{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-9fb4516cb35a6027", "name": "Possibly dead Python function: format", "shortDescription": {"text": "Possibly dead Python function: format"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa2b8983dee7adb3", "name": "Icon-only button without accessible name \u2014 mock-ig/web/src/components/PostModal.jsx:24", "shortDescription": {"text": "Icon-only button without accessible name \u2014 mock-ig/web/src/components/PostModal.jsx:24"}, "fullDescription": {"text": "A `<button>` whose only child is a single glyph or symbol needs `title=` or `aria-label=` so screen readers (and tooltips on hover) work.\n\nWhy: P3 in CHECKLIST.md \u2014 icon-only buttons skipped a title.\nRule id: fq.button.no-label"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d03616b003cac64c", "name": "Icon-only button without accessible name \u2014 mock-ig/web/src/components/FailPanel.jsx:35", "shortDescription": {"text": "Icon-only button without accessible name \u2014 mock-ig/web/src/components/FailPanel.jsx:35"}, "fullDescription": {"text": "A `<button>` whose only child is a single glyph or symbol needs `title=` or `aria-label=` so screen readers (and tooltips on hover) work.\n\nWhy: P3 in CHECKLIST.md \u2014 icon-only buttons skipped a title.\nRule id: fq.button.no-label"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8dcd8d96550e6b92", "name": "Icon-only button without accessible name \u2014 mock-ig/web/src/components/StoryViewer.jsx:37", "shortDescription": {"text": "Icon-only button without accessible name \u2014 mock-ig/web/src/components/StoryViewer.jsx:37"}, "fullDescription": {"text": "A `<button>` whose only child is a single glyph or symbol needs `title=` or `aria-label=` so screen readers (and tooltips on hover) work.\n\nWhy: P3 in CHECKLIST.md \u2014 icon-only buttons skipped a title.\nRule id: fq.button.no-label"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1f66ad88286ca30a", "name": "Dockerfile runs as root: backend/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: backend/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-714c31ca9f474ae6", "name": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c2bb090764bc5769", "name": "Insecure pattern 'direct_innerhtml_assignment' in forum-topic.html:591", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in forum-topic.html:591"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-53bcc89d8847ab20", "name": "Insecure pattern 'local_storage_auth_token' in auth-callback.html:82", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in auth-callback.html:82"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d7bc1851dce191dd", "name": "Insecure pattern 'direct_innerhtml_assignment' in forum-profile.html:357", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in forum-profile.html:357"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f827f07e9b26ccad", "name": "Insecure pattern 'direct_innerhtml_assignment' in forum.html:843", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in forum.html:843"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9dae8b9dd56c815e", "name": "Insecure pattern 'direct_innerhtml_assignment' in purify.min.js:2", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in purify.min.js:2"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c59dc44e443955bb", "name": "Insecure pattern 'node_child_process' in scripts/publish/story-video.mjs:34", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/publish/story-video.mjs:34"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-27bd36683e7dd7aa", "name": "Insecure pattern 'node_child_process' in scripts/publish/auto-merge-routine.mjs:30", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/publish/auto-merge-routine.mjs:30"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ce7d1149c44488c7", "name": "Insecure pattern 'node_child_process' in scripts/publish/queue-state.test.mjs:12", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/publish/queue-state.test.mjs:12"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0b1ef8de7704d5e1", "name": "Insecure pattern 'node_child_process' in scripts/publish/run-publish-reel.mjs:15", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/publish/run-publish-reel.mjs:15"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0fd4712a964a69ce", "name": "Insecure pattern 'node_child_process' in scripts/publish/run-publish.mjs:24", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/publish/run-publish.mjs:24"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-551f96cacd5bdaa5", "name": "Insecure pattern 'node_child_process' in scripts/publish/run-publish-story.mjs:18", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/publish/run-publish-story.mjs:18"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-28d97d8e27ed307a", "name": "Insecure pattern 'node_child_process' in scripts/publish/reel-video.mjs:21", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/publish/reel-video.mjs:21"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4cf10e78da4d666c", "name": "Insecure pattern 'node_child_process' in scripts/news/reddit-rss-fetch.mjs:5", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/news/reddit-rss-fetch.mjs:5"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b884a0658e31b0ef", "name": "Insecure pattern 'node_child_process' in mock-ig/curation-runs.mjs:16", "shortDescription": {"text": "Insecure pattern 'node_child_process' in mock-ig/curation-runs.mjs:16"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0061f9580f94c2ec", "name": "Insecure pattern 'node_child_process' in mock-ig/server.mjs:23", "shortDescription": {"text": "Insecure pattern 'node_child_process' in mock-ig/server.mjs:23"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d51a2b12644ecf87", "name": "Insecure pattern 'cors_wildcard' in mock-ig/server.mjs:50", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in mock-ig/server.mjs:50"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e72c4cbc6a198d90", "name": "Insecure pattern 'exec_used' in mock-ig/runs.mjs:13", "shortDescription": {"text": "Insecure pattern 'exec_used' in mock-ig/runs.mjs:13"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-33969fd70e20bed3", "name": "Insecure pattern 'node_child_process' in mock-ig/runs.mjs:6", "shortDescription": {"text": "Insecure pattern 'node_child_process' in mock-ig/runs.mjs:6"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-98e265fd9b3aeb2c", "name": "Insecure pattern 'cors_wildcard' in cloudflare-worker/reddit-proxy.js:63", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in cloudflare-worker/reddit-proxy.js:63"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-38724fedb5c5e5ad", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2cc052fd80140230", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c380cbf21d59951f", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d1dce03bcc3029d0", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aad457e5c292156c", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1449f9d42e262b84", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-25ff02622faf85fc", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1dd2ffb10e2a735d", "name": "Very large file: media/lib/smplr/index.mjs (3840 lines)", "shortDescription": {"text": "Very large file: media/lib/smplr/index.mjs (3840 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea3b5e389d8c9c0f", "name": "Low test-to-source ratio", "shortDescription": {"text": "Low test-to-source ratio"}, "fullDescription": {"text": "18 tests / 151 src (ratio 0.12)."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 284 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 110 placeholder/mock markers across 28 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bea357a6497a2d5d", "name": "Agent authority lacks a verifier contract: CLAUDE.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: CLAUDE.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9ebaf59860add4c9", "name": "Commented-code block (8 lines) in scripts/cifras-coverage.test.mjs:4", "shortDescription": {"text": "Commented-code block (8 lines) in scripts/cifras-coverage.test.mjs:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3361119bc12a5b2c", "name": "Commented-code block (5 lines) in scripts/apply-pt-pass-2b.mjs:1", "shortDescription": {"text": "Commented-code block (5 lines) in scripts/apply-pt-pass-2b.mjs:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-05762931a52976d4", "name": "Commented-code block (7 lines) in scripts/_design-2026-05-12/pearljamcifras/project/tweaks-panel.jsx:12", "shortDescription": {"text": "Commented-code block (7 lines) in scripts/_design-2026-05-12/pearljamcifras/project/tweaks-panel.jsx:12"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1c80dda1b84f3183", "name": "Commented-code block (6 lines) in scripts/_design-2026-05-12/pearljamcifras/project/cifra-data.js:72", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/_design-2026-05-12/pearljamcifras/project/cifra-data.js:72"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6f5ae95b35de35cc", "name": "Commented-code block (7 lines) in scripts/_design-2026-05-12-v2/pearljamcifras/project/tweaks-panel.jsx:12", "shortDescription": {"text": "Commented-code block (7 lines) in scripts/_design-2026-05-12-v2/pearljamcifras/project/tweaks-panel.jsx:12"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f987f4b2225e8936", "name": "Commented-code block (6 lines) in scripts/_design-2026-05-12-v2/pearljamcifras/project/cifra-data.js:72", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/_design-2026-05-12-v2/pearljamcifras/project/cifra-data.js:72"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a76f15a663e4b512", "name": "Commented-code block (10 lines) in scripts/publish/slide-image.mjs:3", "shortDescription": {"text": "Commented-code block (10 lines) in scripts/publish/slide-image.mjs:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-37b749f302b02845", "name": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/publish/reel.test.mjs:228", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/publish/reel.test.mjs:228"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d7f561186391a3b3", "name": "Commented-code block (10 lines) in scripts/publish/story-video.mjs:3", "shortDescription": {"text": "Commented-code block (10 lines) in scripts/publish/story-video.mjs:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d2304b4d9f772649", "name": "Commented-code block (7 lines) in scripts/publish/queue.mjs:1", "shortDescription": {"text": "Commented-code block (7 lines) in scripts/publish/queue.mjs:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2a9eba6d72584bd5", "name": "Commented-code block (6 lines) in scripts/publish/fontconfig-boot.mjs:1", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/publish/fontconfig-boot.mjs:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-782057fc7aed86d4", "name": "Commented-code block (7 lines) in scripts/publish/auto-merge-routine.mjs:3", "shortDescription": {"text": "Commented-code block (7 lines) in scripts/publish/auto-merge-routine.mjs:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e2a7ebcc495a5462", "name": "Commented-code block (6 lines) in scripts/publish/face-crop.mjs:1", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/publish/face-crop.mjs:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-dcafd35879004cd0", "name": "Legacy-named symbol `postedOld` in scripts/publish/queue-select.test.mjs:168", "shortDescription": {"text": "Legacy-named symbol `postedOld` in scripts/publish/queue-select.test.mjs:168"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2b38b825937c6c7a", "name": "Commented-code block (6 lines) in scripts/publish/queue-state.test.mjs:1", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/publish/queue-state.test.mjs:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bf209c0128dd916e", "name": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/publish/telegram-bot.mjs:45", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/publish/telegram-bot.mjs:45"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6882347e36098f9f", "name": "Commented-code block (6 lines) in scripts/publish/reel-select.mjs:1", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/publish/reel-select.mjs:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a949f41ab9bc2b37", "name": "Commented-code block (10 lines) in scripts/publish/prune-media.mjs:5", "shortDescription": {"text": "Commented-code block (10 lines) in scripts/publish/prune-media.mjs:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-61903e2afb424489", "name": "Commented-code block (6 lines) in scripts/publish/ig-detect-deleted.mjs:23", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/publish/ig-detect-deleted.mjs:23"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c769fdc936b3e235", "name": "Commented-code block (5 lines) in scripts/publish/subject-fallback.mjs:1", "shortDescription": {"text": "Commented-code block (5 lines) in scripts/publish/subject-fallback.mjs:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5f9c86a1ac4fccf7", "name": "Commented-code block (9 lines) in scripts/publish/run-publish-reel.mjs:1", "shortDescription": {"text": "Commented-code block (9 lines) in scripts/publish/run-publish-reel.mjs:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f13a9d47e985e935", "name": "Commented-code block (6 lines) in scripts/publish/instagram.mjs:1", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/publish/instagram.mjs:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-72394efc8792e21b", "name": "Commented-code block (11 lines) in scripts/publish/run-publish.mjs:1", "shortDescription": {"text": "Commented-code block (11 lines) in scripts/publish/run-publish.mjs:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a72f8ce6c16d2a9d", "name": "Commented-code block (6 lines) in scripts/publish/recover-publish.test.mjs:1", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/publish/recover-publish.test.mjs:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-49501f9f77979ad0", "name": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/publish/recover-publish.test.mjs:43", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/publish/recover-publish.test.mjs:43"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9fdd8cc08d4cb08f", "name": "Commented-code block (6 lines) in scripts/publish/detect-deleted.test.mjs:1", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/publish/detect-deleted.test.mjs:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-fa3001d8b21f9206", "name": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/publish/detect-deleted.test.mjs:35", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/publish/detect-deleted.test.mjs:35"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d221e69746e4cb03", "name": "Commented-code block (6 lines) in scripts/publish/story-select.mjs:1", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/publish/story-select.mjs:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9ea5f53a46dc691c", "name": "Commented-code block (9 lines) in scripts/publish/run-publish-story.mjs:1", "shortDescription": {"text": "Commented-code block (9 lines) in scripts/publish/run-publish-story.mjs:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-41ab96201f96a05e", "name": "Commented-code block (5 lines) in scripts/publish/smoke-test.mjs:8", "shortDescription": {"text": "Commented-code block (5 lines) in scripts/publish/smoke-test.mjs:8"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-284ee1a492b03b7f", "name": "Commented-code block (5 lines) in scripts/publish/story-track.mjs:1", "shortDescription": {"text": "Commented-code block (5 lines) in scripts/publish/story-track.mjs:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8d1d0ac386d47ffd", "name": "Commented-code block (5 lines) in scripts/publish/color-cycle.mjs:1", "shortDescription": {"text": "Commented-code block (5 lines) in scripts/publish/color-cycle.mjs:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a9b4edef915e3d24", "name": "Commented-code block (7 lines) in scripts/publish/reel-video.mjs:6", "shortDescription": {"text": "Commented-code block (7 lines) in scripts/publish/reel-video.mjs:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9b8076cddb6fa639", "name": "Commented-code block (6 lines) in scripts/publish/story-styles/caderno-b.mjs:120", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/publish/story-styles/caderno-b.mjs:120"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f3ae5c80569a1626", "name": "Commented-code block (5 lines) in scripts/publish/story-styles/index.mjs:3", "shortDescription": {"text": "Commented-code block (5 lines) in scripts/publish/story-styles/index.mjs:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-81daf8f0be3cd21e", "name": "Commented-code block (5 lines) in scripts/publish/story-styles/editorial-badge.mjs:6", "shortDescription": {"text": "Commented-code block (5 lines) in scripts/publish/story-styles/editorial-badge.mjs:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-03e66823e8f93116", "name": "Commented-code block (7 lines) in scripts/publish/story-styles/brutalist.mjs:1", "shortDescription": {"text": "Commented-code block (7 lines) in scripts/publish/story-styles/brutalist.mjs:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-fa35c597509de6cc", "name": "Commented-code block (7 lines) in scripts/_design-pearljamcifras/project/tweaks-panel.jsx:12", "shortDescription": {"text": "Commented-code block (7 lines) in scripts/_design-pearljamcifras/project/tweaks-panel.jsx:12"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d9a03e4fadeb7125", "name": "Commented-code block (6 lines) in scripts/_design-pearljamcifras/project/cifra-data.js:72", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/_design-pearljamcifras/project/cifra-data.js:72"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cf77ada28e6a6e5b", "name": "Commented-code block (5 lines) in scripts/news/build-news-stubs.mjs:3", "shortDescription": {"text": "Commented-code block (5 lines) in scripts/news/build-news-stubs.mjs:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-14b67c19d4b2af3a", "name": "Commented-code block (5 lines) in scripts/news/community-fetch.mjs:6", "shortDescription": {"text": "Commented-code block (5 lines) in scripts/news/community-fetch.mjs:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2d09094cf959de61", "name": "Commented-code block (5 lines) in scripts/news/reddit-community.mjs:5", "shortDescription": {"text": "Commented-code block (5 lines) in scripts/news/reddit-community.mjs:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-90014cd87426bd9a", "name": "Commented-code block (6 lines) in scripts/news/restore-archived.mjs:8", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/news/restore-archived.mjs:8"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b568a46ae0b63b15", "name": "Commented-code block (6 lines) in scripts/news/setlistfm.mjs:4", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/news/setlistfm.mjs:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c097ab6a347570fd", "name": "Commented-code block (8 lines) in scripts/news/image-cache.mjs:1", "shortDescription": {"text": "Commented-code block (8 lines) in scripts/news/image-cache.mjs:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2cdd57af28921323", "name": "Commented-code block (5 lines) in scripts/news/sources.mjs:9", "shortDescription": {"text": "Commented-code block (5 lines) in scripts/news/sources.mjs:9"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0d31fa517ef6e462", "name": "Commented-code block (6 lines) in scripts/news/recache-images.mjs:1", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/news/recache-images.mjs:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f4e2c5766cfef31b", "name": "Commented-code block (9 lines) in scripts/news/dedupe-history.mjs:10", "shortDescription": {"text": "Commented-code block (9 lines) in scripts/news/dedupe-history.mjs:10"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6c0c60108e5b3cea", "name": "Commented-code block (10 lines) in scripts/news/_summary.mjs:5", "shortDescription": {"text": "Commented-code block (10 lines) in scripts/news/_summary.mjs:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-869f0693271af833", "name": "Commented-code block (5 lines) in scripts/news/fetch-news.mjs:5", "shortDescription": {"text": "Commented-code block (5 lines) in scripts/news/fetch-news.mjs:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7eb3b81a92336d38", "name": "Commented-code block (5 lines) in scripts/news/forum-seed.mjs:7", "shortDescription": {"text": "Commented-code block (5 lines) in scripts/news/forum-seed.mjs:7"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c79f72416bf06785", "name": "Commented-code block (6 lines) in scripts/news/dedupe.mjs:5", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/news/dedupe.mjs:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bc0da5296c186250", "name": "Commented-code block (6 lines) in scripts/news/merge-curated.mjs:88", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/news/merge-curated.mjs:88"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cee7e5fce104959a", "name": "Commented-code block (6 lines) in scripts/news/prune-curated.mjs:8", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/news/prune-curated.mjs:8"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-dbbfd2fc8ea03621", "name": "Commented-code block (5 lines) in scripts/news/curators/routine.mjs:1", "shortDescription": {"text": "Commented-code block (5 lines) in scripts/news/curators/routine.mjs:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-428b5931d424e189", "name": "`fetch()` without try/.catch or AbortSignal \u2014 media/lib/smplr/index.mjs:51", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 media/lib/smplr/index.mjs:51"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9a32bfb842746a02", "name": "Commented-code block (5 lines) in mock-ig/reel-mock.mjs:1", "shortDescription": {"text": "Commented-code block (5 lines) in mock-ig/reel-mock.mjs:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-557a12a65bbdacf1", "name": "Commented-code block (5 lines) in mock-ig/curation-runs.mjs:8", "shortDescription": {"text": "Commented-code block (5 lines) in mock-ig/curation-runs.mjs:8"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d77e5a0dfa537afb", "name": "Commented-code block (5 lines) in mock-ig/curation.mjs:8", "shortDescription": {"text": "Commented-code block (5 lines) in mock-ig/curation.mjs:8"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c9142d0bcea11473", "name": "Commented-code block (6 lines) in mock-ig/server.mjs:7", "shortDescription": {"text": "Commented-code block (6 lines) in mock-ig/server.mjs:7"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1dd8e6972314ccbf", "name": "Commented-code block (6 lines) in mock-ig/story-mock.mjs:1", "shortDescription": {"text": "Commented-code block (6 lines) in mock-ig/story-mock.mjs:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8cbd4a1b421a1f29", "name": "`fetch()` without try/.catch or AbortSignal \u2014 mock-ig/mock.test.mjs:25", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 mock-ig/mock.test.mjs:25"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6bd1177d52cf60df", "name": "Commented-code block (5 lines) in mock-ig/preview.mjs:4", "shortDescription": {"text": "Commented-code block (5 lines) in mock-ig/preview.mjs:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2bd2e7d1b861e62d", "name": "Commented-code block (6 lines) in mock-ig/run.mjs:1", "shortDescription": {"text": "Commented-code block (6 lines) in mock-ig/run.mjs:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e898bf19b565c764", "name": "Commented-code block (5 lines) in mock-ig/store.mjs:19", "shortDescription": {"text": "Commented-code block (5 lines) in mock-ig/store.mjs:19"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4c4031960f9c85f3", "name": "`fetch()` without try/.catch or AbortSignal \u2014 mock-ig/web/src/api.js:5", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 mock-ig/web/src/api.js:5"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-582fe0f9d3f12230", "name": "`fetch()` without try/.catch or AbortSignal \u2014 mock-ig/web/src/components/CurationLab.jsx:12", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 mock-ig/web/src/components/CurationLab.jsx:12"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3194563b284ea910", "name": "Commented-code block (5 lines) in mock-ig/web/src/components/CurationRunsLab.jsx:4", "shortDescription": {"text": "Commented-code block (5 lines) in mock-ig/web/src/components/CurationRunsLab.jsx:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8a560d1d1d1f9475", "name": "Commented-code block (6 lines) in cloudflare-worker/reddit-proxy.js:6", "shortDescription": {"text": "Commented-code block (6 lines) in cloudflare-worker/reddit-proxy.js:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4f385475f70d55d5", "name": "Commented-code block (5 lines) in cloudflare-worker/news-merge-dispatch.js:5", "shortDescription": {"text": "Commented-code block (5 lines) in cloudflare-worker/news-merge-dispatch.js:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-99b8f6ac6e45c957", "name": "`fetch()` without try/.catch or AbortSignal \u2014 cloudflare-worker/news-merge-dispatch.js:54", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 cloudflare-worker/news-merge-dispatch.js:54"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bb654812cd7fa3ae", "name": "FastAPI POST `create_bot_topic` without auth dependency \u2014 backend/app/routes/forum.py:173", "shortDescription": {"text": "FastAPI POST `create_bot_topic` without auth dependency \u2014 backend/app/routes/forum.py:173"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5f3201d98987b7ee", "name": "Dangling fetch: POST https://api.telegram.org/bot${TG_TOKEN}/sendMessage (scripts/publish/auto-merge-routine.mjs:198)", "shortDescription": {"text": "Dangling fetch: POST https://api.telegram.org/bot${TG_TOKEN}/sendMessage (scripts/publish/auto-merge-routine.mjs:198)"}, "fullDescription": {"text": "`scripts/publish/auto-merge-routine.mjs:198` calls `POST https://api.telegram.org/bot${TG_TOKEN}/sendMessage` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.telegram.org/bot/<p>/sendmessage`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-40d2fcdfdcc78071", "name": "Dangling fetch: POST https://api.telegram.org/bot${token}/sendMessage (scripts/publish/run-publish-reel.mjs:218)", "shortDescription": {"text": "Dangling fetch: POST https://api.telegram.org/bot${token}/sendMessage (scripts/publish/run-publish-reel.mjs:218)"}, "fullDescription": {"text": "`scripts/publish/run-publish-reel.mjs:218` calls `POST https://api.telegram.org/bot${token}/sendMessage` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.telegram.org/bot/<p>/sendmessage`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e46de1a7dcc8ef16", "name": "Dangling fetch: POST https://api.telegram.org/bot${token}/sendMessage (scripts/publish/run-publish.mjs:439)", "shortDescription": {"text": "Dangling fetch: POST https://api.telegram.org/bot${token}/sendMessage (scripts/publish/run-publish.mjs:439)"}, "fullDescription": {"text": "`scripts/publish/run-publish.mjs:439` calls `POST https://api.telegram.org/bot${token}/sendMessage` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.telegram.org/bot/<p>/sendmessage`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-527866bcb89779b0", "name": "Dangling fetch: POST https://api.telegram.org/bot${token}/sendMessage (scripts/publish/run-publish-story.mjs:241)", "shortDescription": {"text": "Dangling fetch: POST https://api.telegram.org/bot${token}/sendMessage (scripts/publish/run-publish-story.mjs:241)"}, "fullDescription": {"text": "`scripts/publish/run-publish-story.mjs:241` calls `POST https://api.telegram.org/bot${token}/sendMessage` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.telegram.org/bot/<p>/sendmessage`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2fe6f04df46dd606", "name": "Dangling fetch: POST https://api.telegram.org/bot${token}/sendMessage (scripts/news/community-fetch.mjs:376)", "shortDescription": {"text": "Dangling fetch: POST https://api.telegram.org/bot${token}/sendMessage (scripts/news/community-fetch.mjs:376)"}, "fullDescription": {"text": "`scripts/news/community-fetch.mjs:376` calls `POST https://api.telegram.org/bot${token}/sendMessage` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.telegram.org/bot/<p>/sendmessage`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7d5d8cd183f0fd78", "name": "Dangling fetch: GET /_mock/feed (mock-ig/web/src/api.js:5)", "shortDescription": {"text": "Dangling fetch: GET /_mock/feed (mock-ig/web/src/api.js:5)"}, "fullDescription": {"text": "`mock-ig/web/src/api.js:5` calls `GET /_mock/feed` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/_mock/feed`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c5b855616d02f740", "name": "Dangling fetch: GET /_mock/stories (mock-ig/web/src/api.js:11)", "shortDescription": {"text": "Dangling fetch: GET /_mock/stories (mock-ig/web/src/api.js:11)"}, "fullDescription": {"text": "`mock-ig/web/src/api.js:11` calls `GET /_mock/stories` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/_mock/stories`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-275bb4bb1bb56173", "name": "Dangling fetch: GET /_mock/reels (mock-ig/web/src/api.js:17)", "shortDescription": {"text": "Dangling fetch: GET /_mock/reels (mock-ig/web/src/api.js:17)"}, "fullDescription": {"text": "`mock-ig/web/src/api.js:17` calls `GET /_mock/reels` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/_mock/reels`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eb338da54a59da99", "name": "Dangling fetch: GET /_mock/usage (mock-ig/web/src/api.js:24)", "shortDescription": {"text": "Dangling fetch: GET /_mock/usage (mock-ig/web/src/api.js:24)"}, "fullDescription": {"text": "`mock-ig/web/src/api.js:24` calls `GET /_mock/usage` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/_mock/usage`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-926a785903d4efe8", "name": "Dangling fetch: POST /_mock/reset (mock-ig/web/src/api.js:30)", "shortDescription": {"text": "Dangling fetch: POST /_mock/reset (mock-ig/web/src/api.js:30)"}, "fullDescription": {"text": "`mock-ig/web/src/api.js:30` calls `POST /_mock/reset` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/_mock/reset`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-97fcaf48624a84c6", "name": "Dangling fetch: POST /_mock/delete (mock-ig/web/src/api.js:37)", "shortDescription": {"text": "Dangling fetch: POST /_mock/delete (mock-ig/web/src/api.js:37)"}, "fullDescription": {"text": "`mock-ig/web/src/api.js:37` calls `POST /_mock/delete` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/_mock/delete`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bec9b6db14bf1cb5", "name": "Dangling fetch: GET /_mock/control (mock-ig/web/src/api.js:44)", "shortDescription": {"text": "Dangling fetch: GET /_mock/control (mock-ig/web/src/api.js:44)"}, "fullDescription": {"text": "`mock-ig/web/src/api.js:44` calls `GET /_mock/control` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/_mock/control`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-687adfffa0406090", "name": "Dangling fetch: POST /_mock/fail (mock-ig/web/src/api.js:52)", "shortDescription": {"text": "Dangling fetch: POST /_mock/fail (mock-ig/web/src/api.js:52)"}, "fullDescription": {"text": "`mock-ig/web/src/api.js:52` calls `POST /_mock/fail` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/_mock/fail`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-62e087b0446e8b7c", "name": "Dangling fetch: POST /_mock/sync (mock-ig/web/src/api.js:60)", "shortDescription": {"text": "Dangling fetch: POST /_mock/sync (mock-ig/web/src/api.js:60)"}, "fullDescription": {"text": "`mock-ig/web/src/api.js:60` calls `POST /_mock/sync` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/_mock/sync`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1c553442abc56067", "name": "Dangling fetch: GET /_mock/curation (mock-ig/web/src/api.js:75)", "shortDescription": {"text": "Dangling fetch: GET /_mock/curation (mock-ig/web/src/api.js:75)"}, "fullDescription": {"text": "`mock-ig/web/src/api.js:75` calls `GET /_mock/curation` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/_mock/curation`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3bfab86fbf9d67bb", "name": "Dangling fetch: GET /_mock/curation-runs (mock-ig/web/src/api.js:82)", "shortDescription": {"text": "Dangling fetch: GET /_mock/curation-runs (mock-ig/web/src/api.js:82)"}, "fullDescription": {"text": "`mock-ig/web/src/api.js:82` calls `GET /_mock/curation-runs` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/_mock/curation-runs`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-87205930268c920b", "name": "Dangling fetch: POST /_mock/curation-run (mock-ig/web/src/api.js:90)", "shortDescription": {"text": "Dangling fetch: POST /_mock/curation-run (mock-ig/web/src/api.js:90)"}, "fullDescription": {"text": "`mock-ig/web/src/api.js:90` calls `POST /_mock/curation-run` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/_mock/curation-run`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5ec7cfb154e0b003", "name": "Dangling fetch: GET /_mock/candidates (mock-ig/web/src/api.js:98)", "shortDescription": {"text": "Dangling fetch: GET /_mock/candidates (mock-ig/web/src/api.js:98)"}, "fullDescription": {"text": "`mock-ig/web/src/api.js:98` calls `GET /_mock/candidates` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/_mock/candidates`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9a06dcb6bd78c9c9", "name": "Dangling fetch: POST /_mock/preview (mock-ig/web/src/api.js:105)", "shortDescription": {"text": "Dangling fetch: POST /_mock/preview (mock-ig/web/src/api.js:105)"}, "fullDescription": {"text": "`mock-ig/web/src/api.js:105` calls `POST /_mock/preview` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/_mock/preview`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bbc21317082135af", "name": "Dangling fetch: GET /_mock/runs (mock-ig/web/src/api.js:113)", "shortDescription": {"text": "Dangling fetch: GET /_mock/runs (mock-ig/web/src/api.js:113)"}, "fullDescription": {"text": "`mock-ig/web/src/api.js:113` calls `GET /_mock/runs` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/_mock/runs`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-48791e9fe121c7fd", "name": "Dangling fetch: POST /_mock/run (mock-ig/web/src/api.js:121)", "shortDescription": {"text": "Dangling fetch: POST /_mock/run (mock-ig/web/src/api.js:121)"}, "fullDescription": {"text": "`mock-ig/web/src/api.js:121` calls `POST /_mock/run` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/_mock/run`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bc30b43ed0f83228", "name": "Dangling fetch: POST https://api.github.com/gists (cloudflare-worker/news-merge-dispatch.js:107)", "shortDescription": {"text": "Dangling fetch: POST https://api.github.com/gists (cloudflare-worker/news-merge-dispatch.js:107)"}, "fullDescription": {"text": "`cloudflare-worker/news-merge-dispatch.js:107` calls `POST https://api.github.com/gists` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.github.com/gists`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-916a61a897b44216", "name": "Dangling fetch: POST https://api.github.com/repos/${REPO_OWNER}/${REPO_NAME}/dispatches (cloudflare-worker/news-merge-di", "shortDescription": {"text": "Dangling fetch: POST https://api.github.com/repos/${REPO_OWNER}/${REPO_NAME}/dispatches (cloudflare-worker/news-merge-dispatch.js:138)"}, "fullDescription": {"text": "`cloudflare-worker/news-merge-dispatch.js:138` calls `POST https://api.github.com/repos/${REPO_OWNER}/${REPO_NAME}/dispatches` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.github.com/repos/<p>/<p>/dispatches`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`backend/app/main.py` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6195d9c0f56c4cb6", "name": "Unused endpoint: GET /posts", "shortDescription": {"text": "Unused endpoint: GET /posts"}, "fullDescription": {"text": "`backend/app/routes/feed.py` declares `GET /posts` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d38eae0b19ee450e", "name": "Unused endpoint: POST /posts", "shortDescription": {"text": "Unused endpoint: POST /posts"}, "fullDescription": {"text": "`backend/app/routes/feed.py` declares `POST /posts` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fbf647c887b96333", "name": "Unused endpoint: GET /posts/{post_id}", "shortDescription": {"text": "Unused endpoint: GET /posts/{post_id}"}, "fullDescription": {"text": "`backend/app/routes/feed.py` declares `GET /posts/{post_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-584d341ef931d66e", "name": "Unused endpoint: POST /posts/{post_id}/likes", "shortDescription": {"text": "Unused endpoint: POST /posts/{post_id}/likes"}, "fullDescription": {"text": "`backend/app/routes/feed.py` declares `POST /posts/{post_id}/likes` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-505c45a4790f795f", "name": "Unused endpoint: POST /posts/{post_id}/comments", "shortDescription": {"text": "Unused endpoint: POST /posts/{post_id}/comments"}, "fullDescription": {"text": "`backend/app/routes/feed.py` declares `POST /posts/{post_id}/comments` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-855ced39c3f8d63b", "name": "Unused endpoint: DELETE /comments/{comment_id}", "shortDescription": {"text": "Unused endpoint: DELETE /comments/{comment_id}"}, "fullDescription": {"text": "`backend/app/routes/feed.py` declares `DELETE /comments/{comment_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-42819fbd220a7e59", "name": "Unused endpoint: GET /auth/google/login", "shortDescription": {"text": "Unused endpoint: GET /auth/google/login"}, "fullDescription": {"text": "`backend/app/routes/auth.py` declares `GET /auth/google/login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-392dcbd9c0e4ed85", "name": "Unused endpoint: GET /auth/google/callback", "shortDescription": {"text": "Unused endpoint: GET /auth/google/callback"}, "fullDescription": {"text": "`backend/app/routes/auth.py` declares `GET /auth/google/callback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ac42422b23e45104", "name": "Unused endpoint: GET /auth/me", "shortDescription": {"text": "Unused endpoint: GET /auth/me"}, "fullDescription": {"text": "`backend/app/routes/auth.py` declares `GET /auth/me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4982dbfd71045a81", "name": "Unused endpoint: GET /topics", "shortDescription": {"text": "Unused endpoint: GET /topics"}, "fullDescription": {"text": "`backend/app/routes/forum.py` declares `GET /topics` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-95d0619d95e761f1", "name": "Unused endpoint: POST /topics", "shortDescription": {"text": "Unused endpoint: POST /topics"}, "fullDescription": {"text": "`backend/app/routes/forum.py` declares `POST /topics` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cf92765437224a68", "name": "Unused endpoint: POST /bot/topics", "shortDescription": {"text": "Unused endpoint: POST /bot/topics"}, "fullDescription": {"text": "`backend/app/routes/forum.py` declares `POST /bot/topics` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-42cc14ffa628f535", "name": "Unused endpoint: GET /topics/{topic_id}", "shortDescription": {"text": "Unused endpoint: GET /topics/{topic_id}"}, "fullDescription": {"text": "`backend/app/routes/forum.py` declares `GET /topics/{topic_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d18411a066b7e2c1", "name": "Unused endpoint: GET /users/{user_id}", "shortDescription": {"text": "Unused endpoint: GET /users/{user_id}"}, "fullDescription": {"text": "`backend/app/routes/forum.py` declares `GET /users/{user_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9f06644688cd47af", "name": "Unused endpoint: PATCH /users/me", "shortDescription": {"text": "Unused endpoint: PATCH /users/me"}, "fullDescription": {"text": "`backend/app/routes/forum.py` declares `PATCH /users/me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ebaa440022985b81", "name": "Unused endpoint: GET /users/{user_id}/badges", "shortDescription": {"text": "Unused endpoint: GET /users/{user_id}/badges"}, "fullDescription": {"text": "`backend/app/routes/forum.py` declares `GET /users/{user_id}/badges` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a36976a4f4d61485", "name": "Unused endpoint: POST /topics/{topic_id}/posts", "shortDescription": {"text": "Unused endpoint: POST /topics/{topic_id}/posts"}, "fullDescription": {"text": "`backend/app/routes/forum.py` declares `POST /topics/{topic_id}/posts` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0a748f8fca5af135", "name": "Unused endpoint: POST /reactions", "shortDescription": {"text": "Unused endpoint: POST /reactions"}, "fullDescription": {"text": "`backend/app/routes/forum.py` declares `POST /reactions` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7685e59e2ca19804", "name": "Unused endpoint: DELETE /posts/{post_id}", "shortDescription": {"text": "Unused endpoint: DELETE /posts/{post_id}"}, "fullDescription": {"text": "`backend/app/routes/forum.py` declares `DELETE /posts/{post_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5459c68575e53a0c", "name": "Unused endpoint: DELETE /topics/{topic_id}", "shortDescription": {"text": "Unused endpoint: DELETE /topics/{topic_id}"}, "fullDescription": {"text": "`backend/app/routes/forum.py` declares `DELETE /topics/{topic_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dce97aeb1712ef80", "name": "Unused endpoint: POST /reports", "shortDescription": {"text": "Unused endpoint: POST /reports"}, "fullDescription": {"text": "`backend/app/routes/forum.py` declares `POST /reports` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/24177"}, "properties": {"repository": "andrehz4/setlists-pj-ev", "repoUrl": "https://github.com/andrehz4/setlists-pj-ev", "branch": "main"}, "results": [{"ruleId": "scanner-9fb4516cb35a6027", "level": "note", "message": {"text": "Possibly dead Python function: format"}, "properties": {"repobilityId": "46a918df7787d491", "scanner": "scanner-primary", "fingerprint": "9fb4516cb35a6027", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/core/logging.py:12"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa2b8983dee7adb3", "level": "note", "message": {"text": "Icon-only button without accessible name \u2014 mock-ig/web/src/components/PostModal.jsx:24"}, "properties": {"repobilityId": "a75044a3fde44516", "scanner": "scanner-primary", "fingerprint": "aa2b8983dee7adb3", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.button.no-label"]}}, {"ruleId": "scanner-d03616b003cac64c", "level": "note", "message": {"text": "Icon-only button without accessible name \u2014 mock-ig/web/src/components/FailPanel.jsx:35"}, "properties": {"repobilityId": "da2505725031505c", "scanner": "scanner-primary", "fingerprint": "d03616b003cac64c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.button.no-label"]}}, {"ruleId": "scanner-8dcd8d96550e6b92", "level": "note", "message": {"text": "Icon-only button without accessible name \u2014 mock-ig/web/src/components/StoryViewer.jsx:37"}, "properties": {"repobilityId": "eacd62cc66785b86", "scanner": "scanner-primary", "fingerprint": "8dcd8d96550e6b92", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.button.no-label"]}}, {"ruleId": "scanner-1f66ad88286ca30a", "level": "warning", "message": {"text": "Dockerfile runs as root: backend/Dockerfile"}, "properties": {"repobilityId": "7afd2b0e8a8c9eeb", "scanner": "scanner-primary", "fingerprint": "1f66ad88286ca30a", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-714c31ca9f474ae6", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "properties": {"repobilityId": "3ee84c7a50b4e183", "scanner": "scanner-primary", "fingerprint": "714c31ca9f474ae6", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/Dockerfile"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-714c31ca9f474ae6", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "properties": {"repobilityId": "cca58f3f6e5a0dd6", "scanner": "scanner-primary", "fingerprint": "714c31ca9f474ae6", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/Dockerfile"}, "region": {"startLine": 18}}}]}, {"ruleId": "scanner-c2bb090764bc5769", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in forum-topic.html:591"}, "properties": {"repobilityId": "c291ae8866335a19", "scanner": "scanner-primary", "fingerprint": "c2bb090764bc5769", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "forum-topic.html"}, "region": {"startLine": 591}}}]}, {"ruleId": "scanner-53bcc89d8847ab20", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in auth-callback.html:82"}, "properties": {"repobilityId": "ce7c5382406dab56", "scanner": "scanner-primary", "fingerprint": "53bcc89d8847ab20", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "auth-callback.html"}, "region": {"startLine": 82}}}]}, {"ruleId": "scanner-d7bc1851dce191dd", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in forum-profile.html:357"}, "properties": {"repobilityId": "8d4d9b5966e5729b", "scanner": "scanner-primary", "fingerprint": "d7bc1851dce191dd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "forum-profile.html"}, "region": {"startLine": 357}}}]}, {"ruleId": "scanner-f827f07e9b26ccad", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in forum.html:843"}, "properties": {"repobilityId": "3886daba90121a9f", "scanner": "scanner-primary", "fingerprint": "f827f07e9b26ccad", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "forum.html"}, "region": {"startLine": 843}}}]}, {"ruleId": "scanner-9dae8b9dd56c815e", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in purify.min.js:2"}, "properties": {"repobilityId": "9e157e2eb4f0ec1d", "scanner": "scanner-primary", "fingerprint": "9dae8b9dd56c815e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "purify.min.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-c59dc44e443955bb", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/publish/story-video.mjs:34"}, "properties": {"repobilityId": "d46b014ad2a799d9", "scanner": "scanner-primary", "fingerprint": "c59dc44e443955bb", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/publish/story-video.mjs"}, "region": {"startLine": 34}}}]}, {"ruleId": "scanner-27bd36683e7dd7aa", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/publish/auto-merge-routine.mjs:30"}, "properties": {"repobilityId": "33753fa4e4aef9a0", "scanner": "scanner-primary", "fingerprint": "27bd36683e7dd7aa", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/publish/auto-merge-routine.mjs"}, "region": {"startLine": 30}}}]}, {"ruleId": "scanner-ce7d1149c44488c7", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/publish/queue-state.test.mjs:12"}, "properties": {"repobilityId": "3d5bf38512a315f8", "scanner": "scanner-primary", "fingerprint": "ce7d1149c44488c7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/publish/queue-state.test.mjs"}, "region": {"startLine": 12}}}]}, {"ruleId": "scanner-0b1ef8de7704d5e1", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/publish/run-publish-reel.mjs:15"}, "properties": {"repobilityId": "400d39f054547b89", "scanner": "scanner-primary", "fingerprint": "0b1ef8de7704d5e1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/publish/run-publish-reel.mjs"}, "region": {"startLine": 15}}}]}, {"ruleId": "scanner-0fd4712a964a69ce", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/publish/run-publish.mjs:24"}, "properties": {"repobilityId": "d3da5a48d6bc4a1d", "scanner": "scanner-primary", "fingerprint": "0fd4712a964a69ce", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/publish/run-publish.mjs"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-551f96cacd5bdaa5", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/publish/run-publish-story.mjs:18"}, "properties": {"repobilityId": "59afe0e806bae737", "scanner": "scanner-primary", "fingerprint": "551f96cacd5bdaa5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/publish/run-publish-story.mjs"}, "region": {"startLine": 18}}}]}, {"ruleId": "scanner-28d97d8e27ed307a", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/publish/reel-video.mjs:21"}, "properties": {"repobilityId": "7ca0170536111c8f", "scanner": "scanner-primary", "fingerprint": "28d97d8e27ed307a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/publish/reel-video.mjs"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-4cf10e78da4d666c", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/news/reddit-rss-fetch.mjs:5"}, "properties": {"repobilityId": "5058fcc20a28af63", "scanner": "scanner-primary", "fingerprint": "4cf10e78da4d666c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/news/reddit-rss-fetch.mjs"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-b884a0658e31b0ef", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in mock-ig/curation-runs.mjs:16"}, "properties": {"repobilityId": "85559ce9c7a58fa4", "scanner": "scanner-primary", "fingerprint": "b884a0658e31b0ef", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mock-ig/curation-runs.mjs"}, "region": {"startLine": 16}}}]}, {"ruleId": "scanner-0061f9580f94c2ec", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in mock-ig/server.mjs:23"}, "properties": {"repobilityId": "5094d2f50ac832ad", "scanner": "scanner-primary", "fingerprint": "0061f9580f94c2ec", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mock-ig/server.mjs"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-d51a2b12644ecf87", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in mock-ig/server.mjs:50"}, "properties": {"repobilityId": "d4b00d60da1a4fe7", "scanner": "scanner-primary", "fingerprint": "d51a2b12644ecf87", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mock-ig/server.mjs"}, "region": {"startLine": 50}}}]}, {"ruleId": "scanner-e72c4cbc6a198d90", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in mock-ig/runs.mjs:13"}, "properties": {"repobilityId": "88faf10586af51a5", "scanner": "scanner-primary", "fingerprint": "e72c4cbc6a198d90", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mock-ig/runs.mjs"}, "region": {"startLine": 13}}}]}, {"ruleId": "scanner-33969fd70e20bed3", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in mock-ig/runs.mjs:6"}, "properties": {"repobilityId": "d14301557ba8e424", "scanner": "scanner-primary", "fingerprint": "33969fd70e20bed3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mock-ig/runs.mjs"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-98e265fd9b3aeb2c", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in cloudflare-worker/reddit-proxy.js:63"}, "properties": {"repobilityId": "ca0952d2637965f0", "scanner": "scanner-primary", "fingerprint": "98e265fd9b3aeb2c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "cloudflare-worker/reddit-proxy.js"}, "region": {"startLine": 63}}}]}, {"ruleId": "scanner-38724fedb5c5e5ad", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "213ad1f9fa03379b", "scanner": "scanner-primary", "fingerprint": "38724fedb5c5e5ad", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/publish-instagram.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2cc052fd80140230", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "f4de20783096ae05", "scanner": "scanner-primary", "fingerprint": "2cc052fd80140230", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/publish-reel.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c380cbf21d59951f", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "4d7d022ee4a21d7f", "scanner": "scanner-primary", "fingerprint": "c380cbf21d59951f", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/news.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d1dce03bcc3029d0", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "f462c11764e5551f", "scanner": "scanner-primary", "fingerprint": "d1dce03bcc3029d0", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/community.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aad457e5c292156c", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "5665e3d36cd53771", "scanner": "scanner-primary", "fingerprint": "aad457e5c292156c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/forum-seed.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1449f9d42e262b84", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "ce71d468a210344a", "scanner": "scanner-primary", "fingerprint": "1449f9d42e262b84", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/news-merge.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-25ff02622faf85fc", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "e48500174a3e847d", "scanner": "scanner-primary", "fingerprint": "25ff02622faf85fc", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/publish-story.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1dd2ffb10e2a735d", "level": "note", "message": {"text": "Very large file: media/lib/smplr/index.mjs (3840 lines)"}, "properties": {"repobilityId": "ebb0cfe92533e0c0", "scanner": "scanner-primary", "fingerprint": "1dd2ffb10e2a735d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ea3b5e389d8c9c0f", "level": "note", "message": {"text": "Low test-to-source ratio"}, "properties": {"repobilityId": "ef7b2552cc00a375", "scanner": "scanner-primary", "fingerprint": "ea3b5e389d8c9c0f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["tests"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "ff3cdc4fb58ea752", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "71a9a3d2e027f07a", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "4d412df57821d320", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "efaeaff419431d3f", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "64222c95640b2281", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-bea357a6497a2d5d", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: CLAUDE.md"}, "properties": {"repobilityId": "aae72df3934829ac", "scanner": "scanner-primary", "fingerprint": "bea357a6497a2d5d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "CLAUDE.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9ebaf59860add4c9", "level": "none", "message": {"text": "Commented-code block (8 lines) in scripts/cifras-coverage.test.mjs:4"}, "properties": {"repobilityId": "b987107509816100", "scanner": "scanner-primary", "fingerprint": "9ebaf59860add4c9", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3361119bc12a5b2c", "level": "none", "message": {"text": "Commented-code block (5 lines) in scripts/apply-pt-pass-2b.mjs:1"}, "properties": {"repobilityId": "53b81f34aa651b7c", "scanner": "scanner-primary", "fingerprint": "3361119bc12a5b2c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-05762931a52976d4", "level": "none", "message": {"text": "Commented-code block (7 lines) in scripts/_design-2026-05-12/pearljamcifras/project/tweaks-panel.jsx:12"}, "properties": {"repobilityId": "018a6d64536c8636", "scanner": "scanner-primary", "fingerprint": "05762931a52976d4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1c80dda1b84f3183", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/_design-2026-05-12/pearljamcifras/project/cifra-data.js:72"}, "properties": {"repobilityId": "f79b278f2f80866c", "scanner": "scanner-primary", "fingerprint": "1c80dda1b84f3183", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6f5ae95b35de35cc", "level": "none", "message": {"text": "Commented-code block (7 lines) in scripts/_design-2026-05-12-v2/pearljamcifras/project/tweaks-panel.jsx:12"}, "properties": {"repobilityId": "3eef8166d8681012", "scanner": "scanner-primary", "fingerprint": "6f5ae95b35de35cc", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f987f4b2225e8936", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/_design-2026-05-12-v2/pearljamcifras/project/cifra-data.js:72"}, "properties": {"repobilityId": "199cc06813281421", "scanner": "scanner-primary", "fingerprint": "f987f4b2225e8936", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a76f15a663e4b512", "level": "none", "message": {"text": "Commented-code block (10 lines) in scripts/publish/slide-image.mjs:3"}, "properties": {"repobilityId": "fc70589cc5547117", "scanner": "scanner-primary", "fingerprint": "a76f15a663e4b512", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-37b749f302b02845", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/publish/reel.test.mjs:228"}, "properties": {"repobilityId": "b2b185d98fa14e92", "scanner": "scanner-primary", "fingerprint": "37b749f302b02845", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-d7f561186391a3b3", "level": "none", "message": {"text": "Commented-code block (10 lines) in scripts/publish/story-video.mjs:3"}, "properties": {"repobilityId": "0dc9e6896142f7c8", "scanner": "scanner-primary", "fingerprint": "d7f561186391a3b3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d2304b4d9f772649", "level": "none", "message": {"text": "Commented-code block (7 lines) in scripts/publish/queue.mjs:1"}, "properties": {"repobilityId": "c60fd00b1bac77f7", "scanner": "scanner-primary", "fingerprint": "d2304b4d9f772649", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2a9eba6d72584bd5", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/publish/fontconfig-boot.mjs:1"}, "properties": {"repobilityId": "a8c6ac71d4888e08", "scanner": "scanner-primary", "fingerprint": "2a9eba6d72584bd5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-782057fc7aed86d4", "level": "none", "message": {"text": "Commented-code block (7 lines) in scripts/publish/auto-merge-routine.mjs:3"}, "properties": {"repobilityId": "f31562683c5da936", "scanner": "scanner-primary", "fingerprint": "782057fc7aed86d4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e2a7ebcc495a5462", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/publish/face-crop.mjs:1"}, "properties": {"repobilityId": "ee7c2358d057b392", "scanner": "scanner-primary", "fingerprint": "e2a7ebcc495a5462", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-dcafd35879004cd0", "level": "note", "message": {"text": "Legacy-named symbol `postedOld` in scripts/publish/queue-select.test.mjs:168"}, "properties": {"repobilityId": "d3bdf34c82d3d0d5", "scanner": "scanner-primary", "fingerprint": "dcafd35879004cd0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-2b38b825937c6c7a", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/publish/queue-state.test.mjs:1"}, "properties": {"repobilityId": "793ff824a65759d9", "scanner": "scanner-primary", "fingerprint": "2b38b825937c6c7a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-bf209c0128dd916e", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/publish/telegram-bot.mjs:45"}, "properties": {"repobilityId": "d6feea4645940ea3", "scanner": "scanner-primary", "fingerprint": "bf209c0128dd916e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-6882347e36098f9f", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/publish/reel-select.mjs:1"}, "properties": {"repobilityId": "e611f4cc24a62640", "scanner": "scanner-primary", "fingerprint": "6882347e36098f9f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a949f41ab9bc2b37", "level": "none", "message": {"text": "Commented-code block (10 lines) in scripts/publish/prune-media.mjs:5"}, "properties": {"repobilityId": "b6c5a9a402802221", "scanner": "scanner-primary", "fingerprint": "a949f41ab9bc2b37", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-61903e2afb424489", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/publish/ig-detect-deleted.mjs:23"}, "properties": {"repobilityId": "7d0d66c5ccad4fd4", "scanner": "scanner-primary", "fingerprint": "61903e2afb424489", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c769fdc936b3e235", "level": "none", "message": {"text": "Commented-code block (5 lines) in scripts/publish/subject-fallback.mjs:1"}, "properties": {"repobilityId": "4fa4f1c97e1e8dae", "scanner": "scanner-primary", "fingerprint": "c769fdc936b3e235", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5f9c86a1ac4fccf7", "level": "none", "message": {"text": "Commented-code block (9 lines) in scripts/publish/run-publish-reel.mjs:1"}, "properties": {"repobilityId": "cb2fdde24dd49daf", "scanner": "scanner-primary", "fingerprint": "5f9c86a1ac4fccf7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f13a9d47e985e935", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/publish/instagram.mjs:1"}, "properties": {"repobilityId": "bab81e71dc2e325c", "scanner": "scanner-primary", "fingerprint": "f13a9d47e985e935", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-72394efc8792e21b", "level": "none", "message": {"text": "Commented-code block (11 lines) in scripts/publish/run-publish.mjs:1"}, "properties": {"repobilityId": "3f5d2430cc420df1", "scanner": "scanner-primary", "fingerprint": "72394efc8792e21b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a72f8ce6c16d2a9d", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/publish/recover-publish.test.mjs:1"}, "properties": {"repobilityId": "478045ddf2cf87d9", "scanner": "scanner-primary", "fingerprint": "a72f8ce6c16d2a9d", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-49501f9f77979ad0", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/publish/recover-publish.test.mjs:43"}, "properties": {"repobilityId": "0255e62469891aff", "scanner": "scanner-primary", "fingerprint": "49501f9f77979ad0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-9fdd8cc08d4cb08f", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/publish/detect-deleted.test.mjs:1"}, "properties": {"repobilityId": "db316cef3b5b5cb3", "scanner": "scanner-primary", "fingerprint": "9fdd8cc08d4cb08f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-fa3001d8b21f9206", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/publish/detect-deleted.test.mjs:35"}, "properties": {"repobilityId": "22c20436e2a41d98", "scanner": "scanner-primary", "fingerprint": "fa3001d8b21f9206", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-d221e69746e4cb03", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/publish/story-select.mjs:1"}, "properties": {"repobilityId": "36efcc5f7f8d7f3a", "scanner": "scanner-primary", "fingerprint": "d221e69746e4cb03", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-9ea5f53a46dc691c", "level": "none", "message": {"text": "Commented-code block (9 lines) in scripts/publish/run-publish-story.mjs:1"}, "properties": {"repobilityId": "51690d610fbaf47c", "scanner": "scanner-primary", "fingerprint": "9ea5f53a46dc691c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-41ab96201f96a05e", "level": "none", "message": {"text": "Commented-code block (5 lines) in scripts/publish/smoke-test.mjs:8"}, "properties": {"repobilityId": "e810daecebc84a3b", "scanner": "scanner-primary", "fingerprint": "41ab96201f96a05e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-284ee1a492b03b7f", "level": "none", "message": {"text": "Commented-code block (5 lines) in scripts/publish/story-track.mjs:1"}, "properties": {"repobilityId": "02ea8796db47bdaa", "scanner": "scanner-primary", "fingerprint": "284ee1a492b03b7f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8d1d0ac386d47ffd", "level": "none", "message": {"text": "Commented-code block (5 lines) in scripts/publish/color-cycle.mjs:1"}, "properties": {"repobilityId": "6634e2e50a58216d", "scanner": "scanner-primary", "fingerprint": "8d1d0ac386d47ffd", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a9b4edef915e3d24", "level": "none", "message": {"text": "Commented-code block (7 lines) in scripts/publish/reel-video.mjs:6"}, "properties": {"repobilityId": "4fcadd441001fb10", "scanner": "scanner-primary", "fingerprint": "a9b4edef915e3d24", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-9b8076cddb6fa639", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/publish/story-styles/caderno-b.mjs:120"}, "properties": {"repobilityId": "78c27e68ae60a0ca", "scanner": "scanner-primary", "fingerprint": "9b8076cddb6fa639", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f3ae5c80569a1626", "level": "none", "message": {"text": "Commented-code block (5 lines) in scripts/publish/story-styles/index.mjs:3"}, "properties": {"repobilityId": "3042768509604d26", "scanner": "scanner-primary", "fingerprint": "f3ae5c80569a1626", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-81daf8f0be3cd21e", "level": "none", "message": {"text": "Commented-code block (5 lines) in scripts/publish/story-styles/editorial-badge.mjs:6"}, "properties": {"repobilityId": "3cc2d892cd24a0cc", "scanner": "scanner-primary", "fingerprint": "81daf8f0be3cd21e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-03e66823e8f93116", "level": "none", "message": {"text": "Commented-code block (7 lines) in scripts/publish/story-styles/brutalist.mjs:1"}, "properties": {"repobilityId": "b3bcf91f40e69e31", "scanner": "scanner-primary", "fingerprint": "03e66823e8f93116", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-fa35c597509de6cc", "level": "none", "message": {"text": "Commented-code block (7 lines) in scripts/_design-pearljamcifras/project/tweaks-panel.jsx:12"}, "properties": {"repobilityId": "40d0f8a87aea9233", "scanner": "scanner-primary", "fingerprint": "fa35c597509de6cc", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d9a03e4fadeb7125", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/_design-pearljamcifras/project/cifra-data.js:72"}, "properties": {"repobilityId": "6de87a0e25ceb9d8", "scanner": "scanner-primary", "fingerprint": "d9a03e4fadeb7125", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-cf77ada28e6a6e5b", "level": "none", "message": {"text": "Commented-code block (5 lines) in scripts/news/build-news-stubs.mjs:3"}, "properties": {"repobilityId": "eac3087447168aec", "scanner": "scanner-primary", "fingerprint": "cf77ada28e6a6e5b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-14b67c19d4b2af3a", "level": "none", "message": {"text": "Commented-code block (5 lines) in scripts/news/community-fetch.mjs:6"}, "properties": {"repobilityId": "1c06a3d0f001c1e3", "scanner": "scanner-primary", "fingerprint": "14b67c19d4b2af3a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2d09094cf959de61", "level": "none", "message": {"text": "Commented-code block (5 lines) in scripts/news/reddit-community.mjs:5"}, "properties": {"repobilityId": "002a7aa59e3b64db", "scanner": "scanner-primary", "fingerprint": "2d09094cf959de61", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-90014cd87426bd9a", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/news/restore-archived.mjs:8"}, "properties": {"repobilityId": "db8a7f872449c8d0", "scanner": "scanner-primary", "fingerprint": "90014cd87426bd9a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b568a46ae0b63b15", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/news/setlistfm.mjs:4"}, "properties": {"repobilityId": "eba327926b63f2d0", "scanner": "scanner-primary", "fingerprint": "b568a46ae0b63b15", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c097ab6a347570fd", "level": "none", "message": {"text": "Commented-code block (8 lines) in scripts/news/image-cache.mjs:1"}, "properties": {"repobilityId": "d816dd2ec9f80083", "scanner": "scanner-primary", "fingerprint": "c097ab6a347570fd", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2cdd57af28921323", "level": "none", "message": {"text": "Commented-code block (5 lines) in scripts/news/sources.mjs:9"}, "properties": {"repobilityId": "320f580a1087d0a8", "scanner": "scanner-primary", "fingerprint": "2cdd57af28921323", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0d31fa517ef6e462", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/news/recache-images.mjs:1"}, "properties": {"repobilityId": "eb7f9e3947b6b2da", "scanner": "scanner-primary", "fingerprint": "0d31fa517ef6e462", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f4e2c5766cfef31b", "level": "none", "message": {"text": "Commented-code block (9 lines) in scripts/news/dedupe-history.mjs:10"}, "properties": {"repobilityId": "617729e5e0d63e38", "scanner": "scanner-primary", "fingerprint": "f4e2c5766cfef31b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6c0c60108e5b3cea", "level": "none", "message": {"text": "Commented-code block (10 lines) in scripts/news/_summary.mjs:5"}, "properties": {"repobilityId": "fd3c38a7d7601282", "scanner": "scanner-primary", "fingerprint": "6c0c60108e5b3cea", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-869f0693271af833", "level": "none", "message": {"text": "Commented-code block (5 lines) in scripts/news/fetch-news.mjs:5"}, "properties": {"repobilityId": "9ad73255c2edd5ca", "scanner": "scanner-primary", "fingerprint": "869f0693271af833", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7eb3b81a92336d38", "level": "none", "message": {"text": "Commented-code block (5 lines) in scripts/news/forum-seed.mjs:7"}, "properties": {"repobilityId": "3858c6ede5b85c11", "scanner": "scanner-primary", "fingerprint": "7eb3b81a92336d38", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c79f72416bf06785", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/news/dedupe.mjs:5"}, "properties": {"repobilityId": "1b471959e707a20e", "scanner": "scanner-primary", "fingerprint": "c79f72416bf06785", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-bc0da5296c186250", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/news/merge-curated.mjs:88"}, "properties": {"repobilityId": "185b7ca534104af0", "scanner": "scanner-primary", "fingerprint": "bc0da5296c186250", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-cee7e5fce104959a", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/news/prune-curated.mjs:8"}, "properties": {"repobilityId": "9cce647d7d8b4951", "scanner": "scanner-primary", "fingerprint": "cee7e5fce104959a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-dbbfd2fc8ea03621", "level": "none", "message": {"text": "Commented-code block (5 lines) in scripts/news/curators/routine.mjs:1"}, "properties": {"repobilityId": "3dd37023aec0fa9a", "scanner": "scanner-primary", "fingerprint": "dbbfd2fc8ea03621", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-428b5931d424e189", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 media/lib/smplr/index.mjs:51"}, "properties": {"repobilityId": "5d4261f3705c4660", "scanner": "scanner-primary", "fingerprint": "428b5931d424e189", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-9a32bfb842746a02", "level": "none", "message": {"text": "Commented-code block (5 lines) in mock-ig/reel-mock.mjs:1"}, "properties": {"repobilityId": "21983827538fa1de", "scanner": "scanner-primary", "fingerprint": "9a32bfb842746a02", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-557a12a65bbdacf1", "level": "none", "message": {"text": "Commented-code block (5 lines) in mock-ig/curation-runs.mjs:8"}, "properties": {"repobilityId": "ff1a6c6c4de02988", "scanner": "scanner-primary", "fingerprint": "557a12a65bbdacf1", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d77e5a0dfa537afb", "level": "none", "message": {"text": "Commented-code block (5 lines) in mock-ig/curation.mjs:8"}, "properties": {"repobilityId": "756d6255951bc19a", "scanner": "scanner-primary", "fingerprint": "d77e5a0dfa537afb", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c9142d0bcea11473", "level": "none", "message": {"text": "Commented-code block (6 lines) in mock-ig/server.mjs:7"}, "properties": {"repobilityId": "359c88d5df76a8db", "scanner": "scanner-primary", "fingerprint": "c9142d0bcea11473", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1dd8e6972314ccbf", "level": "none", "message": {"text": "Commented-code block (6 lines) in mock-ig/story-mock.mjs:1"}, "properties": {"repobilityId": "047d980d639bd31d", "scanner": "scanner-primary", "fingerprint": "1dd8e6972314ccbf", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8cbd4a1b421a1f29", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 mock-ig/mock.test.mjs:25"}, "properties": {"repobilityId": "47366c827293c4b3", "scanner": "scanner-primary", "fingerprint": "8cbd4a1b421a1f29", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-6bd1177d52cf60df", "level": "none", "message": {"text": "Commented-code block (5 lines) in mock-ig/preview.mjs:4"}, "properties": {"repobilityId": "a8a5ba45c687f74c", "scanner": "scanner-primary", "fingerprint": "6bd1177d52cf60df", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2bd2e7d1b861e62d", "level": "none", "message": {"text": "Commented-code block (6 lines) in mock-ig/run.mjs:1"}, "properties": {"repobilityId": "539c70966450d0b1", "scanner": "scanner-primary", "fingerprint": "2bd2e7d1b861e62d", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e898bf19b565c764", "level": "none", "message": {"text": "Commented-code block (5 lines) in mock-ig/store.mjs:19"}, "properties": {"repobilityId": "c541269e93bd33cf", "scanner": "scanner-primary", "fingerprint": "e898bf19b565c764", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4c4031960f9c85f3", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 mock-ig/web/src/api.js:5"}, "properties": {"repobilityId": "f2598a4c05a6df9d", "scanner": "scanner-primary", "fingerprint": "4c4031960f9c85f3", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-582fe0f9d3f12230", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 mock-ig/web/src/components/CurationLab.jsx:12"}, "properties": {"repobilityId": "69f1fb56bfa95088", "scanner": "scanner-primary", "fingerprint": "582fe0f9d3f12230", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-3194563b284ea910", "level": "none", "message": {"text": "Commented-code block (5 lines) in mock-ig/web/src/components/CurationRunsLab.jsx:4"}, "properties": {"repobilityId": "e8e9d1ea4763ae78", "scanner": "scanner-primary", "fingerprint": "3194563b284ea910", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8a560d1d1d1f9475", "level": "none", "message": {"text": "Commented-code block (6 lines) in cloudflare-worker/reddit-proxy.js:6"}, "properties": {"repobilityId": "744f74c5aea34470", "scanner": "scanner-primary", "fingerprint": "8a560d1d1d1f9475", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4f385475f70d55d5", "level": "none", "message": {"text": "Commented-code block (5 lines) in cloudflare-worker/news-merge-dispatch.js:5"}, "properties": {"repobilityId": "90e1dc58fcccf8a2", "scanner": "scanner-primary", "fingerprint": "4f385475f70d55d5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-99b8f6ac6e45c957", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 cloudflare-worker/news-merge-dispatch.js:54"}, "properties": {"repobilityId": "c4f05a7e6950bc82", "scanner": "scanner-primary", "fingerprint": "99b8f6ac6e45c957", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-bb654812cd7fa3ae", "level": "error", "message": {"text": "FastAPI POST `create_bot_topic` without auth dependency \u2014 backend/app/routes/forum.py:173"}, "properties": {"repobilityId": "bc92bf180780396e", "scanner": "scanner-primary", "fingerprint": "bb654812cd7fa3ae", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/forum.py"}, "region": {"startLine": 173}}}]}, {"ruleId": "scanner-5f3201d98987b7ee", "level": "error", "message": {"text": "Dangling fetch: POST https://api.telegram.org/bot${TG_TOKEN}/sendMessage (scripts/publish/auto-merge-routine.mjs:198)"}, "properties": {"repobilityId": "d363ed30de41f9ce", "scanner": "scanner-primary", "fingerprint": "5f3201d98987b7ee", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-40d2fcdfdcc78071", "level": "error", "message": {"text": "Dangling fetch: POST https://api.telegram.org/bot${token}/sendMessage (scripts/publish/run-publish-reel.mjs:218)"}, "properties": {"repobilityId": "2e6864c17b1df909", "scanner": "scanner-primary", "fingerprint": "40d2fcdfdcc78071", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-e46de1a7dcc8ef16", "level": "error", "message": {"text": "Dangling fetch: POST https://api.telegram.org/bot${token}/sendMessage (scripts/publish/run-publish.mjs:439)"}, "properties": {"repobilityId": "6171aadc095b4583", "scanner": "scanner-primary", "fingerprint": "e46de1a7dcc8ef16", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-527866bcb89779b0", "level": "error", "message": {"text": "Dangling fetch: POST https://api.telegram.org/bot${token}/sendMessage (scripts/publish/run-publish-story.mjs:241)"}, "properties": {"repobilityId": "8462bbfd1fd24393", "scanner": "scanner-primary", "fingerprint": "527866bcb89779b0", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-2fe6f04df46dd606", "level": "error", "message": {"text": "Dangling fetch: POST https://api.telegram.org/bot${token}/sendMessage (scripts/news/community-fetch.mjs:376)"}, "properties": {"repobilityId": "36675d6e69500cbb", "scanner": "scanner-primary", "fingerprint": "2fe6f04df46dd606", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-7d5d8cd183f0fd78", "level": "error", "message": {"text": "Dangling fetch: GET /_mock/feed (mock-ig/web/src/api.js:5)"}, "properties": {"repobilityId": "32e7ee8d41b8f23c", "scanner": "scanner-primary", "fingerprint": "7d5d8cd183f0fd78", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-c5b855616d02f740", "level": "error", "message": {"text": "Dangling fetch: GET /_mock/stories (mock-ig/web/src/api.js:11)"}, "properties": {"repobilityId": "28e0987e04d754b7", "scanner": "scanner-primary", "fingerprint": "c5b855616d02f740", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-275bb4bb1bb56173", "level": "error", "message": {"text": "Dangling fetch: GET /_mock/reels (mock-ig/web/src/api.js:17)"}, "properties": {"repobilityId": "db599a27a3f7df51", "scanner": "scanner-primary", "fingerprint": "275bb4bb1bb56173", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-eb338da54a59da99", "level": "error", "message": {"text": "Dangling fetch: GET /_mock/usage (mock-ig/web/src/api.js:24)"}, "properties": {"repobilityId": "fea560106af881fa", "scanner": "scanner-primary", "fingerprint": "eb338da54a59da99", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-926a785903d4efe8", "level": "error", "message": {"text": "Dangling fetch: POST /_mock/reset (mock-ig/web/src/api.js:30)"}, "properties": {"repobilityId": "19921904c1f1fc46", "scanner": "scanner-primary", "fingerprint": "926a785903d4efe8", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-97fcaf48624a84c6", "level": "error", "message": {"text": "Dangling fetch: POST /_mock/delete (mock-ig/web/src/api.js:37)"}, "properties": {"repobilityId": "0908a17a3a0d06a1", "scanner": "scanner-primary", "fingerprint": "97fcaf48624a84c6", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-bec9b6db14bf1cb5", "level": "error", "message": {"text": "Dangling fetch: GET /_mock/control (mock-ig/web/src/api.js:44)"}, "properties": {"repobilityId": "6fd78b28257a8e86", "scanner": "scanner-primary", "fingerprint": "bec9b6db14bf1cb5", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-687adfffa0406090", "level": "error", "message": {"text": "Dangling fetch: POST /_mock/fail (mock-ig/web/src/api.js:52)"}, "properties": {"repobilityId": "adea1d6daaff377d", "scanner": "scanner-primary", "fingerprint": "687adfffa0406090", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-62e087b0446e8b7c", "level": "error", "message": {"text": "Dangling fetch: POST /_mock/sync (mock-ig/web/src/api.js:60)"}, "properties": {"repobilityId": "98cc2386b886f59b", "scanner": "scanner-primary", "fingerprint": "62e087b0446e8b7c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-1c553442abc56067", "level": "error", "message": {"text": "Dangling fetch: GET /_mock/curation (mock-ig/web/src/api.js:75)"}, "properties": {"repobilityId": "cdc3df43af36a922", "scanner": "scanner-primary", "fingerprint": "1c553442abc56067", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-3bfab86fbf9d67bb", "level": "error", "message": {"text": "Dangling fetch: GET /_mock/curation-runs (mock-ig/web/src/api.js:82)"}, "properties": {"repobilityId": "c58e9b25bdcd0367", "scanner": "scanner-primary", "fingerprint": "3bfab86fbf9d67bb", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-87205930268c920b", "level": "error", "message": {"text": "Dangling fetch: POST /_mock/curation-run (mock-ig/web/src/api.js:90)"}, "properties": {"repobilityId": "0c9574d879170caa", "scanner": "scanner-primary", "fingerprint": "87205930268c920b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-5ec7cfb154e0b003", "level": "error", "message": {"text": "Dangling fetch: GET /_mock/candidates (mock-ig/web/src/api.js:98)"}, "properties": {"repobilityId": "ab913bc1c6841227", "scanner": "scanner-primary", "fingerprint": "5ec7cfb154e0b003", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-9a06dcb6bd78c9c9", "level": "error", "message": {"text": "Dangling fetch: POST /_mock/preview (mock-ig/web/src/api.js:105)"}, "properties": {"repobilityId": "deb938452714db2d", "scanner": "scanner-primary", "fingerprint": "9a06dcb6bd78c9c9", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-bbc21317082135af", "level": "error", "message": {"text": "Dangling fetch: GET /_mock/runs (mock-ig/web/src/api.js:113)"}, "properties": {"repobilityId": "79122096bba7267a", "scanner": "scanner-primary", "fingerprint": "bbc21317082135af", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-48791e9fe121c7fd", "level": "error", "message": {"text": "Dangling fetch: POST /_mock/run (mock-ig/web/src/api.js:121)"}, "properties": {"repobilityId": "ac6f8039642f8682", "scanner": "scanner-primary", "fingerprint": "48791e9fe121c7fd", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-bc30b43ed0f83228", "level": "error", "message": {"text": "Dangling fetch: POST https://api.github.com/gists (cloudflare-worker/news-merge-dispatch.js:107)"}, "properties": {"repobilityId": "7095063d146dc083", "scanner": "scanner-primary", "fingerprint": "bc30b43ed0f83228", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-916a61a897b44216", "level": "error", "message": {"text": "Dangling fetch: POST https://api.github.com/repos/${REPO_OWNER}/${REPO_NAME}/dispatches (cloudflare-worker/news-merge-dispatch.js:138)"}, "properties": {"repobilityId": "2709adb26e14c8f4", "scanner": "scanner-primary", "fingerprint": "916a61a897b44216", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "9a7ab29051c0367b", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6195d9c0f56c4cb6", "level": "note", "message": {"text": "Unused endpoint: GET /posts"}, "properties": {"repobilityId": "8c95aaadf2725541", "scanner": "scanner-primary", "fingerprint": "6195d9c0f56c4cb6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d38eae0b19ee450e", "level": "note", "message": {"text": "Unused endpoint: POST /posts"}, "properties": {"repobilityId": "e1396cce498fa176", "scanner": "scanner-primary", "fingerprint": "d38eae0b19ee450e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fbf647c887b96333", "level": "note", "message": {"text": "Unused endpoint: GET /posts/{post_id}"}, "properties": {"repobilityId": "6d8b4b4be684ef24", "scanner": "scanner-primary", "fingerprint": "fbf647c887b96333", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-584d341ef931d66e", "level": "note", "message": {"text": "Unused endpoint: POST /posts/{post_id}/likes"}, "properties": {"repobilityId": "abe396d150562250", "scanner": "scanner-primary", "fingerprint": "584d341ef931d66e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-505c45a4790f795f", "level": "note", "message": {"text": "Unused endpoint: POST /posts/{post_id}/comments"}, "properties": {"repobilityId": "db073732f337ee32", "scanner": "scanner-primary", "fingerprint": "505c45a4790f795f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-855ced39c3f8d63b", "level": "note", "message": {"text": "Unused endpoint: DELETE /comments/{comment_id}"}, "properties": {"repobilityId": "d90d013940514be8", "scanner": "scanner-primary", "fingerprint": "855ced39c3f8d63b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-42819fbd220a7e59", "level": "note", "message": {"text": "Unused endpoint: GET /auth/google/login"}, "properties": {"repobilityId": "48a35c12bf45d8c5", "scanner": "scanner-primary", "fingerprint": "42819fbd220a7e59", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-392dcbd9c0e4ed85", "level": "note", "message": {"text": "Unused endpoint: GET /auth/google/callback"}, "properties": {"repobilityId": "8193182dfb4e6279", "scanner": "scanner-primary", "fingerprint": "392dcbd9c0e4ed85", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ac42422b23e45104", "level": "note", "message": {"text": "Unused endpoint: GET /auth/me"}, "properties": {"repobilityId": "aa5bcdf3efdd6979", "scanner": "scanner-primary", "fingerprint": "ac42422b23e45104", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4982dbfd71045a81", "level": "note", "message": {"text": "Unused endpoint: GET /topics"}, "properties": {"repobilityId": "d6f2c293dabaa992", "scanner": "scanner-primary", "fingerprint": "4982dbfd71045a81", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-95d0619d95e761f1", "level": "note", "message": {"text": "Unused endpoint: POST /topics"}, "properties": {"repobilityId": "547d54e91a6355c8", "scanner": "scanner-primary", "fingerprint": "95d0619d95e761f1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cf92765437224a68", "level": "note", "message": {"text": "Unused endpoint: POST /bot/topics"}, "properties": {"repobilityId": "4f70413e92f9d0cf", "scanner": "scanner-primary", "fingerprint": "cf92765437224a68", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-42cc14ffa628f535", "level": "note", "message": {"text": "Unused endpoint: GET /topics/{topic_id}"}, "properties": {"repobilityId": "a861e3ecb9a3f5d4", "scanner": "scanner-primary", "fingerprint": "42cc14ffa628f535", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d18411a066b7e2c1", "level": "note", "message": {"text": "Unused endpoint: GET /users/{user_id}"}, "properties": {"repobilityId": "6a55fe02bbcc7d18", "scanner": "scanner-primary", "fingerprint": "d18411a066b7e2c1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9f06644688cd47af", "level": "note", "message": {"text": "Unused endpoint: PATCH /users/me"}, "properties": {"repobilityId": "b0f145c842e81bad", "scanner": "scanner-primary", "fingerprint": "9f06644688cd47af", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ebaa440022985b81", "level": "note", "message": {"text": "Unused endpoint: GET /users/{user_id}/badges"}, "properties": {"repobilityId": "ff5d7c570be1fd77", "scanner": "scanner-primary", "fingerprint": "ebaa440022985b81", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a36976a4f4d61485", "level": "note", "message": {"text": "Unused endpoint: POST /topics/{topic_id}/posts"}, "properties": {"repobilityId": "d5e348678d3481f1", "scanner": "scanner-primary", "fingerprint": "a36976a4f4d61485", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0a748f8fca5af135", "level": "note", "message": {"text": "Unused endpoint: POST /reactions"}, "properties": {"repobilityId": "8dba014df0214897", "scanner": "scanner-primary", "fingerprint": "0a748f8fca5af135", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7685e59e2ca19804", "level": "note", "message": {"text": "Unused endpoint: DELETE /posts/{post_id}"}, "properties": {"repobilityId": "58cacab3bdb5aefd", "scanner": "scanner-primary", "fingerprint": "7685e59e2ca19804", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5459c68575e53a0c", "level": "note", "message": {"text": "Unused endpoint: DELETE /topics/{topic_id}"}, "properties": {"repobilityId": "4319bc29bc4a82f9", "scanner": "scanner-primary", "fingerprint": "5459c68575e53a0c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dce97aeb1712ef80", "level": "note", "message": {"text": "Unused endpoint: POST /reports"}, "properties": {"repobilityId": "93a21c44dd34ad77", "scanner": "scanner-primary", "fingerprint": "dce97aeb1712ef80", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}