properties": {"scanner": "repobility-threat-engine", "category": "credential_exposure", "severity": "info", "confidence": 0.2, "cwe": "", "owasp": ""}}, {"id": "MINED050", "name": "[MINED050] Stub Only Function (and 13 more): Same pattern found in 13 additional files. Review if needed.", "shortDescription": {"text": "[MINED050] Stub Only Function (and 13 more): Same pattern found in 13 additional files. Review if needed."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-1188 /  for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 0.2, "cwe": "", "owasp": ""}}, {"id": "MINED001", "name": "[MINED001] Bare Except Pass (and 9 more): Same pattern found in 9 additional files. Review if needed.", "shortDescription": {"text": "[MINED001] Bare Except Pass (and 9 more): Same pattern found in 9 additional files. Review if needed."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-755 /  for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 0.2, "cwe": "", "owasp": ""}}, {"id": "SEC128", "name": "[SEC128] Async function without await \u2014 fire-and-forget Promise (AI mistake) (and 80 more): Same pattern found in 80 add", "shortDescription": {"text": "[SEC128] Async function without await \u2014 fire-and-forget Promise (AI mistake) (and 80 more): Same pattern found in 80 additional files. Review if needed."}, "fullDescription": {"text": "Add `await` before each async call, or chain with `.then`. If you intentionally want fire-and-forget, prefix with `void` (TS) or assign to `_` (Python with `asyncio.create_task`) to make the intent explicit and survive lint."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 0.2, "cwe": "", "owasp": ""}}, {"id": "JRN009", "name": "Secret-like setting is echoed into a password input value", "shortDescription": {"text": "Secret-like setting is echoed into a password input value"}, "fullDescription": {"text": "Settings screens sometimes render API keys, tokens, or passwords back into HTML/JSX password fields. That still exposes the secret to page source, browser extensions, screenshots, and DOM scraping."}, "properties": {"scanner": "repobility-journey-contract", "category": "auth", "severity": "high", "confidence": 0.83, "cwe": "", "owasp": ""}}, {"id": "AUC003", "name": "[AUC003] Object-level route lacks visible authorization: A route with an object id-like parameter does not show nearby a", "shortDescription": {"text": "[AUC003] Object-level route lacks visible authorization: A route with an object id-like parameter does not show nearby authentication or authorization evidence. This is a BOLA/IDOR review target. Endpoint: ANY /jobs/<str:job_id>/."}, "fullDescription": {"text": "A route with an object id-like parameter does not show nearby authentication or authorization evidence. This is a BOLA/IDOR review target. Endpoint: ANY /jobs/<str:job_id>/."}, "properties": {"scanner": "repobility-access-control", "category": "auth", "severity": "high", "confidence": 0.7, "cwe": "CWE-639", "owasp": "API1:2023 Broken Object Level Authorization"}}, {"id": "PYSEC-2026-142", "name": "urllib3: PYSEC-2026-142", "shortDescription": {"text": "urllib3: PYSEC-2026-142"}, "fullDescription": {"text": "urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-141", "name": "urllib3: PYSEC-2026-141", "shortDescription": {"text": "urllib3: PYSEC-2026-141"}, "fullDescription": {"text": "urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-whj4-6x5x-4v2j", "name": "pillow: GHSA-whj4-6x5x-4v2j", "shortDescription": {"text": "pillow: GHSA-whj4-6x5x-4v2j"}, "fullDescription": {"text": "FITS GZIP decompression bomb in Pillow"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-pwv6-vv43-88gr", "name": "pillow: GHSA-pwv6-vv43-88gr", "shortDescription": {"text": "pillow: GHSA-pwv6-vv43-88gr"}, "fullDescription": {"text": "Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-165", "name": "pillow: PYSEC-2026-165", "shortDescription": {"text": "pillow: PYSEC-2026-165"}, "fullDescription": {"text": "Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-87", "name": "lxml: PYSEC-2026-87", "shortDescription": {"text": "lxml: PYSEC-2026-87"}, "fullDescription": {"text": "lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML input to read local files. Setting the resolve_entities option explicitly to resolve_entities='internal' or resolve_entities=False disables the local file access. This vulnerability is fixed in 6.1.0."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-537c-gmf6-5ccf", "name": "cryptography: GHSA-537c-gmf6-5ccf", "shortDescription": {"text": "cryptography: GHSA-537c-gmf6-5ccf"}, "fullDescription": {"text": "Vulnerable OpenSSL included in cryptography wheels"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-36", "name": "cryptography: PYSEC-2026-36", "shortDescription": {"text": "cryptography: PYSEC-2026-36"}, "fullDescription": {"text": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-35", "name": "cryptography: PYSEC-2026-35", "shortDescription": {"text": "cryptography: PYSEC-2026-35"}, "fullDescription": {"text": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the \"peer name\" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-179", "name": "pyjwt: PYSEC-2026-179", "shortDescription": {"text": "pyjwt: PYSEC-2026-179"}, "fullDescription": {"text": "PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-178", "name": "pyjwt: PYSEC-2026-178", "shortDescription": {"text": "pyjwt: PYSEC-2026-178"}, "fullDescription": {"text": "PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option (\"b64\": false, RFC 7797), PyJWT performs Base64URL decoding of the compact-serialization payload segment before enforcing the detached-payload rules. For b64=false, PyJWT later discards that decoded payload and replaces it with the caller-provided detached_payload. In practice, this turns the middle segment into an attacker-controlled \u201cwork amplifier\u201d: a remote client can supply an arbitrarily large Base64URL payload segment that forces CPU work + memory allocations even if the signature is invalid. This creates an unauthenticated DoS vector against any endpoint that verifies detached JWS using PyJWT. This vulnerability is fixed in 2.13.0."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-177", "name": "pyjwt: PYSEC-2026-177", "shortDescription": {"text": "pyjwt: PYSEC-2026-177"}, "fullDescription": {"text": "PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an unknown kid value, with no rate limiting. Since kid comes from the unverified token header, an attacker can trigger unlimited outbound requests. The vulnerability surfaces only when a JWKS fetch fails; an attacker can attempt to provoke that with sustained unknown-kid traffic, but the outcome depends on upstream JWKS-endpoint behavior (rate limiting, transient errors) which is beyond the attacker's control. This vulnerability is fixed in 2.13.0."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-176", "name": "pyjwt: PYSEC-2026-176", "shortDescription": {"text": "pyjwt: PYSEC-2026-176"}, "fullDescription": {"text": "PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The token header alg is checked against the caller-supplied algorithms allow-list, but signature verification is performed with the algorithm bound to the PyJWK object instead of the header algorithm. An attacker who controls a registered JWK/JWKS private key can sign with a disallowed algorithm, advertise an allowed algorithm in the JWT header, and still be accepted. The issue affects the documented PyJWKClient.get_signing_key_from_jwt(...) flow. This vulnerability is fixed in 2.13.0."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-175", "name": "pyjwt: PYSEC-2026-175", "shortDescription": {"text": "pyjwt: PYSEC-2026-175"}, "fullDescription": {"text": "PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib's default OpenerDirector registering HTTPHandler, HTTPSHandler, FTPHandler, FileHandler, and DataHandler. There is currently no documented option to restrict which schemes PyJWKClient will fetch. If an application's jku URL ingestion path accepts attacker-influenced URLs (e.g., from JWT header, configuration file, OAuth flow parameter), the attacker can cause PyJWKClient to read arbitrary local files via file:// (SSRF on local filesystem), cause PyJWKClient to attempt FTP / data-URI fetches (broader SSRF surface), or forge tokens that PyJWT verifies as valid. The library does not directly return non-HTTP(S) URI contents to the attacker; the chained \"plant a JWKS to forge tokens\" scenario described in the original report requires additional application-layer flaws (attacker write access to a filesystem path, untrusted jku "}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-120", "name": "pyjwt: PYSEC-2026-120", "shortDescription": {"text": "pyjwt: PYSEC-2026-120"}, "fullDescription": {"text": "PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 \u00a74.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2025-183", "name": "pyjwt: PYSEC-2025-183", "shortDescription": {"text": "pyjwt: PYSEC-2025-183"}, "fullDescription": {"text": "pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement)."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-8p8v-wh79-9r56", "name": "django: GHSA-8p8v-wh79-9r56", "shortDescription": {"text": "django: GHSA-8p8v-wh79-9r56"}, "fullDescription": {"text": "Django vulnerable to Uncontrolled Resource Consumption"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-55", "name": "django: PYSEC-2026-55", "shortDescription": {"text": "django: PYSEC-2026-55"}, "fullDescription": {"text": "An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.\n`django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`'*'`). This can lead to private data being stored and served.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Ahmad Sadeddin for reporting this issue."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-54", "name": "django: PYSEC-2026-54", "shortDescription": {"text": "django: PYSEC-2026-54"}, "fullDescription": {"text": "An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.\nASGI requests with a missing or understated `Content-Length` header can bypass the `FILE_UPLOAD_MAX_MEMORY_SIZE` limit, potentially loading large files into memory and causing service degradation.\n \nAs a reminder, Django expects a limit to be configured at the web server level rather than solely relying on `FILE_UPLOAD_MAX_MEMORY_SIZE`.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Kyle Agronick for reporting this issue."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-53", "name": "django: PYSEC-2026-53", "shortDescription": {"text": "django: PYSEC-2026-53"}, "fullDescription": {"text": "An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.\nAdmin changelist forms using `ModelAdmin.list_editable` incorrectly allowed new\ninstances to be created via forged `POST` data.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Cantina for reporting this issue."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-52", "name": "django: PYSEC-2026-52", "shortDescription": {"text": "django: PYSEC-2026-52"}, "fullDescription": {"text": "An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.\nAdd permissions on inline model instances were not validated on submission of\nforged `POST` data in `GenericInlineModelAdmin`.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank N05ec@LZU-DSLab for reporting this issue."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-51", "name": "django: PYSEC-2026-51", "shortDescription": {"text": "django: PYSEC-2026-51"}, "fullDescription": {"text": "An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.\n`ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguous mapping of two header variants (with hyphens or with underscores) to a single version with underscores.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Tarek Nakkouch for reporting this issue."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-50", "name": "django: PYSEC-2026-50", "shortDescription": {"text": "django: PYSEC-2026-50"}, "fullDescription": {"text": "An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.\nResponse headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that user visits a cached public page.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Cantina for reporting this issue."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-49", "name": "django: PYSEC-2026-49", "shortDescription": {"text": "django: PYSEC-2026-49"}, "fullDescription": {"text": "An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.\nASGI requests with a missing or understated `Content-Length` header could\nbypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit when reading\n`HttpRequest.body`, allowing remote attackers to load an unbounded request body into\nmemory.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Superior for reporting this issue."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-48", "name": "django: PYSEC-2026-48", "shortDescription": {"text": "django: PYSEC-2026-48"}, "fullDescription": {"text": "An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.\n`MultiPartParser` allows remote attackers to degrade performance by submitting multipart uploads with `Content-Transfer-Encoding: base64` including excessive whitespace.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Seokchan Yoon for reporting this issue."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-47", "name": "django: PYSEC-2026-47", "shortDescription": {"text": "django: PYSEC-2026-47"}, "fullDescription": {"text": "An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.\n`.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, with dictionary expansion, used in `FilteredRelation`.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Solomon Kebede for reporting this issue."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-46", "name": "django: PYSEC-2026-46", "shortDescription": {"text": "django: PYSEC-2026-46"}, "fullDescription": {"text": "An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.\n`FilteredRelation` is subject to SQL injection in column aliases via control characters, using a suitably crafted dictionary, with dictionary expansion, as the `**kwargs` passed to `QuerySet` methods `annotate()`, `aggregate()`, `extra()`, `values()`, `values_list()`, and `alias()`.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Solomon Kebede for reporting this issue."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-45", "name": "django: PYSEC-2026-45", "shortDescription": {"text": "django: PYSEC-2026-45"}, "fullDescription": {"text": "An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.\n`django.utils.text.Truncator.chars()` and `Truncator.words()` methods (with `html=True`) and the `truncatechars_html` and `truncatewords_html` template filters allow a remote attacker to cause a potential denial-of-service via crafted inputs containing a large number of unmatched HTML end tags.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Seokchan Yoon for reporting this issue."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-44", "name": "django: PYSEC-2026-44", "shortDescription": {"text": "django: PYSEC-2026-44"}, "fullDescription": {"text": "An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.\nRaster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Tarek Nakkouch for reporting this issue."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-43", "name": "django: PYSEC-2026-43", "shortDescription": {"text": "django: PYSEC-2026-43"}, "fullDescription": {"text": "An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.\n`ASGIRequest` allows a remote attacker to cause a potential denial-of-service via a crafted request with multiple duplicate headers.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Jiyong Yang for reporting this issue."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-42", "name": "django: PYSEC-2026-42", "shortDescription": {"text": "django: PYSEC-2026-42"}, "fullDescription": {"text": "An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.\nThe `django.contrib.auth.handlers.modwsgi.check_password()` function for authentication via `mod_wsgi` allows remote attackers to enumerate users via a timing attack.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Stackered for reporting this issue."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-201", "name": "django: PYSEC-2026-201", "shortDescription": {"text": "django: PYSEC-2026-201"}, "fullDescription": {"text": "An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6.\n`django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitively, which allows remote attackers to read responses that were incorrectly cached because their `Cache-Control` directives used uppercase or mixed-case values.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Ahmed Badawe for reporting this issue."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-200", "name": "django: PYSEC-2026-200", "shortDescription": {"text": "django: PYSEC-2026-200"}, "fullDescription": {"text": "An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15.\n`django.core.mail.backends.smtp.EmailBackend` in Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake when `fail_silently=True`, which allows on-path network attackers to read email content via cleartext interception.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Kasper Dupont for reporting this issue."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-199", "name": "django: PYSEC-2026-199", "shortDescription": {"text": "django: PYSEC-2026-199"}, "fullDescription": {"text": "An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15.\n`django.http.HttpRequest.get_signed_cookie` in Django uses a non-injective salt derivation (concatenating the cookie name and salt argument), which allows a remote attacker to use a cookie in a context different from the one where it was signed, via distinct `(name, salt)` pairs that produce the same concatenation.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Peng Zhou for reporting this issue."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-198", "name": "django: PYSEC-2026-198", "shortDescription": {"text": "django: PYSEC-2026-198"}, "fullDescription": {"text": "An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6.\n`django.utils.cache.has_vary_header()` in Django does not strip leading or trailing whitespace from `Vary` response header values before comparison, which allows remote attackers to read cached responses via requests to URLs whose responses contain whitespace-padded Vary header values.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Navid Rezazadeh for reporting this issue."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "PYSEC-2026-197", "name": "django: PYSEC-2026-197", "shortDescription": {"text": "django: PYSEC-2026-197"}, "fullDescription": {"text": "An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6.\n`django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requests bearing that header without `Cache-Control: public`, which allows remote attackers to read private cached responses via unauthenticated requests to the same URL.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Shai Berger for reporting this issue."}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-96hv-2xvq-fx4p", "name": "ws: GHSA-96hv-2xvq-fx4p", "shortDescription": {"text": "ws: GHSA-96hv-2xvq-fx4p"}, "fullDescription": {"text": "ws: Memory exhaustion DoS from tiny fragments and data chunks"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-c2c7-rcm5-vvqj", "name": "picomatch: GHSA-c2c7-rcm5-vvqj", "shortDescription": {"text": "picomatch: GHSA-c2c7-rcm5-vvqj"}, "fullDescription": {"text": "Picomatch has a ReDoS vulnerability via extglob quantifiers"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-q67f-28xg-22rw", "name": "node-forge: GHSA-q67f-28xg-22rw", "shortDescription": {"text": "node-forge: GHSA-q67f-28xg-22rw"}, "fullDescription": {"text": "Forge has signature forgery in Ed25519 due to missing S > L check"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-ppp5-5v6c-4jwp", "name": "node-forge: GHSA-ppp5-5v6c-4jwp", "shortDescription": {"text": "node-forge: GHSA-ppp5-5v6c-4jwp"}, "fullDescription": {"text": "Forge has signature forgery in RSA-PKCS due to ASN.1 extra field  "}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-5m6q-g25r-mvwx", "name": "node-forge: GHSA-5m6q-g25r-mvwx", "shortDescription": {"text": "node-forge: GHSA-5m6q-g25r-mvwx"}, "fullDescription": {"text": "Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-2328-f5f3-gj25", "name": "node-forge: GHSA-2328-f5f3-gj25", "shortDescription": {"text": "node-forge: GHSA-2328-f5f3-gj25"}, "fullDescription": {"text": "Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-hmw2-7cc7-3qxx", "name": "form-data: GHSA-hmw2-7cc7-3qxx", "shortDescription": {"text": "form-data: GHSA-hmw2-7cc7-3qxx"}, "fullDescription": {"text": "form-data: CRLF injection in form-data via unescaped multipart field names and filenames"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-q8qp-cvcw-x6jj", "name": "axios: GHSA-q8qp-cvcw-x6jj", "shortDescription": {"text": "axios: GHSA-q8qp-cvcw-x6jj"}, "fullDescription": {"text": "Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-pf86-5x62-jrwf", "name": "axios: GHSA-pf86-5x62-jrwf", "shortDescription": {"text": "axios: GHSA-pf86-5x62-jrwf"}, "fullDescription": {"text": "Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-p92q-9vqr-4j8v", "name": "axios: GHSA-p92q-9vqr-4j8v", "shortDescription": {"text": "axios: GHSA-p92q-9vqr-4j8v"}, "fullDescription": {"text": "Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-j5f8-grm9-p9fc", "name": "axios: GHSA-j5f8-grm9-p9fc", "shortDescription": {"text": "axios: GHSA-j5f8-grm9-p9fc"}, "fullDescription": {"text": "Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-hfxv-24rg-xrqf", "name": "axios: GHSA-hfxv-24rg-xrqf", "shortDescription": {"text": "axios: GHSA-hfxv-24rg-xrqf"}, "fullDescription": {"text": "Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-777c-7fjr-54vf", "name": "axios: GHSA-777c-7fjr-54vf", "shortDescription": {"text": "axios: GHSA-777c-7fjr-54vf"}, "fullDescription": {"text": "Allocation of Resources Without Limits or Throttling in Axios"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-6chq-wfr3-2hj9", "name": "axios: GHSA-6chq-wfr3-2hj9", "shortDescription": {"text": "axios: GHSA-6chq-wfr3-2hj9"}, "fullDescription": {"text": "Axios: Header Injection via Prototype Pollution"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-pjwm-pj3p-43mv", "name": "axios: GHSA-pjwm-pj3p-43mv", "shortDescription": {"text": "axios: GHSA-pjwm-pj3p-43mv"}, "fullDescription": {"text": "axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-3g43-6gmg-66jw", "name": "axios: GHSA-3g43-6gmg-66jw", "shortDescription": {"text": "axios: GHSA-3g43-6gmg-66jw"}, "fullDescription": {"text": "axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-35jp-ww65-95wh", "name": "axios: GHSA-35jp-ww65-95wh", "shortDescription": {"text": "axios: GHSA-35jp-ww65-95wh"}, "fullDescription": {"text": "axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-x6wf-f3px-wcqx", "name": "@xmldom/xmldom: GHSA-x6wf-f3px-wcqx", "shortDescription": {"text": "@xmldom/xmldom: GHSA-x6wf-f3px-wcqx"}, "fullDescription": {"text": "xmldom has XML node injection through unvalidated processing instruction serialization"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-wh4c-j3r5-mjhp", "name": "@xmldom/xmldom: GHSA-wh4c-j3r5-mjhp", "shortDescription": {"text": "@xmldom/xmldom: GHSA-wh4c-j3r5-mjhp"}, "fullDescription": {"text": "xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-j759-j44w-7fr8", "name": "@xmldom/xmldom: GHSA-j759-j44w-7fr8", "shortDescription": {"text": "@xmldom/xmldom: GHSA-j759-j44w-7fr8"}, "fullDescription": {"text": "xmldom has XML node injection through unvalidated comment serialization"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-f6ww-3ggp-fr8h", "name": "@xmldom/xmldom: GHSA-f6ww-3ggp-fr8h", "shortDescription": {"text": "@xmldom/xmldom: GHSA-f6ww-3ggp-fr8h"}, "fullDescription": {"text": "xmldom has XML injection through unvalidated DocumentType serialization"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-2v35-w6hq-6mfw", "name": "@xmldom/xmldom: GHSA-2v35-w6hq-6mfw", "shortDescription": {"text": "@xmldom/xmldom: GHSA-2v35-w6hq-6mfw"}, "fullDescription": {"text": "xmldom: Uncontrolled recursion in XML serialization leads to DoS"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "DKC011", "name": "Database service publishes a host port", "shortDescription": {"text": "Database service publishes a host port"}, "fullDescription": {"text": "Publishing database ports to the host increases exposure. Internal Compose networking usually only needs expose, not ports."}, "properties": {"scanner": "repobility-docker", "category": "docker", "severity": "high", "confidence": 0.84, "cwe": "", "owasp": ""}}, {"id": "DKR014", "name": "Dockerfile copies the entire context without .dockerignore", "shortDescription": {"text": "Dockerfile copies the entire context without .dockerignore"}, "fullDescription": {"text": "COPY . or ADD . sends the full build context to Docker. Without .dockerignore this can include secrets, git history, and local artifacts."}, "properties": {"scanner": "repobility-docker", "category": "docker", "severity": "high", "confidence": 0.92, "cwe": "", "owasp": ""}}, {"id": "SEC040", "name": "[SEC040] innerHTML XSS \u2014 template literal with server-supplied data: Setting .innerHTML with a template literal that int", "shortDescription": {"text": "[SEC040] innerHTML XSS \u2014 template literal with server-supplied data: Setting .innerHTML with a template literal that interpolates server-supplied or user-supplied data is the canonical stored/reflected XSS vector. The browser parses the HTM"}, "fullDescription": {"text": "For plain text: use el.textContent = data.value (auto-escapes).\nFor HTML you need to render: el.innerHTML = DOMPurify.sanitize(html).\nFor React/Vue/Svelte: stop using innerHTML; use the framework's binding.\nWhen data comes from CV/PDF parsers, sanitize at the parser boundary too."}, "properties": {"scanner": "repobility-threat-engine", "category": "xss", "severity": "high", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "SEC035", "name": "[SEC035] Unbounded Resource Allocation \u2014 DoS risk: Allocating resources (buffers, recursion stack, large ranges) based o", "shortDescription": {"text": "[SEC035] Unbounded Resource Allocation \u2014 DoS risk: Allocating resources (buffers, recursion stack, large ranges) based on user input without an upper bound. Attackers send `size=10000000` to exhaust memory, or trigger expensive computation."}, "fullDescription": {"text": "Cap user-controlled sizes BEFORE allocation:\n  size = min(int(request.args.get('n', 100)), MAX_SIZE)\nSet framework-level limits:\n  Flask:    app.config['MAX_CONTENT_LENGTH'] = 10 * 1024 * 1024\n  FastAPI:  use middleware to enforce request size\n  Django:   DATA_UPLOAD_MAX_MEMORY_SIZE in settings.py\nNever raise `sys.setrecursionlimit` past 10K without a deeper review."}, "properties": {"scanner": "repobility-threat-engine", "category": "resource_exhaustion", "severity": "high", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "SEC103", "name": "[SEC103] LDAP injection \u2014 non-constant search filter: User input concatenated into an LDAP search filter. Attackers inje", "shortDescription": {"text": "[SEC103] LDAP injection \u2014 non-constant search filter: User input concatenated into an LDAP search filter. Attackers inject `*)(uid=*` style payloads to bypass auth or enumerate accounts."}, "fullDescription": {"text": "Escape with javax.naming.ldap.Rdn.escapeValue or equivalent. For python-ldap, use ldap.filter.escape_filter_chars. Better: use parameterized search APIs (Spring LdapTemplate filter encoders)."}, "properties": {"scanner": "repobility-threat-engine", "category": "injection", "severity": "high", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "MINED009", "name": "[MINED009] Floats For Money: Variable named price/amount/cost typed as float instead of Decimal.", "shortDescription": {"text": "[MINED009] Floats For Money: Variable named price/amount/cost typed as float instead of Decimal."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-682 /  for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "high", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "MINED126", "name": "Workflow container/services image `pgvector/pgvector:pg16` unpinned", "shortDescription": {"text": "Workflow container/services image `pgvector/pgvector:pg16` unpinned"}, "fullDescription": {"text": "`container/services image: pgvector/pgvector:pg16` without `@sha256:...` pulls a mutable tag at workflow-run time. Treat workflow container references with the same supply-chain discipline as Dockerfile FROM lines."}, "properties": {"scanner": "repobility-supply-chain", "category": "dependency", "severity": "high", "confidence": 0.9, "cwe": "", "owasp": ""}}, {"id": "MINED118", "name": "Dockerfile FROM `node:20-slim` not pinned by digest", "shortDescription": {"text": "Dockerfile FROM `node:20-slim` not pinned by digest"}, "fullDescription": {"text": "`FROM node:20-slim` resolves the tag at build time. The registry CAN re-push a different image for the same tag, so every build is potentially different. Production images should pin to `image@sha256:...` for reproducibility + supply-chain integrity."}, "properties": {"scanner": "repobility-supply-chain", "category": "dependency", "severity": "high", "confidence": 0.9, "cwe": "", "owasp": ""}}, {"id": "MINED106", "name": "Phantom test coverage: test_no_context_returns_zero_confidence", "shortDescription": {"text": "Phantom test coverage: test_no_context_returns_zero_confidence"}, "fullDescription": {"text": "Test function `test_no_context_returns_zero_confidence` runs code but contains no assert / expect / should call \u2014 it passes regardless of behaviour. Adds line coverage without verifying anything."}, "properties": {"scanner": "repobility-ast-engine", "category": "quality", "severity": "high", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "MINED108", "name": "`self.request` used but never assigned in __init__", "shortDescription": {"text": "`self.request` used but never assigned in __init__"}, "fullDescription": {"text": "Method `perform_update` of class `EmployeeViewSet` reads `self.request`, but no assignment to it exists in __init__ (and no class-level fallback). This raises AttributeError the first time the method runs against an instance."}, "properties": {"scanner": "repobility-ast-engine", "category": "quality", "severity": "high", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "GHSA-w7jw-789q-3m8p", "name": "shell-quote: GHSA-w7jw-789q-3m8p", "shortDescription": {"text": "shell-quote: GHSA-w7jw-789q-3m8p"}, "fullDescription": {"text": "shell-quote quote() does not escape newlines in object .op values"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "critical", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "generic-api-key", "name": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.", "shortDescription": {"text": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations."}, "fullDescription": {"text": "Gitleaks detected a committed secret or credential pattern."}, "properties": {"scanner": "gitleaks", "category": "credential_exposure", "severity": "critical", "confidence": 0.95, "cwe": "", "owasp": ""}}, {"id": "MINED013", "name": "[MINED013] Password In Url: https://user:password@host \u2014 leaks creds via logs, referrer, error messages.", "shortDescription": {"text": "[MINED013] Password In Url: https://user:password@host \u2014 leaks creds via logs, referrer, error messages."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-200 / A07:2021 for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "critical", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "SEC022", "name": "[SEC022] Database URL With Embedded Credential: A database connection URL contains an embedded username and password. Th", "shortDescription": {"text": "[SEC022] Database URL With Embedded Credential: A database connection URL contains an embedded username and password. These URLs are often copied into defaults, docs, and scripts, then leak working credentials."}, "fullDescription": {"text": "Remove the embedded password, require the URL from a secret store or environment variable, and rotate the database credential."}, "properties": {"scanner": "repobility-threat-engine", "category": "credential_exposure", "severity": "critical", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "MINED107", "name": "Missing import: `email` used but not imported", "shortDescription": {"text": "Missing import: `email` used but not imported"}, "fullDescription": {"text": "The file uses `email.something(...)` but never imports `email`. This raises NameError at runtime the first time the line executes."}, "properties": {"scanner": "repobility-ast-engine", "category": "quality", "severity": "critical", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea3b5e389d8c9c0f", "name": "Low test-to-source ratio", "shortDescription": {"text": "Low test-to-source ratio"}, "fullDescription": {"text": "1 tests / 5 src (ratio 0.20)."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 10 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing ci. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5fa33c73bdb206b7", "name": "Commented-code block (5 lines) in playwright.config.ts:74", "shortDescription": {"text": "Commented-code block (5 lines) in playwright.config.ts:74"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bdf3dfac37ee9958", "name": "Network/subprocess call without timeout or try/except \u2014 check_and_create_course.py:26", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 check_and_create_course.py:26"}, "fullDescription": {"text": "`requests.post(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1b5a76780c3df9aa", "name": "1 env vars used in code but missing from .env.example", "shortDescription": {"text": "1 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `CI`. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/25507"}, "properties": {"repository": "dragneel07-psm/E-LearningWebApp", "repoUrl": "https://github.com/dragneel07-psm/E-LearningWebApp", "branch": "main"}, "results": [{"ruleId": "WEB012", "level": "warning", "message": {"text": "Service worker is present without a web app manifest"}, "properties": {"repobilityId": 224997, "scanner": "repobility-web-presence", "fingerprint": "fcb0b1c9ad72f83092dc6928d3e76ca25d428a654bdcd26192cf227ad67fe1ea", "category": "quality", "severity": "medium", "confidence": 0.72, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "A service worker was discovered but no common web manifest file was found.", "evidence": {"rule_id": "WEB012", "scanner": "repobility-web-presence", "references": ["https://developer.mozilla.org/en-US/docs/Web/Manifest"], "correlation_key": "fp|fcb0b1c9ad72f83092dc6928d3e76ca25d428a654bdcd26192cf227ad67fe1ea"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "manifest.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "WEB003", "level": "warning", "message": {"text": "Public web service has no security.txt"}, "properties": {"repobilityId": 224996, "scanner": "repobility-web-presence", "fingerprint": "5cd26606c5a53c9f403ff7a92a6917c19cf440a23ce03e2b90e8c493312ef8cd", "category": "quality", "severity": "medium", "confidence": 0.78, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Repository looks like a public web app/API but no security.txt file or route was discovered.", "evidence": {"rule_id": "WEB003", "scanner": "repobility-web-presence", "references": ["https://www.rfc-editor.org/rfc/rfc9116", "https://github.com/Lissy93/web-check"], "correlation_key": "fp|5cd26606c5a53c9f403ff7a92a6917c19cf440a23ce03e2b90e8c493312ef8cd"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".well-known/security.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "JRN005", "level": "warning", "message": {"text": "Compliance or security claim is near a placeholder link"}, "properties": {"repobilityId": 224987, "scanner": "repobility-journey-contract", "fingerprint": "8bd55bb38e7c6562375f7a561a62b1725d447fbc0de7c605f318feb52cc6cf92", "category": "quality", "severity": "medium", "confidence": 0.76, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Placeholder link appears near compliance/security claim text.", "evidence": {"rule_id": "JRN005", "scanner": "repobility-journey-contract", "references": ["https://repobility.com/library/authorization/"], "correlation_key": "fp|8bd55bb38e7c6562375f7a561a62b1725d447fbc0de7c605f318feb52cc6cf92"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/components/auth/login-form.tsx"}, "region": {"startLine": 286}}}]}, {"ruleId": "JRN003", "level": "warning", "message": {"text": "Frontend API reference is not matched by discovered backend routes"}, "properties": {"repobilityId": 224986, "scanner": "repobility-journey-contract", "fingerprint": "eb4d903ab6c28b5a34399624ce41897c985d41d73bb75f74b1b5a745ebfb6fec", "category": "quality", "severity": "medium", "confidence": 0.74, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Same-origin /api path appears in frontend code but no discovered backend endpoint has the same route shape.", "evidence": {"rule_id": "JRN003", "scanner": "repobility-journey-contract", "references": ["https://repobility.com/library/authorization/"], "route_shape": "/api/auth", "correlation_key": "fp|eb4d903ab6c28b5a34399624ce41897c985d41d73bb75f74b1b5a745ebfb6fec", "backend_endpoint_count": 85}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/services/api.ts"}, "region": {"startLine": 115}}}]}, {"ruleId": "JRN003", "level": "warning", "message": {"text": "Frontend API reference is not matched by discovered backend routes"}, "properties": {"repobilityId": 224985, "scanner": "repobility-journey-contract", "fingerprint": "01c8fef87b08dc133f1a9b1653fa5fe849ae80379c3ca02ea3fa22fe5da6cdb7", "category": "quality", "severity": "medium", "confidence": 0.74, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Same-origin /api path appears in frontend code but no discovered backend endpoint has the same route shape.", "evidence": {"rule_id": "JRN003", "scanner": "repobility-journey-contract", "references": ["https://repobility.com/library/authorization/"], "route_shape": "/api/...", "correlation_key": "fp|01c8fef87b08dc133f1a9b1653fa5fe849ae80379c3ca02ea3fa22fe5da6cdb7", "backend_endpoint_count": 85}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/services/api.ts"}, "region": {"startLine": 11}}}]}, {"ruleId": "JRN003", "level": "warning", "message": {"text": "Frontend API reference is not matched by discovered backend routes"}, "properties": {"repobilityId": 224984, "scanner": "repobility-journey-contract", "fingerprint": "185a874ae30b95310a261a37bd3dd989d59651b13214ea1ca3c64360e60fa03f", "category": "quality", "severity": "medium", "confidence": 0.74, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Same-origin /api path appears in frontend code but no discovered backend endpoint has the same route shape.", "evidence": {"rule_id": "JRN003", "scanner": "repobility-journey-contract", "references": ["https://repobility.com/library/authorization/"], "route_shape": "/api/academic/submissions", "correlation_key": "fp|185a874ae30b95310a261a37bd3dd989d59651b13214ea1ca3c64360e60fa03f", "backend_endpoint_count": 85}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/public/sw.js"}, "region": {"startLine": 238}}}]}, {"ruleId": "JRN003", "level": "warning", "message": {"text": "Frontend API reference is not matched by discovered backend routes"}, "properties": {"repobilityId": 224983, "scanner": "repobility-journey-contract", "fingerprint": "efe96aca747abf214ec1df8aae7bf1f18b3330d4800f363f5601e9ef6057cde3", "category": "quality", "severity": "medium", "confidence": 0.74, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Same-origin /api path appears in frontend code but no discovered backend endpoint has the same route shape.", "evidence": {"rule_id": "JRN003", "scanner": "repobility-journey-contract", "references": ["https://repobility.com/library/authorization/"], "route_shape": "/api/users/ws-ticket", "correlation_key": "fp|efe96aca747abf214ec1df8aae7bf1f18b3330d4800f363f5601e9ef6057cde3", "backend_endpoint_count": 85}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/lib/ws-ticket.ts"}, "region": {"startLine": 27}}}]}, {"ruleId": "JRN003", "level": "warning", "message": {"text": "Frontend API reference is not matched by discovered backend routes"}, "properties": {"repobilityId": 224982, "scanner": "repobility-journey-contract", "fingerprint": "f7b788071f54340e54113732ae66181bcc3ec43f46fd2c10c54a79417c625b6e", "category": "quality", "severity": "medium", "confidence": 0.74, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Same-origin /api path appears in frontend code but no discovered backend endpoint has the same route shape.", "evidence": {"rule_id": "JRN003", "scanner": "repobility-journey-contract", "references": ["https://repobility.com/library/authorization/"], "route_shape": "/api/hr/salary-slips/{param}/payslip-pdf", "correlation_key": "fp|f7b788071f54340e54113732ae66181bcc3ec43f46fd2c10c54a79417c625b6e", "backend_endpoint_count": 85}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/lib/api.ts"}, "region": {"startLine": 3938}}}]}, {"ruleId": "JRN003", "level": "warning", "message": {"text": "Frontend API reference is not matched by discovered backend routes"}, "properties": {"repobilityId": 224981, "scanner": "repobility-journey-contract", "fingerprint": "7ced7bb8fd20a7bd876ecef0e656ec913fcd7fded0466f067702a4ac129263b4", "category": "quality", "severity": "medium", "confidence": 0.74, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Same-origin /api path appears in frontend code but no discovered backend endpoint has the same route shape.", "evidence": {"rule_id": "JRN003", "scanner": "repobility-journey-contract", "references": ["https://repobility.com/library/authorization/"], "route_shape": "/api/academic/reports/student-performance-excel/{param}", "correlation_key": "fp|7ced7bb8fd20a7bd876ecef0e656ec913fcd7fded0466f067702a4ac129263b4", "backend_endpoint_count": 85}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/lib/api.ts"}, "region": {"startLine": 2224}}}]}, {"ruleId": "JRN003", "level": "warning", "message": {"text": "Frontend API reference is not matched by discovered backend routes"}, "properties": {"repobilityId": 224980, "scanner": "repobility-journey-contract", "fingerprint": "0bfabb2c7512fde5c76e74bd94952e151aa238003ac35d346307ed5f7814695a", "category": "quality", "severity": "medium", "confidence": 0.74, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Same-origin /api path appears in frontend code but no discovered backend endpoint has the same route shape.", "evidence": {"rule_id": "JRN003", "scanner": "repobility-journey-contract", "references": ["https://repobility.com/library/authorization/"], "route_shape": "/api/academic/reports/student-performance/{param}", "correlation_key": "fp|0bfabb2c7512fde5c76e74bd94952e151aa238003ac35d346307ed5f7814695a", "backend_endpoint_count": 85}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/lib/api.ts"}, "region": {"startLine": 2223}}}]}, {"ruleId": "JRN003", "level": "warning", "message": {"text": "Frontend API reference is not matched by discovered backend routes"}, "properties": {"repobilityId": 224979, "scanner": "repobility-journey-contract", "fingerprint": "da6456964986ba7a8ff4d81a060e315d205298bc923d980d0a9c2b50ebec3b42", "category": "quality", "severity": "medium", "confidence": 0.74, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Same-origin /api path appears in frontend code but no discovered backend endpoint has the same route shape.", "evidence": {"rule_id": "JRN003", "scanner": "repobility-journey-contract", "references": ["https://repobility.com/library/authorization/"], "route_shape": "/api/core/tenant-check", "correlation_key": "fp|da6456964986ba7a8ff4d81a060e315d205298bc923d980d0a9c2b50ebec3b42", "backend_endpoint_count": 85}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/hooks/use-tenant-identity.ts"}, "region": {"startLine": 68}}}]}, {"ruleId": "JRN003", "level": "warning", "message": {"text": "Frontend API reference is not matched by discovered backend routes"}, "properties": {"repobilityId": 224978, "scanner": "repobility-journey-contract", "fingerprint": "2869419a49d25d7bc732a39745d2df0cd8ec9f6bfdfc062eb7c7d02fdddc64d7", "category": "quality", "severity": "medium", "confidence": 0.74, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Same-origin /api path appears in frontend code but no discovered backend endpoint has the same route shape.", "evidence": {"rule_id": "JRN003", "scanner": "repobility-journey-contract", "references": ["https://repobility.com/library/authorization/"], "route_shape": "/api/users/2fa/setup", "correlation_key": "fp|2869419a49d25d7bc732a39745d2df0cd8ec9f6bfdfc062eb7c7d02fdddc64d7", "backend_endpoint_count": 85}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/components/auth/saas-login-form.tsx"}, "region": {"startLine": 149}}}]}, {"ruleId": "JRN003", "level": "warning", "message": {"text": "Frontend API reference is not matched by discovered backend routes"}, "properties": {"repobilityId": 224977, "scanner": "repobility-journey-contract", "fingerprint": "44ef85e1ff0eb74de8e955b86f00669e6adc71337c90a374d047a31be95372ca", "category": "quality", "severity": "medium", "confidence": 0.74, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Same-origin /api path appears in frontend code but no discovered backend endpoint has the same route shape.", "evidence": {"rule_id": "JRN003", "scanner": "repobility-journey-contract", "references": ["https://repobility.com/library/authorization/"], "route_shape": "/api/academic/notices", "correlation_key": "fp|44ef85e1ff0eb74de8e955b86f00669e6adc71337c90a374d047a31be95372ca", "backend_endpoint_count": 85}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/school/page.tsx"}, "region": {"startLine": 161}}}]}, {"ruleId": "JRN003", "level": "warning", "message": {"text": "Frontend API reference is not matched by discovered backend routes"}, "properties": {"repobilityId": 224976, "scanner": "repobility-journey-contract", "fingerprint": "d6f68f67bba61bdd617dc43ebf5d2f0a5541bccb65058e1fac8d45aed637d69c", "category": "quality", "severity": "medium", "confidence": 0.74, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Same-origin /api path appears in frontend code but no discovered backend endpoint has the same route shape.", "evidence": {"rule_id": "JRN003", "scanner": "repobility-journey-contract", "references": ["https://repobility.com/library/authorization/"], "route_shape": "/api/core/tenant-check", "correlation_key": "fp|d6f68f67bba61bdd617dc43ebf5d2f0a5541bccb65058e1fac8d45aed637d69c", "backend_endpoint_count": 85}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/school/page.tsx"}, "region": {"startLine": 133}}}]}, {"ruleId": "JRN003", "level": "warning", "message": {"text": "Frontend API reference is not matched by discovered backend routes"}, "properties": {"repobilityId": 224975, "scanner": "repobility-journey-contract", "fingerprint": "4f811f4a1e2b21029b54946e6014e2682aed30a4bd79b9029e5795ce44dc9386", "category": "quality", "severity": "medium", "confidence": 0.74, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Same-origin /api path appears in frontend code but no discovered backend endpoint has the same route shape.", "evidence": {"rule_id": "JRN003", "scanner": "repobility-journey-contract", "references": ["https://repobility.com/library/authorization/"], "route_shape": "/api/users/login", "correlation_key": "fp|4f811f4a1e2b21029b54946e6014e2682aed30a4bd79b9029e5795ce44dc9386", "backend_endpoint_count": 85}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/api/auth/login/route.ts"}, "region": {"startLine": 11}}}]}, {"ruleId": "JRN003", "level": "warning", "message": {"text": "Frontend API reference is not matched by discovered backend routes"}, "properties": {"repobilityId": 224974, "scanner": "repobility-journey-contract", "fingerprint": "966d9f54d815c661b9ca7bd0b6abaec96ac657d5e52b72f63618d498975e71f4", "category": "quality", "severity": "medium", "confidence": 0.74, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Same-origin /api path appears in frontend code but no discovered backend endpoint has the same route shape.", "evidence": {"rule_id": "JRN003", "scanner": "repobility-journey-contract", "references": ["https://repobility.com/library/authorization/"], "route_shape": "/api/users/2fa/activate", "correlation_key": "fp|966d9f54d815c661b9ca7bd0b6abaec96ac657d5e52b72f63618d498975e71f4", "backend_endpoint_count": 85}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/api/auth/2fa-activate/route.ts"}, "region": {"startLine": 13}}}]}, {"ruleId": "JRN003", "level": "warning", "message": {"text": "Frontend API reference is not matched by discovered backend routes"}, "properties": {"repobilityId": 224973, "scanner": "repobility-journey-contract", "fingerprint": "2689142673296f6f84c31d32f8d67d80c941858c69fb5a65d8e1f7bae89160a9", "category": "quality", "severity": "medium", "confidence": 0.74, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Same-origin /api path appears in frontend code but no discovered backend endpoint has the same route shape.", "evidence": {"rule_id": "JRN003", "scanner": "repobility-journey-contract", "references": ["https://repobility.com/library/authorization/"], "route_shape": "/api/billing_school{param}", "correlation_key": "fp|2689142673296f6f84c31d32f8d67d80c941858c69fb5a65d8e1f7bae89160a9", "backend_endpoint_count": 85}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/admin/finance/accounting/page.tsx"}, "region": {"startLine": 18}}}]}, {"ruleId": "AUC009", "level": "warning", "message": {"text": "[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears to perform a sensitive function such as export, invite, role, token, billing, or destructive action without elevated policy evidence. Endpoint: ANY /api/notifications/."}, "properties": {"repobilityId": 224972, "scanner": "repobility-access-control", "fingerprint": "eed1b99e7b31f4576ee1655ee7f0a559cca219d4e0fb106827584db817bf8491", "category": "auth", "severity": "medium", "confidence": 0.68, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"path": "/api/notifications/", "method": "ANY", "scanner": "repobility-access-control", "framework": "Django", "correlation_key": "code|auth|backend/config/urls.py|39|cwe-285", "identity_targets": ["unknown"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/config/urls.py"}, "region": {"startLine": 39}}}]}, {"ruleId": "AUC009", "level": "warning", "message": {"text": "[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears to perform a sensitive function such as export, invite, role, token, billing, or destructive action without elevated policy evidence. Endpoint: ANY /api/ai/."}, "properties": {"repobilityId": 224971, "scanner": "repobility-access-control", "fingerprint": "c8fc5b09c2e40bb0fc0233a22660f474c636426149ab603d938cb2fd342438e8", "category": "auth", "severity": "medium", "confidence": 0.68, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"path": "/api/ai/", "method": "ANY", "scanner": "repobility-access-control", "framework": "Django", "correlation_key": "code|auth|backend/config/urls.py|38|cwe-285", "identity_targets": ["unknown"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/config/urls.py"}, "region": {"startLine": 38}}}]}, {"ruleId": "AUC009", "level": "warning", "message": {"text": "[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears to perform a sensitive function such as export, invite, role, token, billing, or destructive action without elevated policy evidence. Endpoint: ANY /api/billing/."}, "properties": {"repobilityId": 224970, "scanner": "repobility-access-control", "fingerprint": "c62c10b5e2d955196ca460103aa6464593a3514b0f0099d0b7fbb2190007af41", "category": "auth", "severity": "medium", "confidence": 0.68, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"path": "/api/billing/", "method": "ANY", "scanner": "repobility-access-control", "framework": "Django", "correlation_key": "code|auth|backend/config/urls.py|37|cwe-285", "identity_targets": ["unknown"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/config/urls.py"}, "region": {"startLine": 37}}}]}, {"ruleId": "AUC009", "level": "warning", "message": {"text": "[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears to perform a sensitive function such as export, invite, role, token, billing, or destructive action without elevated policy evidence. Endpoint: ANY /api/billing/school/."}, "properties": {"repobilityId": 224969, "scanner": "repobility-access-control", "fingerprint": "cdd189d5fe98d6c8f66cc84f8795b9d4dc64e860be66b115def33a5e1b3ced00", "category": "auth", "severity": "medium", "confidence": 0.68, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"path": "/api/billing/school/", "method": "ANY", "scanner": "repobility-access-control", "framework": "Django", "correlation_key": "code|auth|backend/config/urls.py|36|cwe-285", "identity_targets": ["unknown"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/config/urls.py"}, "region": {"startLine": 36}}}]}, {"ruleId": "AUC009", "level": "warning", "message": {"text": "[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears to perform a sensitive function such as export, invite, role, token, billing, or destructive action without elevated policy evidence. Endpoint: ANY /quizzes/generate/."}, "properties": {"repobilityId": 224968, "scanner": "repobility-access-control", "fingerprint": "1b08af723d01604d5aa0a14bd3ea21c8ffd37c5584cb699f818631c886d95f15", "category": "auth", "severity": "medium", "confidence": 0.68, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"path": "/quizzes/generate/", "method": "ANY", "scanner": "repobility-access-control", "framework": "Django", "correlation_key": "code|auth|backend/ai_engine/urls.py|38|cwe-285", "identity_targets": ["unknown"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/urls.py"}, "region": {"startLine": 38}}}]}, {"ruleId": "AUC009", "level": "warning", "message": {"text": "[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears to perform a sensitive function such as export, invite, role, token, billing, or destructive action without elevated policy evidence. Endpoint: ANY /exams/generate/."}, "properties": {"repobilityId": 224967, "scanner": "repobility-access-control", "fingerprint": "5510d3d9729403e2b60e4e53cf227cb740b10490fd50e2e5495b0b27d46b432b", "category": "auth", "severity": "medium", "confidence": 0.68, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"path": "/exams/generate/", "method": "ANY", "scanner": "repobility-access-control", "framework": "Django", "correlation_key": "code|auth|backend/ai_engine/urls.py|37|cwe-285", "identity_targets": ["unknown"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/urls.py"}, "region": {"startLine": 37}}}]}, {"ruleId": "AUC009", "level": "warning", "message": {"text": "[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears to perform a sensitive function such as export, invite, role, token, billing, or destructive action without elevated policy evidence. Endpoint: ANY /grading/drafts/."}, "properties": {"repobilityId": 224966, "scanner": "repobility-access-control", "fingerprint": "6dbc02a3d91d37e6625d548037857f185b388bc5bf54f36d03620c38bdb2db60", "category": "auth", "severity": "medium", "confidence": 0.68, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"path": "/grading/drafts/", "method": "ANY", "scanner": "repobility-access-control", "framework": "Django", "correlation_key": "code|auth|backend/ai_engine/urls.py|26|cwe-285", "identity_targets": ["unknown"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/urls.py"}, "region": {"startLine": 26}}}]}, {"ruleId": "AUC009", "level": "warning", "message": {"text": "[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears to perform a sensitive function such as export, invite, role, token, billing, or destructive action without elevated policy evidence. Endpoint: ANY /grading/rubrics/."}, "properties": {"repobilityId": 224965, "scanner": "repobility-access-control", "fingerprint": "0f7092fb344319a26bcb7ad3f9ba5474457b0528738ad0d198a4bbb57e4da4c5", "category": "auth", "severity": "medium", "confidence": 0.68, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"path": "/grading/rubrics/", "method": "ANY", "scanner": "repobility-access-control", "framework": "Django", "correlation_key": "code|auth|backend/ai_engine/urls.py|25|cwe-285", "identity_targets": ["unknown"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/urls.py"}, "region": {"startLine": 25}}}]}, {"ruleId": "AUC009", "level": "warning", "message": {"text": "[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears to perform a sensitive function such as export, invite, role, token, billing, or destructive action without elevated policy evidence. Endpoint: ANY /artifacts/."}, "properties": {"repobilityId": 224964, "scanner": "repobility-access-control", "fingerprint": "862a905191b41231f8e39848b09c4308080f97ead30e17abe9d7c7c1edba0172", "category": "auth", "severity": "medium", "confidence": 0.68, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"path": "/artifacts/", "method": "ANY", "scanner": "repobility-access-control", "framework": "Django", "correlation_key": "code|auth|backend/ai_engine/urls.py|24|cwe-285", "identity_targets": ["unknown"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/urls.py"}, "region": {"startLine": 24}}}]}, {"ruleId": "AUC009", "level": "warning", "message": {"text": "[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears to perform a sensitive function such as export, invite, role, token, billing, or destructive action without elevated policy evidence. Endpoint: ANY /readyz/."}, "properties": {"repobilityId": 224963, "scanner": "repobility-access-control", "fingerprint": "fa536d43ca859f78415f5330f6f8655ac4e15f5309e90c0b74eaaaad0ab4f77c", "category": "auth", "severity": "medium", "confidence": 0.68, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"path": "/readyz/", "method": "ANY", "scanner": "repobility-access-control", "framework": "Django", "correlation_key": "code|auth|backend/core/urls.py|39|cwe-285", "identity_targets": ["unknown"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/urls.py"}, "region": {"startLine": 39}}}]}, {"ruleId": "AUC004", "level": "warning", "message": {"text": "[AUC004] Admin route does not show super_admin separation: An administrative route was detected without nearby evidence that platform super_admin access is separated from tenant/application admin access. Endpoint: ANY /analytics/teacher/."}, "properties": {"repobilityId": 224962, "scanner": "repobility-access-control", "fingerprint": "344cb0b58baab54d804f43e0a76c70afe7da2eddc778d073843081064a19da56", "category": "auth", "severity": "medium", "confidence": 0.66, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"path": "/analytics/teacher/", "method": "ANY", "scanner": "repobility-access-control", "framework": "Django", "correlation_key": "code|auth|backend/ai_engine/urls.py|68|cwe-285", "identity_targets": ["unknown", "admin"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/urls.py"}, "region": {"startLine": 68}}}]}, {"ruleId": "AUC004", "level": "warning", "message": {"text": "[AUC004] Admin route does not show super_admin separation: An administrative route was detected without nearby evidence that platform super_admin access is separated from tenant/application admin access. Endpoint: ANY /tutor/chat/."}, "properties": {"repobilityId": 224961, "scanner": "repobility-access-control", "fingerprint": "4629ac2fe5fe9461fc159de461a7235dd34e5ad4f74379c2534acb754a704a78", "category": "auth", "severity": "medium", "confidence": 0.66, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"path": "/tutor/chat/", "method": "ANY", "scanner": "repobility-access-control", "framework": "Django", "correlation_key": "code|auth|backend/ai_engine/urls.py|67|cwe-285", "identity_targets": ["unknown", "admin"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/urls.py"}, "region": {"startLine": 67}}}]}, {"ruleId": "AUC004", "level": "warning", "message": {"text": "[AUC004] Admin route does not show super_admin separation: An administrative route was detected without nearby evidence that platform super_admin access is separated from tenant/application admin access. Endpoint: ANY /chunks/search/."}, "properties": {"repobilityId": 224960, "scanner": "repobility-access-control", "fingerprint": "b40bb76bcb10022b851e21fe3350f264b149fc7ef673d65cdd31fdd0b78ae0eb", "category": "auth", "severity": "medium", "confidence": 0.66, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"path": "/chunks/search/", "method": "ANY", "scanner": "repobility-access-control", "framework": "Django", "correlation_key": "code|auth|backend/ai_engine/urls.py|61|cwe-285", "identity_targets": ["unknown", "admin"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/urls.py"}, "region": {"startLine": 61}}}]}, {"ruleId": "AUC004", "level": "warning", "message": {"text": "[AUC004] Admin route does not show super_admin separation: An administrative route was detected without nearby evidence that platform super_admin access is separated from tenant/application admin access. Endpoint: ANY /jobs/quizzes/."}, "properties": {"repobilityId": 224959, "scanner": "repobility-access-control", "fingerprint": "e1fd875ade4d96ccde18ff5213ab042b8823848becadf90059514a85515d4d1f", "category": "auth", "severity": "medium", "confidence": 0.66, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"path": "/jobs/quizzes/", "method": "ANY", "scanner": "repobility-access-control", "framework": "Django", "correlation_key": "code|auth|backend/ai_engine/urls.py|60|cwe-285", "identity_targets": ["unknown", "admin"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/urls.py"}, "region": {"startLine": 60}}}]}, {"ruleId": "AUC004", "level": "warning", "message": {"text": "[AUC004] Admin route does not show super_admin separation: An administrative route was detected without nearby evidence that platform super_admin access is separated from tenant/application admin access. Endpoint: ANY /jobs/summaries/."}, "properties": {"repobilityId": 224958, "scanner": "repobility-access-control", "fingerprint": "a0143901c7fdde3f55bd969b258af008b5db93425fec504aeeb1cf049d26ad6c", "category": "auth", "severity": "medium", "confidence": 0.66, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"path": "/jobs/summaries/", "method": "ANY", "scanner": "repobility-access-control", "framework": "Django", "correlation_key": "code|auth|backend/ai_engine/urls.py|59|cwe-285", "identity_targets": ["unknown", "admin"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/urls.py"}, "region": {"startLine": 59}}}]}, {"ruleId": "AUC004", "level": "warning", "message": {"text": "[AUC004] Admin route does not show super_admin separation: An administrative route was detected without nearby evidence that platform super_admin access is separated from tenant/application admin access. Endpoint: ANY /saas-ai-usage/."}, "properties": {"repobilityId": 224957, "scanner": "repobility-access-control", "fingerprint": "c56cbd1c7cdcf6f505318522931b4f76373e47ddc710835c939e9dde88a0528a", "category": "auth", "severity": "medium", "confidence": 0.66, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"path": "/saas-ai-usage/", "method": "ANY", "scanner": "repobility-access-control", "framework": "Django", "correlation_key": "code|auth|backend/core/urls.py|47|cwe-285", "identity_targets": ["unknown", "admin"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/urls.py"}, "region": {"startLine": 47}}}]}, {"ruleId": "AUC004", "level": "warning", "message": {"text": "[AUC004] Admin route does not show super_admin separation: An administrative route was detected without nearby evidence that platform super_admin access is separated from tenant/application admin access. Endpoint: ANY /saas-kpi/."}, "properties": {"repobilityId": 224956, "scanner": "repobility-access-control", "fingerprint": "e6bc4c219883eccc65236cf924a02e214bff8f26c296b666669b9329f6f274b5", "category": "auth", "severity": "medium", "confidence": 0.66, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"path": "/saas-kpi/", "method": "ANY", "scanner": "repobility-access-control", "framework": "Django", "correlation_key": "code|auth|backend/core/urls.py|46|cwe-285", "identity_targets": ["unknown", "admin"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/urls.py"}, "region": {"startLine": 46}}}]}, {"ruleId": "AUC004", "level": "warning", "message": {"text": "[AUC004] Admin route does not show super_admin separation: An administrative route was detected without nearby evidence that platform super_admin access is separated from tenant/application admin access. Endpoint: ANY /school-profile/."}, "properties": {"repobilityId": 224955, "scanner": "repobility-access-control", "fingerprint": "b5db43bb4df02f792131bb99270d7982464d8177fd292b75ffe0bcdcc0b01aad", "category": "auth", "severity": "medium", "confidence": 0.66, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"path": "/school-profile/", "method": "ANY", "scanner": "repobility-access-control", "framework": "Django", "correlation_key": "code|auth|backend/core/urls.py|45|cwe-285", "identity_targets": ["unknown", "admin"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/urls.py"}, "region": {"startLine": 45}}}]}, {"ruleId": "AUC004", "level": "warning", "message": {"text": "[AUC004] Admin route does not show super_admin separation: An administrative route was detected without nearby evidence that platform super_admin access is separated from tenant/application admin access. Endpoint: ANY /capabilities/."}, "properties": {"repobilityId": 224954, "scanner": "repobility-access-control", "fingerprint": "d38760a8914b4bbf329da0d646740a4f65c6ef2ca58f6c1643f2bd3fe5513976", "category": "auth", "severity": "medium", "confidence": 0.66, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"path": "/capabilities/", "method": "ANY", "scanner": "repobility-access-control", "framework": "Django", "correlation_key": "code|auth|backend/core/urls.py|44|cwe-285", "identity_targets": ["unknown", "admin"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/urls.py"}, "region": {"startLine": 44}}}]}, {"ruleId": "AUC004", "level": "warning", "message": {"text": "[AUC004] Admin route does not show super_admin separation: An administrative route was detected without nearby evidence that platform super_admin access is separated from tenant/application admin access. Endpoint: ANY /tenant-check/."}, "properties": {"repobilityId": 224953, "scanner": "repobility-access-control", "fingerprint": "16240b0c54772ccb05c7d48fbd776cf54054e76f0d6ec91b27d36441784409bf", "category": "auth", "severity": "medium", "confidence": 0.66, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"path": "/tenant-check/", "method": "ANY", "scanner": "repobility-access-control", "framework": "Django", "correlation_key": "code|auth|backend/core/urls.py|43|cwe-285", "identity_targets": ["unknown", "admin"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/urls.py"}, "region": {"startLine": 43}}}]}, {"ruleId": "AUC002", "level": "warning", "message": {"text": "[AUC002] Low visible authorization coverage in route inventory: Only 32.9% of discovered routes show nearby authentication, authorization, middleware, or public-route evidence."}, "properties": {"repobilityId": 224951, "scanner": "repobility-access-control", "fingerprint": "0b3f7700489cbf584567585aac7c4e9a7ab7acbc82541105ff37e2e514e87ae2", "category": "auth", "severity": "medium", "confidence": 0.74, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"scanner": "repobility-access-control", "endpoint_count": 85, "correlation_key": "fp|0b3f7700489cbf584567585aac7c4e9a7ab7acbc82541105ff37e2e514e87ae2", "auth_visible_percent": 32.9}}}, {"ruleId": "AUC001", "level": "warning", "message": {"text": "[AUC001] No Repobility access matrix policy found: The repository uses web/API frameworks but does not define .repobility/access.yml or equivalent authorization documentation."}, "properties": {"repobilityId": 224950, "scanner": "repobility-access-control", "fingerprint": "f1305052c3ba1e6c1cdb5dccc19e58a8168cf78b176658f32b1fc823df3e9d10", "category": "auth", "severity": "medium", "confidence": 0.92, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"scanner": "repobility-access-control", "frameworks": ["Django", "Next.js"], "expected_files": [".repobility/access.yml", ".repobility/access.yaml", ".repobility/access.json", ".repobility/authorization.yml"], "correlation_key": "fp|f1305052c3ba1e6c1cdb5dccc19e58a8168cf78b176658f32b1fc823df3e9d10"}}}, {"ruleId": "GHSA-gc5v-m9x4-r6x2", "level": "warning", "message": {"text": "requests: GHSA-gc5v-m9x4-r6x2"}, "properties": {"repobilityId": 224947, "scanner": "osv-scanner", "fingerprint": "df69fc105f839b8858988bd945af94347c2e8a5ab6be2c5dec785fcd4d2fc827", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-25645"], "package": "requests", "rule_id": "GHSA-gc5v-m9x4-r6x2", "scanner": "osv-scanner", "correlation_key": "vuln|requests|CVE-2026-25645|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-mf9w-mj56-hr94", "level": "warning", "message": {"text": "python-dotenv: GHSA-mf9w-mj56-hr94"}, "properties": {"repobilityId": 224946, "scanner": "osv-scanner", "fingerprint": "030c6ea3936499659ed910925462b9058f7115cecd98afed139ec104f4c2978a", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-28684"], "package": "python-dotenv", "rule_id": "GHSA-mf9w-mj56-hr94", "scanner": "osv-scanner", "correlation_key": "vuln|python-dotenv|CVE-2026-28684|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-x284-j5p8-9c5p", "level": "warning", "message": {"text": "pypdf: GHSA-x284-j5p8-9c5p"}, "properties": {"repobilityId": 224945, "scanner": "osv-scanner", "fingerprint": "27f78c7cb1b5a129889159ad7e243bc9324d941cbf9554ca48242cfb746355b3", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-41314"], "package": "pypdf", "rule_id": "GHSA-x284-j5p8-9c5p", "scanner": "osv-scanner", "correlation_key": "vuln|pypdf|CVE-2026-41314|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-qpxp-75px-xjcp", "level": "warning", "message": {"text": "pypdf: GHSA-qpxp-75px-xjcp"}, "properties": {"repobilityId": 224944, "scanner": "osv-scanner", "fingerprint": "4361a882bdaa0797e8cd79f8b8ec3250bdae13c82e58c037a49fa5795aa8efbe", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-33123"], "package": "pypdf", "rule_id": "GHSA-qpxp-75px-xjcp", "scanner": "osv-scanner", "correlation_key": "vuln|pypdf|CVE-2026-33123|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-jj6c-8h6c-hppx", "level": "warning", "message": {"text": "pypdf: GHSA-jj6c-8h6c-hppx"}, "properties": {"repobilityId": 224943, "scanner": "osv-scanner", "fingerprint": "1a2326ec87f340ea022c95b81e52212fc747cf2ce1f48d7523de02641eac77f3", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-41168"], "package": "pypdf", "rule_id": "GHSA-jj6c-8h6c-hppx", "scanner": "osv-scanner", "correlation_key": "vuln|pypdf|CVE-2026-41168|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-hqmh-ppp3-xvm7", "level": "warning", "message": {"text": "pypdf: GHSA-hqmh-ppp3-xvm7"}, "properties": {"repobilityId": 224942, "scanner": "osv-scanner", "fingerprint": "65a3fa3edb23f2ad383dcea4f22c17c18691df51f25f0ee173c3369579e75da4", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-31826"], "package": "pypdf", "rule_id": "GHSA-hqmh-ppp3-xvm7", "scanner": "osv-scanner", "correlation_key": "vuln|pypdf|CVE-2026-31826|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-cj93-chg6-vgv8", "level": "warning", "message": {"text": "pypdf: GHSA-cj93-chg6-vgv8"}, "properties": {"repobilityId": 224941, "scanner": "osv-scanner", "fingerprint": "5d62d0f453598430fd5de07dd4ff4cf9cbe78d82a4eaed48110affbd3b7c2668", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-48155"], "package": "pypdf", "rule_id": "GHSA-cj93-chg6-vgv8", "scanner": "osv-scanner", "correlation_key": "vuln|pypdf|CVE-2026-48155|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-9m86-7pmv-2852", "level": "warning", "message": {"text": "pypdf: GHSA-9m86-7pmv-2852"}, "properties": {"repobilityId": 224940, "scanner": "osv-scanner", "fingerprint": "5abf93e2969f3cb4ac55582490108b184ad97c24386ac0e30ea80c0f1cbeb125", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-28804"], "package": "pypdf", "rule_id": "GHSA-9m86-7pmv-2852", "scanner": "osv-scanner", "correlation_key": "vuln|pypdf|CVE-2026-28804|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-87mj-5ggw-8qc3", "level": "warning", "message": {"text": "pypdf: GHSA-87mj-5ggw-8qc3"}, "properties": {"repobilityId": 224939, "scanner": "osv-scanner", "fingerprint": "45e346804fea232f33b5dae6ef01011969c0e83e8525b88a63c807609e94e83b", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-33699"], "package": "pypdf", "rule_id": "GHSA-87mj-5ggw-8qc3", "scanner": "osv-scanner", "correlation_key": "vuln|pypdf|CVE-2026-33699|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-7gw9-cf7v-778f", "level": "warning", "message": {"text": "pypdf: GHSA-7gw9-cf7v-778f"}, "properties": {"repobilityId": 224938, "scanner": "osv-scanner", "fingerprint": "802ddd9febb34aeb0b5d135164438e62a3fb285ca6b538d6961e9e7f48199c05", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-41312"], "package": "pypdf", "rule_id": "GHSA-7gw9-cf7v-778f", "scanner": "osv-scanner", "correlation_key": "vuln|pypdf|CVE-2026-41312|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-4pxv-j86v-mhcw", "level": "warning", "message": {"text": "pypdf: GHSA-4pxv-j86v-mhcw"}, "properties": {"repobilityId": 224937, "scanner": "osv-scanner", "fingerprint": "0dccccdc7963b2c14a912e714f1d2b5ec263b9cee1771ba6a02e72282845004e", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-41313"], "package": "pypdf", "rule_id": "GHSA-4pxv-j86v-mhcw", "scanner": "osv-scanner", "correlation_key": "vuln|pypdf|CVE-2026-41313|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-3crg-w4f6-42mx", "level": "warning", "message": {"text": "pypdf: GHSA-3crg-w4f6-42mx"}, "properties": {"repobilityId": 224936, "scanner": "osv-scanner", "fingerprint": "0df5c20b6d74147ff3cdc10428823deb0743af452751b2b5fe79d338058def92", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-40260"], "package": "pypdf", "rule_id": "GHSA-3crg-w4f6-42mx", "scanner": "osv-scanner", "correlation_key": "vuln|pypdf|CVE-2026-40260|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-248m-82v9-q6g6", "level": "warning", "message": {"text": "pypdf: GHSA-248m-82v9-q6g6"}, "properties": {"repobilityId": 224935, "scanner": "osv-scanner", "fingerprint": "664f0a10302c36ade0d3f0aa40cfb960c63690c2a93ff2869777fe5fcc78e5a7", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-48156"], "package": "pypdf", "rule_id": "GHSA-248m-82v9-q6g6", "scanner": "osv-scanner", "correlation_key": "vuln|pypdf|CVE-2026-48156|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-r73j-pqj5-w3x7", "level": "warning", "message": {"text": "pillow: GHSA-r73j-pqj5-w3x7"}, "properties": {"repobilityId": 224933, "scanner": "osv-scanner", "fingerprint": "2d968015b9f586005b40b03e00f6a5450f00049b67bb47791a9e397bd9744553", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pillow-2026-42310", "CVE-2026-42310"], "package": "pillow", "rule_id": "GHSA-r73j-pqj5-w3x7", "scanner": "osv-scanner", "correlation_key": "vuln|pillow|CVE-2026-42310|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-5xmw-vc9v-4wf2", "level": "warning", "message": {"text": "pillow: GHSA-5xmw-vc9v-4wf2"}, "properties": {"repobilityId": 224931, "scanner": "osv-scanner", "fingerprint": "4bdb08c4c88a89067d5be233bc7f2f295179211bf5d74731d4faf7e38a58b919", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pillow-2026-42309", "CVE-2026-42309"], "package": "pillow", "rule_id": "GHSA-5xmw-vc9v-4wf2", "scanner": "osv-scanner", "correlation_key": "vuln|pillow|CVE-2026-42309|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-65pc-fj4g-8rjx", "level": "warning", "message": {"text": "idna: GHSA-65pc-fj4g-8rjx"}, "properties": {"repobilityId": 224928, "scanner": "osv-scanner", "fingerprint": "096ad1adcda9b23f165f1175fd8691f1cfd4f580557aea52903b73ec76fbc472", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-45409"], "package": "idna", "rule_id": "GHSA-65pc-fj4g-8rjx", "scanner": "osv-scanner", "correlation_key": "vuln|idna|CVE-2024-3651|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-993g-76c3-p5m4", "level": "warning", "message": {"text": "pyjwt: GHSA-993g-76c3-p5m4"}, "properties": {"repobilityId": 224923, "scanner": "osv-scanner", "fingerprint": "009fa03f4ed4451646ab605ac65fbaa6dee1de77779e75d549bbc928fca842c9", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-48522", "PYSEC-2026-175"], "package": "pyjwt", "rule_id": "GHSA-993g-76c3-p5m4", "scanner": "osv-scanner", "correlation_key": "vuln|pyjwt|CVE-2024-21643|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-48c2-rrv3-qjmp", "level": "warning", "message": {"text": "yaml: GHSA-48c2-rrv3-qjmp"}, "properties": {"repobilityId": 224894, "scanner": "osv-scanner", "fingerprint": "64dbe2d8eb72f03d9a8b16cc0ae9f34fb69cbf57b9567f83100ec029d586e457", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-33532"], "package": "yaml", "rule_id": "GHSA-48c2-rrv3-qjmp", "scanner": "osv-scanner", "correlation_key": "vuln|yaml|CVE-2026-33532|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-58qx-3vcg-4xpx", "level": "warning", "message": {"text": "ws: GHSA-58qx-3vcg-4xpx"}, "properties": {"repobilityId": 224893, "scanner": "osv-scanner", "fingerprint": "f773be4039d12c7210316374548128559d643a610ba61acddf0e96c49442c69f", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-45736"], "package": "ws", "rule_id": "GHSA-58qx-3vcg-4xpx", "scanner": "osv-scanner", "correlation_key": "vuln|ws|CVE-2026-45736|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-w5hq-g745-h8pq", "level": "warning", "message": {"text": "uuid: GHSA-w5hq-g745-h8pq"}, "properties": {"repobilityId": 224891, "scanner": "osv-scanner", "fingerprint": "8fe5988086014b3024e965f4a205cc8c04a1eff5bf0547b83d253216f9f36fb6", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-41907"], "package": "uuid", "rule_id": "GHSA-w5hq-g745-h8pq", "scanner": "osv-scanner", "correlation_key": "vuln|uuid|CVE-2026-41907|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-qx2v-qp2m-jg93", "level": "warning", "message": {"text": "postcss: GHSA-qx2v-qp2m-jg93"}, "properties": {"repobilityId": 224889, "scanner": "osv-scanner", "fingerprint": "a643c86045c810eb7bf79a6cc7bf7cfcdaec3f4e6a26b1b15f8d47676588d581", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-41305"], "package": "postcss", "rule_id": "GHSA-qx2v-qp2m-jg93", "scanner": "osv-scanner", "correlation_key": "vuln|postcss|CVE-2026-41305|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-3v7f-55p6-f55p", "level": "warning", "message": {"text": "picomatch: GHSA-3v7f-55p6-f55p"}, "properties": {"repobilityId": 224887, "scanner": "osv-scanner", "fingerprint": "9bd0d34a2eee7e8c9b9c7e423df9af29442539e02cfb5e9d51fd6cb49add9e01", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-33672"], "package": "picomatch", "rule_id": "GHSA-3v7f-55p6-f55p", "scanner": "osv-scanner", "correlation_key": "vuln|picomatch|CVE-2026-33672|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-h67p-54hq-rp68", "level": "warning", "message": {"text": "js-yaml: GHSA-h67p-54hq-rp68"}, "properties": {"repobilityId": 224882, "scanner": "osv-scanner", "fingerprint": "71a3d03890e05559f8dcf7e3efd3aa255287ab688f8412ab1906bf94a48fc4c1", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-53550"], "package": "js-yaml", "rule_id": "GHSA-h67p-54hq-rp68", "scanner": "osv-scanner", "correlation_key": "vuln|js-yaml|CVE-2026-53550|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-r4q5-vmmm-2653", "level": "warning", "message": {"text": "follow-redirects: GHSA-r4q5-vmmm-2653"}, "properties": {"repobilityId": 224880, "scanner": "osv-scanner", "fingerprint": "aa4290bdacf7105ca1ca2299f4f73f116f3d4e4d893465616a91b4f4e7687860", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "package": "follow-redirects", "rule_id": "GHSA-r4q5-vmmm-2653", "scanner": "osv-scanner", "correlation_key": "vuln|follow-redirects|GHSA-R4Q5-VMMM-2653|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-jxxr-4gwj-5jf2", "level": "warning", "message": {"text": "brace-expansion: GHSA-jxxr-4gwj-5jf2"}, "properties": {"repobilityId": 224879, "scanner": "osv-scanner", "fingerprint": "4dc7c53ba63841bf4a9f0efa3953d48fa63972c4a1ec7b0554ccc34f0338cdc0", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-45149"], "package": "brace-expansion", "rule_id": "GHSA-jxxr-4gwj-5jf2", "scanner": "osv-scanner", "correlation_key": "vuln|brace-expansion|CVE-2026-45149|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-f886-m6hf-6m8v", "level": "warning", "message": {"text": "brace-expansion: GHSA-f886-m6hf-6m8v"}, "properties": {"repobilityId": 224878, "scanner": "osv-scanner", "fingerprint": "ac52666a5bb776a742f4669ff19fea5245f23dfe9e62630a2aa590673dc4d5e2", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-33750"], "package": "brace-expansion", "rule_id": "GHSA-f886-m6hf-6m8v", "scanner": "osv-scanner", "correlation_key": "vuln|brace-expansion|CVE-2026-33750|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-xx6v-rp6x-q39c", "level": "warning", "message": {"text": "axios: GHSA-xx6v-rp6x-q39c"}, "properties": {"repobilityId": 224877, "scanner": "osv-scanner", "fingerprint": "7eddddf7cfd97779453024949f06edce789b7f330470f0ae3a9663ce20f12223", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-42042"], "package": "axios", "rule_id": "GHSA-xx6v-rp6x-q39c", "scanner": "osv-scanner", "correlation_key": "vuln|axios|CVE-2026-42042|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-w9j2-pvgh-6h63", "level": "warning", "message": {"text": "axios: GHSA-w9j2-pvgh-6h63"}, "properties": {"repobilityId": 224875, "scanner": "osv-scanner", "fingerprint": "10ad2f0f1ff2300aa8a9ab768e41346140583e2708b536315a938fa6c9eee731", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-42041"], "package": "axios", "rule_id": "GHSA-w9j2-pvgh-6h63", "scanner": "osv-scanner", "correlation_key": "vuln|axios|CVE-2026-42041|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-vf2m-468p-8v99", "level": "warning", "message": {"text": "axios: GHSA-vf2m-468p-8v99"}, "properties": {"repobilityId": 224874, "scanner": "osv-scanner", "fingerprint": "f27c5141b4e066827537aabdd9c0c6cebd8d4f39f2f1626006c60f7376ed67ab", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-42036"], "package": "axios", "rule_id": "GHSA-vf2m-468p-8v99", "scanner": "osv-scanner", "correlation_key": "vuln|axios|CVE-2026-42036|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-m7pr-hjqh-92cm", "level": "warning", "message": {"text": "axios: GHSA-m7pr-hjqh-92cm"}, "properties": {"repobilityId": 224870, "scanner": "osv-scanner", "fingerprint": "faf9d0997cee0d1af8f6427ff3368786af5b5884baea9703451ff2d242aa99eb", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-42038"], "package": "axios", "rule_id": "GHSA-m7pr-hjqh-92cm", "scanner": "osv-scanner", "correlation_key": "vuln|axios|CVE-2026-42038|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-fvcv-3m26-pcqx", "level": "warning", "message": {"text": "axios: GHSA-fvcv-3m26-pcqx"}, "properties": {"repobilityId": 224867, "scanner": "osv-scanner", "fingerprint": "4819466408688740888eaeed083978fc09da7d7a50bcca15602a428dc95081e5", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-40175"], "package": "axios", "rule_id": "GHSA-fvcv-3m26-pcqx", "scanner": "osv-scanner", "correlation_key": "vuln|axios|CVE-2026-40175|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-898c-q2cr-xwhg", "level": "warning", "message": {"text": "axios: GHSA-898c-q2cr-xwhg"}, "properties": {"repobilityId": 224866, "scanner": "osv-scanner", "fingerprint": "e0c5b1e28ba6e289ae9687c1273cc6fab6f4ca43fbba94aaf0ff52f65bf970d1", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44490"], "package": "axios", "rule_id": "GHSA-898c-q2cr-xwhg", "scanner": "osv-scanner", "correlation_key": "vuln|axios|CVE-2026-44490|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-62hf-57xw-28j9", "level": "warning", "message": {"text": "axios: GHSA-62hf-57xw-28j9"}, "properties": {"repobilityId": 224863, "scanner": "osv-scanner", "fingerprint": "9bcb4bfd916c493b593f3f6f3a363667b42aa0210d7c8e86d8691a4bb88722b6", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-42039"], "package": "axios", "rule_id": "GHSA-62hf-57xw-28j9", "scanner": "osv-scanner", "correlation_key": "vuln|axios|CVE-2026-42039|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-5c9x-8gcm-mpgx", "level": "warning", "message": {"text": "axios: GHSA-5c9x-8gcm-mpgx"}, "properties": {"repobilityId": 224862, "scanner": "osv-scanner", "fingerprint": "e7a507d6bac12bfb88bb629ed28159c476ce75df7b5e9a0b37469f12987a0e09", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-42034"], "package": "axios", "rule_id": "GHSA-5c9x-8gcm-mpgx", "scanner": "osv-scanner", "correlation_key": "vuln|axios|CVE-2026-42034|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-445q-vr5w-6q77", "level": "warning", "message": {"text": "axios: GHSA-445q-vr5w-6q77"}, "properties": {"repobilityId": 224861, "scanner": "osv-scanner", "fingerprint": "70778e1b63e059e4145be6220f5acc39a03d2c2e4c185649c9283618245e9cf6", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-42037"], "package": "axios", "rule_id": "GHSA-445q-vr5w-6q77", "scanner": "osv-scanner", "correlation_key": "vuln|axios|CVE-2026-42037|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-3w6x-2g7m-8v23", "level": "warning", "message": {"text": "axios: GHSA-3w6x-2g7m-8v23"}, "properties": {"repobilityId": 224860, "scanner": "osv-scanner", "fingerprint": "fdfa55a418f430b4b35ec4013928bbe5e70c102a4b623a782a1363a278488e6f", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-42044"], "package": "axios", "rule_id": "GHSA-3w6x-2g7m-8v23", "scanner": "osv-scanner", "correlation_key": "vuln|axios|CVE-2026-42044|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-4943-9vgg-gr5r", "level": "warning", "message": {"text": "quill: GHSA-4943-9vgg-gr5r"}, "properties": {"repobilityId": 224850, "scanner": "osv-scanner", "fingerprint": "c9146f3a40b933d42ddad8a0bbb28ee76e1d31e1ebf879cacc4f76876d12b9cb", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2021-3163"], "package": "quill", "rule_id": "GHSA-4943-9vgg-gr5r", "scanner": "osv-scanner", "correlation_key": "vuln|quill|CVE-2021-3163|frontend/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-qx2v-qp2m-jg93", "level": "warning", "message": {"text": "postcss: GHSA-qx2v-qp2m-jg93"}, "properties": {"repobilityId": 224849, "scanner": "osv-scanner", "fingerprint": "2510b8057924327e9299fe8e0754f99daed52ce3ac1ece31b2a82e243beabb2e", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-41305"], "package": "postcss", "rule_id": "GHSA-qx2v-qp2m-jg93", "scanner": "osv-scanner", "correlation_key": "vuln|postcss|CVE-2026-41305|frontend/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-h67p-54hq-rp68", "level": "warning", "message": {"text": "js-yaml: GHSA-h67p-54hq-rp68"}, "properties": {"repobilityId": 224848, "scanner": "osv-scanner", "fingerprint": "e4942792376ace9e7f8eabc8d635ac8c4e6cfe52fc3a6b9290c21f7ed1d98fbf", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-53550"], "package": "js-yaml", "rule_id": "GHSA-h67p-54hq-rp68", "scanner": "osv-scanner", "correlation_key": "vuln|js-yaml|CVE-2026-53550|frontend/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-8988-4f7v-96qf", "level": "warning", "message": {"text": "@opentelemetry/core: GHSA-8988-4f7v-96qf"}, "properties": {"repobilityId": 224846, "scanner": "osv-scanner", "fingerprint": "4e3b08cd73cc9a4b9b4f4e52c47995d35160eb7c6ca46ae40d2ddfc4f6ed2893", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-54285"], "package": "@opentelemetry/core", "rule_id": "GHSA-8988-4f7v-96qf", "scanner": "osv-scanner", "correlation_key": "vuln|opentelemetry/core|CVE-2026-54285|frontend/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-cj93-chg6-vgv8", "level": "warning", "message": {"text": "pypdf: GHSA-cj93-chg6-vgv8"}, "properties": {"repobilityId": 224844, "scanner": "osv-scanner", "fingerprint": "5b12a07bfac5152d981fa286feaf454eeb8f349d43e722a99aff1062f268d47e", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-48155"], "package": "pypdf", "rule_id": "GHSA-cj93-chg6-vgv8", "scanner": "osv-scanner", "correlation_key": "vuln|pypdf|CVE-2026-48155|backend/requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-248m-82v9-q6g6", "level": "warning", "message": {"text": "pypdf: GHSA-248m-82v9-q6g6"}, "properties": {"repobilityId": 224843, "scanner": "osv-scanner", "fingerprint": "82b963095b9c9d76d4541489b0755393abf3aa7c69d374b9a05b54ca8c6882d5", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-48156"], "package": "pypdf", "rule_id": "GHSA-248m-82v9-q6g6", "scanner": "osv-scanner", "correlation_key": "vuln|pypdf|CVE-2026-48156|backend/requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "DKR007", "level": "warning", "message": {"text": "Docker build context has no .dockerignore"}, "properties": {"repobilityId": 224827, "scanner": "repobility-docker", "fingerprint": "c98378cf8c37e4866e89d6ca06a24b7e8c44654aa34e6e4bf1367c4a4c0c5b44", "category": "docker", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Dockerfile exists but repository root has no .dockerignore.", "evidence": {"rule_id": "DKR007", "scanner": "repobility-docker", "references": ["https://docs.docker.com/develop/develop-images/dockerfile_best-practices/"], "correlation_key": "fp|c98378cf8c37e4866e89d6ca06a24b7e8c44654aa34e6e4bf1367c4a4c0c5b44"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".dockerignore"}, "region": {"startLine": 1}}}]}, {"ruleId": "DKR018", "level": "warning", "message": {"text": "Database dump or local database file is included in Docker build context"}, "properties": {"repobilityId": 224823, "scanner": "repobility-docker", "fingerprint": "655485f8d8d660f19955b099504360fbf5ff0f88b2be2fc7d9501b5ab7e7369f", "category": "docker", "severity": "medium", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Database-like artifacts are reachable from the Docker build context and are not ignored.", "evidence": {"rule_id": "DKR018", "scanner": "repobility-docker", "references": ["https://docs.docker.com/develop/develop-images/dockerfile_best-practices/", "https://docs.docker.com/engine/storage/volumes/"], "correlation_key": "fp|655485f8d8d660f19955b099504360fbf5ff0f88b2be2fc7d9501b5ab7e7369f", "database_artifacts": [{"path": "backend/config/db.sqlite3.backup", "size_mb": 0.3}]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".dockerignore"}, "region": {"startLine": 1}}}]}, {"ruleId": "SEC046", "level": "warning", "message": {"text": "[SEC046] Client-side open redirect \u2014 window.location = server-supplied URL: Assigning window.location from a server-supplied URL trusts the server endpoint to never return a hostile destination. If that endpoint is ever subverted (compromised admin, JSON injection, MITM on a webhook), users get redirected to a phishing site they trust because the original page is yours. CWE-601 (server-side OR client-side). Complement to server-side SEC030."}, "properties": {"repobilityId": 224820, "scanner": "repobility-threat-engine", "fingerprint": "89d023a3af35aa5f96173b3bb6c081b0513add4ed3bc2e7a299939584a17be56", "category": "open_redirect", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "location.href = loginPath", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC046", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|89d023a3af35aa5f96173b3bb6c081b0513add4ed3bc2e7a299939584a17be56"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/components/command-palette.tsx"}, "region": {"startLine": 164}}}]}, {"ruleId": "SEC041", "level": "warning", "message": {"text": "[SEC041] Tabnabbing \u2014 target=\"_blank\" without rel=\"noopener noreferrer\": <a target=\"_blank\"> without rel=\"noopener noreferrer\" leaks window.opener to the opened page. The opened page can then run window.opener.location = 'phishing-site' and the parent tab quietly navigates to attacker-controlled content (reverse tabnabbing). OWASP-classic; modern browsers default rel='noopener' for new windows but explicit attribute is still required for compatibility."}, "properties": {"repobilityId": 224815, "scanner": "repobility-threat-engine", "fingerprint": "73777b5ac4f7555d3fafe60cc1e19cea26ad608e5243b19583ce7bdf8f1693d1", "category": "security", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "window.open('', '_blank', 'width=900,height=900')", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC041", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "code|security|token|68|sec041"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/admin/finance/reports/cash-book/page.tsx"}, "region": {"startLine": 68}}}]}, {"ruleId": "SEC041", "level": "warning", "message": {"text": "[SEC041] Tabnabbing \u2014 target=\"_blank\" without rel=\"noopener noreferrer\": <a target=\"_blank\"> without rel=\"noopener noreferrer\" leaks window.opener to the opened page. The opened page can then run window.opener.location = 'phishing-site' and the parent tab quietly navigates to attacker-controlled content (reverse tabnabbing). OWASP-classic; modern browsers default rel='noopener' for new windows but explicit attribute is still required for compatibility."}, "properties": {"repobilityId": 224814, "scanner": "repobility-threat-engine", "fingerprint": "2a04802c669d4a54ca5e0ded7d1511207f81e50c9ead7c280f330fb3342db3e3", "category": "security", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "window.open('', '_blank', 'width=900,height=900')", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC041", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "code|security|token|70|sec041"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/admin/finance/reports/bank-book/page.tsx"}, "region": {"startLine": 70}}}]}, {"ruleId": "SEC041", "level": "warning", "message": {"text": "[SEC041] Tabnabbing \u2014 target=\"_blank\" without rel=\"noopener noreferrer\": <a target=\"_blank\"> without rel=\"noopener noreferrer\" leaks window.opener to the opened page. The opened page can then run window.opener.location = 'phishing-site' and the parent tab quietly navigates to attacker-controlled content (reverse tabnabbing). OWASP-classic; modern browsers default rel='noopener' for new windows but explicit attribute is still required for compatibility."}, "properties": {"repobilityId": 224813, "scanner": "repobility-threat-engine", "fingerprint": "398de18317f7e594b5feb8aae14e131603b9aff7fbb61ccaca128d9b5585ef3e", "category": "security", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "window.open('', '_blank', 'width=1000,height=900')", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC041", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "code|security|token|84|sec041"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/admin/finance/reports/aging/page.tsx"}, "region": {"startLine": 84}}}]}, {"ruleId": "SEC134", "level": "warning", "message": {"text": "[SEC134] AI scaffold leftover \u2014 Lorem ipsum / example.com / John Doe in code: Lorem ipsum / John Doe / example.com left in non-test code. AI agents emit these as 'reasonable defaults' when they don't know real values; the human then forgets to swap them. In production, these break demo flows, send mail to a real example.com host (it's owned by IANA), and leak that the codebase had an AI scaffolding pass."}, "properties": {"repobilityId": 224784, "scanner": "repobility-threat-engine", "fingerprint": "d1e973e5e06738ae916d63d9a47ceaac4b41dfbc7a3b62932754715c75bbc53f", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "\"John Doe\"", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC134", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|d1e973e5e06738ae916d63d9a47ceaac4b41dfbc7a3b62932754715c75bbc53f"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/verify_models.py"}, "region": {"startLine": 67}}}]}, {"ruleId": "SEC015", "level": "warning", "message": {"text": "[SEC015] Insecure Randomness for Security: Weak PRNG used in security-sensitive context. Output is predictable."}, "properties": {"repobilityId": 224783, "scanner": "repobility-threat-engine", "fingerprint": "e151a3d4ad00cae441dfdcf99746eb9113c7a7e97f5f173c512728b181d64320", "category": "crypto", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Security-sensitive keyword found nearby \u2014 weak PRNG is risky here", "evidence": {"match": "tokens = random.randint", "reason": "Security-sensitive keyword found nearby \u2014 weak PRNG is risky here", "rule_id": "SEC015", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "code|crypto|token|87|sec015"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/seed_saas_data.py"}, "region": {"startLine": 87}}}]}, {"ruleId": "SEC042", "level": "warning", "message": {"text": "[SEC042] SQL identifier injection via f-string in cursor execute: f-string SQL normalizes an unsafe pattern. Currently safe when only trusted internal values are interpolated (e.g. self._table in Odoo), but a future contributor can extend the f-string to user input without noticing. CWE-89. Identifiers (table/column names) need a separate escaping path from values."}, "properties": {"repobilityId": 224777, "scanner": "repobility-threat-engine", "fingerprint": "9af731edb37cc7f05924a6f07be6e094fd644ef0308221c45508955666dcd29b", "category": "injection", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "cursor.execute(f\"", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC042", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "code|injection|token|80|sec042"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/create_library_tables_simple.py"}, "region": {"startLine": 80}}}]}, {"ruleId": "SEC042", "level": "warning", "message": {"text": "[SEC042] SQL identifier injection via f-string in cursor execute: f-string SQL normalizes an unsafe pattern. Currently safe when only trusted internal values are interpolated (e.g. self._table in Odoo), but a future contributor can extend the f-string to user input without noticing. CWE-89. Identifiers (table/column names) need a separate escaping path from values."}, "properties": {"repobilityId": 224776, "scanner": "repobility-threat-engine", "fingerprint": "954f9b88863f01e0519395e7410eaa79a6d626827eea466a2a95bbdb46769526", "category": "injection", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "cursor.execute(f\"", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC042", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "code|injection|token|121|sec042"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/create_library_tables_final.py"}, "region": {"startLine": 121}}}]}, {"ruleId": "SEC042", "level": "warning", "message": {"text": "[SEC042] SQL identifier injection via f-string in cursor execute: f-string SQL normalizes an unsafe pattern. Currently safe when only trusted internal values are interpolated (e.g. self._table in Odoo), but a future contributor can extend the f-string to user input without noticing. CWE-89. Identifiers (table/column names) need a separate escaping path from values."}, "properties": {"repobilityId": 224775, "scanner": "repobility-threat-engine", "fingerprint": "b7af1d1d553b916aa5ff50848abba7732d54a988cdd59de6c7af72e048d2ad58", "category": "injection", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "cursor.execute(f\"", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC042", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "code|injection|token|77|sec042"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/create_library_tables.py"}, "region": {"startLine": 77}}}]}, {"ruleId": "SEC003", "level": "warning", "message": {"text": "[SEC003] Hardcoded Secret: Hardcoded secret key found in source code."}, "properties": {"repobilityId": 224757, "scanner": "repobility-threat-engine", "fingerprint": "41aebb3d80d89732e1bee2c25de86ced229c0186f5635d255008549a9e69e856", "category": "credential_exposure", "severity": "medium", "confidence": 0.3, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Low entropy value (3.2 bits) \u2014 may be placeholder or common string", "evidence": {"match": "SECRET_KEY = \"test-secret-key-for-ci-\"", "reason": "Low entropy value (3.2 bits) \u2014 may be placeholder or common string", "rule_id": "SEC003", "scanner": "repobility-threat-engine", "confidence": 0.3, "correlation_key": "secret|token|1|secret_key test-secret-key-for-ci-"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/config/settings/test.py"}, "region": {"startLine": 16}}}]}, {"ruleId": "SEC123", "level": "warning", "message": {"text": "[SEC123] Production stack trace / debug output exposed: Debug mode left on in production exposes stack traces, environment variables, framework internals \u2014 sometimes triggers RCE (Django debug page with arbitrary template eval)."}, "properties": {"repobilityId": 224754, "scanner": "repobility-threat-engine", "fingerprint": "db0f6423a0cf5160d91045f6d978593a076e070a79a45c2228d981f5479dbd2d", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "DEBUG=True", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC123", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|db0f6423a0cf5160d91045f6d978593a076e070a79a45c2228d981f5479dbd2d"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/tests_tenant_security.py"}, "region": {"startLine": 33}}}]}, {"ruleId": "SEC123", "level": "warning", "message": {"text": "[SEC123] Production stack trace / debug output exposed: Debug mode left on in production exposes stack traces, environment variables, framework internals \u2014 sometimes triggers RCE (Django debug page with arbitrary template eval)."}, "properties": {"repobilityId": 224753, "scanner": "repobility-threat-engine", "fingerprint": "10f77c4ffda25afd1852a068af8ab0c0ca564a784b1628824b480fd3137f7394", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "DEBUG = True", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC123", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|10f77c4ffda25afd1852a068af8ab0c0ca564a784b1628824b480fd3137f7394"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/config/settings/local.py"}, "region": {"startLine": 6}}}]}, {"ruleId": "SEC136", "level": "warning", "message": {"text": "[SEC136] AI-typical over-broad exception handler swallowing all errors: Catch-all exception block that silently returns success or no-ops. AI agents reach for this pattern when a flaky test or an unfamiliar API throws \u2014 wrap, swallow, return success. Real bugs are masked, observability is destroyed, and callers think the operation worked. CWE-396 (improperly-generalized exception). Distinct from intentional fallback because there's no log line and the success value is fabricated."}, "properties": {"repobilityId": 224727, "scanner": "repobility-threat-engine", "fingerprint": "efa75007ccf8509f1be382b8fe687da3e5beb2596e3e7a1cbb94f2f4a1bf6777", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "try:\n        from weasyprint import HTML  # type: ignore\n    except Exception:\n        return None", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC136", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|efa75007ccf8509f1be382b8fe687da3e5beb2596e3e7a1cbb94f2f4a1bf6777"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/reports.py"}, "region": {"startLine": 14}}}]}, {"ruleId": "SEC136", "level": "warning", "message": {"text": "[SEC136] AI-typical over-broad exception handler swallowing all errors: Catch-all exception block that silently returns success or no-ops. AI agents reach for this pattern when a flaky test or an unfamiliar API throws \u2014 wrap, swallow, return success. Real bugs are masked, observability is destroyed, and callers think the operation worked. CWE-396 (improperly-generalized exception). Distinct from intentional fallback because there's no log line and the success value is fabricated."}, "properties": {"repobilityId": 224726, "scanner": "repobility-threat-engine", "fingerprint": "435577320fe3a0e529ac8fc72a25b95847ab32d6994ab54c2684177a20948d82", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "try:\n            payload = json.loads(candidate)\n            return payload if isinstance(payload, d", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC136", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|435577320fe3a0e529ac8fc72a25b95847ab32d6994ab54c2684177a20948d82"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/services/lesson_summary_service.py"}, "region": {"startLine": 93}}}]}, {"ruleId": "ERR001", "level": "warning", "message": {"text": "[ERR001] Silent Exception Swallowing: Silently swallowing all exceptions hides bugs. Even in cleanup code, log at DEBUG level."}, "properties": {"repobilityId": 224723, "scanner": "repobility-threat-engine", "fingerprint": "cf4461980ed59a3b604b181e63aa4859d98be27f9f3a05172c738d8230f39949", "category": "error_handling", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "except Exception:\n    pass", "reason": "Pattern matched with no mitigating context found", "rule_id": "ERR001", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|cf4461980ed59a3b604b181e63aa4859d98be27f9f3a05172c738d8230f39949"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/config/celery.py"}, "region": {"startLine": 81}}}]}, {"ruleId": "ERR001", "level": "warning", "message": {"text": "[ERR001] Silent Exception Swallowing: Silently swallowing all exceptions hides bugs. Even in cleanup code, log at DEBUG level."}, "properties": {"repobilityId": 224722, "scanner": "repobility-threat-engine", "fingerprint": "1251ba89a7feba32afef018ca7724dc94a160f69d0761f7952b6b923e3d77b22", "category": "error_handling", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "except Exception:\n                pass", "reason": "Pattern matched with no mitigating context found", "rule_id": "ERR001", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|1251ba89a7feba32afef018ca7724dc94a160f69d0761f7952b6b923e3d77b22"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/services/collaborative_filter_service.py"}, "region": {"startLine": 181}}}]}, {"ruleId": "ERR001", "level": "warning", "message": {"text": "[ERR001] Silent Exception Swallowing: Silently swallowing all exceptions hides bugs. Even in cleanup code, log at DEBUG level."}, "properties": {"repobilityId": 224721, "scanner": "repobility-threat-engine", "fingerprint": "17b119ac5e41f7d8d8f7e2a5ac21626c337f7f461636db3fde61753b3d559477", "category": "error_handling", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "except Exception:\n            pass", "reason": "Pattern matched with no mitigating context found", "rule_id": "ERR001", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|17b119ac5e41f7d8d8f7e2a5ac21626c337f7f461636db3fde61753b3d559477"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/views/erp.py"}, "region": {"startLine": 112}}}]}, {"ruleId": "COMP001", "level": "warning", "message": {"text": "[COMP001] High cognitive complexity: Function `handle` has cognitive complexity 22 (SonarSource scale). Cognitive complexity measures how hard the function is for a human to understand \u2014 nested branches, boolean chains, and recursion all weigh in. Breakdown: continue=2, for=5, if=7, nested_bonus=8."}, "properties": {"repobilityId": 224703, "scanner": "repobility-threat-engine", "fingerprint": "8deeb84c4a2d27ff7a243666d64147b27624ecf9b645d5af24bf207befa61206", "category": "quality", "severity": "medium", "confidence": 0.95, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "AST-derived cognitive complexity score = 22 (severity threshold for medium: 15+).", "evidence": {"scanner": "repobility-threat-engine", "function": "handle", "breakdown": {"if": 7, "for": 5, "continue": 2, "nested_bonus": 8}, "complexity": 22, "correlation_key": "fp|8deeb84c4a2d27ff7a243666d64147b27624ecf9b645d5af24bf207befa61206"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/management/commands/seed_attendance.py"}, "region": {"startLine": 65}}}]}, {"ruleId": "DEPCUR-NPM", "level": "warning", "message": {"text": "npm package `react-native-gesture-handler` is 1 major version(s) behind (2.30.0 -> 3.0.1)"}, "properties": {"repobilityId": 224694, "scanner": "repobility-dependency-currency", "fingerprint": "30070280065a60cf000ebc12e48a7159a7a376438e9c774a22f3ff7e0f021196", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "1 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "react-native-gesture-handler", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "3.0.1", "correlation_key": "fp|30070280065a60cf000ebc12e48a7159a7a376438e9c774a22f3ff7e0f021196", "current_version": "2.30.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "warning", "message": {"text": "npm package `expo-status-bar` is 1 major version(s) behind (55.0.4 -> 56.0.4)"}, "properties": {"repobilityId": 224693, "scanner": "repobility-dependency-currency", "fingerprint": "6fd5ce2f0e7a81a800a1ba013cf718e2f67a29a993731624a47069b600f38b27", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "1 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "expo-status-bar", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "56.0.4", "correlation_key": "fp|6fd5ce2f0e7a81a800a1ba013cf718e2f67a29a993731624a47069b600f38b27", "current_version": "55.0.4"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "warning", "message": {"text": "npm package `expo-sharing` is 1 major version(s) behind (55.0.11 -> 56.0.18)"}, "properties": {"repobilityId": 224692, "scanner": "repobility-dependency-currency", "fingerprint": "955c9ffed15308174c635ea1ba079c5236634f68d7501bce83be56acb1146a0b", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "1 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "expo-sharing", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "56.0.18", "correlation_key": "fp|955c9ffed15308174c635ea1ba079c5236634f68d7501bce83be56acb1146a0b", "current_version": "55.0.11"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "warning", "message": {"text": "npm package `expo-secure-store` is 1 major version(s) behind (55.0.8 -> 56.0.4)"}, "properties": {"repobilityId": 224691, "scanner": "repobility-dependency-currency", "fingerprint": "531c877107c6e59bb63673dc042c09dcaa374c0d7d230dfe64cac6efb4df66ea", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "1 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "expo-secure-store", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "56.0.4", "correlation_key": "fp|531c877107c6e59bb63673dc042c09dcaa374c0d7d230dfe64cac6efb4df66ea", "current_version": "55.0.8"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "warning", "message": {"text": "npm package `expo-notifications` is 1 major version(s) behind (55.0.10 -> 56.0.18)"}, "properties": {"repobilityId": 224690, "scanner": "repobility-dependency-currency", "fingerprint": "6ad8e76d37f67b5323c0158699e059b5231a5a3097e9435561363fad634675c3", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "1 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "expo-notifications", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "56.0.18", "correlation_key": "fp|6ad8e76d37f67b5323c0158699e059b5231a5a3097e9435561363fad634675c3", "current_version": "55.0.10"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "warning", "message": {"text": "npm package `expo-linear-gradient` is 1 major version(s) behind (55.0.8 -> 56.0.4)"}, "properties": {"repobilityId": 224689, "scanner": "repobility-dependency-currency", "fingerprint": "c007ae0921e307fd009fe64ae9fe0be6e56ded7686408139cdcbb07a70ef4ced", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "1 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "expo-linear-gradient", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "56.0.4", "correlation_key": "fp|c007ae0921e307fd009fe64ae9fe0be6e56ded7686408139cdcbb07a70ef4ced", "current_version": "55.0.8"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "warning", "message": {"text": "npm package `expo-font` is 1 major version(s) behind (55.0.4 -> 56.0.7)"}, "properties": {"repobilityId": 224688, "scanner": "repobility-dependency-currency", "fingerprint": "a58ea9098554d282b12b0938b7505e17928513c96b2bbc838f3d8eb2d93eba59", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "1 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "expo-font", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "56.0.7", "correlation_key": "fp|a58ea9098554d282b12b0938b7505e17928513c96b2bbc838f3d8eb2d93eba59", "current_version": "55.0.4"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "warning", "message": {"text": "npm package `expo-file-system` is 1 major version(s) behind (55.0.10 -> 56.0.8)"}, "properties": {"repobilityId": 224687, "scanner": "repobility-dependency-currency", "fingerprint": "4e4963c36c3d5f22853d8dd21fcd56ad00b9d2ef136ea5a7494900fac59fd7e5", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "1 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "expo-file-system", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "56.0.8", "correlation_key": "fp|4e4963c36c3d5f22853d8dd21fcd56ad00b9d2ef136ea5a7494900fac59fd7e5", "current_version": "55.0.10"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "warning", "message": {"text": "npm package `expo-device` is 1 major version(s) behind (55.0.9 -> 56.0.4)"}, "properties": {"repobilityId": 224686, "scanner": "repobility-dependency-currency", "fingerprint": "14c228b49ad0308a8b8bac9fd7bb5388cbbfff05587f9694522ace5c7e51d796", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "1 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "expo-device", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "56.0.4", "correlation_key": "fp|14c228b49ad0308a8b8bac9fd7bb5388cbbfff05587f9694522ace5c7e51d796", "current_version": "55.0.9"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "warning", "message": {"text": "npm package `expo-blur` is 1 major version(s) behind (55.0.8 -> 56.0.3)"}, "properties": {"repobilityId": 224685, "scanner": "repobility-dependency-currency", "fingerprint": "0353d2457cd5ab8873fc80ba983471eaf2e6380e642490a52d103b31d446c9bf", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "1 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "expo-blur", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "56.0.3", "correlation_key": "fp|0353d2457cd5ab8873fc80ba983471eaf2e6380e642490a52d103b31d446c9bf", "current_version": "55.0.8"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "warning", "message": {"text": "npm package `@react-native-community/netinfo` is 1 major version(s) behind (11.5.2 -> 12.0.1)"}, "properties": {"repobilityId": 224680, "scanner": "repobility-dependency-currency", "fingerprint": "b866864fe66f86614934401bedccb2803b4de74337234e499e17fec815e977b9", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "1 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "@react-native-community/netinfo", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "12.0.1", "correlation_key": "fp|b866864fe66f86614934401bedccb2803b4de74337234e499e17fec815e977b9", "current_version": "11.5.2"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "warning", "message": {"text": "npm package `@react-native-async-storage/async-storage` is 1 major version(s) behind (2.2.0 -> 3.1.1)"}, "properties": {"repobilityId": 224679, "scanner": "repobility-dependency-currency", "fingerprint": "e7d7ef350c29fd4203ccd422e2b3e5a186d9bde0c907832f7c61ed4147674277", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "1 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "@react-native-async-storage/async-storage", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "3.1.1", "correlation_key": "fp|e7d7ef350c29fd4203ccd422e2b3e5a186d9bde0c907832f7c61ed4147674277", "current_version": "2.2.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-PY", "level": "warning", "message": {"text": "Python package `psutil` is 1 major version(s) behind (6.1.0 -> 7.2.2)"}, "properties": {"repobilityId": 224678, "scanner": "repobility-dependency-currency", "fingerprint": "11ef61eb0f50c5b2783a8f1bb4cf0da02df266f3693afedc1459f608eb10e4a0", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "1 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "psutil", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "7.2.2", "correlation_key": "fp|11ef61eb0f50c5b2783a8f1bb4cf0da02df266f3693afedc1459f608eb10e4a0", "current_version": "6.1.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 53}}}]}, {"ruleId": "DEPCUR-PY", "level": "warning", "message": {"text": "Python package `gunicorn` is 3 major version(s) behind (23.0.0 -> 26.0.0)"}, "properties": {"repobilityId": 224666, "scanner": "repobility-dependency-currency", "fingerprint": "140a896a04582a3b0c87a0af86badccf233c5d444e671ef0e579a2112bd4a554", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "3 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "gunicorn", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "26.0.0", "correlation_key": "fp|140a896a04582a3b0c87a0af86badccf233c5d444e671ef0e579a2112bd4a554", "current_version": "23.0.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 29}}}]}, {"ruleId": "DEPCUR-PY", "level": "warning", "message": {"text": "Python package `django-redis` is 2 major version(s) behind (5.4.0 -> 7.0.0)"}, "properties": {"repobilityId": 224663, "scanner": "repobility-dependency-currency", "fingerprint": "5dcd260749db47c3fcf56b0b3a93b40eed571e39445821fb32f0c0ab87a68667", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "2 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "django-redis", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "7.0.0", "correlation_key": "fp|5dcd260749db47c3fcf56b0b3a93b40eed571e39445821fb32f0c0ab87a68667", "current_version": "5.4.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 22}}}]}, {"ruleId": "DEPCUR-PY", "level": "warning", "message": {"text": "Python package `Django` is 1 major version(s) behind (5.2.9 -> 6.0.6)"}, "properties": {"repobilityId": 224660, "scanner": "repobility-dependency-currency", "fingerprint": "1eb6f876e105eaf218f7894a752ebc691fa19233ce15ba9e60eaa8e845afbb15", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "1 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "Django", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "6.0.6", "correlation_key": "fp|1eb6f876e105eaf218f7894a752ebc691fa19233ce15ba9e60eaa8e845afbb15", "current_version": "5.2.9"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 16}}}]}, {"ruleId": "MINED115", "level": "warning", "message": {"text": "Action `amondnet/vercel-action` pinned to mutable ref `@v25`"}, "properties": {"repobilityId": 224628, "scanner": "repobility-supply-chain", "fingerprint": "240e33329aeaac4fbd0c73d62240173895178dce5b9bcb47c29c7c073de5cdb6", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|240e33329aeaac4fbd0c73d62240173895178dce5b9bcb47c29c7c073de5cdb6"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 236}}}]}, {"ruleId": "MINED115", "level": "warning", "message": {"text": "Action `amondnet/vercel-action` pinned to mutable ref `@v25`"}, "properties": {"repobilityId": 224625, "scanner": "repobility-supply-chain", "fingerprint": "83879385e5a63c476ed61466f2cc21f40d68c6b444d39ad57665b30051d05558", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|83879385e5a63c476ed61466f2cc21f40d68c6b444d39ad57665b30051d05558"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 208}}}]}, {"ruleId": "MINED115", "level": "warning", "message": {"text": "Action `codecov/codecov-action` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 224618, "scanner": "repobility-supply-chain", "fingerprint": "c02850bd25825a5e43f846f8a69a1f39d11ed908ed9f60b7bcd1e8737dafcca4", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|c02850bd25825a5e43f846f8a69a1f39d11ed908ed9f60b7bcd1e8737dafcca4"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 138}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224557, "scanner": "repobility-ast-engine", "fingerprint": "ad55b61faef95a25e342513da654cefaeb885717ff8d23dfcceccdc462ac959d", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|ad55b61faef95a25e342513da654cefaeb885717ff8d23dfcceccdc462ac959d"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/views_reports.py"}, "region": {"startLine": 297}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224556, "scanner": "repobility-ast-engine", "fingerprint": "dc95880ab6bd30c5b6b48ff98a50f63215316a9f1007e930419c099f8692d1d5", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|dc95880ab6bd30c5b6b48ff98a50f63215316a9f1007e930419c099f8692d1d5"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/views_reports.py"}, "region": {"startLine": 528}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224554, "scanner": "repobility-ast-engine", "fingerprint": "73cbfd4cb162fec35505b63759ccae1d7c065b45a93a8ca53288da9375bedc08", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|73cbfd4cb162fec35505b63759ccae1d7c065b45a93a8ca53288da9375bedc08"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/views.py"}, "region": {"startLine": 614}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224551, "scanner": "repobility-ast-engine", "fingerprint": "a795e04d45672ec75af10813db50d6c827309c56e5fce2b08c77cdee052001b4", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|a795e04d45672ec75af10813db50d6c827309c56e5fce2b08c77cdee052001b4"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/views.py"}, "region": {"startLine": 948}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224549, "scanner": "repobility-ast-engine", "fingerprint": "0ef4f72f1f589d054acd78f351edaba947e735ad56f7e92a9d31f2fd8fc69d51", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|0ef4f72f1f589d054acd78f351edaba947e735ad56f7e92a9d31f2fd8fc69d51"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/views.py"}, "region": {"startLine": 608}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224548, "scanner": "repobility-ast-engine", "fingerprint": "164d7dee59423d90cd5e857f47673793a00956869a8357379a3512cb5b44154a", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|164d7dee59423d90cd5e857f47673793a00956869a8357379a3512cb5b44154a"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/views.py"}, "region": {"startLine": 600}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224547, "scanner": "repobility-ast-engine", "fingerprint": "07377ee66ff840f90dba8c7cc90a9d9894ff81219b525294092e8db05a2d2d18", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|07377ee66ff840f90dba8c7cc90a9d9894ff81219b525294092e8db05a2d2d18"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/views.py"}, "region": {"startLine": 596}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224545, "scanner": "repobility-ast-engine", "fingerprint": "80aeaf450e5a3a1ff0af31571ff73ba0ce5b1eb793240f3c9cb67cee33f65251", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|80aeaf450e5a3a1ff0af31571ff73ba0ce5b1eb793240f3c9cb67cee33f65251"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/views.py"}, "region": {"startLine": 498}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224543, "scanner": "repobility-ast-engine", "fingerprint": "2e650192d0a0893bad9aff31144ed6f28d72d2366395b37ca6cb030309d4dad5", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|2e650192d0a0893bad9aff31144ed6f28d72d2366395b37ca6cb030309d4dad5"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/views.py"}, "region": {"startLine": 977}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224542, "scanner": "repobility-ast-engine", "fingerprint": "3f33cebcc9cca693bdbc6c6d9cea24b03ef3c8b489e0d528429073c9bb82bb82", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|3f33cebcc9cca693bdbc6c6d9cea24b03ef3c8b489e0d528429073c9bb82bb82"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/views.py"}, "region": {"startLine": 971}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224540, "scanner": "repobility-ast-engine", "fingerprint": "9c46272f55b42420c38ac94dad9c639e423812f14a6e548853d7b5279fc243be", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|9c46272f55b42420c38ac94dad9c639e423812f14a6e548853d7b5279fc243be"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/views.py"}, "region": {"startLine": 963}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224530, "scanner": "repobility-ast-engine", "fingerprint": "9773dbf8f73aaf533e08961c751e4884b0c84959d2ad1ce606b8b7206bc8eb7c", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|9773dbf8f73aaf533e08961c751e4884b0c84959d2ad1ce606b8b7206bc8eb7c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/views.py"}, "region": {"startLine": 582}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224529, "scanner": "repobility-ast-engine", "fingerprint": "169920af56c2cc33daca16b8668c4d2097645476042a1b3e43d58afae00bff06", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|169920af56c2cc33daca16b8668c4d2097645476042a1b3e43d58afae00bff06"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/views.py"}, "region": {"startLine": 488}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224528, "scanner": "repobility-ast-engine", "fingerprint": "491bd792acd7e543d645eb6b59bc93e484dd23a76d17a8e823c7a1f9a9a962f5", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|491bd792acd7e543d645eb6b59bc93e484dd23a76d17a8e823c7a1f9a9a962f5"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/views.py"}, "region": {"startLine": 483}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224527, "scanner": "repobility-ast-engine", "fingerprint": "2d6ae5290abcccfb3d108f5178d2fefaf758c95e62e5b2bc178f5aa9dee60877", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|2d6ae5290abcccfb3d108f5178d2fefaf758c95e62e5b2bc178f5aa9dee60877"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/views.py"}, "region": {"startLine": 476}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224526, "scanner": "repobility-ast-engine", "fingerprint": "1af3888e7f4a2cb9977de36fdaf207a40a66f41f082bdec5c279181d704f209a", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|1af3888e7f4a2cb9977de36fdaf207a40a66f41f082bdec5c279181d704f209a"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/gamification/badge_evaluator.py"}, "region": {"startLine": 35}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224522, "scanner": "repobility-ast-engine", "fingerprint": "9c7f28c7ad515fa4305ecdfa85a7221737bcdb19bcd7e40386c23439367a7346", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|9c7f28c7ad515fa4305ecdfa85a7221737bcdb19bcd7e40386c23439367a7346"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/gamification/signals.py"}, "region": {"startLine": 52}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224519, "scanner": "repobility-ast-engine", "fingerprint": "6f003b098148dadb1854693156f51ea710bceeb86aabb4d535d151f26b656793", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|6f003b098148dadb1854693156f51ea710bceeb86aabb4d535d151f26b656793"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/gamification/signals.py"}, "region": {"startLine": 28}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224517, "scanner": "repobility-ast-engine", "fingerprint": "c098fcb5183c89995a2d7acd279fa720677fab2725fcba9e46edec19ce7631b5", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|c098fcb5183c89995a2d7acd279fa720677fab2725fcba9e46edec19ce7631b5"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/vector.py"}, "region": {"startLine": 12}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224516, "scanner": "repobility-ast-engine", "fingerprint": "50ffdc39fd44a60553d721536d4a630e791d9418e08366564f5d4041e666bfcc", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|50ffdc39fd44a60553d721536d4a630e791d9418e08366564f5d4041e666bfcc"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/views.py"}, "region": {"startLine": 706}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224514, "scanner": "repobility-ast-engine", "fingerprint": "5e82eb45517fee6aad1e2f2816956df6fe88bb7f1ca64068438b3d6244ac98d5", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|5e82eb45517fee6aad1e2f2816956df6fe88bb7f1ca64068438b3d6244ac98d5"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/views.py"}, "region": {"startLine": 131}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224513, "scanner": "repobility-ast-engine", "fingerprint": "7cb02c9e2fa7fea1cc42ccd6c4d6c98b386c96c79d0824f1ceb4aaab38c2fc5a", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|7cb02c9e2fa7fea1cc42ccd6c4d6c98b386c96c79d0824f1ceb4aaab38c2fc5a"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/views.py"}, "region": {"startLine": 124}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224498, "scanner": "repobility-ast-engine", "fingerprint": "414d2f1ffd719a864397d135e12fb65054858c6b635ddabc40a57337a02137cf", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|414d2f1ffd719a864397d135e12fb65054858c6b635ddabc40a57337a02137cf"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/serializers.py"}, "region": {"startLine": 203}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224497, "scanner": "repobility-ast-engine", "fingerprint": "ffc7bff3ffd5dfbc45c040b9dfc81f67e6b2c47926d7b298ff59f852f34d4a42", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|ffc7bff3ffd5dfbc45c040b9dfc81f67e6b2c47926d7b298ff59f852f34d4a42"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/async_jobs.py"}, "region": {"startLine": 147}}}]}, {"ruleId": "MINED111", "level": "warning", "message": {"text": "Bare except continues silently"}, "properties": {"repobilityId": 224496, "scanner": "repobility-ast-engine", "fingerprint": "4ca1aa293df16177934bddb5c4942c081253b92c629228de28c8d15996a67681", "category": "quality", "severity": "medium", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "bare-except-without-pass", "owasp": null, "cwe_ids": [], "languages": ["python"], "observations_count": 21610}, "scanner": "repobility-ast-engine", "correlation_key": "fp|4ca1aa293df16177934bddb5c4942c081253b92c629228de28c8d15996a67681"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/async_jobs.py"}, "region": {"startLine": 22}}}]}, {"ruleId": "AIC004", "level": "warning", "message": {"text": "Suspicious implementation file appears unreferenced"}, "properties": {"repobilityId": 224374, "scanner": "repobility-ai-code-hygiene", "fingerprint": "df24bb9d673416708860e5e2b29da03e86327d9467ea6d9af83bf99f4807c228", "category": "quality", "severity": "medium", "confidence": 0.78, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Patch-style source file has no detected inbound reference from other repository files.", "evidence": {"suffix": "fix", "rule_id": "AIC004", "scanner": "repobility-ai-code-hygiene", "references": ["https://knip.dev/", "https://github.com/jendrikseipp/vulture"], "correlation_key": "fp|df24bb9d673416708860e5e2b29da03e86327d9467ea6d9af83bf99f4807c228"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/verify_teacher_fix.py"}, "region": {"startLine": 1}}}]}, {"ruleId": "AIC004", "level": "warning", "message": {"text": "Suspicious implementation file appears unreferenced"}, "properties": {"repobilityId": 224373, "scanner": "repobility-ai-code-hygiene", "fingerprint": "98e58a3fcb04ad8f0d75d4958e2016df90a926e4efff7545a3f97a89c51afb60", "category": "quality", "severity": "medium", "confidence": 0.78, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Patch-style source file has no detected inbound reference from other repository files.", "evidence": {"suffix": "final", "rule_id": "AIC004", "scanner": "repobility-ai-code-hygiene", "references": ["https://knip.dev/", "https://github.com/jendrikseipp/vulture"], "correlation_key": "fp|98e58a3fcb04ad8f0d75d4958e2016df90a926e4efff7545a3f97a89c51afb60"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/create_library_tables_final.py"}, "region": {"startLine": 1}}}]}, {"ruleId": "AIC001", "level": "warning", "message": {"text": "Parallel implementation file sits beside a canonical file"}, "properties": {"repobilityId": 224366, "scanner": "repobility-ai-code-hygiene", "fingerprint": "b62fe3d190a5da5f244476ece15b1edc15c360a6209f8cc0ac1d02275ddccad7", "category": "quality", "severity": "medium", "confidence": 0.82, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Source filename has a patch-style suffix and a same-directory canonical sibling exists.", "evidence": {"suffix": "final", "rule_id": "AIC001", "scanner": "repobility-ai-code-hygiene", "references": ["https://arxiv.org/abs/2601.15195", "https://knip.dev/"], "canonical_file": "backend/scripts/create_library_tables.py", "correlation_key": "fp|b62fe3d190a5da5f244476ece15b1edc15c360a6209f8cc0ac1d02275ddccad7"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/create_library_tables_final.py"}, "region": {"startLine": 1}}}]}, {"ruleId": "WEB011", "level": "note", "message": {"text": "Public web app has no humans.txt"}, "properties": {"repobilityId": 224995, "scanner": "repobility-web-presence", "fingerprint": "bdd551fbe1ab6405480e0d5755632562c2096cb9e9a6a071ef60e4c27a6873f1", "category": "quality", "severity": "low", "confidence": 0.5, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Repository looks like a public web app but no humans.txt file or route was discovered.", "evidence": {"rule_id": "WEB011", "scanner": "repobility-web-presence", "references": ["https://github.com/Lissy93/web-check"], "correlation_key": "fp|bdd551fbe1ab6405480e0d5755632562c2096cb9e9a6a071ef60e4c27a6873f1"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "humans.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "WEB008", "level": "note", "message": {"text": "Public docs site has no llms.txt"}, "properties": {"repobilityId": 224994, "scanner": "repobility-web-presence", "fingerprint": "cdce8ed8706710d39c3e7272dad572dd639cff74fd3d2ac62d8f6f522b891d76", "category": "quality", "severity": "low", "confidence": 0.64, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Repository looks public and documentation-heavy but no llms.txt file or route was discovered.", "evidence": {"rule_id": "WEB008", "scanner": "repobility-web-presence", "references": ["https://llmstxt.org/"], "correlation_key": "fp|cdce8ed8706710d39c3e7272dad572dd639cff74fd3d2ac62d8f6f522b891d76"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "llms.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "WEB002", "level": "note", "message": {"text": "Public web app has no sitemap"}, "properties": {"repobilityId": 224993, "scanner": "repobility-web-presence", "fingerprint": "fccbe72d13ca3ba9197ec37b0daa0802fb6d5ebff54b3eb9f09b59b0f8d0acdf", "category": "quality", "severity": "low", "confidence": 0.72, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Repository looks like a public web app but no sitemap file or route was discovered.", "evidence": {"rule_id": "WEB002", "scanner": "repobility-web-presence", "references": ["https://www.sitemaps.org/protocol.html", "https://github.com/Lissy93/web-check"], "correlation_key": "fp|fccbe72d13ca3ba9197ec37b0daa0802fb6d5ebff54b3eb9f09b59b0f8d0acdf"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "sitemap.xml"}, "region": {"startLine": 1}}}]}, {"ruleId": "WEB001", "level": "note", "message": {"text": "Public web app has no robots.txt"}, "properties": {"repobilityId": 224992, "scanner": "repobility-web-presence", "fingerprint": "cae3f2223945958e14d8eb90f7965fa26b47011cc5be29c2855a4054937e29c4", "category": "quality", "severity": "low", "confidence": 0.74, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Repository looks like a public web app but no robots.txt file or route was discovered.", "evidence": {"rule_id": "WEB001", "scanner": "repobility-web-presence", "references": ["https://www.rfc-editor.org/rfc/rfc9309", "https://github.com/Lissy93/web-check"], "correlation_key": "fp|cae3f2223945958e14d8eb90f7965fa26b47011cc5be29c2855a4054937e29c4"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "robots.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-5239-wwwm-4pmq", "level": "note", "message": {"text": "pygments: GHSA-5239-wwwm-4pmq"}, "properties": {"repobilityId": 224924, "scanner": "osv-scanner", "fingerprint": "877bb1b21669710128f9d5c6fb01bec5d4fefc10779ca23d38c15846f58f768b", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-4539"], "package": "pygments", "rule_id": "GHSA-5239-wwwm-4pmq", "scanner": "osv-scanner", "correlation_key": "vuln|pygments|CVE-2026-4539|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-mjgh-79qc-68w3", "level": "note", "message": {"text": "django: GHSA-mjgh-79qc-68w3"}, "properties": {"repobilityId": 224915, "scanner": "osv-scanner", "fingerprint": "4ca27dae896d56c0d5c73803453e2f83f90dfceb2601bee2bc288236e3c1fd6e", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-django-2026-25674", "CVE-2026-25674"], "package": "django", "rule_id": "GHSA-mjgh-79qc-68w3", "scanner": "osv-scanner", "correlation_key": "vuln|django|CVE-2026-25674|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-xhjh-pmcv-23jw", "level": "note", "message": {"text": "axios: GHSA-xhjh-pmcv-23jw"}, "properties": {"repobilityId": 224876, "scanner": "osv-scanner", "fingerprint": "3a5b8bf7030534d251a9ab4412bd9a141e4772a1979bd302743d186a6803b746", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-42040"], "package": "axios", "rule_id": "GHSA-xhjh-pmcv-23jw", "scanner": "osv-scanner", "correlation_key": "vuln|axios|CVE-2026-42040|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-4x5r-pxfx-6jf8", "level": "note", "message": {"text": "@babel/core: GHSA-4x5r-pxfx-6jf8"}, "properties": {"repobilityId": 224851, "scanner": "osv-scanner", "fingerprint": "266959242bf5fd2754a74fdd0caf1f106080e4205e10a3df8638d425025db670", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-49356"], "package": "@babel/core", "rule_id": "GHSA-4x5r-pxfx-6jf8", "scanner": "osv-scanner", "correlation_key": "vuln|babel/core|CVE-2026-49356|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-4x5r-pxfx-6jf8", "level": "note", "message": {"text": "@babel/core: GHSA-4x5r-pxfx-6jf8"}, "properties": {"repobilityId": 224845, "scanner": "osv-scanner", "fingerprint": "a15879f7d49ef891efffc490c1d1fffd87de58a9b090cfaccfd08009ffc77b7d", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-49356"], "package": "@babel/core", "rule_id": "GHSA-4x5r-pxfx-6jf8", "scanner": "osv-scanner", "correlation_key": "vuln|babel/core|CVE-2026-49356|frontend/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DKC015", "level": "note", "message": {"text": "Database service has no healthcheck"}, "properties": {"repobilityId": 224838, "scanner": "repobility-docker", "fingerprint": "a1907b9a7048030ba3d122d5c8456f40a4b2f0983cf0bdf4c89978df9ac7da20", "category": "docker", "severity": "low", "confidence": 0.72, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Database-like service has no Compose healthcheck.", "evidence": {"rule_id": "DKC015", "scanner": "repobility-docker", "service": "redis", "references": ["https://docs.docker.com/compose/how-tos/startup-order/"], "correlation_key": "fp|a1907b9a7048030ba3d122d5c8456f40a4b2f0983cf0bdf4c89978df9ac7da20"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker-compose.yml"}, "region": {"startLine": 71}}}]}, {"ruleId": "DKC010", "level": "note", "message": {"text": "Compose service lacks no-new-privileges hardening"}, "properties": {"repobilityId": 224836, "scanner": "repobility-docker", "fingerprint": "fe45978786b3bc6c1d954caf32684179b8be83d5e0e7e8bfe81cafe1dda39fcb", "category": "docker", "severity": "low", "confidence": 0.62, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "App-like service has no security_opt no-new-privileges setting.", "evidence": {"rule_id": "DKC010", "scanner": "repobility-docker", "service": "frontend", "references": ["https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html"], "correlation_key": "fp|fe45978786b3bc6c1d954caf32684179b8be83d5e0e7e8bfe81cafe1dda39fcb"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker-compose.yml"}, "region": {"startLine": 46}}}]}, {"ruleId": "DKC006", "level": "note", "message": {"text": "Compose service does not declare a runtime user"}, "properties": {"repobilityId": 224835, "scanner": "repobility-docker", "fingerprint": "e96dc9a8631d7558474b9a47dd7e1eb25ed9ebad78e408c1fd847d59384b9876", "category": "docker", "severity": "low", "confidence": 0.56, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Service has no user setting and Repobility could not prove the image runs non-root.", "evidence": {"rule_id": "DKC006", "scanner": "repobility-docker", "service": "frontend", "references": ["https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html"], "correlation_key": "fp|e96dc9a8631d7558474b9a47dd7e1eb25ed9ebad78e408c1fd847d59384b9876"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker-compose.yml"}, "region": {"startLine": 46}}}]}, {"ruleId": "DKC016", "level": "note", "message": {"text": "App service does not wait for database health"}, "properties": {"repobilityId": 224834, "scanner": "repobility-docker", "fingerprint": "adb92d2320a04c60be1a21466408a69c83f40189f9199c1a72e25604d0abed30", "category": "docker", "severity": "low", "confidence": 0.68, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "App depends on a database-like service without a health-gated dependency.", "evidence": {"rule_id": "DKC016", "scanner": "repobility-docker", "service": "worker", "dependency": "redis", "references": ["https://docs.docker.com/compose/how-tos/startup-order/"], "correlation_key": "fp|adb92d2320a04c60be1a21466408a69c83f40189f9199c1a72e25604d0abed30", "dependency_has_healthcheck": false}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker-compose.yml"}, "region": {"startLine": 24}}}]}, {"ruleId": "DKC010", "level": "note", "message": {"text": "Compose service lacks no-new-privileges hardening"}, "properties": {"repobilityId": 224833, "scanner": "repobility-docker", "fingerprint": "e3922d00291f20fad2c10caefda331b3687799aca5962c30d8ffd4b87154477c", "category": "docker", "severity": "low", "confidence": 0.62, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "App-like service has no security_opt no-new-privileges setting.", "evidence": {"rule_id": "DKC010", "scanner": "repobility-docker", "service": "worker", "references": ["https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html"], "correlation_key": "fp|e3922d00291f20fad2c10caefda331b3687799aca5962c30d8ffd4b87154477c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker-compose.yml"}, "region": {"startLine": 24}}}]}, {"ruleId": "DKC006", "level": "note", "message": {"text": "Compose service does not declare a runtime user"}, "properties": {"repobilityId": 224832, "scanner": "repobility-docker", "fingerprint": "447cf84f6cf70dd9a47d6299d3aeed04fcfaa99584331776a77459a03de76b1f", "category": "docker", "severity": "low", "confidence": 0.56, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Service has no user setting and Repobility could not prove the image runs non-root.", "evidence": {"rule_id": "DKC006", "scanner": "repobility-docker", "service": "worker", "references": ["https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html"], "correlation_key": "fp|447cf84f6cf70dd9a47d6299d3aeed04fcfaa99584331776a77459a03de76b1f"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker-compose.yml"}, "region": {"startLine": 24}}}]}, {"ruleId": "DKC016", "level": "note", "message": {"text": "App service does not wait for database health"}, "properties": {"repobilityId": 224831, "scanner": "repobility-docker", "fingerprint": "f2eb03f4a94fd6fa0cd6cf1b50327cbce953cb322d3b7cd619b7fee23dea9eab", "category": "docker", "severity": "low", "confidence": 0.68, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "App depends on a database-like service without a health-gated dependency.", "evidence": {"rule_id": "DKC016", "scanner": "repobility-docker", "service": "backend", "dependency": "redis", "references": ["https://docs.docker.com/compose/how-tos/startup-order/"], "correlation_key": "fp|f2eb03f4a94fd6fa0cd6cf1b50327cbce953cb322d3b7cd619b7fee23dea9eab", "dependency_has_healthcheck": false}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker-compose.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "DKC010", "level": "note", "message": {"text": "Compose service lacks no-new-privileges hardening"}, "properties": {"repobilityId": 224830, "scanner": "repobility-docker", "fingerprint": "7f80983f54868d8bec198a3977b7dcbe8bfb5f2291356d590fb078148e91780d", "category": "docker", "severity": "low", "confidence": 0.62, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "App-like service has no security_opt no-new-privileges setting.", "evidence": {"rule_id": "DKC010", "scanner": "repobility-docker", "service": "backend", "references": ["https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html"], "correlation_key": "fp|7f80983f54868d8bec198a3977b7dcbe8bfb5f2291356d590fb078148e91780d"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker-compose.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "DKC006", "level": "note", "message": {"text": "Compose service does not declare a runtime user"}, "properties": {"repobilityId": 224829, "scanner": "repobility-docker", "fingerprint": "2ae03d2ca68f689d193058b7c353aabad57bc3d37942d6a7c1406762df909513", "category": "docker", "severity": "low", "confidence": 0.56, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Service has no user setting and Repobility could not prove the image runs non-root.", "evidence": {"rule_id": "DKC006", "scanner": "repobility-docker", "service": "backend", "references": ["https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html"], "correlation_key": "fp|2ae03d2ca68f689d193058b7c353aabad57bc3d37942d6a7c1406762df909513"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker-compose.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "DKR012", "level": "note", "message": {"text": "Dockerfile keeps pip download cache"}, "properties": {"repobilityId": 224825, "scanner": "repobility-docker", "fingerprint": "aecd5256cfce41ab9d683abc9a1edbbcad300990bd3d72d5fb163a59ac68b37e", "category": "docker", "severity": "low", "confidence": 0.72, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "pip install appears without --no-cache-dir.", "evidence": {"rule_id": "DKR012", "scanner": "repobility-docker", "references": ["https://docs.docker.com/develop/develop-images/dockerfile_best-practices/"], "correlation_key": "fp|aecd5256cfce41ab9d683abc9a1edbbcad300990bd3d72d5fb163a59ac68b37e"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/Dockerfile"}, "region": {"startLine": 60}}}]}, {"ruleId": "DKR012", "level": "note", "message": {"text": "Dockerfile keeps pip download cache"}, "properties": {"repobilityId": 224824, "scanner": "repobility-docker", "fingerprint": "4ec4d1521b5640a227bb58234dd2caa7b0bbda884e6752f051bf82d4ebabd95a", "category": "docker", "severity": "low", "confidence": 0.72, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "pip install appears without --no-cache-dir.", "evidence": {"rule_id": "DKR012", "scanner": "repobility-docker", "references": ["https://docs.docker.com/develop/develop-images/dockerfile_best-practices/"], "correlation_key": "fp|4ec4d1521b5640a227bb58234dd2caa7b0bbda884e6752f051bf82d4ebabd95a"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/Dockerfile"}, "region": {"startLine": 27}}}]}, {"ruleId": "SEC006", "level": "note", "message": {"text": "[SEC006] XSS Risk: Direct HTML injection without sanitization."}, "properties": {"repobilityId": 224811, "scanner": "repobility-threat-engine", "fingerprint": "20b952b55a597084f51d777c6f3960bd96fd465ba9ac683e5c069f6f87f6846f", "category": "injection", "severity": "low", "confidence": 0.4, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "No user-input source (request/query/fetch/URL) found \u2014 may be static content", "evidence": {"match": "document.write(h", "reason": "No user-input source (request/query/fetch/URL) found \u2014 may be static content", "rule_id": "SEC006", "scanner": "repobility-threat-engine", "confidence": 0.4, "correlation_key": "code|injection|token|70|sec006"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/admin/finance/reports/cash-book/page.tsx"}, "region": {"startLine": 70}}}]}, {"ruleId": "SEC006", "level": "note", "message": {"text": "[SEC006] XSS Risk: Direct HTML injection without sanitization."}, "properties": {"repobilityId": 224810, "scanner": "repobility-threat-engine", "fingerprint": "91b72fc1e1ae73097680ce180c34481218ce04fa3d24bc64e7659701165a9548", "category": "injection", "severity": "low", "confidence": 0.4, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "No user-input source (request/query/fetch/URL) found \u2014 may be static content", "evidence": {"match": "document.write(h", "reason": "No user-input source (request/query/fetch/URL) found \u2014 may be static content", "rule_id": "SEC006", "scanner": "repobility-threat-engine", "confidence": 0.4, "correlation_key": "code|injection|token|72|sec006"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/admin/finance/reports/bank-book/page.tsx"}, "region": {"startLine": 72}}}]}, {"ruleId": "SEC006", "level": "note", "message": {"text": "[SEC006] XSS Risk: Direct HTML injection without sanitization."}, "properties": {"repobilityId": 224809, "scanner": "repobility-threat-engine", "fingerprint": "f1d1d32526b333dc93765f8fe145a956651ffa0f9de6ed6afacf80b1fc56f333", "category": "injection", "severity": "low", "confidence": 0.4, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "No user-input source (request/query/fetch/URL) found \u2014 may be static content", "evidence": {"match": "document.write(h", "reason": "No user-input source (request/query/fetch/URL) found \u2014 may be static content", "rule_id": "SEC006", "scanner": "repobility-threat-engine", "confidence": 0.4, "correlation_key": "code|injection|token|86|sec006"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/admin/finance/reports/aging/page.tsx"}, "region": {"startLine": 86}}}]}, {"ruleId": "SEC124", "level": "note", "message": {"text": "[SEC124] TOCTOU file access (os.access then open): Check-then-use file pattern (access/exists then open) lets an attacker swap the file between check and use (symlink attack). `mktemp` is deprecated for the same reason."}, "properties": {"repobilityId": 224770, "scanner": "repobility-threat-engine", "fingerprint": "f257e510d281e4771bad16e1e00556a8fa35ee3933482fa674aeea3d98403fa6", "category": "race_condition", "severity": "low", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "os.path.exists(\"school_demo.sqlite3\"):\n        with open(\"schema_verification.txt\", \"w", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC124", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|f257e510d281e4771bad16e1e00556a8fa35ee3933482fa674aeea3d98403fa6"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/check_demo_schema.py"}, "region": {"startLine": 8}}}]}, {"ruleId": "COMP001", "level": "note", "message": {"text": "[COMP001] High cognitive complexity: Function `get_progress_percentage` has cognitive complexity 11 (SonarSource scale). Cognitive complexity measures how hard the function is for a human to understand \u2014 nested branches, boolean chains, and recursion all weigh in. Breakdown: else=1, except=1, for=1, if=3, nested_bonus=4, or=1."}, "properties": {"repobilityId": 224704, "scanner": "repobility-threat-engine", "fingerprint": "8a05ee478d577783af6cc155702a8bd011227457696c377ec96d6a3f70069552", "category": "quality", "severity": "low", "confidence": 0.95, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "AST-derived cognitive complexity score = 11 (severity threshold for low: 8+).", "evidence": {"scanner": "repobility-threat-engine", "function": "get_progress_percentage", "breakdown": {"if": 3, "or": 1, "for": 1, "else": 1, "except": 1, "nested_bonus": 4}, "complexity": 11, "correlation_key": "fp|8a05ee478d577783af6cc155702a8bd011227457696c377ec96d6a3f70069552"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/serializers/academic.py"}, "region": {"startLine": 69}}}]}, {"ruleId": "DEPCUR-NPM", "level": "note", "message": {"text": "npm package `@radix-ui/react-avatar` is minor version(s) behind (1.1.11 -> 1.2.0)"}, "properties": {"repobilityId": 224700, "scanner": "repobility-dependency-currency", "fingerprint": "76e402b07d6f4cac1fc95c7c5498b5fb96f21988b9044378051acb80fb786f6f", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "@radix-ui/react-avatar", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "1.2.0", "correlation_key": "fp|76e402b07d6f4cac1fc95c7c5498b5fb96f21988b9044378051acb80fb786f6f", "current_version": "1.1.11"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "note", "message": {"text": "npm package `@hookform/resolvers` is minor version(s) behind (5.2.2 -> 5.4.0)"}, "properties": {"repobilityId": 224697, "scanner": "repobility-dependency-currency", "fingerprint": "dcf10c4724d5fba621a9e18632a0a6b574eebd9b8befdf95083c54a663a7d9f1", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "@hookform/resolvers", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "5.4.0", "correlation_key": "fp|dcf10c4724d5fba621a9e18632a0a6b574eebd9b8befdf95083c54a663a7d9f1", "current_version": "5.2.2"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "note", "message": {"text": "npm package `react-native-safe-area-context` is minor version(s) behind (5.6.2 -> 5.8.0)"}, "properties": {"repobilityId": 224695, "scanner": "repobility-dependency-currency", "fingerprint": "2d06dfe929c71f8b698d4816b241e22e73306fa1f8e80b6769ad5c4e3d37fe8a", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "react-native-safe-area-context", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "5.8.0", "correlation_key": "fp|2d06dfe929c71f8b698d4816b241e22e73306fa1f8e80b6769ad5c4e3d37fe8a", "current_version": "5.6.2"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "note", "message": {"text": "npm package `axios` is minor version(s) behind (1.13.5 -> 1.18.0)"}, "properties": {"repobilityId": 224684, "scanner": "repobility-dependency-currency", "fingerprint": "f6ce4c2ee19ca4f8e71ab366f922e03a1392c058268b4d326e758f92e236d0fe", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "axios", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "1.18.0", "correlation_key": "fp|f6ce4c2ee19ca4f8e71ab366f922e03a1392c058268b4d326e758f92e236d0fe", "current_version": "1.13.5"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "note", "message": {"text": "npm package `@react-navigation/native-stack` is minor version(s) behind (7.14.2 -> 7.17.5)"}, "properties": {"repobilityId": 224683, "scanner": "repobility-dependency-currency", "fingerprint": "19b6599121f9462c9418742bb58f5a46f9e4cf32e5ec535b307478378d55b2d6", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "@react-navigation/native-stack", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "7.17.5", "correlation_key": "fp|19b6599121f9462c9418742bb58f5a46f9e4cf32e5ec535b307478378d55b2d6", "current_version": "7.14.2"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "note", "message": {"text": "npm package `@react-navigation/native` is minor version(s) behind (7.1.31 -> 7.3.3)"}, "properties": {"repobilityId": 224682, "scanner": "repobility-dependency-currency", "fingerprint": "a2e6b9d64996b665e0e99ef13f866783c9ab76786eaabb80dfce2f12ce4338f8", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "@react-navigation/native", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "7.3.3", "correlation_key": "fp|a2e6b9d64996b665e0e99ef13f866783c9ab76786eaabb80dfce2f12ce4338f8", "current_version": "7.1.31"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "note", "message": {"text": "npm package `@react-navigation/bottom-tabs` is minor version(s) behind (7.15.2 -> 7.18.2)"}, "properties": {"repobilityId": 224681, "scanner": "repobility-dependency-currency", "fingerprint": "7ba9101fc620fb22f0f79a8c423b1d21fdaa590733de8dab305625002c390e00", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "@react-navigation/bottom-tabs", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "7.18.2", "correlation_key": "fp|7ba9101fc620fb22f0f79a8c423b1d21fdaa590733de8dab305625002c390e00", "current_version": "7.15.2"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `prometheus_client` is minor version(s) behind (0.21.0 -> 0.25.0)"}, "properties": {"repobilityId": 224677, "scanner": "repobility-dependency-currency", "fingerprint": "1d063959636bc428bdc42658dcc9634708ce009368100c4d92f3d9aa49b17355", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "prometheus_client", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "0.25.0", "correlation_key": "fp|1d063959636bc428bdc42658dcc9634708ce009368100c4d92f3d9aa49b17355", "current_version": "0.21.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 52}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `platformdirs` is minor version(s) behind (4.9.2 -> 4.10.0)"}, "properties": {"repobilityId": 224676, "scanner": "repobility-dependency-currency", "fingerprint": "6e546b5a21c33be294c4242a69e55bcacba5e8f9d501f7381d11672a24f9588d", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "platformdirs", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "4.10.0", "correlation_key": "fp|6e546b5a21c33be294c4242a69e55bcacba5e8f9d501f7381d11672a24f9588d", "current_version": "4.9.2"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 51}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `packaging` is minor version(s) behind (26.0 -> 26.2)"}, "properties": {"repobilityId": 224674, "scanner": "repobility-dependency-currency", "fingerprint": "f26d7d616beb8c2cf02ee0470c49f5d076da05e3a318468ac5e6e1eb99a86977", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "packaging", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "26.2", "correlation_key": "fp|f26d7d616beb8c2cf02ee0470c49f5d076da05e3a318468ac5e6e1eb99a86977", "current_version": "26.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 48}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `openai` is minor version(s) behind (2.24.0 -> 2.41.1)"}, "properties": {"repobilityId": 224673, "scanner": "repobility-dependency-currency", "fingerprint": "abe41c0ca5c49588aea5a2312313c46117516f9ca74ce19c731f1e2ff4f2b295", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "openai", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "2.41.1", "correlation_key": "fp|abe41c0ca5c49588aea5a2312313c46117516f9ca74ce19c731f1e2ff4f2b295", "current_version": "2.24.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 45}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `mdit-py-plugins` is minor version(s) behind (0.5.0 -> 0.6.1)"}, "properties": {"repobilityId": 224672, "scanner": "repobility-dependency-currency", "fingerprint": "547693f697a56e09a8d1e227a31cfed2f8562447b0febb5b8f78d114d00d0320", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "mdit-py-plugins", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "0.6.1", "correlation_key": "fp|547693f697a56e09a8d1e227a31cfed2f8562447b0febb5b8f78d114d00d0320", "current_version": "0.5.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 41}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `markdown-it-py` is minor version(s) behind (4.0.0 -> 4.2.0)"}, "properties": {"repobilityId": 224671, "scanner": "repobility-dependency-currency", "fingerprint": "d6401cea5a0532c5148220f374f1cd3128e2dd6da3659e61235de33bdf859000", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "markdown-it-py", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "4.2.0", "correlation_key": "fp|d6401cea5a0532c5148220f374f1cd3128e2dd6da3659e61235de33bdf859000", "current_version": "4.0.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 39}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `linkify-it-py` is minor version(s) behind (2.0.3 -> 2.1.0)"}, "properties": {"repobilityId": 224670, "scanner": "repobility-dependency-currency", "fingerprint": "765e93c51e6b52f9fb3a0d4077d9eb7ba15e742526b2dcf6a3840236ba482c5f", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "linkify-it-py", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "2.1.0", "correlation_key": "fp|765e93c51e6b52f9fb3a0d4077d9eb7ba15e742526b2dcf6a3840236ba482c5f", "current_version": "2.0.3"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 37}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `kiwisolver` is minor version(s) behind (1.4.9 -> 1.5.0)"}, "properties": {"repobilityId": 224669, "scanner": "repobility-dependency-currency", "fingerprint": "6ac7aec1578f8245ebf0caaed18da3b2e29df48571f5f56e5d8e99852910eea5", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "kiwisolver", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "1.5.0", "correlation_key": "fp|6ac7aec1578f8245ebf0caaed18da3b2e29df48571f5f56e5d8e99852910eea5", "current_version": "1.4.9"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 36}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `jiter` is minor version(s) behind (0.13.0 -> 0.15.0)"}, "properties": {"repobilityId": 224668, "scanner": "repobility-dependency-currency", "fingerprint": "3f44bffb9749ac53c2934a8b236448acdc0f971837e82f2091dee36eccd604f8", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "jiter", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "0.15.0", "correlation_key": "fp|3f44bffb9749ac53c2934a8b236448acdc0f971837e82f2091dee36eccd604f8", "current_version": "0.13.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 35}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `idna` is minor version(s) behind (3.11 -> 3.18)"}, "properties": {"repobilityId": 224667, "scanner": "repobility-dependency-currency", "fingerprint": "d6ca22b7d19af951a87c4dc0eb6a401ea94aa2b44198ae5eff7c18d58d476310", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "idna", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "3.18", "correlation_key": "fp|d6ca22b7d19af951a87c4dc0eb6a401ea94aa2b44198ae5eff7c18d58d476310", "current_version": "3.11"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 34}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `djangorestframework` is minor version(s) behind (3.16.1 -> 3.17.1)"}, "properties": {"repobilityId": 224665, "scanner": "repobility-dependency-currency", "fingerprint": "e7ae7fec6e662c75b880af447d97bab4b7cc62ebfc52569fa00a4bc63c93066d", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "djangorestframework", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "3.17.1", "correlation_key": "fp|e7ae7fec6e662c75b880af447d97bab4b7cc62ebfc52569fa00a4bc63c93066d", "current_version": "3.16.1"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 24}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `django-tenants` is minor version(s) behind (3.9.0 -> 3.10.1)"}, "properties": {"repobilityId": 224664, "scanner": "repobility-dependency-currency", "fingerprint": "d1a621e532e4d222977c8c5a3d374dd796a479ee1070cadf9bfe75a5533d00f2", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "django-tenants", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "3.10.1", "correlation_key": "fp|d1a621e532e4d222977c8c5a3d374dd796a479ee1070cadf9bfe75a5533d00f2", "current_version": "3.9.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 23}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `dj-database-url` is minor version(s) behind (3.0.1 -> 3.1.2)"}, "properties": {"repobilityId": 224659, "scanner": "repobility-dependency-currency", "fingerprint": "b09a89fbe18d89a559847b67b6d29ad63260c6cf1b6ca071180fecd03ac0bcf7", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "dj-database-url", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "3.1.2", "correlation_key": "fp|b09a89fbe18d89a559847b67b6d29ad63260c6cf1b6ca071180fecd03ac0bcf7", "current_version": "3.0.1"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 15}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `certifi` is minor version(s) behind (2026.2.25 -> 2026.5.20)"}, "properties": {"repobilityId": 224657, "scanner": "repobility-dependency-currency", "fingerprint": "fa496907e74da0c09f478665328f232c310652b0fac540eb06049d70656fb1f8", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "certifi", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "2026.5.20", "correlation_key": "fp|fa496907e74da0c09f478665328f232c310652b0fac540eb06049d70656fb1f8", "current_version": "2026.2.25"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 7}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `beautifulsoup4` is minor version(s) behind (4.14.3 -> 4.15.0)"}, "properties": {"repobilityId": 224656, "scanner": "repobility-dependency-currency", "fingerprint": "80550def09cf60f461fd7e66c27c0be1e1eaa5721f0e18783954368554ef1209", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "beautifulsoup4", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "4.15.0", "correlation_key": "fp|80550def09cf60f461fd7e66c27c0be1e1eaa5721f0e18783954368554ef1209", "current_version": "4.14.3"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 6}}}]}, {"ruleId": "DEPCUR-PY", "level": "note", "message": {"text": "Python package `anyio` is minor version(s) behind (4.12.1 -> 4.14.0)"}, "properties": {"repobilityId": 224654, "scanner": "repobility-dependency-currency", "fingerprint": "2063c321ae619aa127265ea84bc810811732e3b2993d0bc155127012237250c4", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "anyio", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "4.14.0", "correlation_key": "fp|2063c321ae619aa127265ea84bc810811732e3b2993d0bc155127012237250c4", "current_version": "4.12.1"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 2}}}]}, {"ruleId": "MINED116", "level": "note", "message": {"text": "Workflow references `secrets.SLACK_WEBHOOK` in a `pull_request` workflow"}, "properties": {"repobilityId": 224651, "scanner": "repobility-supply-chain", "fingerprint": "e4554389854e5544240e079d058645605f8befc00dac4555a69e226087e54e9f", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-pull-request-secrets", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|e4554389854e5544240e079d058645605f8befc00dac4555a69e226087e54e9f"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/backend-ci.yml"}, "region": {"startLine": 273}}}]}, {"ruleId": "MINED116", "level": "note", "message": {"text": "Workflow references `secrets.DIGITALOCEAN_ACCESS_TOKEN` in a `pull_request` workflow"}, "properties": {"repobilityId": 224650, "scanner": "repobility-supply-chain", "fingerprint": "853caae36657f925d460d4e4d7061364b89d703a19ff0fcd70672fb6ef3976a2", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-pull-request-secrets", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|853caae36657f925d460d4e4d7061364b89d703a19ff0fcd70672fb6ef3976a2"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/backend-ci.yml"}, "region": {"startLine": 265}}}]}, {"ruleId": "MINED116", "level": "note", "message": {"text": "Workflow references `secrets.PRODUCTION_DATABASE_URL` in a `pull_request` workflow"}, "properties": {"repobilityId": 224649, "scanner": "repobility-supply-chain", "fingerprint": "025bafeda9e15f8bd5cff53deca14c1d2abe3f0db72eca967b263ba9ba9c1060", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-pull-request-secrets", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|025bafeda9e15f8bd5cff53deca14c1d2abe3f0db72eca967b263ba9ba9c1060"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/backend-ci.yml"}, "region": {"startLine": 255}}}]}, {"ruleId": "MINED116", "level": "note", "message": {"text": "Workflow references `secrets.DIGITALOCEAN_ACCESS_TOKEN` in a `pull_request` workflow"}, "properties": {"repobilityId": 224648, "scanner": "repobility-supply-chain", "fingerprint": "7135090af8f00f8e3314e4746035a18f532f58b8f1fc6624e0c64efec5c8d41c", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-pull-request-secrets", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|7135090af8f00f8e3314e4746035a18f532f58b8f1fc6624e0c64efec5c8d41c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/backend-ci.yml"}, "region": {"startLine": 228}}}]}, {"ruleId": "MINED116", "level": "note", "message": {"text": "Workflow references `secrets.STAGING_DATABASE_URL` in a `pull_request` workflow"}, "properties": {"repobilityId": 224647, "scanner": "repobility-supply-chain", "fingerprint": "d18c5fcbd289366954a9d4e95aa1a60384c4271e60463230a7c714e7b79b6fa5", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-pull-request-secrets", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|d18c5fcbd289366954a9d4e95aa1a60384c4271e60463230a7c714e7b79b6fa5"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/backend-ci.yml"}, "region": {"startLine": 218}}}]}, {"ruleId": "MINED116", "level": "note", "message": {"text": "Workflow references `secrets.DOCKER_USERNAME` in a `pull_request` workflow"}, "properties": {"repobilityId": 224646, "scanner": "repobility-supply-chain", "fingerprint": "e586d9f8737ef659948920da279a9834e81c22eeb7d908b416dc0e4c2444d680", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-pull-request-secrets", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|e586d9f8737ef659948920da279a9834e81c22eeb7d908b416dc0e4c2444d680"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/backend-ci.yml"}, "region": {"startLine": 194}}}]}, {"ruleId": "MINED116", "level": "note", "message": {"text": "Workflow references `secrets.DOCKER_USERNAME` in a `pull_request` workflow"}, "properties": {"repobilityId": 224645, "scanner": "repobility-supply-chain", "fingerprint": "70718ce7637a3f571f72bd33c47553ebd3f73cd035695bcd38451a23455e4aaf", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-pull-request-secrets", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|70718ce7637a3f571f72bd33c47553ebd3f73cd035695bcd38451a23455e4aaf"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/backend-ci.yml"}, "region": {"startLine": 193}}}]}, {"ruleId": "MINED116", "level": "note", "message": {"text": "Workflow references `secrets.DOCKER_USERNAME` in a `pull_request` workflow"}, "properties": {"repobilityId": 224644, "scanner": "repobility-supply-chain", "fingerprint": "ed6c4927face4a1e0717b82a5815e1ce9d9aeb2eda011dcdbeacf9ce77481a50", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-pull-request-secrets", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|ed6c4927face4a1e0717b82a5815e1ce9d9aeb2eda011dcdbeacf9ce77481a50"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/backend-ci.yml"}, "region": {"startLine": 192}}}]}, {"ruleId": "MINED116", "level": "note", "message": {"text": "Workflow references `secrets.DOCKER_USERNAME` in a `pull_request` workflow"}, "properties": {"repobilityId": 224643, "scanner": "repobility-supply-chain", "fingerprint": "5a22ae7b9a1cb9cd996ca63155bc30cd4792b5591e3cb09ececa9667ca4366ea", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-pull-request-secrets", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|5a22ae7b9a1cb9cd996ca63155bc30cd4792b5591e3cb09ececa9667ca4366ea"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/backend-ci.yml"}, "region": {"startLine": 191}}}]}, {"ruleId": "MINED116", "level": "note", "message": {"text": "Workflow references `secrets.DOCKER_PASSWORD` in a `pull_request` workflow"}, "properties": {"repobilityId": 224642, "scanner": "repobility-supply-chain", "fingerprint": "080bd634750ff03cacc5abe6367bdf5e640913d3ee60fd58725f177830a6ab7c", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-pull-request-secrets", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|080bd634750ff03cacc5abe6367bdf5e640913d3ee60fd58725f177830a6ab7c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/backend-ci.yml"}, "region": {"startLine": 183}}}]}, {"ruleId": "MINED116", "level": "note", "message": {"text": "Workflow references `secrets.DOCKER_USERNAME` in a `pull_request` workflow"}, "properties": {"repobilityId": 224641, "scanner": "repobility-supply-chain", "fingerprint": "67cda3630e4c97f7c10c5876359efef74735cbee2627a2959a30cb038e995eac", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-pull-request-secrets", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|67cda3630e4c97f7c10c5876359efef74735cbee2627a2959a30cb038e995eac"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/backend-ci.yml"}, "region": {"startLine": 182}}}]}, {"ruleId": "MINED116", "level": "note", "message": {"text": "Workflow references `secrets.SLACK_WEBHOOK` in a `pull_request` workflow"}, "properties": {"repobilityId": 224640, "scanner": "repobility-supply-chain", "fingerprint": "5cc46de8014d8a0012e8c061f3251a2c54e4fc0028e6928e0513fa084292ada0", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-pull-request-secrets", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|5cc46de8014d8a0012e8c061f3251a2c54e4fc0028e6928e0513fa084292ada0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 270}}}]}, {"ruleId": "MINED116", "level": "note", "message": {"text": "Workflow references `secrets.VERCEL_PROJECT_ID` in a `pull_request` workflow"}, "properties": {"repobilityId": 224639, "scanner": "repobility-supply-chain", "fingerprint": "7a1a7e5238204fc1850cce47c00da2814c5d6fb4a88f497866b280c21afe4f93", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-pull-request-secrets", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|7a1a7e5238204fc1850cce47c00da2814c5d6fb4a88f497866b280c21afe4f93"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 260}}}]}, {"ruleId": "MINED116", "level": "note", "message": {"text": "Workflow references `secrets.VERCEL_ORG_ID` in a `pull_request` workflow"}, "properties": {"repobilityId": 224638, "scanner": "repobility-supply-chain", "fingerprint": "09ecca433f91cb3cd2544a6025025ce0596fc1e84ecf54de9ddf0f292e6c8f59", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-pull-request-secrets", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|09ecca433f91cb3cd2544a6025025ce0596fc1e84ecf54de9ddf0f292e6c8f59"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 259}}}]}, {"ruleId": "MINED116", "level": "note", "message": {"text": "Workflow references `secrets.VERCEL_TOKEN` in a `pull_request` workflow"}, "properties": {"repobilityId": 224637, "scanner": "repobility-supply-chain", "fingerprint": "e987d8cfdd269786ca8ad03299e175de45fdf6a5c6de888aefe9948dfb7a15dd", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-pull-request-secrets", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|e987d8cfdd269786ca8ad03299e175de45fdf6a5c6de888aefe9948dfb7a15dd"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 258}}}]}, {"ruleId": "MINED116", "level": "note", "message": {"text": "Workflow references `secrets.VERCEL_PROJECT_ID` in a `pull_request` workflow"}, "properties": {"repobilityId": 224636, "scanner": "repobility-supply-chain", "fingerprint": "c8ea65201f921edc8964a2ea17935c1fca8cdb1b429e8349ad06e7be98a18e9a", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-pull-request-secrets", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|c8ea65201f921edc8964a2ea17935c1fca8cdb1b429e8349ad06e7be98a18e9a"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 240}}}]}, {"ruleId": "MINED116", "level": "note", "message": {"text": "Workflow references `secrets.VERCEL_ORG_ID` in a `pull_request` workflow"}, "properties": {"repobilityId": 224635, "scanner": "repobility-supply-chain", "fingerprint": "83aac6acbcbd79867a6bcb162995d76703f283bdba3a31852bcade21376a9382", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-pull-request-secrets", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|83aac6acbcbd79867a6bcb162995d76703f283bdba3a31852bcade21376a9382"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 239}}}]}, {"ruleId": "MINED116", "level": "note", "message": {"text": "Workflow references `secrets.VERCEL_TOKEN` in a `pull_request` workflow"}, "properties": {"repobilityId": 224634, "scanner": "repobility-supply-chain", "fingerprint": "84157a713893eebd60aef8ce62d634cd7b9292e1d52366ddb9eda370b15be987", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-pull-request-secrets", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|84157a713893eebd60aef8ce62d634cd7b9292e1d52366ddb9eda370b15be987"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 238}}}]}, {"ruleId": "MINED116", "level": "note", "message": {"text": "Workflow references `secrets.VERCEL_PROJECT_ID` in a `pull_request` workflow"}, "properties": {"repobilityId": 224633, "scanner": "repobility-supply-chain", "fingerprint": "7f9b5b440dbde4ddec48711a354f57e5bcaf197329f53275373f285056c949f0", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-pull-request-secrets", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|7f9b5b440dbde4ddec48711a354f57e5bcaf197329f53275373f285056c949f0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 212}}}]}, {"ruleId": "MINED116", "level": "note", "message": {"text": "Workflow references `secrets.VERCEL_ORG_ID` in a `pull_request` workflow"}, "properties": {"repobilityId": 224632, "scanner": "repobility-supply-chain", "fingerprint": "f6344d925d0a5cbf55e5652ea430782b652ca81b6375ca4e2d4ea7adae4960e9", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-pull-request-secrets", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|f6344d925d0a5cbf55e5652ea430782b652ca81b6375ca4e2d4ea7adae4960e9"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 211}}}]}, {"ruleId": "MINED116", "level": "note", "message": {"text": "Workflow references `secrets.VERCEL_TOKEN` in a `pull_request` workflow"}, "properties": {"repobilityId": 224631, "scanner": "repobility-supply-chain", "fingerprint": "e846a6717ecb1852d3a7ca1f0e13dcfec8a228eeb565edb4995e40dd0a824fd0", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-pull-request-secrets", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|e846a6717ecb1852d3a7ca1f0e13dcfec8a228eeb565edb4995e40dd0a824fd0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 210}}}]}, {"ruleId": "MINED116", "level": "note", "message": {"text": "Workflow references `secrets.SNYK_TOKEN` in a `pull_request` workflow"}, "properties": {"repobilityId": 224630, "scanner": "repobility-supply-chain", "fingerprint": "4768835370f9249d08e6c8bccc2a3a5ccf7ec5d8ef72313bc03bd7dc745c4f76", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-pull-request-secrets", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|4768835370f9249d08e6c8bccc2a3a5ccf7ec5d8ef72313bc03bd7dc745c4f76"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 194}}}]}, {"ruleId": "MINED116", "level": "note", "message": {"text": "Workflow references `secrets.NEXT_PUBLIC_API_URL` in a `pull_request` workflow"}, "properties": {"repobilityId": 224629, "scanner": "repobility-supply-chain", "fingerprint": "fee0103a32e7456959465224c1846315ec2d567719f32b34dc00c49e94d9a379", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-pull-request-secrets", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|fee0103a32e7456959465224c1846315ec2d567719f32b34dc00c49e94d9a379"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 172}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/checkout` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 224627, "scanner": "repobility-supply-chain", "fingerprint": "2a55c8fc6f5db8c04c911b925b30e17a314b8ffda9c286c013ad4cf37d1270d9", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|2a55c8fc6f5db8c04c911b925b30e17a314b8ffda9c286c013ad4cf37d1270d9"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 233}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/github-script` pinned to mutable ref `@v7`"}, "properties": {"repobilityId": 224626, "scanner": "repobility-supply-chain", "fingerprint": "bdaffe60c713bd6ec400814a97e82eb891cd5e0f9acbc93298b8ad1651dc00bc", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|bdaffe60c713bd6ec400814a97e82eb891cd5e0f9acbc93298b8ad1651dc00bc"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 216}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/checkout` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 224624, "scanner": "repobility-supply-chain", "fingerprint": "f94a513edebbf50008a2bdc1b8e986dda5c5031ef050183f043d17eb56672d18", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|f94a513edebbf50008a2bdc1b8e986dda5c5031ef050183f043d17eb56672d18"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 205}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/checkout` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 224622, "scanner": "repobility-supply-chain", "fingerprint": "5e6725ff411716003a0893d5242401ee119b6a8f4d1d299e2efdee1d0bdf102a", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|5e6725ff411716003a0893d5242401ee119b6a8f4d1d299e2efdee1d0bdf102a"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 188}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/cache` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 224621, "scanner": "repobility-supply-chain", "fingerprint": "db8698f4ddc04dd6a8b3d977d628a86a9367423ec49c96a7bb88c1b4cf0a5e33", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|db8698f4ddc04dd6a8b3d977d628a86a9367423ec49c96a7bb88c1b4cf0a5e33"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 158}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/setup-node` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 224620, "scanner": "repobility-supply-chain", "fingerprint": "0e5571b7cf0d4b420da43b8aa71835b20cf3135f3887d3cf5f88ffb3f4112372", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|0e5571b7cf0d4b420da43b8aa71835b20cf3135f3887d3cf5f88ffb3f4112372"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 153}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/checkout` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 224619, "scanner": "repobility-supply-chain", "fingerprint": "ed2557b5e070e6859d41f207b25e9a305d1c13db8de5cb132b8ab1072860ea97", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|ed2557b5e070e6859d41f207b25e9a305d1c13db8de5cb132b8ab1072860ea97"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 150}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/cache` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 224617, "scanner": "repobility-supply-chain", "fingerprint": "917230b94ffa1b4deebe7056cb0cac523ad60e7fd32afa5ae9ba724ff32d2a2d", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|917230b94ffa1b4deebe7056cb0cac523ad60e7fd32afa5ae9ba724ff32d2a2d"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 115}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/setup-node` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 224616, "scanner": "repobility-supply-chain", "fingerprint": "1579a2b85561f1552ee2553d6714420c4a1376c9615d7a96d18a06af6080d11b", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|1579a2b85561f1552ee2553d6714420c4a1376c9615d7a96d18a06af6080d11b"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 110}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/checkout` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 224615, "scanner": "repobility-supply-chain", "fingerprint": "09d93ab4941c657b1a9fa93140690940468859ba56a028bd4ad470ba4dd8c180", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|09d93ab4941c657b1a9fa93140690940468859ba56a028bd4ad470ba4dd8c180"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 107}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/cache` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 224614, "scanner": "repobility-supply-chain", "fingerprint": "c85249a3d279152993409e64ddc8d57b679da745817fb9b27ddc532713415e6e", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|c85249a3d279152993409e64ddc8d57b679da745817fb9b27ddc532713415e6e"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 84}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/setup-node` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 224613, "scanner": "repobility-supply-chain", "fingerprint": "b258aee6a0da2411e1e77a03ec42c4b523e1d511b21a0f3f64792126314a48e4", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|b258aee6a0da2411e1e77a03ec42c4b523e1d511b21a0f3f64792126314a48e4"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 79}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/checkout` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 224612, "scanner": "repobility-supply-chain", "fingerprint": "6dfd629fc39b8e5822c18737d5167ea37da1bf8ae94dc9f6c494af347ec57dc0", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|6dfd629fc39b8e5822c18737d5167ea37da1bf8ae94dc9f6c494af347ec57dc0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 76}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/cache` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 224611, "scanner": "repobility-supply-chain", "fingerprint": "64b5c5ffdfdb824e11aaf74f367ffe28994bf23463549933a33d132510c1206f", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|64b5c5ffdfdb824e11aaf74f367ffe28994bf23463549933a33d132510c1206f"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 48}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/setup-node` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 224610, "scanner": "repobility-supply-chain", "fingerprint": "648d2d3e9dbf348c693d045acdde81a60d7d16dd2d5c60981d96012be87add67", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|648d2d3e9dbf348c693d045acdde81a60d7d16dd2d5c60981d96012be87add67"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 43}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/checkout` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 224609, "scanner": "repobility-supply-chain", "fingerprint": "b7befed032073f7a464588e33aaff28b517aa090e0c787d63352c95eb11cac6a", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|b7befed032073f7a464588e33aaff28b517aa090e0c787d63352c95eb11cac6a"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 40}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/setup-node` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 224608, "scanner": "repobility-supply-chain", "fingerprint": "4ac51750db818d13d40dffba1911367b4278190f07614f210f0c871ea46603ff", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|4ac51750db818d13d40dffba1911367b4278190f07614f210f0c871ea46603ff"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 24}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/checkout` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 224607, "scanner": "repobility-supply-chain", "fingerprint": "db2bd75ccd25b7245933f9db24d2b52f321b472bf15efd00b21e9998a025240e", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|db2bd75ccd25b7245933f9db24d2b52f321b472bf15efd00b21e9998a025240e"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 21}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/upload-artifact` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 224606, "scanner": "repobility-supply-chain", "fingerprint": "9197b8cb12b45c6e48c4af198aee3b270335310ecac53ba764846b533fb817c9", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|9197b8cb12b45c6e48c4af198aee3b270335310ecac53ba764846b533fb817c9"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/playwright.yml"}, "region": {"startLine": 37}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/setup-node` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 224605, "scanner": "repobility-supply-chain", "fingerprint": "6caacd07944f53423003be2007d327ef4f59b4dfb4ff561111e3acbfd6ce0216", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|6caacd07944f53423003be2007d327ef4f59b4dfb4ff561111e3acbfd6ce0216"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/playwright.yml"}, "region": {"startLine": 28}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/checkout` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 224604, "scanner": "repobility-supply-chain", "fingerprint": "8ecb3c2d5f41652dddaa77a2ef5fdd864800fecff83cf875081467d43e4e122f", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|8ecb3c2d5f41652dddaa77a2ef5fdd864800fecff83cf875081467d43e4e122f"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/playwright.yml"}, "region": {"startLine": 27}}}]}, {"ruleId": "AIC005", "level": "note", "message": {"text": "Duplicate top-level symbol appears in a patch-style file"}, "properties": {"repobilityId": 224450, "scanner": "repobility-ai-code-hygiene", "fingerprint": "0ec2be822b38a3d980ebf2ec07fc8f86bad3ac1b763ac67ae5ca74d561ff3ccc", "category": "quality", "severity": "low", "confidence": 0.64, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Patch-style file defines a top-level symbol also defined in another source file.", "evidence": {"symbol": "get_token", "rule_id": "AIC005", "scanner": "repobility-ai-code-hygiene", "references": ["https://github.com/jendrikseipp/vulture", "https://knip.dev/"], "duplicate_file": "backend/scripts/verify_admin_panel.py", "correlation_key": "fp|0ec2be822b38a3d980ebf2ec07fc8f86bad3ac1b763ac67ae5ca74d561ff3ccc"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/verify_teacher_fix.py"}, "region": {"startLine": 1}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224448, "scanner": "repobility-ai-code-hygiene", "fingerprint": "1729a17c09a72fe60ece537f64403681fa9a565bc216dd9d725dcbf92d39f96c", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/scripts/create_tables_v3.py", "duplicate_line": 79, "correlation_key": "fp|1729a17c09a72fe60ece537f64403681fa9a565bc216dd9d725dcbf92d39f96c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/fix_tables_now.py"}, "region": {"startLine": 5}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224447, "scanner": "repobility-ai-code-hygiene", "fingerprint": "202886344205594cf8fb0b30b8d6af8806538cb78bdcfc0836ba4b9e005111cd", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/scripts/create_tables_v2.py", "duplicate_line": 36, "correlation_key": "fp|202886344205594cf8fb0b30b8d6af8806538cb78bdcfc0836ba4b9e005111cd"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/fix_library_migration.py"}, "region": {"startLine": 60}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224445, "scanner": "repobility-ai-code-hygiene", "fingerprint": "07c18930947389eb020a57a8629791a6949390cc25802bb6274625650553f038", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/scripts/create_library_tables_final.py", "duplicate_line": 67, "correlation_key": "fp|07c18930947389eb020a57a8629791a6949390cc25802bb6274625650553f038"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/fix_library_migration.py"}, "region": {"startLine": 59}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224443, "scanner": "repobility-ai-code-hygiene", "fingerprint": "d7dd7bb5468c94a0ea990f788de7b3b5cf7f88a8ba9e6f9e29407d1f2b750cbb", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/scripts/create_library_tables.py", "duplicate_line": 11, "correlation_key": "fp|d7dd7bb5468c94a0ea990f788de7b3b5cf7f88a8ba9e6f9e29407d1f2b750cbb"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/fix_library_migration.py"}, "region": {"startLine": 42}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224440, "scanner": "repobility-ai-code-hygiene", "fingerprint": "ec9146ea73066b413427dc20d1600f1701f45611425060983e1b5a5b3866b7b5", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/scripts/create_tables_direct.py", "duplicate_line": 18, "correlation_key": "fp|ec9146ea73066b413427dc20d1600f1701f45611425060983e1b5a5b3866b7b5"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/create_via_django.py"}, "region": {"startLine": 17}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224437, "scanner": "repobility-ai-code-hygiene", "fingerprint": "e9b9a5b01305644dc955087b33bcea519c21d681fbecb5ea705a1bc2f003fb35", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/scripts/create_library_tables_final.py", "duplicate_line": 46, "correlation_key": "fp|e9b9a5b01305644dc955087b33bcea519c21d681fbecb5ea705a1bc2f003fb35"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/create_via_django.py"}, "region": {"startLine": 13}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224435, "scanner": "repobility-ai-code-hygiene", "fingerprint": "63f42dd583dfae4fab968123993747014fed035efa7912c2fd270b8560989ba8", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/scripts/create_library_tables_final.py", "duplicate_line": 46, "correlation_key": "fp|63f42dd583dfae4fab968123993747014fed035efa7912c2fd270b8560989ba8"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/create_tables_v3.py"}, "region": {"startLine": 81}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224434, "scanner": "repobility-ai-code-hygiene", "fingerprint": "449e3cac80c21760ea19d598af4ca34f2a7687a16b57bdb6a9b12feabb025655", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/scripts/create_tables_v2.py", "duplicate_line": 61, "correlation_key": "fp|449e3cac80c21760ea19d598af4ca34f2a7687a16b57bdb6a9b12feabb025655"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/create_tables_v3.py"}, "region": {"startLine": 24}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224432, "scanner": "repobility-ai-code-hygiene", "fingerprint": "fcd5a39116048fa187d3c92dca4ceba50d4333d630ebfd8f52f021febce721a9", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/scripts/create_library_tables_final.py", "duplicate_line": 46, "correlation_key": "fp|fcd5a39116048fa187d3c92dca4ceba50d4333d630ebfd8f52f021febce721a9"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/create_tables_v2.py"}, "region": {"startLine": 15}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224431, "scanner": "repobility-ai-code-hygiene", "fingerprint": "6a1262cf5374949635cfe7fc20a4c897e8e91a4ba12fa310d9ad10adb95383e3", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/scripts/create_library_tables_final.py", "duplicate_line": 46, "correlation_key": "fp|6a1262cf5374949635cfe7fc20a4c897e8e91a4ba12fa310d9ad10adb95383e3"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/create_tables_direct.py"}, "region": {"startLine": 14}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224425, "scanner": "repobility-ai-code-hygiene", "fingerprint": "56d95ccc453217edc345010e38b00c399525f9341a2b0b17f944521a889728d0", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/scripts/create_library_tables_final.py", "duplicate_line": 46, "correlation_key": "fp|56d95ccc453217edc345010e38b00c399525f9341a2b0b17f944521a889728d0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/create_library_tables_simple.py"}, "region": {"startLine": 16}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224417, "scanner": "repobility-ai-code-hygiene", "fingerprint": "77bacffb9b29ec60e4275b36fb78e0860ff8fabfb0fb1adac31985eb61b7f3f2", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/scripts/create_library_tables_final.py", "duplicate_line": 53, "correlation_key": "fp|77bacffb9b29ec60e4275b36fb78e0860ff8fabfb0fb1adac31985eb61b7f3f2"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/create_library_tables.py"}, "region": {"startLine": 17}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224415, "scanner": "repobility-ai-code-hygiene", "fingerprint": "1c3849400a3e8fe4ad3c4e001982ebe79cd57a40213062638eaadfe8b2bd1264", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/ai_engine/tests_async_queue.py", "duplicate_line": 37, "correlation_key": "fp|1c3849400a3e8fe4ad3c4e001982ebe79cd57a40213062638eaadfe8b2bd1264"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/notifications/tests_async_delivery.py"}, "region": {"startLine": 67}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224413, "scanner": "repobility-ai-code-hygiene", "fingerprint": "0acc9afc22f53e6b681f9517c6bf1b4dea6fe72079275aa0f8161f2cce96e9c3", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/core/tenant_isolation_base.py", "duplicate_line": 61, "correlation_key": "fp|0acc9afc22f53e6b681f9517c6bf1b4dea6fe72079275aa0f8161f2cce96e9c3"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/tests_tenant_isolation.py"}, "region": {"startLine": 45}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224408, "scanner": "repobility-ai-code-hygiene", "fingerprint": "68ae18987a2364831d869bb78ff928b63e8d6d97cc89b00b180aafa7e2d4908a", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/billing/urls.py", "duplicate_line": 11, "correlation_key": "fp|68ae18987a2364831d869bb78ff928b63e8d6d97cc89b00b180aafa7e2d4908a"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_saas/urls.py"}, "region": {"startLine": 7}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224406, "scanner": "repobility-ai-code-hygiene", "fingerprint": "997b8515ec38dd933a2be062ad9d5647ff600e0dd61abfeb232891f81f6167d1", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/ai_engine/services/admin_assistant_service.py", "duplicate_line": 41, "correlation_key": "fp|997b8515ec38dd933a2be062ad9d5647ff600e0dd61abfeb232891f81f6167d1"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/services/risk_analytics_service.py"}, "region": {"startLine": 275}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224403, "scanner": "repobility-ai-code-hygiene", "fingerprint": "1a73785044d70d61704951e517df9aa157111abea7172a3f275f7a9fd7d5f773", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/ai_engine/services/admin_assistant_service.py", "duplicate_line": 46, "correlation_key": "fp|1a73785044d70d61704951e517df9aa157111abea7172a3f275f7a9fd7d5f773"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/services/quiz_generator_service.py"}, "region": {"startLine": 25}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224399, "scanner": "repobility-ai-code-hygiene", "fingerprint": "58e88b2764049531180edc8d1302fcac69429b9140f557dddbdfabdd0beb1b10", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/ai_engine/services/assisted_grading_service.py", "duplicate_line": 15, "correlation_key": "fp|58e88b2764049531180edc8d1302fcac69429b9140f557dddbdfabdd0beb1b10"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/services/quiz_generator_service.py"}, "region": {"startLine": 17}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224398, "scanner": "repobility-ai-code-hygiene", "fingerprint": "ab41332eaa09ff2572cf961f18c75ce0777f56ec9b7362de921018607e10a485", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/ai_engine/services/admin_assistant_service.py", "duplicate_line": 46, "correlation_key": "fp|ab41332eaa09ff2572cf961f18c75ce0777f56ec9b7362de921018607e10a485"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/services/exam_generator_service.py"}, "region": {"startLine": 21}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224394, "scanner": "repobility-ai-code-hygiene", "fingerprint": "cd3605acea6178735af574ace49b4f1d9d9c62589e8497f24d36ba2ad263eafb", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/ai_engine/services/assisted_grading_service.py", "duplicate_line": 14, "correlation_key": "fp|cd3605acea6178735af574ace49b4f1d9d9c62589e8497f24d36ba2ad263eafb"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/services/exam_generator_service.py"}, "region": {"startLine": 12}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224393, "scanner": "repobility-ai-code-hygiene", "fingerprint": "b647b0f2203a2cda88962d40a2083512b8a76ab2ab149901dff795dd072709cb", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/ai_engine/services/admin_assistant_service.py", "duplicate_line": 46, "correlation_key": "fp|b647b0f2203a2cda88962d40a2083512b8a76ab2ab149901dff795dd072709cb"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/services/assisted_grading_service.py"}, "region": {"startLine": 23}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224392, "scanner": "repobility-ai-code-hygiene", "fingerprint": "4c4b134e12ece4bd2e8aef8b608e6e7216ff9bd48a5fb1294460bc9ea3e4e045", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/academic/views/exam.py", "duplicate_line": 44, "correlation_key": "fp|4c4b134e12ece4bd2e8aef8b608e6e7216ff9bd48a5fb1294460bc9ea3e4e045"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/views/reports.py"}, "region": {"startLine": 62}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224389, "scanner": "repobility-ai-code-hygiene", "fingerprint": "b6ead525c79ae5e49bd07dcf2c5837bd5fcab135585904689054cd9f85670fb9", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/academic/views/exam.py", "duplicate_line": 112, "correlation_key": "fp|b6ead525c79ae5e49bd07dcf2c5837bd5fcab135585904689054cd9f85670fb9"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/views/question.py"}, "region": {"startLine": 73}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224388, "scanner": "repobility-ai-code-hygiene", "fingerprint": "c5728628183d742182db924d612688a4175432605c9f7f979b2a5aa169dcf3a7", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/academic/views/assessment_core.py", "duplicate_line": 86, "correlation_key": "fp|c5728628183d742182db924d612688a4175432605c9f7f979b2a5aa169dcf3a7"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/views/question.py"}, "region": {"startLine": 64}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224387, "scanner": "repobility-ai-code-hygiene", "fingerprint": "3850f78c213ffdfa5598795001591b6757b6d3c645746e2c2ff0a09d168d5dc3", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/academic/views/assessment_core.py", "duplicate_line": 87, "correlation_key": "fp|3850f78c213ffdfa5598795001591b6757b6d3c645746e2c2ff0a09d168d5dc3"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/views/exam.py"}, "region": {"startLine": 104}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224384, "scanner": "repobility-ai-code-hygiene", "fingerprint": "d8574ed138523ec3e1b76cd63d2fde87ee05b26696fb4db58a1769f109612973", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/academic/tests_class_subject_visibility.py", "duplicate_line": 12, "correlation_key": "fp|d8574ed138523ec3e1b76cd63d2fde87ee05b26696fb4db58a1769f109612973"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/tests_exam_rbac.py"}, "region": {"startLine": 21}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224383, "scanner": "repobility-ai-code-hygiene", "fingerprint": "37fc8b9f1a9dfdca1fa2c84424b189412e3643cddda051572c92ef5ad0e20c67", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/academic/tests_assessment_rbac.py", "duplicate_line": 20, "correlation_key": "fp|37fc8b9f1a9dfdca1fa2c84424b189412e3643cddda051572c92ef5ad0e20c67"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/tests_exam_rbac.py"}, "region": {"startLine": 19}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224381, "scanner": "repobility-ai-code-hygiene", "fingerprint": "4b83ab53808c5d757c8b40c4b48742460c0392e26a21bd459d030c6a2fe1f4dc", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/academic/tests_assessment_rbac.py", "duplicate_line": 20, "correlation_key": "fp|4b83ab53808c5d757c8b40c4b48742460c0392e26a21bd459d030c6a2fe1f4dc"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/tests_class_subject_visibility.py"}, "region": {"startLine": 10}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224378, "scanner": "repobility-ai-code-hygiene", "fingerprint": "732897ca3e71dd436a5f720226279d4f59ac46134b59141de1a3c80f5eee56e1", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/academic/tests_assessment_rbac.py", "duplicate_line": 66, "correlation_key": "fp|732897ca3e71dd436a5f720226279d4f59ac46134b59141de1a3c80f5eee56e1"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/tests_audit_logging.py"}, "region": {"startLine": 39}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 224375, "scanner": "repobility-ai-code-hygiene", "fingerprint": "4ee08988b3d5e3d249347aae8b354db15ea8fd1b6ae8f6b14dfb384fda222716", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "backend/academic/tests_assessment_rbac.py", "duplicate_line": 79, "correlation_key": "fp|4ee08988b3d5e3d249347aae8b354db15ea8fd1b6ae8f6b14dfb384fda222716"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/tests_attendance_rbac.py"}, "region": {"startLine": 51}}}]}, {"ruleId": "AIC002", "level": "note", "message": {"text": "Source file name looks like an AI patch artifact"}, "properties": {"repobilityId": 224372, "scanner": "repobility-ai-code-hygiene", "fingerprint": "1fffb306342ca7228133c9802d84be62db3b400eebf7648f2f93e905730337c5", "category": "quality", "severity": "low", "confidence": 0.62, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Source filename contains a temporary or patch-style suffix.", "evidence": {"suffix": "fix", "rule_id": "AIC002", "scanner": "repobility-ai-code-hygiene", "references": ["https://arxiv.org/abs/2601.15195"], "correlation_key": "fp|1fffb306342ca7228133c9802d84be62db3b400eebf7648f2f93e905730337c5"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/verify_teacher_fix.py"}, "region": {"startLine": 1}}}]}, {"ruleId": "AIC002", "level": "note", "message": {"text": "Source file name looks like an AI patch artifact"}, "properties": {"repobilityId": 224367, "scanner": "repobility-ai-code-hygiene", "fingerprint": "b1ed18fef1abfb00058f78de6cc56e074cfd473243f6f9d6e8fc0501c9254f79", "category": "quality", "severity": "low", "confidence": 0.62, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Source filename contains a temporary or patch-style suffix.", "evidence": {"suffix": "backup", "rule_id": "AIC002", "scanner": "repobility-ai-code-hygiene", "references": ["https://arxiv.org/abs/2601.15195"], "correlation_key": "fp|b1ed18fef1abfb00058f78de6cc56e074cfd473243f6f9d6e8fc0501c9254f79"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/verify_backup.py"}, "region": {"startLine": 1}}}]}, {"ruleId": "MINED055", "level": "none", "message": {"text": "[MINED055] Npm Install No Lockfile: Production image runs npm install (resolves new versions on every build) instead of npm ci."}, "properties": {"repobilityId": 224822, "scanner": "repobility-threat-engine", "fingerprint": "8522448215077bb29bcaad64add4aea7a31f8b515551a0387d44130d6e79589d", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "npm-install-no-lockfile", "owasp": "A06:2021", "cwe_ids": ["CWE-1357"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348030+00:00", "triaged_in_corpus": 12, "observations_count": 317602, "ai_coder_pattern_id": 42}, "scanner": "repobility-threat-engine", "correlation_key": "fp|8522448215077bb29bcaad64add4aea7a31f8b515551a0387d44130d6e79589d"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/setup-all.sh"}, "region": {"startLine": 115}}}]}, {"ruleId": "MINED058", "level": "none", "message": {"text": "[MINED058] React Dangerously Set Html: dangerouslySetInnerHTML bypasses Reacts JSX escaping. Pair with DOMPurify or never use with user data."}, "properties": {"repobilityId": 224821, "scanner": "repobility-threat-engine", "fingerprint": "1626646eb10b7b2b3eb198dcaed1d477f9f4436dc5b6fe106821315806cbc6a7", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "react-dangerously-set-html", "owasp": "A03:2021", "cwe_ids": ["CWE-79"], "languages": ["javascript", "typescript"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348037+00:00", "triaged_in_corpus": 12, "observations_count": 255650, "ai_coder_pattern_id": 49}, "scanner": "repobility-threat-engine", "correlation_key": "fp|1626646eb10b7b2b3eb198dcaed1d477f9f4436dc5b6fe106821315806cbc6a7"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/components/ui/safe-html.tsx"}, "region": {"startLine": 27}}}]}, {"ruleId": "MINED045", "level": "none", "message": {"text": "[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError if wrong."}, "properties": {"repobilityId": 224819, "scanner": "repobility-threat-engine", "fingerprint": "7cd4a614a5a35952f7097891f4fef70d47dde7e27f1b5137b8ea19f0fc7dbd7d", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "ts-non-null-assertion", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["typescript", "tsx"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348005+00:00", "triaged_in_corpus": 12, "observations_count": 1810954, "ai_coder_pattern_id": 105}, "scanner": "repobility-threat-engine", "correlation_key": "fp|7cd4a614a5a35952f7097891f4fef70d47dde7e27f1b5137b8ea19f0fc7dbd7d"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/components/ui/layer-focus.ts"}, "region": {"startLine": 10}}}]}, {"ruleId": "MINED045", "level": "none", "message": {"text": "[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError if wrong."}, "properties": {"repobilityId": 224818, "scanner": "repobility-threat-engine", "fingerprint": "27493c82e5afc6b23ca5dec5ebcf8c7604cb600836d9d096834c4cf9cfe0d03d", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "ts-non-null-assertion", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["typescript", "tsx"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348005+00:00", "triaged_in_corpus": 12, "observations_count": 1810954, "ai_coder_pattern_id": 105}, "scanner": "repobility-threat-engine", "correlation_key": "fp|27493c82e5afc6b23ca5dec5ebcf8c7604cb600836d9d096834c4cf9cfe0d03d"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/components/service-worker-registrar.tsx"}, "region": {"startLine": 15}}}]}, {"ruleId": "MINED045", "level": "none", "message": {"text": "[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError if wrong."}, "properties": {"repobilityId": 224817, "scanner": "repobility-threat-engine", "fingerprint": "0924a9282892bb8f4ab14f0d79e539bbfdd62cf6eca3e1006867b10e3369c8f3", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "ts-non-null-assertion", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["typescript", "tsx"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348005+00:00", "triaged_in_corpus": 12, "observations_count": 1810954, "ai_coder_pattern_id": 105}, "scanner": "repobility-threat-engine", "correlation_key": "fp|0924a9282892bb8f4ab14f0d79e539bbfdd62cf6eca3e1006867b10e3369c8f3"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/student/courses/[courseId]/page.tsx"}, "region": {"startLine": 94}}}]}, {"ruleId": "SEC041", "level": "none", "message": {"text": "[SEC041] Tabnabbing \u2014 target=\"_blank\" without rel=\"noopener noreferrer\" (and 6 more): Same pattern found in 6 additional files. Review if needed."}, "properties": {"repobilityId": 224816, "scanner": "repobility-threat-engine", "fingerprint": "236b9082872ac7a42c27890199ef5179bde4d7aa3347f7072e6b3159646f3e4a", "category": "security", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 6 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"reason": "Deduplicated summary only: 6 additional occurrences found. The top occurrences remain visible as actionable findings.", "rule_id": "SEC041", "scanner": "repobility-threat-engine", "confidence": 0.2, "correlation_key": "fp|236b9082872ac7a42c27890199ef5179bde4d7aa3347f7072e6b3159646f3e4a"}}}, {"ruleId": "SEC006", "level": "none", "message": {"text": "[SEC006] XSS Risk (and 3 more): Same pattern found in 3 additional files. Review if needed."}, "properties": {"repobilityId": 224812, "scanner": "repobility-threat-engine", "fingerprint": "d9f1affcacb96541cb9dfea69fa7d055adaca1abde44138d49cbaaea5562cb22", "category": "injection", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 3 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"reason": "Deduplicated summary only: 3 additional occurrences found. The top occurrences remain visible as actionable findings.", "rule_id": "SEC006", "scanner": "repobility-threat-engine", "confidence": 0.2, "correlation_key": "fp|d9f1affcacb96541cb9dfea69fa7d055adaca1abde44138d49cbaaea5562cb22"}}}, {"ruleId": "MINED056", "level": "none", "message": {"text": "[MINED056] React Key As Index (and 30 more): Same pattern found in 30 additional files. Review if needed."}, "properties": {"repobilityId": 224808, "scanner": "repobility-threat-engine", "fingerprint": "083c83d3dbef3a6ec3bd0e13c37238fca8e9a4f708de1c372301f0d80a845d42", "category": "quality", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 30 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"mined": true, "mining": {"slug": "react-key-as-index", "owasp": null, "cwe_ids": ["CWE-682"], "languages": ["typescript", "tsx", "javascript", "jsx"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348032+00:00", "triaged_in_corpus": 12, "observations_count": 299917, "ai_coder_pattern_id": 135}, "scanner": "repobility-threat-engine", "aggregated": true, "correlation_key": "fp|083c83d3dbef3a6ec3bd0e13c37238fca8e9a4f708de1c372301f0d80a845d42", "aggregated_count": 30}}}, {"ruleId": "MINED056", "level": "none", "message": {"text": "[MINED056] React Key As Index: key={index} in map() \u2014 re-renders the wrong elements on re-order."}, "properties": {"repobilityId": 224807, "scanner": "repobility-threat-engine", "fingerprint": "65dffaf711797b2c47d99c57f2a4dfcb499b8c397737e58e501f1b758e3292d1", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "react-key-as-index", "owasp": null, "cwe_ids": ["CWE-682"], "languages": ["typescript", "tsx", "javascript", "jsx"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348032+00:00", "triaged_in_corpus": 12, "observations_count": 299917, "ai_coder_pattern_id": 135}, "scanner": "repobility-threat-engine", "correlation_key": "fp|65dffaf711797b2c47d99c57f2a4dfcb499b8c397737e58e501f1b758e3292d1"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/admin/finance/reports/bank-book/page.tsx"}, "region": {"startLine": 121}}}]}, {"ruleId": "MINED056", "level": "none", "message": {"text": "[MINED056] React Key As Index: key={index} in map() \u2014 re-renders the wrong elements on re-order."}, "properties": {"repobilityId": 224806, "scanner": "repobility-threat-engine", "fingerprint": "3414c3e0bee5d166669e0765b487f090aa661672945e115c465cd11aa823f457", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "react-key-as-index", "owasp": null, "cwe_ids": ["CWE-682"], "languages": ["typescript", "tsx", "javascript", "jsx"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348032+00:00", "triaged_in_corpus": 12, "observations_count": 299917, "ai_coder_pattern_id": 135}, "scanner": "repobility-threat-engine", "correlation_key": "fp|3414c3e0bee5d166669e0765b487f090aa661672945e115c465cd11aa823f457"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/admin/finance/reports/aging/page.tsx"}, "region": {"startLine": 144}}}]}, {"ruleId": "MINED056", "level": "none", "message": {"text": "[MINED056] React Key As Index: key={index} in map() \u2014 re-renders the wrong elements on re-order."}, "properties": {"repobilityId": 224805, "scanner": "repobility-threat-engine", "fingerprint": "b0c5c1080cd2041f8d1fbd696ec265890f4205e633ff3bcc95973d0fff0d4b1d", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "react-key-as-index", "owasp": null, "cwe_ids": ["CWE-682"], "languages": ["typescript", "tsx", "javascript", "jsx"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348032+00:00", "triaged_in_corpus": 12, "observations_count": 299917, "ai_coder_pattern_id": 135}, "scanner": "repobility-threat-engine", "correlation_key": "fp|b0c5c1080cd2041f8d1fbd696ec265890f4205e633ff3bcc95973d0fff0d4b1d"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/admin/academic/students/import-students-dialog.tsx"}, "region": {"startLine": 105}}}]}, {"ruleId": "MINED054", "level": "none", "message": {"text": "[MINED054] Ts As Any (and 17 more): Same pattern found in 17 additional files. Review if needed."}, "properties": {"repobilityId": 224804, "scanner": "repobility-threat-engine", "fingerprint": "1f38ec8ee427c878650366a6c48e200528f96ac717745ebf5485e970f5194715", "category": "quality", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 17 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"mined": true, "mining": {"slug": "ts-as-any", "owasp": null, "cwe_ids": ["CWE-704"], "languages": ["typescript", "tsx"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348028+00:00", "triaged_in_corpus": 12, "observations_count": 341218, "ai_coder_pattern_id": 98}, "scanner": "repobility-threat-engine", "aggregated": true, "correlation_key": "fp|1f38ec8ee427c878650366a6c48e200528f96ac717745ebf5485e970f5194715", "aggregated_count": 17}}}, {"ruleId": "MINED054", "level": "none", "message": {"text": "[MINED054] Ts As Any: Casting to any (as any) bypasses type checking entirely."}, "properties": {"repobilityId": 224803, "scanner": "repobility-threat-engine", "fingerprint": "0db8149f9b0a93bda60777d53aa2005a7a23efd15a22bf18007b1294acfd614b", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "ts-as-any", "owasp": null, "cwe_ids": ["CWE-704"], "languages": ["typescript", "tsx"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348028+00:00", "triaged_in_corpus": 12, "observations_count": 341218, "ai_coder_pattern_id": 98}, "scanner": "repobility-threat-engine", "correlation_key": "fp|0db8149f9b0a93bda60777d53aa2005a7a23efd15a22bf18007b1294acfd614b"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/admin/finance/PaymentDialog.tsx"}, "region": {"startLine": 200}}}]}, {"ruleId": "MINED054", "level": "none", "message": {"text": "[MINED054] Ts As Any: Casting to any (as any) bypasses type checking entirely."}, "properties": {"repobilityId": 224802, "scanner": "repobility-threat-engine", "fingerprint": "508be6917fc6f50c9839cad6b1018d447a7d371196d9affa361ddabf8394cbee", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "ts-as-any", "owasp": null, "cwe_ids": ["CWE-704"], "languages": ["typescript", "tsx"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348028+00:00", "triaged_in_corpus": 12, "observations_count": 341218, "ai_coder_pattern_id": 98}, "scanner": "repobility-threat-engine", "correlation_key": "fp|508be6917fc6f50c9839cad6b1018d447a7d371196d9affa361ddabf8394cbee"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/admin/communication/announcements/page.tsx"}, "region": {"startLine": 54}}}]}, {"ruleId": "MINED054", "level": "none", "message": {"text": "[MINED054] Ts As Any: Casting to any (as any) bypasses type checking entirely."}, "properties": {"repobilityId": 224801, "scanner": "repobility-threat-engine", "fingerprint": "b6db490a7e22c955957be039ec60f47a2851ab75ae2cbf30c403fb01bf8a660e", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "ts-as-any", "owasp": null, "cwe_ids": ["CWE-704"], "languages": ["typescript", "tsx"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348028+00:00", "triaged_in_corpus": 12, "observations_count": 341218, "ai_coder_pattern_id": 98}, "scanner": "repobility-threat-engine", "correlation_key": "fp|b6db490a7e22c955957be039ec60f47a2851ab75ae2cbf30c403fb01bf8a660e"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/admin/academic/page.tsx"}, "region": {"startLine": 69}}}]}, {"ruleId": "MINED052", "level": "none", "message": {"text": "[MINED052] Ts Any Typed (and 29 more): Same pattern found in 29 additional files. Review if needed."}, "properties": {"repobilityId": 224797, "scanner": "repobility-threat-engine", "fingerprint": "3808f6a38755825e7766258ff75e3bea14540b118dcfb7ac1f49a9562464335b", "category": "quality", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 29 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"mined": true, "mining": {"slug": "ts-any-typed", "owasp": null, "cwe_ids": ["CWE-704"], "languages": ["typescript", "tsx"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348022+00:00", "triaged_in_corpus": 12, "observations_count": 496002, "ai_coder_pattern_id": 97}, "scanner": "repobility-threat-engine", "aggregated": true, "correlation_key": "fp|3808f6a38755825e7766258ff75e3bea14540b118dcfb7ac1f49a9562464335b", "aggregated_count": 29}}}, {"ruleId": "MINED052", "level": "none", "message": {"text": "[MINED052] Ts Any Typed: : any used as type annotation. Defeats TypeScript type safety."}, "properties": {"repobilityId": 224796, "scanner": "repobility-threat-engine", "fingerprint": "1cc3de0565b101e74327f3815edb88275fc6878f0541c1371e586ebdd90d7862", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "ts-any-typed", "owasp": null, "cwe_ids": ["CWE-704"], "languages": ["typescript", "tsx"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348022+00:00", "triaged_in_corpus": 12, "observations_count": 496002, "ai_coder_pattern_id": 97}, "scanner": "repobility-threat-engine", "correlation_key": "fp|1cc3de0565b101e74327f3815edb88275fc6878f0541c1371e586ebdd90d7862"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/(auth)/verify-email/page.tsx"}, "region": {"startLine": 39}}}]}, {"ruleId": "MINED052", "level": "none", "message": {"text": "[MINED052] Ts Any Typed: : any used as type annotation. Defeats TypeScript type safety."}, "properties": {"repobilityId": 224795, "scanner": "repobility-threat-engine", "fingerprint": "8a820684b4124b4a09946093cd111d7a48bf594a97829fcccf35a4611f0d0a6c", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "ts-any-typed", "owasp": null, "cwe_ids": ["CWE-704"], "languages": ["typescript", "tsx"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348022+00:00", "triaged_in_corpus": 12, "observations_count": 496002, "ai_coder_pattern_id": 97}, "scanner": "repobility-threat-engine", "correlation_key": "fp|8a820684b4124b4a09946093cd111d7a48bf594a97829fcccf35a4611f0d0a6c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/(auth)/reset-password/page.tsx"}, "region": {"startLine": 67}}}]}, {"ruleId": "MINED052", "level": "none", "message": {"text": "[MINED052] Ts Any Typed: : any used as type annotation. Defeats TypeScript type safety."}, "properties": {"repobilityId": 224794, "scanner": "repobility-threat-engine", "fingerprint": "f40683e01c6efe1b513fd613cb0c410c1aad28ca9ad7149172a966099fa52a58", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "ts-any-typed", "owasp": null, "cwe_ids": ["CWE-704"], "languages": ["typescript", "tsx"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348022+00:00", "triaged_in_corpus": 12, "observations_count": 496002, "ai_coder_pattern_id": 97}, "scanner": "repobility-threat-engine", "correlation_key": "fp|f40683e01c6efe1b513fd613cb0c410c1aad28ca9ad7149172a966099fa52a58"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/(auth)/forgot-password/page.tsx"}, "region": {"startLine": 31}}}]}, {"ruleId": "MINED044", "level": "none", "message": {"text": "[MINED044] Js Console Log Prod (and 65 more): Same pattern found in 65 additional files. Review if needed."}, "properties": {"repobilityId": 224793, "scanner": "repobility-threat-engine", "fingerprint": "8c584a6afeb483daa894d96ed46df3d66f6c287ea5cde35191175756b61d3654", "category": "quality", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 65 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"mined": true, "mining": {"slug": "js-console-log-prod", "owasp": null, "cwe_ids": ["CWE-532"], "languages": ["javascript", "typescript", "tsx", "jsx"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348003+00:00", "triaged_in_corpus": 10, "observations_count": 1940833, "ai_coder_pattern_id": 102}, "scanner": "repobility-threat-engine", "aggregated": true, "correlation_key": "fp|8c584a6afeb483daa894d96ed46df3d66f6c287ea5cde35191175756b61d3654", "aggregated_count": 65}}}, {"ruleId": "MINED044", "level": "none", "message": {"text": "[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger or removed."}, "properties": {"repobilityId": 224792, "scanner": "repobility-threat-engine", "fingerprint": "0e5d8ec3c48d24928f24be6cd2f057698991cdc52b92ad138bff0cd8a07a3e33", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "js-console-log-prod", "owasp": null, "cwe_ids": ["CWE-532"], "languages": ["javascript", "typescript", "tsx", "jsx"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348003+00:00", "triaged_in_corpus": 10, "observations_count": 1940833, "ai_coder_pattern_id": 102}, "scanner": "repobility-threat-engine", "correlation_key": "fp|0e5d8ec3c48d24928f24be6cd2f057698991cdc52b92ad138bff0cd8a07a3e33"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/(saas)/saas/audit/page.tsx"}, "region": {"startLine": 54}}}]}, {"ruleId": "MINED044", "level": "none", "message": {"text": "[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger or removed."}, "properties": {"repobilityId": 224791, "scanner": "repobility-threat-engine", "fingerprint": "acf0a9ff31f19b8a9f545381362133487c84b89c68dba521b76cd39b6bbb686d", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "js-console-log-prod", "owasp": null, "cwe_ids": ["CWE-532"], "languages": ["javascript", "typescript", "tsx", "jsx"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348003+00:00", "triaged_in_corpus": 10, "observations_count": 1940833, "ai_coder_pattern_id": 102}, "scanner": "repobility-threat-engine", "correlation_key": "fp|acf0a9ff31f19b8a9f545381362133487c84b89c68dba521b76cd39b6bbb686d"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/(auth)/reset-password/page.tsx"}, "region": {"startLine": 68}}}]}, {"ruleId": "MINED044", "level": "none", "message": {"text": "[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger or removed."}, "properties": {"repobilityId": 224790, "scanner": "repobility-threat-engine", "fingerprint": "79b74d7f39ac3c7eeb8c2382719b9205f408e83dda64c98be8a387fbb88db766", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "js-console-log-prod", "owasp": null, "cwe_ids": ["CWE-532"], "languages": ["javascript", "typescript", "tsx", "jsx"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348003+00:00", "triaged_in_corpus": 10, "observations_count": 1940833, "ai_coder_pattern_id": 102}, "scanner": "repobility-threat-engine", "correlation_key": "fp|79b74d7f39ac3c7eeb8c2382719b9205f408e83dda64c98be8a387fbb88db766"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/(auth)/forgot-password/page.tsx"}, "region": {"startLine": 32}}}]}, {"ruleId": "MINED077", "level": "none", "message": {"text": "[MINED077] Python Open No Context: fp = open(path) outside with-block leaks file handles."}, "properties": {"repobilityId": 224789, "scanner": "repobility-threat-engine", "fingerprint": "9fc861976005de0dc9c7a46bd1baabe19eff70449f4aaed172fcce9caab58a4f", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "python-open-no-context", "owasp": null, "cwe_ids": ["CWE-772"], "languages": ["python"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348081+00:00", "triaged_in_corpus": 12, "observations_count": 7864, "ai_coder_pattern_id": 123}, "scanner": "repobility-threat-engine", "correlation_key": "fp|9fc861976005de0dc9c7a46bd1baabe19eff70449f4aaed172fcce9caab58a4f"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "fix_virtualenv.py"}, "region": {"startLine": 1}}}]}, {"ruleId": "MINED077", "level": "none", "message": {"text": "[MINED077] Python Open No Context: fp = open(path) outside with-block leaks file handles."}, "properties": {"repobilityId": 224788, "scanner": "repobility-threat-engine", "fingerprint": "541f08ccb4500ca9519afeec40ae0f887ff27a9ffd05790de7ac2d08aadcbc91", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "python-open-no-context", "owasp": null, "cwe_ids": ["CWE-772"], "languages": ["python"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348081+00:00", "triaged_in_corpus": 12, "observations_count": 7864, "ai_coder_pattern_id": 123}, "scanner": "repobility-threat-engine", "correlation_key": "fp|541f08ccb4500ca9519afeec40ae0f887ff27a9ffd05790de7ac2d08aadcbc91"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "fix_reqs.py"}, "region": {"startLine": 2}}}]}, {"ruleId": "MINED064", "level": "none", "message": {"text": "[MINED064] Python Input Call: input() blocks for stdin. Inappropriate in services."}, "properties": {"repobilityId": 224786, "scanner": "repobility-threat-engine", "fingerprint": "80c0487dee22b0cad8157fdb7b69b89e5a0534f1cfaf26d3ae79a22306899be2", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "python-input-call", "owasp": null, "cwe_ids": [], "languages": ["python"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348050+00:00", "triaged_in_corpus": 12, "observations_count": 66378, "ai_coder_pattern_id": 124}, "scanner": "repobility-threat-engine", "correlation_key": "fp|80c0487dee22b0cad8157fdb7b69b89e5a0534f1cfaf26d3ae79a22306899be2"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/users/management/commands/reset_saas_admin_password.py"}, "region": {"startLine": 51}}}]}, {"ruleId": "MINED064", "level": "none", "message": {"text": "[MINED064] Python Input Call: input() blocks for stdin. Inappropriate in services."}, "properties": {"repobilityId": 224785, "scanner": "repobility-threat-engine", "fingerprint": "cfd43972866eabc5a5646518f868ed14f0acd4a66e76a6fb77f359bc5ba3d8d4", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "python-input-call", "owasp": null, "cwe_ids": [], "languages": ["python"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348050+00:00", "triaged_in_corpus": 12, "observations_count": 66378, "ai_coder_pattern_id": 124}, "scanner": "repobility-threat-engine", "correlation_key": "fp|cfd43972866eabc5a5646518f868ed14f0acd4a66e76a6fb77f359bc5ba3d8d4"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/users/management/commands/create_saas_admin.py"}, "region": {"startLine": 54}}}]}, {"ruleId": "MINED007", "level": "none", "message": {"text": "[MINED007] Sql String Concat (and 1 more): Same pattern found in 1 additional files. Review if needed."}, "properties": {"repobilityId": 224782, "scanner": "repobility-threat-engine", "fingerprint": "e26ae1cb6d5e6b3636745868137a3ed501e41dbf21d6ef701e227d6c5e30ee94", "category": "quality", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 1 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"mined": true, "mining": {"slug": "sql-string-concat", "owasp": "A03:2021", "cwe_ids": ["CWE-89"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.347914+00:00", "triaged_in_corpus": 20, "observations_count": 210457, "ai_coder_pattern_id": 12}, "scanner": "repobility-threat-engine", "aggregated": true, "correlation_key": "fp|e26ae1cb6d5e6b3636745868137a3ed501e41dbf21d6ef701e227d6c5e30ee94", "aggregated_count": 1}}}, {"ruleId": "SEC042", "level": "none", "message": {"text": "[SEC042] SQL identifier injection via f-string in cursor execute (and 1 more): Same pattern found in 1 additional files. Review if needed."}, "properties": {"repobilityId": 224778, "scanner": "repobility-threat-engine", "fingerprint": "9c6144ea4dcde9d0b4668e2973c3a3ade6a7ab0b3ded26ced010bb3cc88cc066", "category": "injection", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 1 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"reason": "Deduplicated summary only: 1 additional occurrences found. The top occurrences remain visible as actionable findings.", "rule_id": "SEC042", "scanner": "repobility-threat-engine", "confidence": 0.2, "correlation_key": "fp|9c6144ea4dcde9d0b4668e2973c3a3ade6a7ab0b3ded26ced010bb3cc88cc066"}}}, {"ruleId": "SEC004", "level": "none", "message": {"text": "[SEC004] SQL Injection Risk (and 1 more): Same pattern found in 1 additional files. Review if needed."}, "properties": {"repobilityId": 224774, "scanner": "repobility-threat-engine", "fingerprint": "402803a4488b136e50cf5da9e3b45d2b73fd564c0b15ea70616f1598f1198a44", "category": "injection", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 1 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"reason": "Deduplicated summary only: 1 additional occurrences found. The top occurrences remain visible as actionable findings.", "rule_id": "SEC004", "scanner": "repobility-threat-engine", "confidence": 0.2, "correlation_key": "fp|402803a4488b136e50cf5da9e3b45d2b73fd564c0b15ea70616f1598f1198a44"}}}, {"ruleId": "MINED049", "level": "none", "message": {"text": "[MINED049] Print Pii (and 12 more): Same pattern found in 12 additional files. Review if needed."}, "properties": {"repobilityId": 224769, "scanner": "repobility-threat-engine", "fingerprint": "9ece0f568e9840c52adbdab37185d96872f43341824ca63ab63036a8afcea935", "category": "quality", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 12 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"mined": true, "mining": {"slug": "print-pii", "owasp": "A09:2021", "cwe_ids": ["CWE-532"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348015+00:00", "triaged_in_corpus": 12, "observations_count": 676566, "ai_coder_pattern_id": 26}, "scanner": "repobility-threat-engine", "aggregated": true, "correlation_key": "fp|9ece0f568e9840c52adbdab37185d96872f43341824ca63ab63036a8afcea935", "aggregated_count": 12}}}, {"ruleId": "MINED049", "level": "none", "message": {"text": "[MINED049] Print Pii: Logging password/token/email/ssn directly to stdout."}, "properties": {"repobilityId": 224768, "scanner": "repobility-threat-engine", "fingerprint": "862c67ac94efd2ca31ba9673a32124bd9cb69eac0a741f9bcd3afab7d730ec01", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "print-pii", "owasp": "A09:2021", "cwe_ids": ["CWE-532"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348015+00:00", "triaged_in_corpus": 12, "observations_count": 676566, "ai_coder_pattern_id": 26}, "scanner": "repobility-threat-engine", "correlation_key": "fp|862c67ac94efd2ca31ba9673a32124bd9cb69eac0a741f9bcd3afab7d730ec01"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/debug_auth.py"}, "region": {"startLine": 58}}}]}, {"ruleId": "MINED049", "level": "none", "message": {"text": "[MINED049] Print Pii: Logging password/token/email/ssn directly to stdout."}, "properties": {"repobilityId": 224767, "scanner": "repobility-threat-engine", "fingerprint": "22ca2176bf04a56682839e29ca1f12d318bd34982ca69a725b229a05acbde777", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "print-pii", "owasp": "A09:2021", "cwe_ids": ["CWE-532"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348015+00:00", "triaged_in_corpus": 12, "observations_count": 676566, "ai_coder_pattern_id": 26}, "scanner": "repobility-threat-engine", "correlation_key": "fp|22ca2176bf04a56682839e29ca1f12d318bd34982ca69a725b229a05acbde777"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/create_demo_accounts.py"}, "region": {"startLine": 26}}}]}, {"ruleId": "MINED049", "level": "none", "message": {"text": "[MINED049] Print Pii: Logging password/token/email/ssn directly to stdout."}, "properties": {"repobilityId": 224766, "scanner": "repobility-threat-engine", "fingerprint": "888d77046defb518088933a3350e4d2014afe2ad25f81e5d7ca7379b59d46349", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "print-pii", "owasp": "A09:2021", "cwe_ids": ["CWE-532"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348015+00:00", "triaged_in_corpus": 12, "observations_count": 676566, "ai_coder_pattern_id": 26}, "scanner": "repobility-threat-engine", "correlation_key": "fp|888d77046defb518088933a3350e4d2014afe2ad25f81e5d7ca7379b59d46349"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/check_auth.py"}, "region": {"startLine": 19}}}]}, {"ruleId": "MINED053", "level": "none", "message": {"text": "[MINED053] Placeholder Default Username (and 7 more): Same pattern found in 7 additional files. Review if needed."}, "properties": {"repobilityId": 224765, "scanner": "repobility-threat-engine", "fingerprint": "503cd594f58202b8b139ed21391a749ab8c9ed5971e10bf1374181f4eab19b18", "category": "quality", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 7 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"mined": true, "mining": {"slug": "placeholder-default-username", "owasp": null, "cwe_ids": ["CWE-1392", "CWE-798"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348025+00:00", "triaged_in_corpus": 10, "observations_count": 456953, "ai_coder_pattern_id": 44}, "scanner": "repobility-threat-engine", "aggregated": true, "correlation_key": "fp|503cd594f58202b8b139ed21391a749ab8c9ed5971e10bf1374181f4eab19b18", "aggregated_count": 7}}}, {"ruleId": "MINED053", "level": "none", "message": {"text": "[MINED053] Placeholder Default Username: foo@bar.com / john.doe@example.com / admin/admin / changeme \u2014 typical AI placeholder credentials."}, "properties": {"repobilityId": 224764, "scanner": "repobility-threat-engine", "fingerprint": "28a577ef47beba5bd2327c7e0e9c3d29e1d29bcbe824fa9f53796984b7ecf96c", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "placeholder-default-username", "owasp": null, "cwe_ids": ["CWE-1392", "CWE-798"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348025+00:00", "triaged_in_corpus": 10, "observations_count": 456953, "ai_coder_pattern_id": 44}, "scanner": "repobility-threat-engine", "correlation_key": "fp|28a577ef47beba5bd2327c7e0e9c3d29e1d29bcbe824fa9f53796984b7ecf96c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/debug_connectivity.py"}, "region": {"startLine": 19}}}]}, {"ruleId": "MINED053", "level": "none", "message": {"text": "[MINED053] Placeholder Default Username: foo@bar.com / john.doe@example.com / admin/admin / changeme \u2014 typical AI placeholder credentials."}, "properties": {"repobilityId": 224763, "scanner": "repobility-threat-engine", "fingerprint": "6ece67341272a03cd5204c423375334fffd0901762cfe5b26be7d2a916bed940", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "placeholder-default-username", "owasp": null, "cwe_ids": ["CWE-1392", "CWE-798"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348025+00:00", "triaged_in_corpus": 10, "observations_count": 456953, "ai_coder_pattern_id": 44}, "scanner": "repobility-threat-engine", "correlation_key": "fp|6ece67341272a03cd5204c423375334fffd0901762cfe5b26be7d2a916bed940"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/debug_check_urls.py"}, "region": {"startLine": 11}}}]}, {"ruleId": "MINED053", "level": "none", "message": {"text": "[MINED053] Placeholder Default Username: foo@bar.com / john.doe@example.com / admin/admin / changeme \u2014 typical AI placeholder credentials."}, "properties": {"repobilityId": 224762, "scanner": "repobility-threat-engine", "fingerprint": "4a1498788f6b81d63ccabaa93bfca05f8a05e629f56e738f656bf3d68bc8b716", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "placeholder-default-username", "owasp": null, "cwe_ids": ["CWE-1392", "CWE-798"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348025+00:00", "triaged_in_corpus": 10, "observations_count": 456953, "ai_coder_pattern_id": 44}, "scanner": "repobility-threat-engine", "correlation_key": "fp|4a1498788f6b81d63ccabaa93bfca05f8a05e629f56e738f656bf3d68bc8b716"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/tests_tenant.py"}, "region": {"startLine": 19}}}]}, {"ruleId": "MINED065", "level": "none", "message": {"text": "[MINED065] Cors Wildcard: Access-Control-Allow-Origin: * exposes the API to any browser origin. Acceptable for public read-only endpoints; dangerous when paired with credentials or write endpoints."}, "properties": {"repobilityId": 224761, "scanner": "repobility-threat-engine", "fingerprint": "c643f6ee2bb8a2e7400e8977a8a5c26112caf8a3939c82440ff918393e1f6d1c", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "cors-wildcard", "owasp": "A05:2021", "cwe_ids": ["CWE-942", "CWE-346"], "languages": ["python", "javascript", "typescript", "yaml", "json"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348052+00:00", "triaged_in_corpus": 12, "observations_count": 63910, "ai_coder_pattern_id": 46}, "scanner": "repobility-threat-engine", "correlation_key": "fp|c643f6ee2bb8a2e7400e8977a8a5c26112caf8a3939c82440ff918393e1f6d1c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/tests_security_headers.py"}, "region": {"startLine": 26}}}]}, {"ruleId": "MINED069", "level": "none", "message": {"text": "[MINED069] Debug True Prod: Django/Flask DEBUG=True or app.debug=True in non-test files."}, "properties": {"repobilityId": 224756, "scanner": "repobility-threat-engine", "fingerprint": "b181145d557c642d28fadcb26e2b3ca17bdd40264f4909f8f2f584d6445cac9e", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "debug-true-prod", "owasp": "A05:2021", "cwe_ids": ["CWE-489"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348063+00:00", "triaged_in_corpus": 12, "observations_count": 37393, "ai_coder_pattern_id": 17}, "scanner": "repobility-threat-engine", "correlation_key": "fp|b181145d557c642d28fadcb26e2b3ca17bdd40264f4909f8f2f584d6445cac9e"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/tests_tenant_security.py"}, "region": {"startLine": 33}}}]}, {"ruleId": "MINED069", "level": "none", "message": {"text": "[MINED069] Debug True Prod: Django/Flask DEBUG=True or app.debug=True in non-test files."}, "properties": {"repobilityId": 224755, "scanner": "repobility-threat-engine", "fingerprint": "81aeafc846a7b755d7565d36db100f1bc47a995f3ac2ac28a842c21d27ca9870", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "debug-true-prod", "owasp": "A05:2021", "cwe_ids": ["CWE-489"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348063+00:00", "triaged_in_corpus": 12, "observations_count": 37393, "ai_coder_pattern_id": 17}, "scanner": "repobility-threat-engine", "correlation_key": "fp|81aeafc846a7b755d7565d36db100f1bc47a995f3ac2ac28a842c21d27ca9870"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/config/settings/local.py"}, "region": {"startLine": 6}}}]}, {"ruleId": "MINED067", "level": "none", "message": {"text": "[MINED067] Python Requests No Timeout (and 17 more): Same pattern found in 17 additional files. Review if needed."}, "properties": {"repobilityId": 224751, "scanner": "repobility-threat-engine", "fingerprint": "233c5ff424bf50cd15192d14743f67b90793bfa1fab81c490adaa04a81aadf90", "category": "quality", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 17 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"mined": true, "mining": {"slug": "python-requests-no-timeout", "owasp": null, "cwe_ids": ["CWE-400"], "languages": ["python"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348058+00:00", "triaged_in_corpus": 12, "observations_count": 45429, "ai_coder_pattern_id": 122}, "scanner": "repobility-threat-engine", "aggregated": true, "correlation_key": "fp|233c5ff424bf50cd15192d14743f67b90793bfa1fab81c490adaa04a81aadf90", "aggregated_count": 17}}}, {"ruleId": "MINED067", "level": "none", "message": {"text": "[MINED067] Python Requests No Timeout: requests.get/post/etc. without timeout= can hang forever."}, "properties": {"repobilityId": 224750, "scanner": "repobility-threat-engine", "fingerprint": "b0cebc3ca81674a2011950fd8d520211a7a003264b29e7d81c4a736b339bbf46", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "python-requests-no-timeout", "owasp": null, "cwe_ids": ["CWE-400"], "languages": ["python"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348058+00:00", "triaged_in_corpus": 12, "observations_count": 45429, "ai_coder_pattern_id": 122}, "scanner": "repobility-threat-engine", "correlation_key": "fp|b0cebc3ca81674a2011950fd8d520211a7a003264b29e7d81c4a736b339bbf46"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/notifications/services.py"}, "region": {"startLine": 59}}}]}, {"ruleId": "MINED067", "level": "none", "message": {"text": "[MINED067] Python Requests No Timeout: requests.get/post/etc. without timeout= can hang forever."}, "properties": {"repobilityId": 224749, "scanner": "repobility-threat-engine", "fingerprint": "e9c5266f4fccb8d30b06d4367b395fa400d8225b4a796cad4494f34974b94c41", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "python-requests-no-timeout", "owasp": null, "cwe_ids": ["CWE-400"], "languages": ["python"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348058+00:00", "triaged_in_corpus": 12, "observations_count": 45429, "ai_coder_pattern_id": 122}, "scanner": "repobility-threat-engine", "correlation_key": "fp|e9c5266f4fccb8d30b06d4367b395fa400d8225b4a796cad4494f34974b94c41"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/email_backends/resend_backend.py"}, "region": {"startLine": 60}}}]}, {"ruleId": "MINED067", "level": "none", "message": {"text": "[MINED067] Python Requests No Timeout: requests.get/post/etc. without timeout= can hang forever."}, "properties": {"repobilityId": 224748, "scanner": "repobility-threat-engine", "fingerprint": "16d0c633d1903baa805c8b58db15dff4475e4ffe9a51e26b6462f152d072956f", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "python-requests-no-timeout", "owasp": null, "cwe_ids": ["CWE-400"], "languages": ["python"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348058+00:00", "triaged_in_corpus": 12, "observations_count": 45429, "ai_coder_pattern_id": 122}, "scanner": "repobility-threat-engine", "correlation_key": "fp|16d0c633d1903baa805c8b58db15dff4475e4ffe9a51e26b6462f152d072956f"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/payment_gateways.py"}, "region": {"startLine": 57}}}]}, {"ruleId": "SEC078", "level": "none", "message": {"text": "[SEC078] Python: requests without timeout (and 17 more): Same pattern found in 17 additional files. Review if needed."}, "properties": {"repobilityId": 224745, "scanner": "repobility-threat-engine", "fingerprint": "60ea8b64e0e0b055aafeb008900f1204b39f3dd5ae6bf83646af00e4d894de02", "category": "quality", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 17 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"reason": "Deduplicated summary only: 17 additional occurrences found. The top occurrences remain visible as actionable findings.", "rule_id": "SEC078", "scanner": "repobility-threat-engine", "confidence": 0.2, "correlation_key": "fp|60ea8b64e0e0b055aafeb008900f1204b39f3dd5ae6bf83646af00e4d894de02"}}}, {"ruleId": "MINED072", "level": "none", "message": {"text": "[MINED072] Python Pass Only Class: class Foo: pass \u2014 stub waiting to be filled in."}, "properties": {"repobilityId": 224741, "scanner": "repobility-threat-engine", "fingerprint": "e7d2f2fbeac59fb65ddb528144eef027c76805299d26c2a5305345d51e73a88c", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "python-pass-only-class", "owasp": null, "cwe_ids": ["CWE-1188"], "languages": ["python"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348069+00:00", "triaged_in_corpus": 10, "observations_count": 14245, "ai_coder_pattern_id": 143}, "scanner": "repobility-threat-engine", "correlation_key": "fp|e7d2f2fbeac59fb65ddb528144eef027c76805299d26c2a5305345d51e73a88c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/models/tenant.py"}, "region": {"startLine": 113}}}]}, {"ruleId": "MINED072", "level": "none", "message": {"text": "[MINED072] Python Pass Only Class: class Foo: pass \u2014 stub waiting to be filled in."}, "properties": {"repobilityId": 224740, "scanner": "repobility-threat-engine", "fingerprint": "9a302e1da32749d33fd07c4498676088cd937a8207ac75ae20a357600b8d7355", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "python-pass-only-class", "owasp": null, "cwe_ids": ["CWE-1188"], "languages": ["python"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348069+00:00", "triaged_in_corpus": 10, "observations_count": 14245, "ai_coder_pattern_id": 143}, "scanner": "repobility-threat-engine", "correlation_key": "fp|9a302e1da32749d33fd07c4498676088cd937a8207ac75ae20a357600b8d7355"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing/legacy_views.py"}, "region": {"startLine": 26}}}]}, {"ruleId": "SEC029", "level": "none", "message": {"text": "[SEC029] Server-Side Request Forgery (SSRF) \u2014 outbound HTTP from user input (and 7 more): Same pattern found in 7 additional files. Review if needed."}, "properties": {"repobilityId": 224739, "scanner": "repobility-threat-engine", "fingerprint": "ca5810ac6a2691831acbb4a51605672ba83c57f5592204a59181f6375036bfee", "category": "ssrf", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 7 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"reason": "Deduplicated summary only: 7 additional occurrences found. The top occurrences remain visible as actionable findings.", "rule_id": "SEC029", "scanner": "repobility-threat-engine", "confidence": 0.2, "correlation_key": "fp|ca5810ac6a2691831acbb4a51605672ba83c57f5592204a59181f6375036bfee"}}}, {"ruleId": "SEC020", "level": "none", "message": {"text": "[SEC020] Secret Printed to Logs (and 16 more): Same pattern found in 16 additional files. Review if needed."}, "properties": {"repobilityId": 224735, "scanner": "repobility-threat-engine", "fingerprint": "a96aca186fb6d91aad331aff0ba4bc8ff5a4cd37df57b4abaafbb06900914ba7", "category": "credential_exposure", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 16 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"reason": "Deduplicated summary only: 16 additional occurrences found. The top occurrences remain visible as actionable findings.", "rule_id": "SEC020", "scanner": "repobility-threat-engine", "confidence": 0.2, "correlation_key": "fp|a96aca186fb6d91aad331aff0ba4bc8ff5a4cd37df57b4abaafbb06900914ba7"}}}, {"ruleId": "SEC020", "level": "none", "message": {"text": "[SEC020] Secret Printed to Logs: Debug or diagnostic code appears to print a credential-bearing value. This is a frequent AI-assisted coding failure: the helper exposes the exact value needed for troubleshooting."}, "properties": {"repobilityId": 224734, "scanner": "repobility-threat-engine", "fingerprint": "468c2b02cafbb75539e7ede3d3af300db8f1b2e51f92649ba83efa978cce1c25", "category": "credential_exposure", "severity": "info", "confidence": 0.15, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Log message mentions credential-related metadata but does not print a credential-bearing value", "evidence": {"match": "print(f\"   Password: <redacted>\")", "reason": "Log message mentions credential-related metadata but does not print a credential-bearing value", "rule_id": "SEC020", "scanner": "repobility-threat-engine", "confidence": 0.15, "correlation_key": "secret|token|2|print f password: redacted"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/create_demo_accounts.py"}, "region": {"startLine": 26}}}]}, {"ruleId": "SEC020", "level": "none", "message": {"text": "[SEC020] Secret Printed to Logs: Debug or diagnostic code appears to print a credential-bearing value. This is a frequent AI-assisted coding failure: the helper exposes the exact value needed for troubleshooting."}, "properties": {"repobilityId": 224733, "scanner": "repobility-threat-engine", "fingerprint": "20d4da25329d7515964b07c176cada99e3914e65f8b572040f0c279d4bf826d9", "category": "credential_exposure", "severity": "info", "confidence": 0.15, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Log message mentions credential-related metadata but does not print a credential-bearing value", "evidence": {"match": "logger.warning(\"Token budget deduction failed (non-fatal)", "reason": "Log message mentions credential-related metadata but does not print a credential-bearing value", "rule_id": "SEC020", "scanner": "repobility-threat-engine", "confidence": 0.15, "correlation_key": "secret|token|14|logger.warning token budget deduction failed non-fatal"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/services/token_budget_service.py"}, "region": {"startLine": 142}}}]}, {"ruleId": "MINED043", "level": "none", "message": {"text": "[MINED043] Http Not Https (and 2 more): Same pattern found in 2 additional files. Review if needed."}, "properties": {"repobilityId": 224731, "scanner": "repobility-threat-engine", "fingerprint": "62ff231053d16ded91f5d63a99a8b7f9a8d879f1bee1b23442cfa6701d92f730", "category": "quality", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 2 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"mined": true, "mining": {"slug": "http-not-https", "owasp": "A02:2021", "cwe_ids": ["CWE-319"], "precision": 0.917, "promoted_at": "2026-05-18T14:01:32.347999+00:00", "triaged_in_corpus": 12, "observations_count": 4113831, "ai_coder_pattern_id": 15}, "scanner": "repobility-threat-engine", "aggregated": true, "correlation_key": "fp|62ff231053d16ded91f5d63a99a8b7f9a8d879f1bee1b23442cfa6701d92f730", "aggregated_count": 2}}}, {"ruleId": "MINED043", "level": "none", "message": {"text": "[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle credentials or data."}, "properties": {"repobilityId": 224730, "scanner": "repobility-threat-engine", "fingerprint": "2dbeb35f5f9acc0956644f779f3cbecf8d56e0424844d05854020728d6c912b4", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "http-not-https", "owasp": "A02:2021", "cwe_ids": ["CWE-319"], "precision": 0.917, "promoted_at": "2026-05-18T14:01:32.347999+00:00", "triaged_in_corpus": 12, "observations_count": 4113831, "ai_coder_pattern_id": 15}, "scanner": "repobility-threat-engine", "correlation_key": "fp|2dbeb35f5f9acc0956644f779f3cbecf8d56e0424844d05854020728d6c912b4"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/run_dev.sh"}, "region": {"startLine": 44}}}]}, {"ruleId": "MINED043", "level": "none", "message": {"text": "[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle credentials or data."}, "properties": {"repobilityId": 224729, "scanner": "repobility-threat-engine", "fingerprint": "cba15ec5de2a4635bec6bcfd769e6bc07f96d6c16efafe988bfc69b74fc72a20", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "http-not-https", "owasp": "A02:2021", "cwe_ids": ["CWE-319"], "precision": 0.917, "promoted_at": "2026-05-18T14:01:32.347999+00:00", "triaged_in_corpus": 12, "observations_count": 4113831, "ai_coder_pattern_id": 15}, "scanner": "repobility-threat-engine", "correlation_key": "fp|cba15ec5de2a4635bec6bcfd769e6bc07f96d6c16efafe988bfc69b74fc72a20"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/notifications/services.py"}, "region": {"startLine": 39}}}]}, {"ruleId": "MINED043", "level": "none", "message": {"text": "[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle credentials or data."}, "properties": {"repobilityId": 224728, "scanner": "repobility-threat-engine", "fingerprint": "144df3c4e2c828a99f9c0ecd4988340f9eb8917ee2da087ebe5da2334dbf9ea7", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "http-not-https", "owasp": "A02:2021", "cwe_ids": ["CWE-319"], "precision": 0.917, "promoted_at": "2026-05-18T14:01:32.347999+00:00", "triaged_in_corpus": 12, "observations_count": 4113831, "ai_coder_pattern_id": 15}, "scanner": "repobility-threat-engine", "correlation_key": "fp|144df3c4e2c828a99f9c0ecd4988340f9eb8917ee2da087ebe5da2334dbf9ea7"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/services/provider_config.py"}, "region": {"startLine": 38}}}]}, {"ruleId": "MINED076", "level": "none", "message": {"text": "[MINED076] Catch And Reraise Noop: except X: raise X \u2014 adds no value, hides traceback if AI accidentally changes message."}, "properties": {"repobilityId": 224725, "scanner": "repobility-threat-engine", "fingerprint": "27e9ce7f410a49745222d91a542375a3dce920137546ea33a57dc1f1407d1a5c", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "catch-and-reraise-noop", "owasp": null, "cwe_ids": [], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348079+00:00", "triaged_in_corpus": 10, "observations_count": 8333, "ai_coder_pattern_id": 45}, "scanner": "repobility-threat-engine", "correlation_key": "fp|27e9ce7f410a49745222d91a542375a3dce920137546ea33a57dc1f1407d1a5c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/services/ai_client.py"}, "region": {"startLine": 195}}}]}, {"ruleId": "ERR001", "level": "none", "message": {"text": "[ERR001] Silent Exception Swallowing (and 3 more): Same pattern found in 3 additional files. Review if needed."}, "properties": {"repobilityId": 224724, "scanner": "repobility-threat-engine", "fingerprint": "8a4bd872da419130753367ef5a61efa729f221dd8f26dbedd7003551d50a5f41", "category": "error_handling", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 3 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"reason": "Deduplicated summary only: 3 additional occurrences found. The top occurrences remain visible as actionable findings.", "rule_id": "ERR001", "scanner": "repobility-threat-engine", "confidence": 0.2, "correlation_key": "fp|8a4bd872da419130753367ef5a61efa729f221dd8f26dbedd7003551d50a5f41"}}}, {"ruleId": "SEC001", "level": "none", "message": {"text": "[SEC001] Hardcoded Password (and 42 more): Same pattern found in 42 additional files. Review if needed."}, "properties": {"repobilityId": 224720, "scanner": "repobility-threat-engine", "fingerprint": "0251e7361f4cda8ae51bfdfc6f556760fe734583fb6f6507af6005db1fabf60f", "category": "credential_exposure", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 42 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"reason": "Deduplicated summary only: 42 additional occurrences found. The top occurrences remain visible as actionable findings.", "rule_id": "SEC001", "scanner": "repobility-threat-engine", "confidence": 0.2, "correlation_key": "fp|0251e7361f4cda8ae51bfdfc6f556760fe734583fb6f6507af6005db1fabf60f"}}}, {"ruleId": "MINED050", "level": "none", "message": {"text": "[MINED050] Stub Only Function (and 13 more): Same pattern found in 13 additional files. Review if needed."}, "properties": {"repobilityId": 224718, "scanner": "repobility-threat-engine", "fingerprint": "7279be3bf1fcb1aa10ba0c2ac1be9be53dc68b6d651aeb9501d6be025f645add", "category": "quality", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 13 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"mined": true, "mining": {"slug": "stub-only-function", "owasp": null, "cwe_ids": ["CWE-1188"], "languages": ["python"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348017+00:00", "triaged_in_corpus": 12, "observations_count": 633513, "ai_coder_pattern_id": 2}, "scanner": "repobility-threat-engine", "aggregated": true, "correlation_key": "fp|7279be3bf1fcb1aa10ba0c2ac1be9be53dc68b6d651aeb9501d6be025f645add", "aggregated_count": 13}}}, {"ruleId": "MINED050", "level": "none", "message": {"text": "[MINED050] Stub Only Function: Function declared but body is just pass, return None, raise NotImplementedError, or TODO comment."}, "properties": {"repobilityId": 224717, "scanner": "repobility-threat-engine", "fingerprint": "143284f5b1899421f637f960a988f5a08a7d85522ed60bbfa4b8ad711836efdd", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "stub-only-function", "owasp": null, "cwe_ids": ["CWE-1188"], "languages": ["python"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348017+00:00", "triaged_in_corpus": 12, "observations_count": 633513, "ai_coder_pattern_id": 2}, "scanner": "repobility-threat-engine", "correlation_key": "fp|143284f5b1899421f637f960a988f5a08a7d85522ed60bbfa4b8ad711836efdd"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/views/events.py"}, "region": {"startLine": 81}}}]}, {"ruleId": "MINED050", "level": "none", "message": {"text": "[MINED050] Stub Only Function: Function declared but body is just pass, return None, raise NotImplementedError, or TODO comment."}, "properties": {"repobilityId": 224716, "scanner": "repobility-threat-engine", "fingerprint": "3453737bdb2808635f8216c59e67232658d82eb6ed7b43d2722fcf2015c8aa6a", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "stub-only-function", "owasp": null, "cwe_ids": ["CWE-1188"], "languages": ["python"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348017+00:00", "triaged_in_corpus": 12, "observations_count": 633513, "ai_coder_pattern_id": 2}, "scanner": "repobility-threat-engine", "correlation_key": "fp|3453737bdb2808635f8216c59e67232658d82eb6ed7b43d2722fcf2015c8aa6a"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/views/erp.py"}, "region": {"startLine": 113}}}]}, {"ruleId": "MINED050", "level": "none", "message": {"text": "[MINED050] Stub Only Function: Function declared but body is just pass, return None, raise NotImplementedError, or TODO comment."}, "properties": {"repobilityId": 224715, "scanner": "repobility-threat-engine", "fingerprint": "8792fcde68d9667af992f4cc62423c182609d0ad7ae33d96bd915a5f03deece3", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "stub-only-function", "owasp": null, "cwe_ids": ["CWE-1188"], "languages": ["python"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348017+00:00", "triaged_in_corpus": 12, "observations_count": 633513, "ai_coder_pattern_id": 2}, "scanner": "repobility-threat-engine", "correlation_key": "fp|8792fcde68d9667af992f4cc62423c182609d0ad7ae33d96bd915a5f03deece3"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/services/grading_service.py"}, "region": {"startLine": 39}}}]}, {"ruleId": "MINED001", "level": "none", "message": {"text": "[MINED001] Bare Except Pass (and 9 more): Same pattern found in 9 additional files. Review if needed."}, "properties": {"repobilityId": 224714, "scanner": "repobility-threat-engine", "fingerprint": "e92ca7660e8c577d998ed38d702bd0e28a30f0eb9fe80341db09927c32f0423f", "category": "quality", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 9 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"mined": true, "mining": {"slug": "bare-except-pass", "owasp": null, "cwe_ids": ["CWE-755"], "languages": ["python"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.347744+00:00", "triaged_in_corpus": 15, "observations_count": 1550824, "ai_coder_pattern_id": 6}, "scanner": "repobility-threat-engine", "aggregated": true, "correlation_key": "fp|e92ca7660e8c577d998ed38d702bd0e28a30f0eb9fe80341db09927c32f0423f", "aggregated_count": 9}}}, {"ruleId": "SEC128", "level": "none", "message": {"text": "[SEC128] Async function without await \u2014 fire-and-forget Promise (AI mistake) (and 80 more): Same pattern found in 80 additional files. Review if needed."}, "properties": {"repobilityId": 224710, "scanner": "repobility-threat-engine", "fingerprint": "868497fe79f215272919a8244f997b4c49df70698a822a30d9d87f9ac348b460", "category": "quality", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 80 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"reason": "Deduplicated summary only: 80 additional occurrences found. The top occurrences remain visible as actionable findings.", "rule_id": "SEC128", "scanner": "repobility-threat-engine", "confidence": 0.2, "correlation_key": "fp|868497fe79f215272919a8244f997b4c49df70698a822a30d9d87f9ac348b460"}}}, {"ruleId": "COMP001", "level": "none", "message": {"text": "[COMP001] High cognitive complexity (and 122 more): Same pattern found in 122 additional files. Review if needed."}, "properties": {"repobilityId": 224706, "scanner": "repobility-threat-engine", "fingerprint": "39f0b5c37f86c1559bc3437eba99af696af1275f882336d07e8d6d0a42381dbf", "category": "quality", "severity": "info", "confidence": 0.2, "triageState": "false_positive", "verdict": "likely_fp", "isResolved": true, "reason": "Deduplicated summary only: 122 additional occurrences found. The top occurrences remain visible as actionable findings.", "evidence": {"scanner": "repobility-threat-engine", "function": "handle", "breakdown": {"if": 7, "for": 5, "continue": 2, "nested_bonus": 8}, "aggregated": true, "complexity": 22, "correlation_key": "fp|39f0b5c37f86c1559bc3437eba99af696af1275f882336d07e8d6d0a42381dbf", "aggregated_count": 122}}}, {"ruleId": "DEPCUR-NPM", "level": "none", "message": {"text": "npm package `@radix-ui/react-dropdown-menu` is patch version(s) behind (2.1.16 -> 2.1.18)"}, "properties": {"repobilityId": 224702, "scanner": "repobility-dependency-currency", "fingerprint": "3660fe83031c6878e9338f14f8b1b57c6d0f5f451d31aba29935390cafb5aafb", "category": "dependency", "severity": "info", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "patch version(s) behind", "signal": "currency", "cwe_ids": [], "package": "@radix-ui/react-dropdown-menu", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "2.1.18", "correlation_key": "fp|3660fe83031c6878e9338f14f8b1b57c6d0f5f451d31aba29935390cafb5aafb", "current_version": "2.1.16"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "none", "message": {"text": "npm package `@radix-ui/react-dialog` is patch version(s) behind (1.1.15 -> 1.1.17)"}, "properties": {"repobilityId": 224701, "scanner": "repobility-dependency-currency", "fingerprint": "5bf359bd55a27fe9f94349fad99152dc61243b1c7dfb89eb4561bf96dafcd7fc", "category": "dependency", "severity": "info", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "patch version(s) behind", "signal": "currency", "cwe_ids": [], "package": "@radix-ui/react-dialog", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "1.1.17", "correlation_key": "fp|5bf359bd55a27fe9f94349fad99152dc61243b1c7dfb89eb4561bf96dafcd7fc", "current_version": "1.1.15"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "none", "message": {"text": "npm package `@radix-ui/react-alert-dialog` is patch version(s) behind (1.1.15 -> 1.1.17)"}, "properties": {"repobilityId": 224699, "scanner": "repobility-dependency-currency", "fingerprint": "d2efdb068ba1aea8a2dc5d6932a82cb50e39d89a4b3c2ab0bfc18e3cd8bfb2e2", "category": "dependency", "severity": "info", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "patch version(s) behind", "signal": "currency", "cwe_ids": [], "package": "@radix-ui/react-alert-dialog", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "1.1.17", "correlation_key": "fp|d2efdb068ba1aea8a2dc5d6932a82cb50e39d89a4b3c2ab0bfc18e3cd8bfb2e2", "current_version": "1.1.15"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "none", "message": {"text": "npm package `@radix-ui/react-accordion` is patch version(s) behind (1.2.12 -> 1.2.14)"}, "properties": {"repobilityId": 224698, "scanner": "repobility-dependency-currency", "fingerprint": "84fe6d439b1b60ba450cde3c17afc4a29a74e5757de1622211481dacb30923e1", "category": "dependency", "severity": "info", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "patch version(s) behind", "signal": "currency", "cwe_ids": [], "package": "@radix-ui/react-accordion", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "1.2.14", "correlation_key": "fp|84fe6d439b1b60ba450cde3c17afc4a29a74e5757de1622211481dacb30923e1", "current_version": "1.2.12"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "none", "message": {"text": "npm package `zustand` is patch version(s) behind (5.0.11 -> 5.0.14)"}, "properties": {"repobilityId": 224696, "scanner": "repobility-dependency-currency", "fingerprint": "35716012bf0a4ce5f6f651ecf9f0debdc38407b3805e7d9aa731571a008508f0", "category": "dependency", "severity": "info", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "patch version(s) behind", "signal": "currency", "cwe_ids": [], "package": "zustand", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "5.0.14", "correlation_key": "fp|35716012bf0a4ce5f6f651ecf9f0debdc38407b3805e7d9aa731571a008508f0", "current_version": "5.0.11"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-PY", "level": "none", "message": {"text": "Python package `pandas` is patch version(s) behind (3.0.1 -> 3.0.3)"}, "properties": {"repobilityId": 224675, "scanner": "repobility-dependency-currency", "fingerprint": "3630a40445a0ac2f892cb2609ba45c3dbd9d2e78a8ee0dbff0b8b57d78ab2ea1", "category": "dependency", "severity": "info", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "patch version(s) behind", "signal": "currency", "cwe_ids": [], "package": "pandas", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "3.0.3", "correlation_key": "fp|3630a40445a0ac2f892cb2609ba45c3dbd9d2e78a8ee0dbff0b8b57d78ab2ea1", "current_version": "3.0.1"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 49}}}]}, {"ruleId": "DEPCUR-PY", "level": "none", "message": {"text": "Python package `django-jazzmin` is patch version(s) behind (3.0.1 -> 3.0.4)"}, "properties": {"repobilityId": 224662, "scanner": "repobility-dependency-currency", "fingerprint": "e3a3bfc47bd820c7deb08383cf2f67bb66e166f705645256b7698b31e5d4ae3d", "category": "dependency", "severity": "info", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "patch version(s) behind", "signal": "currency", "cwe_ids": [], "package": "django-jazzmin", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "3.0.4", "correlation_key": "fp|e3a3bfc47bd820c7deb08383cf2f67bb66e166f705645256b7698b31e5d4ae3d", "current_version": "3.0.1"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 21}}}]}, {"ruleId": "DEPCUR-PY", "level": "none", "message": {"text": "Python package `django-auditlog` is patch version(s) behind (3.4.0 -> 3.4.1)"}, "properties": {"repobilityId": 224661, "scanner": "repobility-dependency-currency", "fingerprint": "a845ef211af730d775ba3dc8ebbe444234c6ded7840bf0c6da605503b32f600d", "category": "dependency", "severity": "info", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "patch version(s) behind", "signal": "currency", "cwe_ids": [], "package": "django-auditlog", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "3.4.1", "correlation_key": "fp|a845ef211af730d775ba3dc8ebbe444234c6ded7840bf0c6da605503b32f600d", "current_version": "3.4.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 17}}}]}, {"ruleId": "DEPCUR-PY", "level": "none", "message": {"text": "Python package `charset-normalizer` is patch version(s) behind (3.4.4 -> 3.4.7)"}, "properties": {"repobilityId": 224658, "scanner": "repobility-dependency-currency", "fingerprint": "72d70d9681d2f290965a762ef5d3414170f5bcb06d45ac7308553aa268129b4c", "category": "dependency", "severity": "info", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "patch version(s) behind", "signal": "currency", "cwe_ids": [], "package": "charset-normalizer", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "3.4.7", "correlation_key": "fp|72d70d9681d2f290965a762ef5d3414170f5bcb06d45ac7308553aa268129b4c", "current_version": "3.4.4"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 9}}}]}, {"ruleId": "DEPCUR-PY", "level": "none", "message": {"text": "Python package `arabic-reshaper` is patch version(s) behind (3.0.0 -> 3.0.1)"}, "properties": {"repobilityId": 224655, "scanner": "repobility-dependency-currency", "fingerprint": "c78c8ed94e8866b1640f664b5a557d88d04a69becce82e6e90c8026e237f0df7", "category": "dependency", "severity": "info", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "patch version(s) behind", "signal": "currency", "cwe_ids": [], "package": "arabic-reshaper", "scanner": "repobility-dependency-currency", "ecosystem": "pypi", "languages": ["python"], "latest_version": "3.0.1", "correlation_key": "fp|c78c8ed94e8866b1640f664b5a557d88d04a69becce82e6e90c8026e237f0df7", "current_version": "3.0.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 3}}}]}, {"ruleId": "DEPCUR-NPM", "level": "none", "message": {"text": "npm package `dotenv` is patch version(s) behind (17.4.1 -> 17.4.2)"}, "properties": {"repobilityId": 224653, "scanner": "repobility-dependency-currency", "fingerprint": "c4df25e2a8897b4b1213e87aa97db58a80b4ee036da1a78eb3b763916b6e2a77", "category": "dependency", "severity": "info", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "patch version(s) behind", "signal": "currency", "cwe_ids": [], "package": "dotenv", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "17.4.2", "correlation_key": "fp|c4df25e2a8897b4b1213e87aa97db58a80b4ee036da1a78eb3b763916b6e2a77", "current_version": "17.4.1"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "JRN009", "level": "error", "message": {"text": "Secret-like setting is echoed into a password input value"}, "properties": {"repobilityId": 224991, "scanner": "repobility-journey-contract", "fingerprint": "c22a68f763a18b9c1aabcfdd78816817523af87d41e142a4de486a12e0e7a93a", "category": "auth", "severity": "high", "confidence": 0.83, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "A password or secret-named input is populated from a secret-like variable instead of a masked placeholder.", "evidence": {"rule_id": "JRN009", "scanner": "repobility-journey-contract", "references": ["https://cheatsheetseries.owasp.org/cheatsheets/Session_Management_Cheat_Sheet.html"], "correlation_key": "code|auth|token|123|jrn009"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/components/add-teacher-dialog.tsx"}, "region": {"startLine": 123}}}]}, {"ruleId": "JRN009", "level": "error", "message": {"text": "Secret-like setting is echoed into a password input value"}, "properties": {"repobilityId": 224990, "scanner": "repobility-journey-contract", "fingerprint": "57b86c0d7b892ab9c688206c1e559b976cff5f05703d04716a20a5021525d11c", "category": "auth", "severity": "high", "confidence": 0.83, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "A password or secret-named input is populated from a secret-like variable instead of a masked placeholder.", "evidence": {"rule_id": "JRN009", "scanner": "repobility-journey-contract", "references": ["https://cheatsheetseries.owasp.org/cheatsheets/Session_Management_Cheat_Sheet.html"], "correlation_key": "code|auth|token|142|jrn009"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/components/add-student-dialog.tsx"}, "region": {"startLine": 142}}}]}, {"ruleId": "JRN009", "level": "error", "message": {"text": "Secret-like setting is echoed into a password input value"}, "properties": {"repobilityId": 224989, "scanner": "repobility-journey-contract", "fingerprint": "d1fd203977a4b23d2fe316275fc936cf5149410a89471924681866a6ee45e69c", "category": "auth", "severity": "high", "confidence": 0.83, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "A password or secret-named input is populated from a secret-like variable instead of a masked placeholder.", "evidence": {"rule_id": "JRN009", "scanner": "repobility-journey-contract", "references": ["https://cheatsheetseries.owasp.org/cheatsheets/Session_Management_Cheat_Sheet.html"], "correlation_key": "code|auth|token|443|jrn009"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/admin/settings/staff-access/page.tsx"}, "region": {"startLine": 443}}}]}, {"ruleId": "JRN009", "level": "error", "message": {"text": "Secret-like setting is echoed into a password input value"}, "properties": {"repobilityId": 224988, "scanner": "repobility-journey-contract", "fingerprint": "915bcff2a68ed35d808cc6669ba150381b6e2177989dfffe4f7989123f2cf5c6", "category": "auth", "severity": "high", "confidence": 0.83, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "A password or secret-named input is populated from a secret-like variable instead of a masked placeholder.", "evidence": {"rule_id": "JRN009", "scanner": "repobility-journey-contract", "references": ["https://cheatsheetseries.owasp.org/cheatsheets/Session_Management_Cheat_Sheet.html"], "correlation_key": "code|auth|frontend/app/ saas /saas/staff/page.tsx|445|jrn009"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/(saas)/saas/staff/page.tsx"}, "region": {"startLine": 445}}}]}, {"ruleId": "AUC003", "level": "error", "message": {"text": "[AUC003] Object-level route lacks visible authorization: A route with an object id-like parameter does not show nearby authentication or authorization evidence. This is a BOLA/IDOR review target. Endpoint: ANY /jobs/<str:job_id>/."}, "properties": {"repobilityId": 224952, "scanner": "repobility-access-control", "fingerprint": "b9424e7eb38a75c99f3297725c717e5e055b51e02dfe1e47687b196896b0180e", "category": "auth", "severity": "high", "confidence": 0.7, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"path": "/jobs/<str:job_id>/", "method": "ANY", "scanner": "repobility-access-control", "framework": "Django", "correlation_key": "code|auth|backend/core/urls.py|41|cwe-639", "identity_targets": ["unknown", "owner"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/urls.py"}, "region": {"startLine": 41}}}]}, {"ruleId": "PYSEC-2026-142", "level": "error", "message": {"text": "urllib3: PYSEC-2026-142"}, "properties": {"repobilityId": 224949, "scanner": "osv-scanner", "fingerprint": "5f2e02d2c659d3ab15658789dfa42b355fce18e5357980b9a56ee43e7eb42b6a", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2026-44432", "GHSA-mf9v-mfxr-j63j"], "package": "urllib3", "rule_id": "PYSEC-2026-142", "scanner": "osv-scanner", "correlation_key": "vuln|urllib3|CVE-2026-44432|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-mf9v-mfxr-j63j", "PYSEC-2026-142"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["5f2e02d2c659d3ab15658789dfa42b355fce18e5357980b9a56ee43e7eb42b6a", "6bba33e0c2d8ac349b1ac06c49b7247b9b2fcff3ba63a1aa2c9b824716e5827b"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-141", "level": "error", "message": {"text": "urllib3: PYSEC-2026-141"}, "properties": {"repobilityId": 224948, "scanner": "osv-scanner", "fingerprint": "c9782ea239ddf9652bd8aa66c5c6c4ebee4d2b704faaab015341940a64bb5ee3", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2026-44431", "GHSA-qccp-gfcp-xxvc"], "package": "urllib3", "rule_id": "PYSEC-2026-141", "scanner": "osv-scanner", "correlation_key": "vuln|urllib3|CVE-2026-44431|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-qccp-gfcp-xxvc", "PYSEC-2026-141"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["8fea5709b1e04c1904accc4ad0dc76733fefc920773cbaba3c59a24994880532", "c9782ea239ddf9652bd8aa66c5c6c4ebee4d2b704faaab015341940a64bb5ee3"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-whj4-6x5x-4v2j", "level": "error", "message": {"text": "pillow: GHSA-whj4-6x5x-4v2j"}, "properties": {"repobilityId": 224934, "scanner": "osv-scanner", "fingerprint": "ab9c5303f10ecea59f859c1e7a68f477494fb8f4a1f9a96d15f0c051b8af8d37", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pillow-2026-40192", "CVE-2026-40192"], "package": "pillow", "rule_id": "GHSA-whj4-6x5x-4v2j", "scanner": "osv-scanner", "correlation_key": "vuln|pillow|CVE-2026-40192|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-pwv6-vv43-88gr", "level": "error", "message": {"text": "pillow: GHSA-pwv6-vv43-88gr"}, "properties": {"repobilityId": 224932, "scanner": "osv-scanner", "fingerprint": "448d12408dbd68671cd59b7187f414ae3afc2b14932fdc749eb5f8d71612cae9", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-pillow-2026-42311", "CVE-2026-42311"], "package": "pillow", "rule_id": "GHSA-pwv6-vv43-88gr", "scanner": "osv-scanner", "correlation_key": "vuln|pillow|CVE-2026-42311|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-165", "level": "error", "message": {"text": "pillow: PYSEC-2026-165"}, "properties": {"repobilityId": 224930, "scanner": "osv-scanner", "fingerprint": "b2d0c00c5823d4b04eec1c4e32d586e888ddbc60fa050a2a51719fa9a4ece963", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["BIT-pillow-2026-42308", "CVE-2026-42308", "GHSA-wjx4-4jcj-g98j"], "package": "pillow", "rule_id": "PYSEC-2026-165", "scanner": "osv-scanner", "correlation_key": "vuln|pillow|CVE-2026-42308|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-wjx4-4jcj-g98j", "PYSEC-2026-165"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["61ea0d010246eb729c784dba0206c629efa749d819d6f24cbe2dd9cbd4966e99", "b2d0c00c5823d4b04eec1c4e32d586e888ddbc60fa050a2a51719fa9a4ece963"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-87", "level": "error", "message": {"text": "lxml: PYSEC-2026-87"}, "properties": {"repobilityId": 224929, "scanner": "osv-scanner", "fingerprint": "57e96b9801c134a817a0972843002a06c0681c2469d31acfb0a75334eca5c6cc", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2026-41066", "GHSA-vfmq-68hx-4jfw"], "package": "lxml", "rule_id": "PYSEC-2026-87", "scanner": "osv-scanner", "correlation_key": "vuln|lxml|CVE-2026-41066|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-vfmq-68hx-4jfw", "PYSEC-2026-87"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["57e96b9801c134a817a0972843002a06c0681c2469d31acfb0a75334eca5c6cc", "b79d9a76eb4b6780ceedd1368a02f722861f752f14e3e7c4daf1a67af52287a2"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-537c-gmf6-5ccf", "level": "error", "message": {"text": "cryptography: GHSA-537c-gmf6-5ccf"}, "properties": {"repobilityId": 224927, "scanner": "osv-scanner", "fingerprint": "344bb377368dafa8eb8d56bb150c1109743771d399df825f5dce564de2146bc0", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "package": "cryptography", "rule_id": "GHSA-537c-gmf6-5ccf", "scanner": "osv-scanner", "correlation_key": "vuln|cryptography|GHSA-537C-GMF6-5CCF|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-36", "level": "error", "message": {"text": "cryptography: PYSEC-2026-36"}, "properties": {"repobilityId": 224926, "scanner": "osv-scanner", "fingerprint": "2f05b9d2c61a40e393516596518d278162399a34d4e26a2748185ee962ddc3cf", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2026-39892", "GHSA-p423-j2cm-9vmq"], "package": "cryptography", "rule_id": "PYSEC-2026-36", "scanner": "osv-scanner", "correlation_key": "vuln|cryptography|CVE-2026-39892|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-p423-j2cm-9vmq", "PYSEC-2026-36"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["2f05b9d2c61a40e393516596518d278162399a34d4e26a2748185ee962ddc3cf", "802329a66d7a78d7bbe0de294abde248f8e39d26f9add175bbe9f3017be02d02"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-35", "level": "error", "message": {"text": "cryptography: PYSEC-2026-35"}, "properties": {"repobilityId": 224925, "scanner": "osv-scanner", "fingerprint": "e580ab29be5c803aad3ab1049b00299716cedc9d9def3598054dbe135499dc02", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2026-34073", "GHSA-m959-cc7f-wv43"], "package": "cryptography", "rule_id": "PYSEC-2026-35", "scanner": "osv-scanner", "correlation_key": "vuln|cryptography|CVE-2026-34073|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-m959-cc7f-wv43", "PYSEC-2026-35"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["13d2c33e4d0203f565b9314f298ab91d3c0326d5db90d8390badc36608a90c1d", "e580ab29be5c803aad3ab1049b00299716cedc9d9def3598054dbe135499dc02"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-179", "level": "error", "message": {"text": "pyjwt: PYSEC-2026-179"}, "properties": {"repobilityId": 224922, "scanner": "osv-scanner", "fingerprint": "5c3eafc67979022f561e9d4f5419a08a2752d1c1403b6231e0286243dc4de621", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2026-48526", "GHSA-xgmm-8j9v-c9wx"], "package": "pyjwt", "rule_id": "PYSEC-2026-179", "scanner": "osv-scanner", "correlation_key": "vuln|pyjwt|CVE-2026-48526|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-xgmm-8j9v-c9wx", "PYSEC-2026-179"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["5c3eafc67979022f561e9d4f5419a08a2752d1c1403b6231e0286243dc4de621", "f3012a3d1e2725b6278b7171a74879760f8c9f0a9b25b83c0c9822678cdef484"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-178", "level": "error", "message": {"text": "pyjwt: PYSEC-2026-178"}, "properties": {"repobilityId": 224921, "scanner": "osv-scanner", "fingerprint": "d78da9b30f77c7f52b6df8d66103d01f553e3bf4dd2178d5ea0b37402014cb9a", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2026-48525", "GHSA-w7vc-732c-9m39"], "package": "pyjwt", "rule_id": "PYSEC-2026-178", "scanner": "osv-scanner", "correlation_key": "vuln|pyjwt|CVE-2026-48525|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-w7vc-732c-9m39", "PYSEC-2026-178"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["5c7ae0513a43d3cad822cd4a50f81ad0c01a853a172cc7fdc2d6f6664f07b128", "d78da9b30f77c7f52b6df8d66103d01f553e3bf4dd2178d5ea0b37402014cb9a"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-177", "level": "error", "message": {"text": "pyjwt: PYSEC-2026-177"}, "properties": {"repobilityId": 224920, "scanner": "osv-scanner", "fingerprint": "3efd69038a22cfd1254fc5996a1045b73353f48034b55443c679a98678e7502c", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2026-48524", "GHSA-fhv5-28vv-h8m8"], "package": "pyjwt", "rule_id": "PYSEC-2026-177", "scanner": "osv-scanner", "correlation_key": "vuln|pyjwt|CVE-2026-48524|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-fhv5-28vv-h8m8", "PYSEC-2026-177"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["3efd69038a22cfd1254fc5996a1045b73353f48034b55443c679a98678e7502c", "e6b6441f13ee74f7a385be18b3b88e0d27b607a6122dba9a391fd5321473d979"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-176", "level": "error", "message": {"text": "pyjwt: PYSEC-2026-176"}, "properties": {"repobilityId": 224919, "scanner": "osv-scanner", "fingerprint": "9cb579ee2b69105ef3545f61add1d1fc5f5837e9259e9562ac305e1b2edfcbbb", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2026-48523", "GHSA-jq35-7prp-9v3f"], "package": "pyjwt", "rule_id": "PYSEC-2026-176", "scanner": "osv-scanner", "correlation_key": "vuln|pyjwt|CVE-2026-48523|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-jq35-7prp-9v3f", "PYSEC-2026-176"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["9cb579ee2b69105ef3545f61add1d1fc5f5837e9259e9562ac305e1b2edfcbbb", "d821a2f23ab10263e27ea95f2c7062a8f76c86a34f394baf4e6b07e128b4f705"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-175", "level": "error", "message": {"text": "pyjwt: PYSEC-2026-175"}, "properties": {"repobilityId": 224918, "scanner": "osv-scanner", "fingerprint": "6e43e9e4fcddce5ed9d95508ee3af57e07c02f8be6ef2b4c716c8f00f38e9ef4", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-48522", "GHSA-993g-76c3-p5m4"], "package": "pyjwt", "rule_id": "PYSEC-2026-175", "scanner": "osv-scanner", "correlation_key": "vuln|pyjwt|CVE-2026-48522|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-120", "level": "error", "message": {"text": "pyjwt: PYSEC-2026-120"}, "properties": {"repobilityId": 224917, "scanner": "osv-scanner", "fingerprint": "6caf36498d4b7abad005b1eea81f754040e2c0f5f6d1a01b3f08a9b5547a758b", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2026-32597", "GHSA-752w-5fwx-jx9f"], "package": "pyjwt", "rule_id": "PYSEC-2026-120", "scanner": "osv-scanner", "correlation_key": "vuln|pyjwt|CVE-2026-32597|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-752w-5fwx-jx9f", "PYSEC-2026-120"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["6caf36498d4b7abad005b1eea81f754040e2c0f5f6d1a01b3f08a9b5547a758b", "da6dc263e76a00782090dfbe78086c251f57fcc2dcfd38bca8beeb965dbd2935"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2025-183", "level": "error", "message": {"text": "pyjwt: PYSEC-2025-183"}, "properties": {"repobilityId": 224916, "scanner": "osv-scanner", "fingerprint": "08fa77768ae9edd3e21f014bbff428488520df9887a5882063d44c06b9bb7250", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-45768"], "package": "pyjwt", "rule_id": "PYSEC-2025-183", "scanner": "osv-scanner", "correlation_key": "vuln|pyjwt|CVE-2025-45768|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-8p8v-wh79-9r56", "level": "error", "message": {"text": "django: GHSA-8p8v-wh79-9r56"}, "properties": {"repobilityId": 224914, "scanner": "osv-scanner", "fingerprint": "e8e935a91bc671b4435126fa4cb19510da004b88795df09782e3ae3c8f00d8f4", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-django-2026-25673", "CVE-2026-25673"], "package": "django", "rule_id": "GHSA-8p8v-wh79-9r56", "scanner": "osv-scanner", "correlation_key": "vuln|django|CVE-2026-25673|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-55", "level": "error", "message": {"text": "django: PYSEC-2026-55"}, "properties": {"repobilityId": 224913, "scanner": "osv-scanner", "fingerprint": "88120c39de34e37f183cfbbf5293d697963c13f17140ea696e516aaef5410fe4", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["BIT-django-2026-6907", "CVE-2026-6907", "GHSA-5hrc-gvxj-w55p"], "package": "django", "rule_id": "PYSEC-2026-55", "scanner": "osv-scanner", "correlation_key": "vuln|django|CVE-2026-6907|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-5hrc-gvxj-w55p", "PYSEC-2026-55"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["88120c39de34e37f183cfbbf5293d697963c13f17140ea696e516aaef5410fe4", "f22fc6d9e1e6c81b9454d700aedc887567ff03e3d6a03c3e4d4edc8df47c3c26"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-54", "level": "error", "message": {"text": "django: PYSEC-2026-54"}, "properties": {"repobilityId": 224912, "scanner": "osv-scanner", "fingerprint": "ea7752cf94709abc63759ca50187172bc2b72c8b4b65930c0e9aed8278363b1b", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["BIT-django-2026-5766", "CVE-2026-5766", "GHSA-w26r-rmm8-9c29"], "package": "django", "rule_id": "PYSEC-2026-54", "scanner": "osv-scanner", "correlation_key": "vuln|django|CVE-2026-5766|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-w26r-rmm8-9c29", "PYSEC-2026-54"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["d3685cdf4508c07a7bd62da65ed0fe1676e82bde713cac32d792be764ae054aa", "ea7752cf94709abc63759ca50187172bc2b72c8b4b65930c0e9aed8278363b1b"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-53", "level": "error", "message": {"text": "django: PYSEC-2026-53"}, "properties": {"repobilityId": 224911, "scanner": "osv-scanner", "fingerprint": "e218ac60a68211b297da95eff1d0b7a150bb12325b46f91cd168f4199a92a94c", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["BIT-django-2026-4292", "CVE-2026-4292", "GHSA-mmwr-2jhp-mc7j"], "package": "django", "rule_id": "PYSEC-2026-53", "scanner": "osv-scanner", "correlation_key": "vuln|django|CVE-2026-4292|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-mmwr-2jhp-mc7j", "PYSEC-2026-53"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["42d7fbd081dbb6d8247afc2b3a361fd9d025d18435d3b6895c7b4d5bcdcc3b07", "e218ac60a68211b297da95eff1d0b7a150bb12325b46f91cd168f4199a92a94c"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-52", "level": "error", "message": {"text": "django: PYSEC-2026-52"}, "properties": {"repobilityId": 224910, "scanner": "osv-scanner", "fingerprint": "b2d177c1e8be3dcc7c4aa5781764a6631b73689791a6d040e59976412a23b62d", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["BIT-django-2026-4277", "CVE-2026-4277", "GHSA-pwjp-ccjc-ghwg"], "package": "django", "rule_id": "PYSEC-2026-52", "scanner": "osv-scanner", "correlation_key": "vuln|django|CVE-2026-4277|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-pwjp-ccjc-ghwg", "PYSEC-2026-52"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["b2d177c1e8be3dcc7c4aa5781764a6631b73689791a6d040e59976412a23b62d", "bbb0523762eea127be7223db8744f63070b26df63de57e70688fc7cc04ea08d5"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-51", "level": "error", "message": {"text": "django: PYSEC-2026-51"}, "properties": {"repobilityId": 224909, "scanner": "osv-scanner", "fingerprint": "373c94c69597361e99aa20759ee0bbac182aac7236f4c91762c45372663e1e83", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["BIT-django-2026-3902", "CVE-2026-3902", "GHSA-mvfq-ggxm-9mc5"], "package": "django", "rule_id": "PYSEC-2026-51", "scanner": "osv-scanner", "correlation_key": "vuln|django|CVE-2026-3902|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-mvfq-ggxm-9mc5", "PYSEC-2026-51"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["373c94c69597361e99aa20759ee0bbac182aac7236f4c91762c45372663e1e83", "b10444f710bcb0fd2d600af25c375efb3d7c6d8bb9e3d2343d6bb60f727eea96"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-50", "level": "error", "message": {"text": "django: PYSEC-2026-50"}, "properties": {"repobilityId": 224908, "scanner": "osv-scanner", "fingerprint": "23a02ab2399b5f316c8d017209c88f8b2f4fb13de5164606563c32e57fa16ab6", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["BIT-django-2026-35192", "CVE-2026-35192", "GHSA-7h2m-m8vj-598h"], "package": "django", "rule_id": "PYSEC-2026-50", "scanner": "osv-scanner", "correlation_key": "vuln|django|CVE-2026-35192|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-7h2m-m8vj-598h", "PYSEC-2026-50"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["23a02ab2399b5f316c8d017209c88f8b2f4fb13de5164606563c32e57fa16ab6", "bb41658fd3d6d81ab10607297e3e89e2d089c4b53886825ce640b7d2f963085c"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-49", "level": "error", "message": {"text": "django: PYSEC-2026-49"}, "properties": {"repobilityId": 224907, "scanner": "osv-scanner", "fingerprint": "65c348f29487596ae9935d29ddf22f7a8568b1909a2992f931e9317c72ca10df", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["BIT-django-2026-33034", "CVE-2026-33034", "GHSA-933h-hp56-hf7m"], "package": "django", "rule_id": "PYSEC-2026-49", "scanner": "osv-scanner", "correlation_key": "vuln|django|CVE-2026-33034|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-933h-hp56-hf7m", "PYSEC-2026-49"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["65c348f29487596ae9935d29ddf22f7a8568b1909a2992f931e9317c72ca10df", "775ae958f3d756f93acb3b14aa98d4ca0298f476a2a3a1b09fbb76564dc9a90b"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-48", "level": "error", "message": {"text": "django: PYSEC-2026-48"}, "properties": {"repobilityId": 224906, "scanner": "osv-scanner", "fingerprint": "a4bf4f301aab1d998c4946d629a987cd11648a9882a556377e343c7c9f010425", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["BIT-django-2026-33033", "CVE-2026-33033", "GHSA-5mf9-h53q-7mhq"], "package": "django", "rule_id": "PYSEC-2026-48", "scanner": "osv-scanner", "correlation_key": "vuln|django|CVE-2026-33033|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-5mf9-h53q-7mhq", "PYSEC-2026-48"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["a4bf4f301aab1d998c4946d629a987cd11648a9882a556377e343c7c9f010425", "ab7f45d6ab4fa618c117feb2bf5c2b2d11c9b901670a947cb8d026b7503c9b35"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-47", "level": "error", "message": {"text": "django: PYSEC-2026-47"}, "properties": {"repobilityId": 224905, "scanner": "osv-scanner", "fingerprint": "4ad2f054cfbe2e8c6271accac8340121884cd65b35530ccd155b42f5db07194e", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["BIT-django-2026-1312", "CVE-2026-1312", "GHSA-6426-9fv3-65x8"], "package": "django", "rule_id": "PYSEC-2026-47", "scanner": "osv-scanner", "correlation_key": "vuln|django|CVE-2026-1312|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-6426-9fv3-65x8", "PYSEC-2026-47"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["12fee80551fa113ea1ea195f2eb9a8386c70c24d278a5d17c478910211ed3a64", "4ad2f054cfbe2e8c6271accac8340121884cd65b35530ccd155b42f5db07194e"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-46", "level": "error", "message": {"text": "django: PYSEC-2026-46"}, "properties": {"repobilityId": 224904, "scanner": "osv-scanner", "fingerprint": "033e553f81edbabac3ef13cf0cf51444bc50b16ad7553283c075491d416ce72c", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["BIT-django-2026-1287", "CVE-2026-1287", "GHSA-gvg8-93h5-g6qq"], "package": "django", "rule_id": "PYSEC-2026-46", "scanner": "osv-scanner", "correlation_key": "vuln|django|CVE-2026-1287|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-gvg8-93h5-g6qq", "PYSEC-2026-46"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["033e553f81edbabac3ef13cf0cf51444bc50b16ad7553283c075491d416ce72c", "d9478108642dc8bddb95c3373837036e6645db90535d6cc765bbc17a2519a901"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-45", "level": "error", "message": {"text": "django: PYSEC-2026-45"}, "properties": {"repobilityId": 224903, "scanner": "osv-scanner", "fingerprint": "6bee9d91947dd29a77cf1a050fc02f3749bea0018bbefbc48d369efbe0f934e7", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["BIT-django-2026-1285", "CVE-2026-1285", "GHSA-4rrr-2h4v-f3j9"], "package": "django", "rule_id": "PYSEC-2026-45", "scanner": "osv-scanner", "correlation_key": "vuln|django|CVE-2026-1285|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-4rrr-2h4v-f3j9", "PYSEC-2026-45"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["6124042744b8a3c6f15579cfd277dda5fd7ec85f4ebd00aa38881ac21f45223b", "6bee9d91947dd29a77cf1a050fc02f3749bea0018bbefbc48d369efbe0f934e7"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-44", "level": "error", "message": {"text": "django: PYSEC-2026-44"}, "properties": {"repobilityId": 224902, "scanner": "osv-scanner", "fingerprint": "3ce25e3ae550305def172b189d3c07393d756aad00c608e1e7551535f2d0beb8", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["BIT-django-2026-1207", "CVE-2026-1207", "GHSA-mwm9-4648-f68q"], "package": "django", "rule_id": "PYSEC-2026-44", "scanner": "osv-scanner", "correlation_key": "vuln|django|CVE-2026-1207|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-mwm9-4648-f68q", "PYSEC-2026-44"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["3ce25e3ae550305def172b189d3c07393d756aad00c608e1e7551535f2d0beb8", "4bf37368a7bb3f07d63e9db4669759a7d5cab095265754d63ce0937e5301561c"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-43", "level": "error", "message": {"text": "django: PYSEC-2026-43"}, "properties": {"repobilityId": 224901, "scanner": "osv-scanner", "fingerprint": "62cc91765f3e215f9f6b00b5d331e4cb715231df73afcc3b6a224d69a983d1fc", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["BIT-django-2025-14550", "CVE-2025-14550", "GHSA-33mw-q7rj-mjwj"], "package": "django", "rule_id": "PYSEC-2026-43", "scanner": "osv-scanner", "correlation_key": "vuln|django|CVE-2025-14550|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-33mw-q7rj-mjwj", "PYSEC-2026-43"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["0e3f83bb3846b6f5a4dfec239ffb7d990ab4ba93cc557989890b08c0d76937ea", "62cc91765f3e215f9f6b00b5d331e4cb715231df73afcc3b6a224d69a983d1fc"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-42", "level": "error", "message": {"text": "django: PYSEC-2026-42"}, "properties": {"repobilityId": 224900, "scanner": "osv-scanner", "fingerprint": "d75db6e33691c797dfe533534b13299177a90ef33e96b0f3a422cdd5e8958926", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 1 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["BIT-django-2025-13473", "CVE-2025-13473", "GHSA-2mcm-79hx-8fxw"], "package": "django", "rule_id": "PYSEC-2026-42", "scanner": "osv-scanner", "correlation_key": "vuln|django|CVE-2025-13473|requirements.txt", "duplicate_count": 1, "duplicate_rule_ids": ["GHSA-2mcm-79hx-8fxw", "PYSEC-2026-42"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["d75db6e33691c797dfe533534b13299177a90ef33e96b0f3a422cdd5e8958926", "e3c6daa1ed7abebf5d5b3b410fe3814f74af9238c3ca5d79585d137dd06aec56"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-201", "level": "error", "message": {"text": "django: PYSEC-2026-201"}, "properties": {"repobilityId": 224899, "scanner": "osv-scanner", "fingerprint": "f6f2755d5b389ab4e61a692090f5ae9eb66772f460cf3258a32f220cacd6f473", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-django-2026-8404", "CVE-2026-8404"], "package": "django", "rule_id": "PYSEC-2026-201", "scanner": "osv-scanner", "correlation_key": "vuln|django|CVE-2026-8404|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-200", "level": "error", "message": {"text": "django: PYSEC-2026-200"}, "properties": {"repobilityId": 224898, "scanner": "osv-scanner", "fingerprint": "a799c76d27a41bbf488599332dc36e3f4a193cafc9461b159798646d09fe4a97", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-django-2026-7666", "CVE-2026-7666"], "package": "django", "rule_id": "PYSEC-2026-200", "scanner": "osv-scanner", "correlation_key": "vuln|django|CVE-2026-7666|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-199", "level": "error", "message": {"text": "django: PYSEC-2026-199"}, "properties": {"repobilityId": 224897, "scanner": "osv-scanner", "fingerprint": "226cff64523aa1583cde1a58d727e966f69598b5cd1ad5c0a0107e19e664aed6", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-django-2026-6873", "CVE-2026-6873"], "package": "django", "rule_id": "PYSEC-2026-199", "scanner": "osv-scanner", "correlation_key": "vuln|django|CVE-2026-6873|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-198", "level": "error", "message": {"text": "django: PYSEC-2026-198"}, "properties": {"repobilityId": 224896, "scanner": "osv-scanner", "fingerprint": "8281a0fa77435abe4b91a86b858c9c72ea40354cc7b8f7f1f9e90986442f6aeb", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-django-2026-48587", "CVE-2026-48587"], "package": "django", "rule_id": "PYSEC-2026-198", "scanner": "osv-scanner", "correlation_key": "vuln|django|CVE-2026-48587|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "PYSEC-2026-197", "level": "error", "message": {"text": "django: PYSEC-2026-197"}, "properties": {"repobilityId": 224895, "scanner": "osv-scanner", "fingerprint": "c1644e58741fea542f4452f1486f8eec09174533cc4b9fde2e1ae2e1e8602769", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["BIT-django-2026-35193", "CVE-2026-35193"], "package": "django", "rule_id": "PYSEC-2026-197", "scanner": "osv-scanner", "correlation_key": "vuln|django|CVE-2026-35193|requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-96hv-2xvq-fx4p", "level": "error", "message": {"text": "ws: GHSA-96hv-2xvq-fx4p"}, "properties": {"repobilityId": 224892, "scanner": "osv-scanner", "fingerprint": "9c9493b427a02fb56a6f28b50cd6692524fc329ac778b7ffa0a204aa0ac73a7c", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-48779"], "package": "ws", "rule_id": "GHSA-96hv-2xvq-fx4p", "scanner": "osv-scanner", "correlation_key": "vuln|ws|CVE-2026-48779|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-c2c7-rcm5-vvqj", "level": "error", "message": {"text": "picomatch: GHSA-c2c7-rcm5-vvqj"}, "properties": {"repobilityId": 224888, "scanner": "osv-scanner", "fingerprint": "770a27bb8ae9ebf1dc9c2215564b21d713abf99e18aa8716cbbcb2f855aa4c08", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-33671"], "package": "picomatch", "rule_id": "GHSA-c2c7-rcm5-vvqj", "scanner": "osv-scanner", "correlation_key": "vuln|picomatch|CVE-2026-33671|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-q67f-28xg-22rw", "level": "error", "message": {"text": "node-forge: GHSA-q67f-28xg-22rw"}, "properties": {"repobilityId": 224886, "scanner": "osv-scanner", "fingerprint": "72ea8ba26f75fb73142525e079eb3867908de70ff42b2e1cec82d6b701014dba", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-33895"], "package": "node-forge", "rule_id": "GHSA-q67f-28xg-22rw", "scanner": "osv-scanner", "correlation_key": "vuln|node-forge|CVE-2026-33895|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-ppp5-5v6c-4jwp", "level": "error", "message": {"text": "node-forge: GHSA-ppp5-5v6c-4jwp"}, "properties": {"repobilityId": 224885, "scanner": "osv-scanner", "fingerprint": "0a2e62b4708ae674853f13322912d28144bbda93d587a2c4acc7c16055e14c4a", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-33894"], "package": "node-forge", "rule_id": "GHSA-ppp5-5v6c-4jwp", "scanner": "osv-scanner", "correlation_key": "vuln|node-forge|CVE-2026-33894|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-5m6q-g25r-mvwx", "level": "error", "message": {"text": "node-forge: GHSA-5m6q-g25r-mvwx"}, "properties": {"repobilityId": 224884, "scanner": "osv-scanner", "fingerprint": "f7336747aa6a5e9dd1d1f2781ee54137cd754773b61e805fbc9987a772432d25", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-33891"], "package": "node-forge", "rule_id": "GHSA-5m6q-g25r-mvwx", "scanner": "osv-scanner", "correlation_key": "vuln|node-forge|CVE-2026-33891|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-2328-f5f3-gj25", "level": "error", "message": {"text": "node-forge: GHSA-2328-f5f3-gj25"}, "properties": {"repobilityId": 224883, "scanner": "osv-scanner", "fingerprint": "2fb516ca68294b2a2411316344bd3307cd554026528f3cc64f28371d96954573", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-33896"], "package": "node-forge", "rule_id": "GHSA-2328-f5f3-gj25", "scanner": "osv-scanner", "correlation_key": "vuln|node-forge|CVE-2026-33896|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-hmw2-7cc7-3qxx", "level": "error", "message": {"text": "form-data: GHSA-hmw2-7cc7-3qxx"}, "properties": {"repobilityId": 224881, "scanner": "osv-scanner", "fingerprint": "e233255211fa4f6b42bf3dc10b77d13574334f19c20c6c50452000bbda5d6628", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-12143"], "package": "form-data", "rule_id": "GHSA-hmw2-7cc7-3qxx", "scanner": "osv-scanner", "correlation_key": "vuln|form-data|CVE-2026-12143|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-q8qp-cvcw-x6jj", "level": "error", "message": {"text": "axios: GHSA-q8qp-cvcw-x6jj"}, "properties": {"repobilityId": 224873, "scanner": "osv-scanner", "fingerprint": "88c00a5f80ba6fef9e203e3dd280ba3827f9691fe11771112a250db878029917", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-42264"], "package": "axios", "rule_id": "GHSA-q8qp-cvcw-x6jj", "scanner": "osv-scanner", "correlation_key": "vuln|axios|CVE-2026-42264|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-pf86-5x62-jrwf", "level": "error", "message": {"text": "axios: GHSA-pf86-5x62-jrwf"}, "properties": {"repobilityId": 224872, "scanner": "osv-scanner", "fingerprint": "f5e456cbebb4c1c0642a67033892726c0502f49d7c89601f6cba36a82f696264", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-42033"], "package": "axios", "rule_id": "GHSA-pf86-5x62-jrwf", "scanner": "osv-scanner", "correlation_key": "vuln|axios|CVE-2026-42033|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-p92q-9vqr-4j8v", "level": "error", "message": {"text": "axios: GHSA-p92q-9vqr-4j8v"}, "properties": {"repobilityId": 224871, "scanner": "osv-scanner", "fingerprint": "a27df285c71aca549103eeaf436006a2d37cfbe4440182cf1c2e71e5a9ddc754", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44487"], "package": "axios", "rule_id": "GHSA-p92q-9vqr-4j8v", "scanner": "osv-scanner", "correlation_key": "vuln|axios|CVE-2026-44487|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-j5f8-grm9-p9fc", "level": "error", "message": {"text": "axios: GHSA-j5f8-grm9-p9fc"}, "properties": {"repobilityId": 224869, "scanner": "osv-scanner", "fingerprint": "cf523ec1328536409a39f3bfb2988920c5b739e71fc97c88fb033ef8f68a81a2", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44486"], "package": "axios", "rule_id": "GHSA-j5f8-grm9-p9fc", "scanner": "osv-scanner", "correlation_key": "vuln|axios|CVE-2026-44486|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-hfxv-24rg-xrqf", "level": "error", "message": {"text": "axios: GHSA-hfxv-24rg-xrqf"}, "properties": {"repobilityId": 224868, "scanner": "osv-scanner", "fingerprint": "8d8a8c1b5ec3ecf7b8d85b727c7b76cd3b87c5dbceacba9499ad49da53830bc7", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44496"], "package": "axios", "rule_id": "GHSA-hfxv-24rg-xrqf", "scanner": "osv-scanner", "correlation_key": "vuln|axios|CVE-2026-44496|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-777c-7fjr-54vf", "level": "error", "message": {"text": "axios: GHSA-777c-7fjr-54vf"}, "properties": {"repobilityId": 224865, "scanner": "osv-scanner", "fingerprint": "96bc38a4956ea261bfcb321d50b6a4137353ba10f48b65eb077e5ec42db66644", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44488"], "package": "axios", "rule_id": "GHSA-777c-7fjr-54vf", "scanner": "osv-scanner", "correlation_key": "vuln|axios|CVE-2026-44488|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-6chq-wfr3-2hj9", "level": "error", "message": {"text": "axios: GHSA-6chq-wfr3-2hj9"}, "properties": {"repobilityId": 224864, "scanner": "osv-scanner", "fingerprint": "b55fe320ff0571d996374b6ff484e57c16b7d9436d79eac6fe1bfd804011418c", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-42035"], "package": "axios", "rule_id": "GHSA-6chq-wfr3-2hj9", "scanner": "osv-scanner", "correlation_key": "vuln|axios|CVE-2026-42035|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-pjwm-pj3p-43mv", "level": "error", "message": {"text": "axios: GHSA-pjwm-pj3p-43mv"}, "properties": {"repobilityId": 224859, "scanner": "osv-scanner", "fingerprint": "50a4e5ded99918f600fe53dd2a4a3471fb43495eddf8a58bd8bdaacbc50454cb", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "Collapsed 2 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "", "aliases": ["CVE-2026-44492"], "package": "axios", "rule_id": "GHSA-pjwm-pj3p-43mv", "scanner": "osv-scanner", "correlation_key": "vuln|axios|CVE-2025-62718|mobile/package-lock.json", "duplicate_count": 2, "duplicate_rule_ids": ["GHSA-3p68-rc4w-qgx5", "GHSA-pjwm-pj3p-43mv", "GHSA-pmwg-cvhr-8vh7"], "duplicate_scanners": ["osv-scanner"], "duplicate_fingerprints": ["50a4e5ded99918f600fe53dd2a4a3471fb43495eddf8a58bd8bdaacbc50454cb", "56ec4e869062f91908317fd5a130ae8f8abeb06f0e2089ea11b0d50ec3cd6e2f", "74b9186a8b85779e43a1fef1cfd3118cd4eea8f6859781eef287ec211ebc0b71"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-3g43-6gmg-66jw", "level": "error", "message": {"text": "axios: GHSA-3g43-6gmg-66jw"}, "properties": {"repobilityId": 224858, "scanner": "osv-scanner", "fingerprint": "eff490034f7f0e4658f290467d113dfc1c7464b79abf1b5e0fc8bc99ade8f167", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44495"], "package": "axios", "rule_id": "GHSA-3g43-6gmg-66jw", "scanner": "osv-scanner", "correlation_key": "vuln|axios|CVE-2026-44495|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-35jp-ww65-95wh", "level": "error", "message": {"text": "axios: GHSA-35jp-ww65-95wh"}, "properties": {"repobilityId": 224857, "scanner": "osv-scanner", "fingerprint": "fb72865ae592deeb4409260e60ce8f00e578c00b9eaf1c902a25bfea8eb51b1c", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44494"], "package": "axios", "rule_id": "GHSA-35jp-ww65-95wh", "scanner": "osv-scanner", "correlation_key": "vuln|axios|CVE-2026-44494|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-x6wf-f3px-wcqx", "level": "error", "message": {"text": "@xmldom/xmldom: GHSA-x6wf-f3px-wcqx"}, "properties": {"repobilityId": 224856, "scanner": "osv-scanner", "fingerprint": "d15f6ea0f0000381312a229c66e9cc857cc824102a552d2240af17042f7a7d31", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-41675"], "package": "@xmldom/xmldom", "rule_id": "GHSA-x6wf-f3px-wcqx", "scanner": "osv-scanner", "correlation_key": "vuln|xmldom/xmldom|CVE-2026-41675|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-wh4c-j3r5-mjhp", "level": "error", "message": {"text": "@xmldom/xmldom: GHSA-wh4c-j3r5-mjhp"}, "properties": {"repobilityId": 224855, "scanner": "osv-scanner", "fingerprint": "e001d2e79afbdb37ef839ab3d36c62aff5fb28114a19d2aa12f1a6c47a29805a", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-34601"], "package": "@xmldom/xmldom", "rule_id": "GHSA-wh4c-j3r5-mjhp", "scanner": "osv-scanner", "correlation_key": "vuln|xmldom/xmldom|CVE-2026-34601|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-j759-j44w-7fr8", "level": "error", "message": {"text": "@xmldom/xmldom: GHSA-j759-j44w-7fr8"}, "properties": {"repobilityId": 224854, "scanner": "osv-scanner", "fingerprint": "73a2b8ba2a128adb6be9e3e02f42656af4e23b10a25c050d06fd873d0c488fa3", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-41672"], "package": "@xmldom/xmldom", "rule_id": "GHSA-j759-j44w-7fr8", "scanner": "osv-scanner", "correlation_key": "vuln|xmldom/xmldom|CVE-2026-41672|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-f6ww-3ggp-fr8h", "level": "error", "message": {"text": "@xmldom/xmldom: GHSA-f6ww-3ggp-fr8h"}, "properties": {"repobilityId": 224853, "scanner": "osv-scanner", "fingerprint": "cdd0a56b9a7840d28a8e8e68dde9e430b34709e3bc07e01e6e69a16ad91a5dc7", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-41674"], "package": "@xmldom/xmldom", "rule_id": "GHSA-f6ww-3ggp-fr8h", "scanner": "osv-scanner", "correlation_key": "vuln|xmldom/xmldom|CVE-2026-41674|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-2v35-w6hq-6mfw", "level": "error", "message": {"text": "@xmldom/xmldom: GHSA-2v35-w6hq-6mfw"}, "properties": {"repobilityId": 224852, "scanner": "osv-scanner", "fingerprint": "bc67a72d065d1eeb5f321eea9ed7d1c79f6c120ac6bc475e59a823d2b8ab59a5", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-41673"], "package": "@xmldom/xmldom", "rule_id": "GHSA-2v35-w6hq-6mfw", "scanner": "osv-scanner", "correlation_key": "vuln|xmldom/xmldom|CVE-2026-41673|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-hmw2-7cc7-3qxx", "level": "error", "message": {"text": "form-data: GHSA-hmw2-7cc7-3qxx"}, "properties": {"repobilityId": 224847, "scanner": "osv-scanner", "fingerprint": "8bf0b89982739c208078f0f04120762d4f2c36eb2733b993127b22c81d2e0ab8", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-12143"], "package": "form-data", "rule_id": "GHSA-hmw2-7cc7-3qxx", "scanner": "osv-scanner", "correlation_key": "vuln|form-data|CVE-2026-12143|frontend/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-537c-gmf6-5ccf", "level": "error", "message": {"text": "cryptography: GHSA-537c-gmf6-5ccf"}, "properties": {"repobilityId": 224842, "scanner": "osv-scanner", "fingerprint": "77f5acb15b25dfabd248535ee1e7ad111dbca17c0c68b29145554f4af294def0", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "package": "cryptography", "rule_id": "GHSA-537c-gmf6-5ccf", "scanner": "osv-scanner", "correlation_key": "vuln|cryptography|GHSA-537C-GMF6-5CCF|backend/requirements.txt"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/requirements.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "DKC011", "level": "error", "message": {"text": "Database service publishes a host port"}, "properties": {"repobilityId": 224837, "scanner": "repobility-docker", "fingerprint": "e0b6214d03a14cde4846c28a4d4cb0cbdb37e1156bc15231fbe24e9d2f589350", "category": "docker", "severity": "high", "confidence": 0.84, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Database-like image publishes host ports without a loopback-only bind.", "evidence": {"ports": [{"raw": "6379:6379", "target": "6379", "host_ip": "", "published": "6379"}], "rule_id": "DKC011", "scanner": "repobility-docker", "service": "redis", "references": ["https://docs.docker.com/compose/how-tos/environment-variables/best-practices/", "https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html"], "exposure_scope": "public", "correlation_key": "fp|e0b6214d03a14cde4846c28a4d4cb0cbdb37e1156bc15231fbe24e9d2f589350"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker-compose.yml"}, "region": {"startLine": 71}}}]}, {"ruleId": "DKR014", "level": "error", "message": {"text": "Dockerfile copies the entire context without .dockerignore"}, "properties": {"repobilityId": 224828, "scanner": "repobility-docker", "fingerprint": "8f7d92b4b513c397661c9974cd73dbe40621ea58335f90e2973564e293a875d9", "category": "docker", "severity": "high", "confidence": 0.92, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Broad context copy and missing .dockerignore were found together.", "evidence": {"rule_id": "DKR014", "scanner": "repobility-docker", "references": ["https://docs.docker.com/develop/develop-images/dockerfile_best-practices/"], "correlation_key": "fp|8f7d92b4b513c397661c9974cd73dbe40621ea58335f90e2973564e293a875d9"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/Dockerfile"}, "region": {"startLine": 11}}}]}, {"ruleId": "DKR014", "level": "error", "message": {"text": "Dockerfile copies the entire context without .dockerignore"}, "properties": {"repobilityId": 224826, "scanner": "repobility-docker", "fingerprint": "5118084c0d233b8199ddf3287421383b4152637707c41792fc910f7d3588932a", "category": "docker", "severity": "high", "confidence": 0.92, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Broad context copy and missing .dockerignore were found together.", "evidence": {"rule_id": "DKR014", "scanner": "repobility-docker", "references": ["https://docs.docker.com/develop/develop-images/dockerfile_best-practices/"], "correlation_key": "fp|5118084c0d233b8199ddf3287421383b4152637707c41792fc910f7d3588932a"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/Dockerfile"}, "region": {"startLine": 63}}}]}, {"ruleId": "SEC040", "level": "error", "message": {"text": "[SEC040] innerHTML XSS \u2014 template literal with server-supplied data: Setting .innerHTML with a template literal that interpolates server-supplied or user-supplied data is the canonical stored/reflected XSS vector. The browser parses the HTML and executes any <script> or event-handler attributes in the data. CWE-79. Especially dangerous when the data comes from a CV parser, profile field, or any user-input pipeline."}, "properties": {"repobilityId": 224800, "scanner": "repobility-threat-engine", "fingerprint": "786ad005b415cb3af3549b466968b000081797317f37dbcfb8e2765d892b29de", "category": "xss", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "map((cell) => `\"${cell ?? ''}", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC040", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|786ad005b415cb3af3549b466968b000081797317f37dbcfb8e2765d892b29de"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/components/generate-reports-dialog.tsx"}, "region": {"startLine": 19}}}]}, {"ruleId": "SEC040", "level": "error", "message": {"text": "[SEC040] innerHTML XSS \u2014 template literal with server-supplied data: Setting .innerHTML with a template literal that interpolates server-supplied or user-supplied data is the canonical stored/reflected XSS vector. The browser parses the HTML and executes any <script> or event-handler attributes in the data. CWE-79. Especially dangerous when the data comes from a CV parser, profile field, or any user-input pipeline."}, "properties": {"repobilityId": 224799, "scanner": "repobility-threat-engine", "fingerprint": "368b2c260d4aeb26f1e4d8dab38efb4d1933c71af0e393dc4009685851703f1a", "category": "xss", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "map(([k, v]) => `${k}: ${String(v)}", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC040", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|368b2c260d4aeb26f1e4d8dab38efb4d1933c71af0e393dc4009685851703f1a"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/admin/system/audit-logs/page.tsx"}, "region": {"startLine": 35}}}]}, {"ruleId": "SEC040", "level": "error", "message": {"text": "[SEC040] innerHTML XSS \u2014 template literal with server-supplied data: Setting .innerHTML with a template literal that interpolates server-supplied or user-supplied data is the canonical stored/reflected XSS vector. The browser parses the HTML and executes any <script> or event-handler attributes in the data. CWE-79. Especially dangerous when the data comes from a CV parser, profile field, or any user-input pipeline."}, "properties": {"repobilityId": 224798, "scanner": "repobility-threat-engine", "fingerprint": "49ca9300befcbc61ea2ded6b1d9335be46d74d34f0ab9abd5eac1dfb1d59137b", "category": "xss", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "map(([key, value]) => `${key}: ${String(value)}", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC040", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|49ca9300befcbc61ea2ded6b1d9335be46d74d34f0ab9abd5eac1dfb1d59137b"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/app/(saas)/saas/audit/page.tsx"}, "region": {"startLine": 31}}}]}, {"ruleId": "SEC035", "level": "error", "message": {"text": "[SEC035] Unbounded Resource Allocation \u2014 DoS risk: Allocating resources (buffers, recursion stack, large ranges) based on user input without an upper bound. Attackers send `size=10000000` to exhaust memory, or trigger expensive computation. CWE-770/400. Examples: CVE-2023-44487 (HTTP/2 Rapid Reset), countless YAML/XML billion-laughs variants."}, "properties": {"repobilityId": 224787, "scanner": "repobility-threat-engine", "fingerprint": "72c84273f83d690f32f89fb9bf97c3436185b233be20aa9f561abf161dea8d62", "category": "resource_exhaustion", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "bytes(user.", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC035", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|72c84273f83d690f32f89fb9bf97c3436185b233be20aa9f561abf161dea8d62"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/users/tests_email_verification.py"}, "region": {"startLine": 46}}}]}, {"ruleId": "SEC004", "level": "error", "message": {"text": "[SEC004] SQL Injection Risk: String interpolation in SQL execution. Allows SQL injection."}, "properties": {"repobilityId": 224773, "scanner": "repobility-threat-engine", "fingerprint": "0ab71ac14bae27aba35798d82be78182dd69199779f4bbfd2c284a7d6eed6f8a", "category": "injection", "severity": "high", "confidence": 0.5, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "SQL string interpolation found, but user-controlled taint was not proven from local context.", "evidence": {"match": "cursor.execute(f\"", "reason": "SQL string interpolation found, but user-controlled taint was not proven from local context.", "rule_id": "SEC004", "scanner": "repobility-threat-engine", "confidence": 0.5, "correlation_key": "code|injection|token|80|sec004"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/create_library_tables_simple.py"}, "region": {"startLine": 80}}}]}, {"ruleId": "SEC004", "level": "error", "message": {"text": "[SEC004] SQL Injection Risk: String interpolation in SQL execution. Allows SQL injection."}, "properties": {"repobilityId": 224772, "scanner": "repobility-threat-engine", "fingerprint": "cd4cd5bac0d6eda8450f4a54d35be60ce3f97cd050285fe187eee6a362a79b6b", "category": "injection", "severity": "high", "confidence": 0.5, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "SQL string interpolation found, but user-controlled taint was not proven from local context.", "evidence": {"match": "cursor.execute(f\"", "reason": "SQL string interpolation found, but user-controlled taint was not proven from local context.", "rule_id": "SEC004", "scanner": "repobility-threat-engine", "confidence": 0.5, "correlation_key": "code|injection|token|121|sec004"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/create_library_tables_final.py"}, "region": {"startLine": 121}}}]}, {"ruleId": "SEC004", "level": "error", "message": {"text": "[SEC004] SQL Injection Risk: String interpolation in SQL execution. Allows SQL injection."}, "properties": {"repobilityId": 224771, "scanner": "repobility-threat-engine", "fingerprint": "5ce0adeb22a0c27745d80912d87eb0d37c717634704ad6adb8731e072f3f9916", "category": "injection", "severity": "high", "confidence": 0.5, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "SQL string interpolation found, but user-controlled taint was not proven from local context.", "evidence": {"match": "cursor.execute(f\"", "reason": "SQL string interpolation found, but user-controlled taint was not proven from local context.", "rule_id": "SEC004", "scanner": "repobility-threat-engine", "confidence": 0.5, "correlation_key": "code|injection|token|77|sec004"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/create_library_tables.py"}, "region": {"startLine": 77}}}]}, {"ruleId": "SEC103", "level": "error", "message": {"text": "[SEC103] LDAP injection \u2014 non-constant search filter: User input concatenated into an LDAP search filter. Attackers inject `*)(uid=*` style payloads to bypass auth or enumerate accounts."}, "properties": {"repobilityId": 224752, "scanner": "repobility-threat-engine", "fingerprint": "ade6fc282a1792687fb138a979b43490969e2b6fafcfafc3962f7e2e3f5efd76", "category": "injection", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": ".search(r\"-(\\d+)", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC103", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "code|injection|token|190|sec103"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/tasks.py"}, "region": {"startLine": 190}}}]}, {"ruleId": "MINED009", "level": "error", "message": {"text": "[MINED009] Floats For Money: Variable named price/amount/cost typed as float instead of Decimal."}, "properties": {"repobilityId": 224747, "scanner": "repobility-threat-engine", "fingerprint": "e72e16da90da49565246250ccda873f3acf92c9f8c5d300c4f19b4b8ed7d31f5", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "floats-for-money", "owasp": null, "cwe_ids": ["CWE-682"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.347918+00:00", "triaged_in_corpus": 15, "observations_count": 208571, "ai_coder_pattern_id": 20}, "scanner": "repobility-threat-engine", "correlation_key": "fp|e72e16da90da49565246250ccda873f3acf92c9f8c5d300c4f19b4b8ed7d31f5"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/views_payment_gateway.py"}, "region": {"startLine": 113}}}]}, {"ruleId": "MINED009", "level": "error", "message": {"text": "[MINED009] Floats For Money: Variable named price/amount/cost typed as float instead of Decimal."}, "properties": {"repobilityId": 224746, "scanner": "repobility-threat-engine", "fingerprint": "d98239dd87c9680d974631d90b34f8577b79371394d7ca221345ba8c2d7c895a", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "floats-for-money", "owasp": null, "cwe_ids": ["CWE-682"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.347918+00:00", "triaged_in_corpus": 15, "observations_count": 208571, "ai_coder_pattern_id": 20}, "scanner": "repobility-threat-engine", "correlation_key": "fp|d98239dd87c9680d974631d90b34f8577b79371394d7ca221345ba8c2d7c895a"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/payment_gateways.py"}, "region": {"startLine": 35}}}]}, {"ruleId": "SEC078", "level": "error", "message": {"text": "[SEC078] Python: requests without timeout: requests.get/post without a timeout will hang indefinitely on a non-responsive server, causing thread exhaustion and ReDoS. Ported from bandit B113 (Apache-2.0). NOTE: this regex is heuristic; a real AST check is preferred for accuracy."}, "properties": {"repobilityId": 224744, "scanner": "repobility-threat-engine", "fingerprint": "8cf6201eac353a89565b800a96d7347071e5e69eef81fc04e4885affb240c8cc", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "requests.post(", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC078", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|8cf6201eac353a89565b800a96d7347071e5e69eef81fc04e4885affb240c8cc"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/notifications/services.py"}, "region": {"startLine": 59}}}]}, {"ruleId": "SEC078", "level": "error", "message": {"text": "[SEC078] Python: requests without timeout: requests.get/post without a timeout will hang indefinitely on a non-responsive server, causing thread exhaustion and ReDoS. Ported from bandit B113 (Apache-2.0). NOTE: this regex is heuristic; a real AST check is preferred for accuracy."}, "properties": {"repobilityId": 224743, "scanner": "repobility-threat-engine", "fingerprint": "19e43520d4658e5cf0b1b9fee4b1445aa74bf3dd5205b5c23a98f66b1a2e5be5", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "requests.post(", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC078", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|19e43520d4658e5cf0b1b9fee4b1445aa74bf3dd5205b5c23a98f66b1a2e5be5"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/email_backends/resend_backend.py"}, "region": {"startLine": 60}}}]}, {"ruleId": "SEC078", "level": "error", "message": {"text": "[SEC078] Python: requests without timeout: requests.get/post without a timeout will hang indefinitely on a non-responsive server, causing thread exhaustion and ReDoS. Ported from bandit B113 (Apache-2.0). NOTE: this regex is heuristic; a real AST check is preferred for accuracy."}, "properties": {"repobilityId": 224742, "scanner": "repobility-threat-engine", "fingerprint": "a7dc9e85bfa3e632dffeae243f54f947501031682d78635e0e895cac88efe798", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "requests.post(", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC078", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|a7dc9e85bfa3e632dffeae243f54f947501031682d78635e0e895cac88efe798"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/payment_gateways.py"}, "region": {"startLine": 57}}}]}, {"ruleId": "SEC029", "level": "error", "message": {"text": "[SEC029] Server-Side Request Forgery (SSRF) \u2014 outbound HTTP from user input: Outbound HTTP request to a user-controlled URL without allowlist validation. Attackers can probe internal services (169.254.169.254 metadata, internal Kubernetes endpoints, file:// URIs), exfiltrate data, or pivot through your network. SSRF is OWASP A10:2021 and a frequent foothold in cloud breaches."}, "properties": {"repobilityId": 224738, "scanner": "repobility-threat-engine", "fingerprint": "2321e3252ded882031c57a8bec4e2938ab1694fa8fa2403c2cae0898d599e0b1", "category": "ssrf", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "requests.post(\n                    self.api_url", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC029", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|2321e3252ded882031c57a8bec4e2938ab1694fa8fa2403c2cae0898d599e0b1"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/email_backends/resend_backend.py"}, "region": {"startLine": 60}}}]}, {"ruleId": "SEC029", "level": "error", "message": {"text": "[SEC029] Server-Side Request Forgery (SSRF) \u2014 outbound HTTP from user input: Outbound HTTP request to a user-controlled URL without allowlist validation. Attackers can probe internal services (169.254.169.254 metadata, internal Kubernetes endpoints, file:// URIs), exfiltrate data, or pivot through your network. SSRF is OWASP A10:2021 and a frequent foothold in cloud breaches."}, "properties": {"repobilityId": 224737, "scanner": "repobility-threat-engine", "fingerprint": "b1b73561cf829e7f570c05c1a21bec000e99b89744bf496d321fdadd7e9d2103", "category": "ssrf", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "requests.post(\n                EsewaGateway.get_verify_url", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC029", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|b1b73561cf829e7f570c05c1a21bec000e99b89744bf496d321fdadd7e9d2103"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/payment_gateways.py"}, "region": {"startLine": 57}}}]}, {"ruleId": "SEC029", "level": "error", "message": {"text": "[SEC029] Server-Side Request Forgery (SSRF) \u2014 outbound HTTP from user input: Outbound HTTP request to a user-controlled URL without allowlist validation. Attackers can probe internal services (169.254.169.254 metadata, internal Kubernetes endpoints, file:// URIs), exfiltrate data, or pivot through your network. SSRF is OWASP A10:2021 and a frequent foothold in cloud breaches."}, "properties": {"repobilityId": 224736, "scanner": "repobility-threat-engine", "fingerprint": "8f9d0f00c907d8bb73b5bf9ae33cc4f4c9119fae1565ff9b152c2d80e85a06b5", "category": "ssrf", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "urllib.request.urlopen(r", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC029", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|8f9d0f00c907d8bb73b5bf9ae33cc4f4c9119fae1565ff9b152c2d80e85a06b5"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/services/video_transcript_service.py"}, "region": {"startLine": 122}}}]}, {"ruleId": "SEC020", "level": "error", "message": {"text": "[SEC020] Secret Printed to Logs: Debug or diagnostic code appears to print a credential-bearing value. This is a frequent AI-assisted coding failure: the helper exposes the exact value needed for troubleshooting."}, "properties": {"repobilityId": 224732, "scanner": "repobility-threat-engine", "fingerprint": "594a8e15634266a93addff3e48da18764937c7396547bf563dccd02f81777106", "category": "credential_exposure", "severity": "high", "confidence": 0.92, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Formatted expression outputs a credential-bearing value directly.", "evidence": {"match": "print(f\"DB: {db} | User: {email} | Password: <redacted>} | Match: {match}\")", "reason": "Formatted expression outputs a credential-bearing value directly.", "rule_id": "SEC020", "scanner": "repobility-threat-engine", "confidence": 0.92, "correlation_key": "secret|token|1|print f db: db user: email password: redacted match: match"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/check_auth.py"}, "region": {"startLine": 19}}}]}, {"ruleId": "MINED001", "level": "error", "message": {"text": "[MINED001] Bare Except Pass: except: pass or except Exception: pass \u2014 silently swallows everything including KeyboardInterrupt and bugs."}, "properties": {"repobilityId": 224713, "scanner": "repobility-threat-engine", "fingerprint": "1af55d70ca4e6ed503ecdb9d69caf0172e19629e9de33d0dcdeff549d1986953", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "bare-except-pass", "owasp": null, "cwe_ids": ["CWE-755"], "languages": ["python"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.347744+00:00", "triaged_in_corpus": 15, "observations_count": 1550824, "ai_coder_pattern_id": 6}, "scanner": "repobility-threat-engine", "correlation_key": "fp|1af55d70ca4e6ed503ecdb9d69caf0172e19629e9de33d0dcdeff549d1986953"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/views/events.py"}, "region": {"startLine": 80}}}]}, {"ruleId": "MINED001", "level": "error", "message": {"text": "[MINED001] Bare Except Pass: except: pass or except Exception: pass \u2014 silently swallows everything including KeyboardInterrupt and bugs."}, "properties": {"repobilityId": 224712, "scanner": "repobility-threat-engine", "fingerprint": "cbc158aef07f2039082ed9b970d5192205ce29608c07cfe87a3ce94114bd9f10", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "bare-except-pass", "owasp": null, "cwe_ids": ["CWE-755"], "languages": ["python"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.347744+00:00", "triaged_in_corpus": 15, "observations_count": 1550824, "ai_coder_pattern_id": 6}, "scanner": "repobility-threat-engine", "correlation_key": "fp|cbc158aef07f2039082ed9b970d5192205ce29608c07cfe87a3ce94114bd9f10"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/views/erp.py"}, "region": {"startLine": 112}}}]}, {"ruleId": "MINED001", "level": "error", "message": {"text": "[MINED001] Bare Except Pass: except: pass or except Exception: pass \u2014 silently swallows everything including KeyboardInterrupt and bugs."}, "properties": {"repobilityId": 224711, "scanner": "repobility-threat-engine", "fingerprint": "08575f9cd6d9375c07ce7ca3bce68faf24aad2b9ed3fbfef98931685e91b5e2b", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "bare-except-pass", "owasp": null, "cwe_ids": ["CWE-755"], "languages": ["python"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.347744+00:00", "triaged_in_corpus": 15, "observations_count": 1550824, "ai_coder_pattern_id": 6}, "scanner": "repobility-threat-engine", "correlation_key": "fp|08575f9cd6d9375c07ce7ca3bce68faf24aad2b9ed3fbfef98931685e91b5e2b"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/services/grading_service.py"}, "region": {"startLine": 38}}}]}, {"ruleId": "SEC128", "level": "error", "message": {"text": "[SEC128] Async function without await \u2014 fire-and-forget Promise (AI mistake): Async call invoked without `await` returns an unhandled Promise. The outer function resolves before the inner work completes \u2014 DB writes lost, emails not sent, race conditions. This is one of the top-3 errors AI coders make: they understand async-shape but drop the await keyword when chaining multiple ops. Surfaces as flaky tests or silently dropped data in production."}, "properties": {"repobilityId": 224709, "scanner": "repobility-threat-engine", "fingerprint": "1369b590b9aa114481c31f01280ca7a5435f4c8503f4e651ff290470a7630002", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "ExamSeating.objects.create(\n                    exam=exam,\n                    stud", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC128", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|1369b590b9aa114481c31f01280ca7a5435f4c8503f4e651ff290470a7630002"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/services/exam_service.py"}, "region": {"startLine": 56}}}]}, {"ruleId": "SEC128", "level": "error", "message": {"text": "[SEC128] Async function without await \u2014 fire-and-forget Promise (AI mistake): Async call invoked without `await` returns an unhandled Promise. The outer function resolves before the inner work completes \u2014 DB writes lost, emails not sent, race conditions. This is one of the top-3 errors AI coders make: they understand async-shape but drop the await keyword when chaining multiple ops. Surfaces as flaky tests or silently dropped data in production."}, "properties": {"repobilityId": 224708, "scanner": "repobility-threat-engine", "fingerprint": "b811358ea512c2d0774f40013b8f7611dc0927cc3aa110316aed42eeeb728758", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "serializer.save()", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC128", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|b811358ea512c2d0774f40013b8f7611dc0927cc3aa110316aed42eeeb728758"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/services/bulk_import.py"}, "region": {"startLine": 153}}}]}, {"ruleId": "SEC128", "level": "error", "message": {"text": "[SEC128] Async function without await \u2014 fire-and-forget Promise (AI mistake): Async call invoked without `await` returns an unhandled Promise. The outer function resolves before the inner work completes \u2014 DB writes lost, emails not sent, race conditions. This is one of the top-3 errors AI coders make: they understand async-shape but drop the await keyword when chaining multiple ops. Surfaces as flaky tests or silently dropped data in production."}, "properties": {"repobilityId": 224707, "scanner": "repobility-threat-engine", "fingerprint": "ec84bad066884ee2330af1c9240f73949e8f3aa3344e12e17ab6562d1f40fd75", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "assessment.save(update_fields=[\"type\"])", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC128", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|ec84bad066884ee2330af1c9240f73949e8f3aa3344e12e17ab6562d1f40fd75"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/serializers/exam.py"}, "region": {"startLine": 66}}}]}, {"ruleId": "COMP001", "level": "error", "message": {"text": "[COMP001] High cognitive complexity: Function `process_file` has cognitive complexity 35 (SonarSource scale). Cognitive complexity measures how hard the function is for a human to understand \u2014 nested branches, boolean chains, and recursion all weigh in. Breakdown: continue=1, else=4, except=4, for=1, if=10, nested_bonus=14, ternary=1."}, "properties": {"repobilityId": 224705, "scanner": "repobility-threat-engine", "fingerprint": "56a47c9db0ee0cca426c965077610b6d8376c830b9a590f3c2401c583831c13e", "category": "quality", "severity": "high", "confidence": 0.95, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "AST-derived cognitive complexity score = 35 (severity threshold for high: 25+).", "evidence": {"scanner": "repobility-threat-engine", "function": "process_file", "breakdown": {"if": 10, "for": 1, "else": 4, "except": 4, "ternary": 1, "continue": 1, "nested_bonus": 14}, "complexity": 35, "correlation_key": "fp|56a47c9db0ee0cca426c965077610b6d8376c830b9a590f3c2401c583831c13e"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/services/bulk_import.py"}, "region": {"startLine": 20}}}]}, {"ruleId": "MINED126", "level": "error", "message": {"text": "Workflow container/services image `pgvector/pgvector:pg16` unpinned"}, "properties": {"repobilityId": 224652, "scanner": "repobility-supply-chain", "fingerprint": "f6b3ff280e0c7ac101cfd0ac331846ad28ff9b45340c4c617340be155b75e0a1", "category": "dependency", "severity": "high", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-container-unpinned", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|f6b3ff280e0c7ac101cfd0ac331846ad28ff9b45340c4c617340be155b75e0a1"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/backend-ci.yml"}, "region": {"startLine": 67}}}]}, {"ruleId": "MINED115", "level": "error", "message": {"text": "Action `snyk/actions/node` tracks moving branch `@master`"}, "properties": {"repobilityId": 224623, "scanner": "repobility-supply-chain", "fingerprint": "667080952b849bfb9074d9a6790a919893a2f60a312a68361c6a3a217c86031b", "category": "dependency", "severity": "high", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|667080952b849bfb9074d9a6790a919893a2f60a312a68361c6a3a217c86031b"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/frontend-ci.yml"}, "region": {"startLine": 191}}}]}, {"ruleId": "MINED118", "level": "error", "message": {"text": "Dockerfile FROM `node:20-slim` not pinned by digest"}, "properties": {"repobilityId": 224603, "scanner": "repobility-supply-chain", "fingerprint": "63c28a491eddcc740359d09b9bd5693c46129c4f42e4ced73f09b20c4f7e3f4b", "category": "dependency", "severity": "high", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "docker-from-unpinned", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["dockerfile"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|63c28a491eddcc740359d09b9bd5693c46129c4f42e4ced73f09b20c4f7e3f4b"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/Dockerfile"}, "region": {"startLine": 17}}}]}, {"ruleId": "MINED118", "level": "error", "message": {"text": "Dockerfile FROM `node:20-slim` not pinned by digest"}, "properties": {"repobilityId": 224602, "scanner": "repobility-supply-chain", "fingerprint": "42356c881771b902ad7fd7638fc88fff148c6459d2ade489e2cab66cd40b6131", "category": "dependency", "severity": "high", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "docker-from-unpinned", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["dockerfile"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|42356c881771b902ad7fd7638fc88fff148c6459d2ade489e2cab66cd40b6131"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/Dockerfile"}, "region": {"startLine": 8}}}]}, {"ruleId": "MINED118", "level": "error", "message": {"text": "Dockerfile FROM `node:20-slim` not pinned by digest"}, "properties": {"repobilityId": 224601, "scanner": "repobility-supply-chain", "fingerprint": "e4d61f55d548de3f2a4e7d9307c2d9ec268f79374cb8b8f2a547a03550d94a6e", "category": "dependency", "severity": "high", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "docker-from-unpinned", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["dockerfile"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|e4d61f55d548de3f2a4e7d9307c2d9ec268f79374cb8b8f2a547a03550d94a6e"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/Dockerfile"}, "region": {"startLine": 2}}}]}, {"ruleId": "MINED118", "level": "error", "message": {"text": "Dockerfile FROM `python:3.13-slim` not pinned by digest"}, "properties": {"repobilityId": 224600, "scanner": "repobility-supply-chain", "fingerprint": "dca931413b3ef5dc111554dcab0e92d9c185996bd0dafb180b7ebf8e4baa9125", "category": "dependency", "severity": "high", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "docker-from-unpinned", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["dockerfile"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|dca931413b3ef5dc111554dcab0e92d9c185996bd0dafb180b7ebf8e4baa9125"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/Dockerfile"}, "region": {"startLine": 35}}}]}, {"ruleId": "MINED118", "level": "error", "message": {"text": "Dockerfile FROM `python:3.13-slim` not pinned by digest"}, "properties": {"repobilityId": 224599, "scanner": "repobility-supply-chain", "fingerprint": "0ce98d40afd9423c91ad1b0d52b443ed2eaca3f06881a1401b509e4040096b22", "category": "dependency", "severity": "high", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "docker-from-unpinned", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["dockerfile"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|0ce98d40afd9423c91ad1b0d52b443ed2eaca3f06881a1401b509e4040096b22"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/Dockerfile"}, "region": {"startLine": 2}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_no_context_returns_zero_confidence"}, "properties": {"repobilityId": 224588, "scanner": "repobility-ast-engine", "fingerprint": "ff1eafdca14189b9a52d695725be396bd64cb4b2962c92697aa733b7385ad2f0", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|ff1eafdca14189b9a52d695725be396bd64cb4b2962c92697aa733b7385ad2f0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/tests_phase4.py"}, "region": {"startLine": 212}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_reports"}, "properties": {"repobilityId": 224587, "scanner": "repobility-ast-engine", "fingerprint": "75cfe5f89d308233bbe0672376cc397c4e9dabd6e44e108970c48f7cb9b4a5b3", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|75cfe5f89d308233bbe0672376cc397c4e9dabd6e44e108970c48f7cb9b4a5b3"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/verify_reports_v2.py"}, "region": {"startLine": 25}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_admin_student_management"}, "properties": {"repobilityId": 224586, "scanner": "repobility-ast-engine", "fingerprint": "e62c41d0bd5703fdc8ed99beb7e7f0ce0bef695b8daeca43f81e3dc6039e542c", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|e62c41d0bd5703fdc8ed99beb7e7f0ce0bef695b8daeca43f81e3dc6039e542c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/verify_admin_panel.py"}, "region": {"startLine": 22}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_complete_workflow"}, "properties": {"repobilityId": 224585, "scanner": "repobility-ast-engine", "fingerprint": "23f12d51c31cd7d65de8ab89996b3e6624a2726b4203b7208c2ce8be715f32ec", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|23f12d51c31cd7d65de8ab89996b3e6624a2726b4203b7208c2ce8be715f32ec"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/verify_hall_tickets.py"}, "region": {"startLine": 36}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_ai_feedback"}, "properties": {"repobilityId": 224583, "scanner": "repobility-ast-engine", "fingerprint": "921582dbd39fce7d05be98bd7aec85f330804c2b8b7cbeb35a9f413576d43ef3", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|921582dbd39fce7d05be98bd7aec85f330804c2b8b7cbeb35a9f413576d43ef3"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/verify_sprint7.py"}, "region": {"startLine": 29}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_gradebook"}, "properties": {"repobilityId": 224581, "scanner": "repobility-ast-engine", "fingerprint": "ebeb6f859480cdf82361a8af20ce504b6be9af5afb50ff693db8a29588e1799b", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|ebeb6f859480cdf82361a8af20ce504b6be9af5afb50ff693db8a29588e1799b"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/verify_sprint7.py"}, "region": {"startLine": 12}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_student_endpoints"}, "properties": {"repobilityId": 224580, "scanner": "repobility-ast-engine", "fingerprint": "b854a741c78f0aa5e565532e0365b649f6623325f6ec5fdf8b8cf964bb87689c", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|b854a741c78f0aa5e565532e0365b649f6623325f6ec5fdf8b8cf964bb87689c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/verify_student_dashboard.py"}, "region": {"startLine": 22}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_parent_portal"}, "properties": {"repobilityId": 224579, "scanner": "repobility-ast-engine", "fingerprint": "7307302dc8888af68e94e549059dca1e943b48b52d22c07620b584f8d5d8732a", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|7307302dc8888af68e94e549059dca1e943b48b52d22c07620b584f8d5d8732a"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/verify_parent_portal.py"}, "region": {"startLine": 22}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_password"}, "properties": {"repobilityId": 224578, "scanner": "repobility-ast-engine", "fingerprint": "e4628a9d44e0156ca57932227faf588e865e2b0f90fc0887fd7073c8443486db", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|e4628a9d44e0156ca57932227faf588e865e2b0f90fc0887fd7073c8443486db"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/check_auth.py"}, "region": {"startLine": 15}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_library_setup"}, "properties": {"repobilityId": 224577, "scanner": "repobility-ast-engine", "fingerprint": "d1c7f19df4eedb74b87976466cfc8fd647b17aeb35866df3fa0a0cd546fc56d3", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|d1c7f19df4eedb74b87976466cfc8fd647b17aeb35866df3fa0a0cd546fc56d3"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/test_library.py"}, "region": {"startLine": 21}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_teacher_endpoints"}, "properties": {"repobilityId": 224575, "scanner": "repobility-ast-engine", "fingerprint": "1110b3a4f87ad094023b9e969e42d5d93efb4cfcf1e7d51b9ee4821480d0d41a", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|1110b3a4f87ad094023b9e969e42d5d93efb4cfcf1e7d51b9ee4821480d0d41a"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/verify_teacher_fix.py"}, "region": {"startLine": 23}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_import"}, "properties": {"repobilityId": 224572, "scanner": "repobility-ast-engine", "fingerprint": "e288d85d85b0c25f4b2d158156b6834e244975e6581615614815f13416581749", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|e288d85d85b0c25f4b2d158156b6834e244975e6581615614815f13416581749"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/verify_import_service.py"}, "region": {"startLine": 26}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_grading_flow"}, "properties": {"repobilityId": 224571, "scanner": "repobility-ast-engine", "fingerprint": "5cbba55b15133ace4d867c94a6b6348f3ab5e53c5b615a05889f1a1178deff96", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|5cbba55b15133ace4d867c94a6b6348f3ab5e53c5b615a05889f1a1178deff96"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/tests_grading.py"}, "region": {"startLine": 33}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_balanced_entry"}, "properties": {"repobilityId": 224569, "scanner": "repobility-ast-engine", "fingerprint": "eb167b92d8ed357acdaec42ed367f8bd42783762f32b7844bebb62f8b2292909", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|eb167b92d8ed357acdaec42ed367f8bd42783762f32b7844bebb62f8b2292909"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/tests_nas.py"}, "region": {"startLine": 258}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_both_zero_is_valid"}, "properties": {"repobilityId": 224565, "scanner": "repobility-ast-engine", "fingerprint": "d7f88bc5e71f3b78f8dd2cd14189d07006fcf7d292c3e1f6fe6ebb9aae6407ed", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|d7f88bc5e71f3b78f8dd2cd14189d07006fcf7d292c3e1f6fe6ebb9aae6407ed"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/tests_nas.py"}, "region": {"startLine": 236}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_valid_credit_only"}, "properties": {"repobilityId": 224562, "scanner": "repobility-ast-engine", "fingerprint": "4de85b05e5a88d063daaf65f2ee38aea59cc33a53ded22db29498112e8fddb5e", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|4de85b05e5a88d063daaf65f2ee38aea59cc33a53ded22db29498112e8fddb5e"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/tests_nas.py"}, "region": {"startLine": 232}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_valid_debit_only"}, "properties": {"repobilityId": 224559, "scanner": "repobility-ast-engine", "fingerprint": "38c203353dec7fd005a0faf8aaaf6ecd7ee873e143c89004d84fa1c04be09956", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|38c203353dec7fd005a0faf8aaaf6ecd7ee873e143c89004d84fa1c04be09956"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/tests_nas.py"}, "region": {"startLine": 228}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_bs_date_str_format"}, "properties": {"repobilityId": 224558, "scanner": "repobility-ast-engine", "fingerprint": "cc7190ab8a155af8c2f02b6be82185d3d698263a2d3f9ce86d03aba76fa3a89b", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|cc7190ab8a155af8c2f02b6be82185d3d698263a2d3f9ce86d03aba76fa3a89b"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing_school/tests_nas.py"}, "region": {"startLine": 168}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_tenant_delete_uses_public_schema_and_force_drop"}, "properties": {"repobilityId": 224518, "scanner": "repobility-ast-engine", "fingerprint": "6ec7e0ca3f9864f73c85ff3bb70980934725481f74279fc8f4a35c709c1acc47", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|6ec7e0ca3f9864f73c85ff3bb70980934725481f74279fc8f4a35c709c1acc47"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/tests_admin_audit.py"}, "region": {"startLine": 129}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_ai_connection"}, "properties": {"repobilityId": 224510, "scanner": "repobility-ast-engine", "fingerprint": "a8b2e69f153572affb0a53cd924f641f5d8ea964223675a0517639ffb9e1366c", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|a8b2e69f153572affb0a53cd924f641f5d8ea964223675a0517639ffb9e1366c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/views.py"}, "region": {"startLine": 600}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_happy_path_document"}, "properties": {"repobilityId": 224506, "scanner": "repobility-ast-engine", "fingerprint": "155458d4bc84bb3ea7d3bf1c9b6fff403c62a7cb5fc74f1ddb54e70377565224", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|155458d4bc84bb3ea7d3bf1c9b6fff403c62a7cb5fc74f1ddb54e70377565224"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/tests_upload_validation.py"}, "region": {"startLine": 105}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_valid_png_accepted"}, "properties": {"repobilityId": 224505, "scanner": "repobility-ast-engine", "fingerprint": "63fa689b2674b5f1b7c42b901861fe9a52f7f2614f549736a900c29c984956af", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|63fa689b2674b5f1b7c42b901861fe9a52f7f2614f549736a900c29c984956af"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/tests_upload_validation.py"}, "region": {"startLine": 89}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_plain_csv_accepted"}, "properties": {"repobilityId": 224503, "scanner": "repobility-ast-engine", "fingerprint": "6ddbf372d5339fafe603c74d2be1e4a1824f18a3ab6780eaea9081b9e5a52f9c", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|6ddbf372d5339fafe603c74d2be1e4a1824f18a3ab6780eaea9081b9e5a52f9c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/tests_upload_validation.py"}, "region": {"startLine": 71}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_accepts_pdf"}, "properties": {"repobilityId": 224502, "scanner": "repobility-ast-engine", "fingerprint": "7d75852a0df1a511c7e28f3b4a2336bf111823be164f462556cbeef9cab738ee", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|7d75852a0df1a511c7e28f3b4a2336bf111823be164f462556cbeef9cab738ee"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/tests_upload_validation.py"}, "region": {"startLine": 43}}}]}, {"ruleId": "MINED106", "level": "error", "message": {"text": "Phantom test coverage: test_accepts_file_within_limit"}, "properties": {"repobilityId": 224501, "scanner": "repobility-ast-engine", "fingerprint": "e4c70877b342afba94be9aab9835f3eea65e53f52394092f077ca97f15e5925c", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "phantom-test-coverage", "owasp": null, "cwe_ids": ["CWE-1126"], "languages": ["python"], "observations_count": 982154}, "scanner": "repobility-ast-engine", "correlation_key": "fp|e4c70877b342afba94be9aab9835f3eea65e53f52394092f077ca97f15e5925c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/tests_upload_validation.py"}, "region": {"startLine": 34}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.request` used but never assigned in __init__"}, "properties": {"repobilityId": 224491, "scanner": "repobility-ast-engine", "fingerprint": "f6e459d53823fde9460b61ad69be6a51bbef4bb72dc4e15c1357298b07e3f600", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|f6e459d53823fde9460b61ad69be6a51bbef4bb72dc4e15c1357298b07e3f600"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/views.py"}, "region": {"startLine": 123}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.request` used but never assigned in __init__"}, "properties": {"repobilityId": 224490, "scanner": "repobility-ast-engine", "fingerprint": "00eb4c72bbec52a1e47119eb1ca395569cb555e0eadc43382b6233df70b3526d", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|00eb4c72bbec52a1e47119eb1ca395569cb555e0eadc43382b6233df70b3526d"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/views.py"}, "region": {"startLine": 109}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.request` used but never assigned in __init__"}, "properties": {"repobilityId": 224488, "scanner": "repobility-ast-engine", "fingerprint": "51b33d3c9621cfd62ad411f33263a699be96bfc2ef5ff815f3b55ca9ae02d15c", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|51b33d3c9621cfd62ad411f33263a699be96bfc2ef5ff815f3b55ca9ae02d15c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/views.py"}, "region": {"startLine": 110}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.request` used but never assigned in __init__"}, "properties": {"repobilityId": 224484, "scanner": "repobility-ast-engine", "fingerprint": "1210db0ab0a376d6ca91740829aa4f972d2fb12805d4fdb5060ec812ba3565ce", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|1210db0ab0a376d6ca91740829aa4f972d2fb12805d4fdb5060ec812ba3565ce"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/views.py"}, "region": {"startLine": 96}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.request` used but never assigned in __init__"}, "properties": {"repobilityId": 224483, "scanner": "repobility-ast-engine", "fingerprint": "1ab15e424ce0604e87e4283acc7879260e5e280c5ef983a425e8a27f860b6326", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|1ab15e424ce0604e87e4283acc7879260e5e280c5ef983a425e8a27f860b6326"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/views.py"}, "region": {"startLine": 95}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.request` used but never assigned in __init__"}, "properties": {"repobilityId": 224482, "scanner": "repobility-ast-engine", "fingerprint": "6b2bb25ff6a3c620a4e835f743caacfc976812c0676663ff11707c27f7117595", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|6b2bb25ff6a3c620a4e835f743caacfc976812c0676663ff11707c27f7117595"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/views.py"}, "region": {"startLine": 94}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.action` used but never assigned in __init__"}, "properties": {"repobilityId": 224480, "scanner": "repobility-ast-engine", "fingerprint": "70bd5a6a3c4a7036f4d1ac8dcedf4c2f7b4faceca016fa6b72107aa554cc7062", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|70bd5a6a3c4a7036f4d1ac8dcedf4c2f7b4faceca016fa6b72107aa554cc7062"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/views.py"}, "region": {"startLine": 87}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.request` used but never assigned in __init__"}, "properties": {"repobilityId": 224478, "scanner": "repobility-ast-engine", "fingerprint": "f616c369c6e6701c43d8e03c57c1f6fe49dc68996803bbe647d4c1cc7daebd4d", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|f616c369c6e6701c43d8e03c57c1f6fe49dc68996803bbe647d4c1cc7daebd4d"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/views.py"}, "region": {"startLine": 75}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.request` used but never assigned in __init__"}, "properties": {"repobilityId": 224477, "scanner": "repobility-ast-engine", "fingerprint": "cc56a3cb7b7e00e3bac065073baa94a2607205306db2c3640767f9a7f0d3680c", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|cc56a3cb7b7e00e3bac065073baa94a2607205306db2c3640767f9a7f0d3680c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/views.py"}, "region": {"startLine": 76}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.request` used but never assigned in __init__"}, "properties": {"repobilityId": 224473, "scanner": "repobility-ast-engine", "fingerprint": "d5879450a6619685c8c76c2fa2b6e1b929a75e9ff9bdbd47a521a84a23659ef3", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|d5879450a6619685c8c76c2fa2b6e1b929a75e9ff9bdbd47a521a84a23659ef3"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/views.py"}, "region": {"startLine": 67}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.request` used but never assigned in __init__"}, "properties": {"repobilityId": 224472, "scanner": "repobility-ast-engine", "fingerprint": "e8a68f7f4b5781f8d1871c9824325eea9598b6cada90b48dc9a22f9815fec176", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|e8a68f7f4b5781f8d1871c9824325eea9598b6cada90b48dc9a22f9815fec176"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/views.py"}, "region": {"startLine": 68}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.request` used but never assigned in __init__"}, "properties": {"repobilityId": 224471, "scanner": "repobility-ast-engine", "fingerprint": "6e8b81e5636bcf07197d45082c6fdf3a29f7120b82788b94e8cce757f40e45b6", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|6e8b81e5636bcf07197d45082c6fdf3a29f7120b82788b94e8cce757f40e45b6"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/views.py"}, "region": {"startLine": 58}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.request` used but never assigned in __init__"}, "properties": {"repobilityId": 224470, "scanner": "repobility-ast-engine", "fingerprint": "32effefb50a2ecc4534e74171365ca5a55cd09e59206821475267cc8b0a22025", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|32effefb50a2ecc4534e74171365ca5a55cd09e59206821475267cc8b0a22025"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/views.py"}, "region": {"startLine": 59}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.request` used but never assigned in __init__"}, "properties": {"repobilityId": 224468, "scanner": "repobility-ast-engine", "fingerprint": "26f8a7988769817143673068f5c417b91d2d122be72ede4ed5b0bbcaa55e0fd7", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|26f8a7988769817143673068f5c417b91d2d122be72ede4ed5b0bbcaa55e0fd7"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/views.py"}, "region": {"startLine": 46}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.instance` used but never assigned in __init__"}, "properties": {"repobilityId": 224467, "scanner": "repobility-ast-engine", "fingerprint": "27ec63e3db2d1bf7c92704ffc428b32894f7cda433b9a56b9c91fbab59a204f5", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|27ec63e3db2d1bf7c92704ffc428b32894f7cda433b9a56b9c91fbab59a204f5"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/serializers.py"}, "region": {"startLine": 158}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.instance` used but never assigned in __init__"}, "properties": {"repobilityId": 224465, "scanner": "repobility-ast-engine", "fingerprint": "e24de8e97fec558943d6058745d01009c31f15c3cd8ed253dd6fbe2c6a4cf65b", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|e24de8e97fec558943d6058745d01009c31f15c3cd8ed253dd6fbe2c6a4cf65b"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/serializers.py"}, "region": {"startLine": 157}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.instance` used but never assigned in __init__"}, "properties": {"repobilityId": 224464, "scanner": "repobility-ast-engine", "fingerprint": "f01da88de6fdb056e888532203085035fb7ce5b5c5855b44b565262f772c2625", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|f01da88de6fdb056e888532203085035fb7ce5b5c5855b44b565262f772c2625"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/serializers.py"}, "region": {"startLine": 116}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.instance` used but never assigned in __init__"}, "properties": {"repobilityId": 224462, "scanner": "repobility-ast-engine", "fingerprint": "f5cf3fa7a680ff1cc958f43f29494d30248cb93c3ecaf67b41b1d6d5628356dd", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|f5cf3fa7a680ff1cc958f43f29494d30248cb93c3ecaf67b41b1d6d5628356dd"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/serializers.py"}, "region": {"startLine": 115}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.instance` used but never assigned in __init__"}, "properties": {"repobilityId": 224460, "scanner": "repobility-ast-engine", "fingerprint": "811bcec15cbc0b3437c108015eb68d9ea4c92fc6192451df936bd08688d36b32", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|811bcec15cbc0b3437c108015eb68d9ea4c92fc6192451df936bd08688d36b32"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/serializers.py"}, "region": {"startLine": 49}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.instance` used but never assigned in __init__"}, "properties": {"repobilityId": 224459, "scanner": "repobility-ast-engine", "fingerprint": "06e0c30809e99741e99aff8e2d7eb11fc6abe3ca89e5244ff57e5093ff68f63a", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|06e0c30809e99741e99aff8e2d7eb11fc6abe3ca89e5244ff57e5093ff68f63a"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/serializers.py"}, "region": {"startLine": 48}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.request` used but never assigned in __init__"}, "properties": {"repobilityId": 224458, "scanner": "repobility-ast-engine", "fingerprint": "eb6a9fad25f72493d95f47dbd979da2959fdb5d67ee39483853f62549410772c", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|eb6a9fad25f72493d95f47dbd979da2959fdb5d67ee39483853f62549410772c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/views_appraisal.py"}, "region": {"startLine": 127}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.request` used but never assigned in __init__"}, "properties": {"repobilityId": 224456, "scanner": "repobility-ast-engine", "fingerprint": "7cb9ff9d37ba9ac99ab1f92d72e34d358931b7d701fbf9cdd788667538eaee46", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|7cb9ff9d37ba9ac99ab1f92d72e34d358931b7d701fbf9cdd788667538eaee46"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/views_appraisal.py"}, "region": {"startLine": 121}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.request` used but never assigned in __init__"}, "properties": {"repobilityId": 224455, "scanner": "repobility-ast-engine", "fingerprint": "d4c82b29e7bbb0400dd3879d3632478e9fe96394561e91f40316444815122004", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|d4c82b29e7bbb0400dd3879d3632478e9fe96394561e91f40316444815122004"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/views_appraisal.py"}, "region": {"startLine": 115}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.request` used but never assigned in __init__"}, "properties": {"repobilityId": 224454, "scanner": "repobility-ast-engine", "fingerprint": "e9fb9c1a20d3d1776077ef3a0185e63a2e0a1e97b77316b60f0eaf6a36e6f112", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|e9fb9c1a20d3d1776077ef3a0185e63a2e0a1e97b77316b60f0eaf6a36e6f112"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/views_appraisal.py"}, "region": {"startLine": 92}}}]}, {"ruleId": "MINED108", "level": "error", "message": {"text": "`self.request` used but never assigned in __init__"}, "properties": {"repobilityId": 224452, "scanner": "repobility-ast-engine", "fingerprint": "1823d1cccf6eafd83387fe4f12a6fdae52a2953fd39c5d077f9a245f9cd9adb2", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "self-attr-never-set", "owasp": null, "cwe_ids": ["CWE-476"], "languages": ["python"], "observations_count": 25998}, "scanner": "repobility-ast-engine", "correlation_key": "fp|1823d1cccf6eafd83387fe4f12a6fdae52a2953fd39c5d077f9a245f9cd9adb2"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/hr_payroll/views_appraisal.py"}, "region": {"startLine": 86}}}]}, {"ruleId": "GHSA-w7jw-789q-3m8p", "level": "error", "message": {"text": "shell-quote: GHSA-w7jw-789q-3m8p"}, "properties": {"repobilityId": 224890, "scanner": "osv-scanner", "fingerprint": "b116d085a33b8a683ae0d7aa119b7b7bb952cdb6e1ed269007e977fef62b0309", "category": "dependency", "severity": "critical", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-9277"], "package": "shell-quote", "rule_id": "GHSA-w7jw-789q-3m8p", "scanner": "osv-scanner", "correlation_key": "vuln|shell-quote|CVE-2026-9277|mobile/package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mobile/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "generic-api-key", "level": "error", "message": {"text": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations."}, "properties": {"repobilityId": 224841, "scanner": "gitleaks", "fingerprint": "48d76200f62dd95151079ca2f863683c57bf857cf72297a8549dbacbfd2d6625", "category": "credential_exposure", "severity": "critical", "confidence": 0.95, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "HTTP_IDEMPOTENCY_KEY=\"REDACTED\"", "rule_id": "generic-api-key", "scanner": "gitleaks", "detector": "generic-api-key", "correlation_key": "secret|token|46|http_idempotency_key redacted"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing/tests_security.py"}, "region": {"startLine": 466}}}]}, {"ruleId": "generic-api-key", "level": "error", "message": {"text": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations."}, "properties": {"repobilityId": 224840, "scanner": "gitleaks", "fingerprint": "75be2be1d6da7bcc81aee7177e19ee3c8dc3daa8a45a6ea7592d04fc30724a54", "category": "credential_exposure", "severity": "critical", "confidence": 0.95, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "HTTP_IDEMPOTENCY_KEY=\"REDACTED\"", "rule_id": "generic-api-key", "scanner": "gitleaks", "detector": "generic-api-key", "correlation_key": "secret|token|45|http_idempotency_key redacted"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing/tests_security.py"}, "region": {"startLine": 456}}}]}, {"ruleId": "generic-api-key", "level": "error", "message": {"text": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations."}, "properties": {"repobilityId": 224839, "scanner": "gitleaks", "fingerprint": "e64520c8cb4cb58dde0bfc65bb52c18e8e8057670b46133caa6d4c8041930ca6", "category": "credential_exposure", "severity": "critical", "confidence": 0.95, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "HTTP_IDEMPOTENCY_KEY=\"REDACTED\"", "rule_id": "generic-api-key", "scanner": "gitleaks", "detector": "generic-api-key", "correlation_key": "secret|token|44|http_idempotency_key redacted"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/billing/tests_security.py"}, "region": {"startLine": 450}}}]}, {"ruleId": "MINED007", "level": "error", "message": {"text": "[MINED007] Sql String Concat: cursor.execute(f\"... {user_input} ...\") \u2014 SQL injection."}, "properties": {"repobilityId": 224781, "scanner": "repobility-threat-engine", "fingerprint": "b1cb8f3589befeb25101d2c999c49345f0892f29f648120ca94794fbf7d3e370", "category": "quality", "severity": "critical", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "sql-string-concat", "owasp": "A03:2021", "cwe_ids": ["CWE-89"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.347914+00:00", "triaged_in_corpus": 20, "observations_count": 210457, "ai_coder_pattern_id": 12}, "scanner": "repobility-threat-engine", "correlation_key": "fp|b1cb8f3589befeb25101d2c999c49345f0892f29f648120ca94794fbf7d3e370"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/create_library_tables_simple.py"}, "region": {"startLine": 80}}}]}, {"ruleId": "MINED007", "level": "error", "message": {"text": "[MINED007] Sql String Concat: cursor.execute(f\"... {user_input} ...\") \u2014 SQL injection."}, "properties": {"repobilityId": 224780, "scanner": "repobility-threat-engine", "fingerprint": "9d0b90df1596ecaff0eb9c026c1cf4a81bcb58663897870ac59a6eebec2e7ded", "category": "quality", "severity": "critical", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "sql-string-concat", "owasp": "A03:2021", "cwe_ids": ["CWE-89"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.347914+00:00", "triaged_in_corpus": 20, "observations_count": 210457, "ai_coder_pattern_id": 12}, "scanner": "repobility-threat-engine", "correlation_key": "fp|9d0b90df1596ecaff0eb9c026c1cf4a81bcb58663897870ac59a6eebec2e7ded"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/create_library_tables_final.py"}, "region": {"startLine": 121}}}]}, {"ruleId": "MINED007", "level": "error", "message": {"text": "[MINED007] Sql String Concat: cursor.execute(f\"... {user_input} ...\") \u2014 SQL injection."}, "properties": {"repobilityId": 224779, "scanner": "repobility-threat-engine", "fingerprint": "b8f9f36a87aea22a8a373f600c4915c6123ea0810c0db2d55625e1734e2319ff", "category": "quality", "severity": "critical", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "sql-string-concat", "owasp": "A03:2021", "cwe_ids": ["CWE-89"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.347914+00:00", "triaged_in_corpus": 20, "observations_count": 210457, "ai_coder_pattern_id": 12}, "scanner": "repobility-threat-engine", "correlation_key": "fp|b8f9f36a87aea22a8a373f600c4915c6123ea0810c0db2d55625e1734e2319ff"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/create_library_tables.py"}, "region": {"startLine": 77}}}]}, {"ruleId": "MINED013", "level": "error", "message": {"text": "[MINED013] Password In Url: https://user:password@host \u2014 leaks creds via logs, referrer, error messages."}, "properties": {"repobilityId": 224760, "scanner": "repobility-threat-engine", "fingerprint": "2a9ffc14ff2d1971c4810e41702b904d9fe7fa47dfb76506bc45a25fbb2c82a7", "category": "quality", "severity": "critical", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "password-in-url", "owasp": "A07:2021", "cwe_ids": ["CWE-200"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.347928+00:00", "triaged_in_corpus": 20, "observations_count": 121646, "ai_coder_pattern_id": 37}, "scanner": "repobility-threat-engine", "correlation_key": "fp|2a9ffc14ff2d1971c4810e41702b904d9fe7fa47dfb76506bc45a25fbb2c82a7"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/config/settings/test.py"}, "region": {"startLine": 26}}}]}, {"ruleId": "SEC022", "level": "error", "message": {"text": "[SEC022] Database URL With Embedded Credential: A database connection URL contains an embedded username and password. These URLs are often copied into defaults, docs, and scripts, then leak working credentials."}, "properties": {"repobilityId": 224759, "scanner": "repobility-threat-engine", "fingerprint": "6457d121752c12a1ba56f3628068a0c154bdb72047656b1126dae864d31a294e", "category": "credential_exposure", "severity": "critical", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "postgresql://user:pass@", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC022", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "secret|backend/scripts/print_db.py|1|postgresql://user:pass"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/scripts/print_db.py"}, "region": {"startLine": 8}}}]}, {"ruleId": "SEC022", "level": "error", "message": {"text": "[SEC022] Database URL With Embedded Credential: A database connection URL contains an embedded username and password. These URLs are often copied into defaults, docs, and scripts, then leak working credentials."}, "properties": {"repobilityId": 224758, "scanner": "repobility-threat-engine", "fingerprint": "d19622340140cba64a0541154691ce1862c57de9de13742c9e13fd263cc67481", "category": "credential_exposure", "severity": "critical", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "postgres://postgres:postgres@", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC022", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "secret|token|2|token"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/config/settings/test.py"}, "region": {"startLine": 26}}}]}, {"ruleId": "SEC001", "level": "error", "message": {"text": "[SEC001] Hardcoded Password: Hardcoded password found in source code."}, "properties": {"repobilityId": 224719, "scanner": "repobility-threat-engine", "fingerprint": "7dc6aa69ea9f6c91bffbda880a458ab96e1a39864cbbc93754c9b2b2582a3bf8", "category": "credential_exposure", "severity": "critical", "confidence": 0.9, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "High entropy value (3.8 bits) \u2014 likely real secret Collapsed 2 duplicate scanner signal(s) for the same underlying issue.", "evidence": {"match": "password=\"<redacted>\"", "reason": "High entropy value (3.8 bits) \u2014 likely real secret", "rule_id": "SEC001", "scanner": "repobility-threat-engine", "confidence": 0.9, "correlation_key": "secret|token|3|password redacted", "duplicate_count": 2, "duplicate_rule_ids": ["SEC001"], "duplicate_scanners": ["repobility-threat-engine"], "duplicate_fingerprints": ["7dc6aa69ea9f6c91bffbda880a458ab96e1a39864cbbc93754c9b2b2582a3bf8", "858b9f69b82d7900f2cf557454f50539bb7fdb30c89037fe6cec63e8eab74c62", "f9fdc06797e0f38f9bb5d583ae056ab15da466834b9278fc2b2665c1a79b9b67"]}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/tests_chunk_search_api.py"}, "region": {"startLine": 38}}}]}, {"ruleId": "MINED107", "level": "error", "message": {"text": "Missing import: `email` used but not imported"}, "properties": {"repobilityId": 224598, "scanner": "repobility-ast-engine", "fingerprint": "28312c10136814ed87c7c1c2b1a0b21ee592f149287e5fa45ce66bb563ca2c5e", "category": "quality", "severity": "critical", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "missing-import-python", "owasp": "A06:2021", "cwe_ids": ["CWE-1075"], "languages": ["python"], "observations_count": 2192}, "scanner": "repobility-ast-engine", "correlation_key": "fp|28312c10136814ed87c7c1c2b1a0b21ee592f149287e5fa45ce66bb563ca2c5e"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/management/commands/reconcile_public_users_to_tenants.py"}, "region": {"startLine": 354}}}]}, {"ruleId": "MINED107", "level": "error", "message": {"text": "Missing import: `email` used but not imported"}, "properties": {"repobilityId": 224597, "scanner": "repobility-ast-engine", "fingerprint": "5f3ec1990865b02f4b957a1b83e7d48ef80e60cee868996f9ebfbe1b903d7b85", "category": "quality", "severity": "critical", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "missing-import-python", "owasp": "A06:2021", "cwe_ids": ["CWE-1075"], "languages": ["python"], "observations_count": 2192}, "scanner": "repobility-ast-engine", "correlation_key": "fp|5f3ec1990865b02f4b957a1b83e7d48ef80e60cee868996f9ebfbe1b903d7b85"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/management/commands/upsert_tenant_user.py"}, "region": {"startLine": 70}}}]}, {"ruleId": "MINED107", "level": "error", "message": {"text": "Missing import: `email` used but not imported"}, "properties": {"repobilityId": 224596, "scanner": "repobility-ast-engine", "fingerprint": "4bc1669b88949c7cd91957db5374ff8281abbbe47448cff91720de0a75695046", "category": "quality", "severity": "critical", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "missing-import-python", "owasp": "A06:2021", "cwe_ids": ["CWE-1075"], "languages": ["python"], "observations_count": 2192}, "scanner": "repobility-ast-engine", "correlation_key": "fp|4bc1669b88949c7cd91957db5374ff8281abbbe47448cff91720de0a75695046"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/serializers/profiles.py"}, "region": {"startLine": 46}}}]}, {"ruleId": "MINED107", "level": "error", "message": {"text": "Missing import: `warnings` used but not imported"}, "properties": {"repobilityId": 224595, "scanner": "repobility-ast-engine", "fingerprint": "b077b2072b066a07b4659c95683649ffd7fc84f5ffe04c08345abdb568e5a989", "category": "quality", "severity": "critical", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "missing-import-python", "owasp": "A06:2021", "cwe_ids": ["CWE-1075"], "languages": ["python"], "observations_count": 2192}, "scanner": "repobility-ast-engine", "correlation_key": "fp|b077b2072b066a07b4659c95683649ffd7fc84f5ffe04c08345abdb568e5a989"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/services/academic_year_service.py"}, "region": {"startLine": 659}}}]}, {"ruleId": "MINED107", "level": "error", "message": {"text": "Missing import: `email` used but not imported"}, "properties": {"repobilityId": 224594, "scanner": "repobility-ast-engine", "fingerprint": "e97efe0d05a8bcc7ece6868e63b53a145854deb2d2c1321b6096c5d5fcf36216", "category": "quality", "severity": "critical", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "missing-import-python", "owasp": "A06:2021", "cwe_ids": ["CWE-1075"], "languages": ["python"], "observations_count": 2192}, "scanner": "repobility-ast-engine", "correlation_key": "fp|e97efe0d05a8bcc7ece6868e63b53a145854deb2d2c1321b6096c5d5fcf36216"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/views/profiles.py"}, "region": {"startLine": 956}}}]}, {"ruleId": "MINED107", "level": "error", "message": {"text": "Missing import: `html` used but not imported"}, "properties": {"repobilityId": 224593, "scanner": "repobility-ast-engine", "fingerprint": "e1290231ab9885e9ace54fcc524f61d14fe028eef68e4dd7a0ad48a4d473545f", "category": "quality", "severity": "critical", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "missing-import-python", "owasp": "A06:2021", "cwe_ids": ["CWE-1075"], "languages": ["python"], "observations_count": 2192}, "scanner": "repobility-ast-engine", "correlation_key": "fp|e1290231ab9885e9ace54fcc524f61d14fe028eef68e4dd7a0ad48a4d473545f"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/views/reports.py"}, "region": {"startLine": 875}}}]}, {"ruleId": "MINED107", "level": "error", "message": {"text": "Missing import: `warnings` used but not imported"}, "properties": {"repobilityId": 224592, "scanner": "repobility-ast-engine", "fingerprint": "7ccba8a5790bf6610855aca4f9706ff39e1435f873ba3e0732023012f6372a3e", "category": "quality", "severity": "critical", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "missing-import-python", "owasp": "A06:2021", "cwe_ids": ["CWE-1075"], "languages": ["python"], "observations_count": 2192}, "scanner": "repobility-ast-engine", "correlation_key": "fp|7ccba8a5790bf6610855aca4f9706ff39e1435f873ba3e0732023012f6372a3e"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/academic/views/academic.py"}, "region": {"startLine": 225}}}]}, {"ruleId": "MINED107", "level": "error", "message": {"text": "Missing import: `queue` used but not imported"}, "properties": {"repobilityId": 224591, "scanner": "repobility-ast-engine", "fingerprint": "d5edaee581523d49490d48a715e47c886ce2e48af6f3bb93235bfb9603aaed2a", "category": "quality", "severity": "critical", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "missing-import-python", "owasp": "A06:2021", "cwe_ids": ["CWE-1075"], "languages": ["python"], "observations_count": 2192}, "scanner": "repobility-ast-engine", "correlation_key": "fp|d5edaee581523d49490d48a715e47c886ce2e48af6f3bb93235bfb9603aaed2a"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/ai_engine/services/knowledge_graph_service.py"}, "region": {"startLine": 373}}}]}, {"ruleId": "MINED107", "level": "error", "message": {"text": "Missing import: `email` used but not imported"}, "properties": {"repobilityId": 224589, "scanner": "repobility-ast-engine", "fingerprint": "848345792e68b3f3d94940f891688cbdb8a823f52b08fc20c4b476c415575cb1", "category": "quality", "severity": "critical", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "missing-import-python", "owasp": "A06:2021", "cwe_ids": ["CWE-1075"], "languages": ["python"], "observations_count": 2192}, "scanner": "repobility-ast-engine", "correlation_key": "fp|848345792e68b3f3d94940f891688cbdb8a823f52b08fc20c4b476c415575cb1"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/users/views.py"}, "region": {"startLine": 552}}}]}, {"ruleId": "MINED107", "level": "error", "message": {"text": "Missing import: `html` used but not imported"}, "properties": {"repobilityId": 224507, "scanner": "repobility-ast-engine", "fingerprint": "93f8cef09a9044a976646bba2b8459b02a287f76bd5c32a52e75e2dc2059d8df", "category": "quality", "severity": "critical", "confidence": 1.0, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "missing-import-python", "owasp": "A06:2021", "cwe_ids": ["CWE-1075"], "languages": ["python"], "observations_count": 2192}, "scanner": "repobility-ast-engine", "correlation_key": "fp|93f8cef09a9044a976646bba2b8459b02a287f76bd5c32a52e75e2dc2059d8df"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/core/reports.py"}, "region": {"startLine": 32}}}]}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-ea3b5e389d8c9c0f", "level": "note", "message": {"text": "Low test-to-source ratio"}, "properties": {"repobilityId": "ef7b2552cc00a375", "scanner": "scanner-primary", "fingerprint": "ea3b5e389d8c9c0f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["tests"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "48534c3e92ea5ab8", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "fb7929cb7b20be50", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-5fa33c73bdb206b7", "level": "none", "message": {"text": "Commented-code block (5 lines) in playwright.config.ts:74"}, "properties": {"repobilityId": "32f434a67b1ad4a1", "scanner": "scanner-primary", "fingerprint": "5fa33c73bdb206b7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-bdf3dfac37ee9958", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 check_and_create_course.py:26"}, "properties": {"repobilityId": "337226e292a0fa45", "scanner": "scanner-primary", "fingerprint": "bdf3dfac37ee9958", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-1b5a76780c3df9aa", "level": "none", "message": {"text": "1 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "d04379b337b44a15", "scanner": "scanner-primary", "fingerprint": "1b5a76780c3df9aa", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}]}]}