{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-daffa53e5df18fb2", "name": "Stray `console.log` in TS/JS \u2014 tests/helpers/websocket-client.ts:40", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/helpers/websocket-client.ts:40"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b26294d91b5ec62c", "name": "Stray `console.log` in TS/JS \u2014 tests/e2e/byop-happy-path.test.ts:59", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e/byop-happy-path.test.ts:59"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-82e4fa2ab6479781", "name": "Stray `console.log` in TS/JS \u2014 scripts/deploy.ts:123", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/deploy.ts:123"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-64a8958e6a27fb59", "name": "Stray `console.log` in TS/JS \u2014 scripts/undeploy.ts:95", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/undeploy.ts:95"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5e3a8997a73a816d", "name": "Stray `console.log` in TS/JS \u2014 scripts/copy-landing-pages.ts:42", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/copy-landing-pages.ts:42"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c33c7881107b5f2a", "name": "Stray `console.log` in TS/JS \u2014 scripts/setup.ts:63", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/setup.ts:63"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f9318a061b0be6ed", "name": "TODO/FIXME marker in shipping code \u2014 worker/types/secretsTemplates.ts:189", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 worker/types/secretsTemplates.ts:189"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7706818613e6142e", "name": "Stray `console.log` in TS/JS \u2014 worker/middleware/auth/routeAuth.ts:74", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/middleware/auth/routeAuth.ts:74"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ca84bc0d4c0147a9", "name": "Stray `console.log` in TS/JS \u2014 worker/api/controllers/modelConfig/byokHelper.ts:128", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/api/controllers/modelConfig/byokHelper.ts:128"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-19f45ffe40b6dd76", "name": "TODO/FIXME marker in shipping code \u2014 worker/database/services/AuthService.ts:590", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 worker/database/services/AuthService.ts:590"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-790890ada55d38aa", "name": "TODO/FIXME marker in shipping code \u2014 worker/agents/prompts.ts:1366", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 worker/agents/prompts.ts:1366"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2893918cfd6c4a19", "name": "Stray `console.log` in TS/JS \u2014 worker/agents/prompts.ts:913", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/agents/prompts.ts:913"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f56b00ac6f8af067", "name": "Stray `console.log` in TS/JS \u2014 worker/agents/utils/templateCustomizer.ts:106", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/agents/utils/templateCustomizer.ts:106"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1d9c378022cfddd2", "name": "Stray `console.log` in TS/JS \u2014 worker/agents/assistants/realtimeCodeFixer.ts:541", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/agents/assistants/realtimeCodeFixer.ts:541"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6c34d4887bce5dd4", "name": "Stray `console.log` in TS/JS \u2014 worker/agents/inferutils/infer.ts:139", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/agents/inferutils/infer.ts:139"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-532a04fe1858ecc8", "name": "Stray `console.log` in TS/JS \u2014 worker/agents/inferutils/schemaFormatters.ts:725", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/agents/inferutils/schemaFormatters.ts:725"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-61b34151018c75cf", "name": "Stray `console.log` in TS/JS \u2014 worker/agents/inferutils/core.ts:57", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/agents/inferutils/core.ts:57"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4e3446b6d64c43b9", "name": "Stray `console.log` in TS/JS \u2014 worker/agents/services/implementations/FileManager.ts:48", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/agents/services/implementations/FileManager.ts:48"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-caa33f2e09faa03b", "name": "TODO/FIXME marker in shipping code \u2014 worker/agents/core/smartGeneratorAgent.ts:38", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 worker/agents/core/smartGeneratorAgent.ts:38"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-84cbeb03c9ff1f67", "name": "Stray `console.log` in TS/JS \u2014 worker/agents/output-formats/streaming-formats/scof.test.ts:32", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/agents/output-formats/streaming-formats/scof.test.ts:32"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e5403d02d2f1707c", "name": "Stray `console.log` in TS/JS \u2014 worker/agents/output-formats/streaming-formats/scof-comprehensive.test.ts:41", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/agents/output-formats/streaming-formats/scof-comprehensive.test.ts:41"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-85d120b82ae5bc1b", "name": "Stray `console.log` in TS/JS \u2014 worker/agents/output-formats/diff-formats/udiff.test.ts:52", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/agents/output-formats/diff-formats/udiff.test.ts:52"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b2f5399421f0b23e", "name": "Stray `console.log` in TS/JS \u2014 worker/agents/output-formats/diff-formats/search-replace.test.ts:7", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/agents/output-formats/diff-formats/search-replace.test.ts:7"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b3cf3a3819f0368e", "name": "TODO/FIXME marker in shipping code \u2014 worker/agents/output-formats/diff-formats/udiff-comprehensive.test.ts:513", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 worker/agents/output-formats/diff-formats/udiff-comprehensive.test.ts:513"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-15e3bc00058c8816", "name": "Stray `console.log` in TS/JS \u2014 worker/agents/planning/blueprint.ts:343", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/agents/planning/blueprint.ts:343"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-866535c4c51b6c92", "name": "TODO/FIXME marker in shipping code \u2014 worker/services/code-fixer/fixers/ts2304.ts:266", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 worker/services/code-fixer/fixers/ts2304.ts:266"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ba2c69838cd0ffd1", "name": "Stray `console.log` in TS/JS \u2014 worker/services/sandbox/sandboxSdkClient.ts:111", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/services/sandbox/sandboxSdkClient.ts:111"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-384741177fa478d7", "name": "Stray `console.log` in TS/JS \u2014 worker/services/sandbox/factory.ts:8", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/services/sandbox/factory.ts:8"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2884d86b0096f2ee", "name": "TODO/FIXME marker in shipping code \u2014 worker/services/analysis/CodeAnalysisService.ts:25", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 worker/services/analysis/CodeAnalysisService.ts:25"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3cf75711bb1c2f9e", "name": "Stray `console.log` in TS/JS \u2014 worker/services/deployer/api/cloudflare-api.ts:188", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/services/deployer/api/cloudflare-api.ts:188"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b984e6eb7e76a39a", "name": "Stray `console.log` in TS/JS \u2014 worker/services/aigateway-proxy/controller.ts:11", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 worker/services/aigateway-proxy/controller.ts:11"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9d3fca431d46c638", "name": "Stray `console.log` in TS/JS \u2014 container/process-monitor.ts:418", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 container/process-monitor.ts:418"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-08982ae27af08089", "name": "Stray `console.log` in TS/JS \u2014 container/cli-tools.ts:119", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 container/cli-tools.ts:119"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3875c25029568dd9", "name": "Stray `console.log` in TS/JS \u2014 container/monitor-cli.test.ts:46", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 container/monitor-cli.test.ts:46"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-94522e0db2cbfb3c", "name": "Stray `console.log` in TS/JS \u2014 src/utils/screenshot.ts:208", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/utils/screenshot.ts:208"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e2e4b14aa96a1177", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/image-attachment-preview.tsx:52", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/image-attachment-preview.tsx:52"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2108f3dc50e57438", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/config-card.tsx:198", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/config-card.tsx:198"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-441a8693e61af419", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/layout/app-sidebar.tsx:124", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/layout/app-sidebar.tsx:124"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-911cb1a6d68147d0", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/layout/global-header.tsx:72", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/layout/global-header.tsx:72"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e7253eb8e41b61de", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/shared/AppCard.tsx:284", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/shared/AppCard.tsx:284"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6f763ecd975b7d29", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/ui/model-selector.tsx:193", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/ui/model-selector.tsx:193"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9464c9f335979a74", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/byop/GitHubRepositoryList.tsx:211", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/byop/GitHubRepositoryList.tsx:211"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-dbfbf747508239ab", "name": "Stray `console.log` in TS/JS \u2014 src/contexts/limits-context.tsx:72", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/contexts/limits-context.tsx:72"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c577488129098711", "name": "Stray `console.log` in TS/JS \u2014 src/lib/api-client.ts:389", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/lib/api-client.ts:389"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-faa06112a826b491", "name": "TODO/FIXME marker in shipping code \u2014 src/routes/home.tsx:42", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 src/routes/home.tsx:42"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-65eee19d76c33991", "name": "Stray `console.log` in TS/JS \u2014 src/routes/chat/utils/file-state-helpers.ts:58", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/routes/chat/utils/file-state-helpers.ts:58"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-54b488e5c5eed097", "name": "`truncate` class without `title=` for hover reveal \u2014 src/routes/chat/components/file-explorer.tsx:40", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/routes/chat/components/file-explorer.tsx:40"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-587c56cf5b976309", "name": "`truncate` class without `title=` for hover reveal \u2014 src/routes/chat/components/debug-panel.tsx:880", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/routes/chat/components/debug-panel.tsx:880"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2b0603add96d9b3d", "name": "Stray `console.log` in TS/JS \u2014 src/routes/chat/components/preview-iframe.tsx:72", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/routes/chat/components/preview-iframe.tsx:72"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a6879fc2f9da7367", "name": "`truncate` class without `title=` for hover reveal \u2014 src/routes/chat/components/phase-timeline.tsx:515", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/routes/chat/components/phase-timeline.tsx:515"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5dda5baf0c533af1", "name": "`truncate` class without `title=` for hover reveal \u2014 src/routes/app/index.tsx:949", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/routes/app/index.tsx:949"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-139c42f28ade1137", "name": "Stray `console.log` in TS/JS \u2014 src/hooks/use-byop.ts:88", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/hooks/use-byop.ts:88"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5dc380dc64294cb7", "name": "Stray `console.log` in TS/JS \u2014 src/features/app/index.ts:49", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/features/app/index.ts:49"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cbdde17da04841dd", "name": "Stray `console.log` in TS/JS \u2014 src/features/general/index.tsx:44", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/features/general/index.tsx:44"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a27c6be7295a63b0", "name": "Stray `console.log` in TS/JS \u2014 src/features/presentation/index.tsx:92", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/features/presentation/index.tsx:92"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b65bfe0ff91beb1c", "name": "`truncate` class without `title=` for hover reveal \u2014 src/features/presentation/components/PresentationPreview.tsx:169", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/presentation/components/PresentationPreview.tsx:169"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d960daa2776ac774", "name": "Stray `console.log` in TS/JS \u2014 debug-tools/test-ai-gateway-analytics.ts:662", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 debug-tools/test-ai-gateway-analytics.ts:662"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e97a933adab0e294", "name": "Insecure pattern 'node_child_process' in scripts/deploy.ts:16", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/deploy.ts:16"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-78ad42c213bebde5", "name": "Insecure pattern 'node_child_process' in scripts/undeploy.ts:21", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/undeploy.ts:21"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4e5cfb552a27e762", "name": "Insecure pattern 'node_child_process' in scripts/setup.ts:3", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/setup.ts:3"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-452e8cf9be27d924", "name": "Insecure pattern 'cors_wildcard' in worker/api/controllers/screenshots/controller.ts:172", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in worker/api/controllers/screenshots/controller.ts:172"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8f401f235745b5ff", "name": "Insecure pattern 'cors_wildcard' in worker/agents/core/codingAgent.ts:800", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in worker/agents/core/codingAgent.ts:800"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0cc410e25ffffb4b", "name": "Insecure pattern 'node_child_process' in container/process-monitor.ts:2", "shortDescription": {"text": "Insecure pattern 'node_child_process' in container/process-monitor.ts:2"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-25e154d41d8dba4d", "name": "Insecure pattern 'exec_used' in container/bun-sqlite.d.ts:14", "shortDescription": {"text": "Insecure pattern 'exec_used' in container/bun-sqlite.d.ts:14"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6fc26c9857519a91", "name": "Insecure pattern 'node_child_process' in container/monitor-cli.test.ts:5", "shortDescription": {"text": "Insecure pattern 'node_child_process' in container/monitor-cli.test.ts:5"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e389f4af196fb8dc", "name": "Possible secret in src/components/auth/login-modal.tsx", "shortDescription": {"text": "Possible secret in src/components/auth/login-modal.tsx"}, "fullDescription": {"text": "Detected pattern matching password_literal. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-73cac6004da3ba33", "name": "Insecure pattern 'local_storage_auth_token' in src/lib/api-client.ts:266", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in src/lib/api-client.ts:266"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-65c561827a3f3d93", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1d988a919dff22ba", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-28c4a04bd807da0c", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-27924aa79fa4a517", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-26b9b311e08cf9b3", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0a8684948b726644", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9cc0655987a97af2", "name": "Very large file: scripts/deploy.ts (2131 lines)", "shortDescription": {"text": "Very large file: scripts/deploy.ts (2131 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b04992e15589bde0", "name": "Very large file: scripts/setup.ts (2121 lines)", "shortDescription": {"text": "Very large file: scripts/setup.ts (2121 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-196b806a3bb262d3", "name": "Very large file: worker/agents/prompts.ts (1502 lines)", "shortDescription": {"text": "Very large file: worker/agents/prompts.ts (1502 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cafe4da8d3aae386", "name": "Very large file: worker/agents/inferutils/schemaFormatters.ts (1311 lines)", "shortDescription": {"text": "Very large file: worker/agents/inferutils/schemaFormatters.ts (1311 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6d0e1ec0d57b212f", "name": "Very large file: worker/agents/core/simpleGeneratorAgent.ts (2863 lines)", "shortDescription": {"text": "Very large file: worker/agents/core/simpleGeneratorAgent.ts (2863 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a332ff368b948a83", "name": "Very large file: worker/agents/core/behaviors/base.ts (2398 lines)", "shortDescription": {"text": "Very large file: worker/agents/core/behaviors/base.ts (2398 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5896b6d3b21a2338", "name": "Very large file: worker/services/sandbox/sandboxSdkClient.ts (2919 lines)", "shortDescription": {"text": "Very large file: worker/services/sandbox/sandboxSdkClient.ts (2919 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-676477bb83db1a0d", "name": "Very large file: container/monitor-cli.test.ts (3052 lines)", "shortDescription": {"text": "Very large file: container/monitor-cli.test.ts (3052 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8ef8053939e60cf6", "name": "Very large file: src/routes/settings/index.tsx (1834 lines)", "shortDescription": {"text": "Very large file: src/routes/settings/index.tsx (1834 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7213b6460487be67", "name": "Very large file: src/routes/chat/components/debug-panel.tsx (1099 lines)", "shortDescription": {"text": "Very large file: src/routes/chat/components/debug-panel.tsx (1099 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "32 test file(s) for 469 source file(s) (ratio 0.07). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c7659ce6e2b0e01f", "name": "40 TODO/FIXME markers", "shortDescription": {"text": "40 TODO/FIXME markers"}, "fullDescription": {"text": "High count of TODO/FIXME/HACK markers \u2014 track them as issues so they're not forgotten."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bed23407a409157d", "name": "Node manifest has dependencies but no lockfile: container/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: container/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 777 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 193 placeholder/mock markers across 53 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing lockfile. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-478734530777971a", "name": "Commented-code block (5 lines) in vite.config.ts:18", "shortDescription": {"text": "Commented-code block (5 lines) in vite.config.ts:18"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a0cb745fd34cebe1", "name": "Commented-code block (5 lines) in worker-secrets.d.ts:107", "shortDescription": {"text": "Commented-code block (5 lines) in worker-secrets.d.ts:107"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5eb9522e8f6f1530", "name": "Commented-code block (6 lines) in drizzle.config.remote.ts:6", "shortDescription": {"text": "Commented-code block (6 lines) in drizzle.config.remote.ts:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5c0c4674518104e0", "name": "Commented-code block (6 lines) in drizzle.config.local.ts:6", "shortDescription": {"text": "Commented-code block (6 lines) in drizzle.config.local.ts:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f1414c3634019472", "name": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/copy-landing-pages.ts:19", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/copy-landing-pages.ts:19"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-77400a26c84ab59a", "name": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/setup.ts:692", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/setup.ts:692"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0dfe07e59be37b31", "name": "Commented-code block (7 lines) in worker/index.ts:221", "shortDescription": {"text": "Commented-code block (7 lines) in worker/index.ts:221"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-463f107c33a44e82", "name": "`fetch()` without try/.catch or AbortSignal \u2014 worker/index.ts:111", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/index.ts:111"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f4f70b98bafbeb40", "name": "Commented-code block (6 lines) in worker/app.ts:34", "shortDescription": {"text": "Commented-code block (6 lines) in worker/app.ts:34"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4a3b29b039525cfb", "name": "`fetch()` without try/.catch or AbortSignal \u2014 worker/app.ts:129", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/app.ts:129"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2e06af67eff6e159", "name": "Commented-code block (9 lines) in worker/api/websocketTypes.ts:386", "shortDescription": {"text": "Commented-code block (9 lines) in worker/api/websocketTypes.ts:386"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e1e157a6c3d5646b", "name": "Commented-code block (5 lines) in worker/api/routes/imagesRoutes.ts:15", "shortDescription": {"text": "Commented-code block (5 lines) in worker/api/routes/imagesRoutes.ts:15"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-04d16fa7e7909102", "name": "`fetch()` without try/.catch or AbortSignal \u2014 worker/api/routes/byopRoutes.ts:66", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/api/routes/byopRoutes.ts:66"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-14b156d70f1e4afb", "name": "`fetch()` without try/.catch or AbortSignal \u2014 worker/api/controllers/sentry/tunnelController.ts:66", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/api/controllers/sentry/tunnelController.ts:66"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fd96f7f9ccc71bab", "name": "Commented-code block (6 lines) in worker/api/controllers/agent/controller.ts:134", "shortDescription": {"text": "Commented-code block (6 lines) in worker/api/controllers/agent/controller.ts:134"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ffba49218ffbe36b", "name": "`fetch()` without try/.catch or AbortSignal \u2014 worker/api/controllers/agent/controller.ts:286", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/api/controllers/agent/controller.ts:286"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-baf4d5f81a696acf", "name": "Commented-code block (10 lines) in worker/api/controllers/screenshots/controller.ts:52", "shortDescription": {"text": "Commented-code block (10 lines) in worker/api/controllers/screenshots/controller.ts:52"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0946ae073ba824cb", "name": "`fetch()` without try/.catch or AbortSignal \u2014 worker/api/controllers/byop/controller.ts:366", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/api/controllers/byop/controller.ts:366"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7568848ad52acb78", "name": "Commented-code block (5 lines) in worker/api/controllers/appView/controller.ts:116", "shortDescription": {"text": "Commented-code block (5 lines) in worker/api/controllers/appView/controller.ts:116"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1a61737afd4af148", "name": "Commented-code block (6 lines) in worker/api/controllers/appView/types.ts:41", "shortDescription": {"text": "Commented-code block (6 lines) in worker/api/controllers/appView/types.ts:41"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6da1e6dde057805d", "name": "`fetch()` without try/.catch or AbortSignal \u2014 worker/utils/images.ts:112", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/utils/images.ts:112"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c525423ee8cfc394", "name": "Commented-code block (5 lines) in worker/observability/sentry.ts:34", "shortDescription": {"text": "Commented-code block (5 lines) in worker/observability/sentry.ts:34"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-64cf2e4805335182", "name": "Commented-code block (5 lines) in worker/agents/prompts.ts:1285", "shortDescription": {"text": "Commented-code block (5 lines) in worker/agents/prompts.ts:1285"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2cf2785742d552cc", "name": "`fetch()` without try/.catch or AbortSignal \u2014 worker/agents/prompts.ts:566", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/agents/prompts.ts:566"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ee37f36e301972eb", "name": "Commented-code block (6 lines) in worker/agents/constants.ts:78", "shortDescription": {"text": "Commented-code block (6 lines) in worker/agents/constants.ts:78"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d00b2925f1b6178c", "name": "Commented-code block (17 lines) in worker/agents/operations/PhaseImplementation.ts:304", "shortDescription": {"text": "Commented-code block (17 lines) in worker/agents/operations/PhaseImplementation.ts:304"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3710a4dd2660c84f", "name": "Commented-code block (6 lines) in worker/agents/operations/ImageGeneration.ts:78", "shortDescription": {"text": "Commented-code block (6 lines) in worker/agents/operations/ImageGeneration.ts:78"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5c079bd69c233fd4", "name": "Commented-code block (6 lines) in worker/agents/operations/SimpleCodeGeneration.ts:10", "shortDescription": {"text": "Commented-code block (6 lines) in worker/agents/operations/SimpleCodeGeneration.ts:10"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-367f854f186d7cb5", "name": "Commented-code block (11 lines) in worker/agents/inferutils/config.ts:70", "shortDescription": {"text": "Commented-code block (11 lines) in worker/agents/inferutils/config.ts:70"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-47e2ca83c5821ef7", "name": "Commented-code block (6 lines) in worker/agents/inferutils/schemaFormatters.ts:54", "shortDescription": {"text": "Commented-code block (6 lines) in worker/agents/inferutils/schemaFormatters.ts:54"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d802c7dce1d99800", "name": "Commented-code block (6 lines) in worker/agents/inferutils/core.ts:178", "shortDescription": {"text": "Commented-code block (6 lines) in worker/agents/inferutils/core.ts:178"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1062749f2e3aa946", "name": "`fetch()` without try/.catch or AbortSignal \u2014 worker/agents/inferutils/imageGeneration.ts:144", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/agents/inferutils/imageGeneration.ts:144"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c509f11fafc0a727", "name": "Commented-code block (6 lines) in worker/agents/services/implementations/DeploymentManager.ts:108", "shortDescription": {"text": "Commented-code block (6 lines) in worker/agents/services/implementations/DeploymentManager.ts:108"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1eda569cd0842355", "name": "Commented-code block (5 lines) in worker/agents/core/codingAgent.ts:155", "shortDescription": {"text": "Commented-code block (5 lines) in worker/agents/core/codingAgent.ts:155"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f27507211fc99b08", "name": "Commented-code block (12 lines) in worker/agents/core/state.ts:171", "shortDescription": {"text": "Commented-code block (12 lines) in worker/agents/core/state.ts:171"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-63b3be3d821de9f4", "name": "Commented-code block (7 lines) in worker/agents/core/websocket.ts:227", "shortDescription": {"text": "Commented-code block (7 lines) in worker/agents/core/websocket.ts:227"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-03fcf2e2b0720169", "name": "Legacy-named symbol `stateWithDeprecated` in worker/agents/core/stateMigration.ts:273", "shortDescription": {"text": "Legacy-named symbol `stateWithDeprecated` in worker/agents/core/stateMigration.ts:273"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-91886f0db1e0759c", "name": "Commented-code block (5 lines) in worker/agents/core/stateMigration.ts:281", "shortDescription": {"text": "Commented-code block (5 lines) in worker/agents/core/stateMigration.ts:281"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cce0caf8b13c1b0e", "name": "Commented-code block (6 lines) in worker/agents/core/simpleGeneratorAgent.ts:154", "shortDescription": {"text": "Commented-code block (6 lines) in worker/agents/core/simpleGeneratorAgent.ts:154"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2820793b503d38ba", "name": "`fetch()` without try/.catch or AbortSignal \u2014 worker/agents/core/simpleGeneratorAgent.ts:2243", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/agents/core/simpleGeneratorAgent.ts:2243"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7c3d5ec1577a22c3", "name": "Commented-code block (5 lines) in worker/agents/core/behaviors/base.ts:516", "shortDescription": {"text": "Commented-code block (5 lines) in worker/agents/core/behaviors/base.ts:516"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-34d4c531b88f0e84", "name": "`fetch()` without try/.catch or AbortSignal \u2014 worker/agents/core/behaviors/base.ts:1772", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/agents/core/behaviors/base.ts:1772"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2c418cf1638573ed", "name": "Commented-code block (5 lines) in worker/agents/core/behaviors/agentic.ts:133", "shortDescription": {"text": "Commented-code block (5 lines) in worker/agents/core/behaviors/agentic.ts:133"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7f03383971e1eca8", "name": "Commented-code block (8 lines) in worker/agents/core/behaviors/phasic.ts:321", "shortDescription": {"text": "Commented-code block (8 lines) in worker/agents/core/behaviors/phasic.ts:321"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-57f75a32de48e1ac", "name": "Commented-code block (5 lines) in worker/agents/output-formats/streaming-formats/xml-stream.ts:161", "shortDescription": {"text": "Commented-code block (5 lines) in worker/agents/output-formats/streaming-formats/xml-stream.ts:161"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b06e37550f479d87", "name": "Commented-code block (5 lines) in worker/agents/output-formats/streaming-formats/base.ts:18", "shortDescription": {"text": "Commented-code block (5 lines) in worker/agents/output-formats/streaming-formats/base.ts:18"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c5201f1b9501a7cf", "name": "Commented-code block (7 lines) in worker/agents/output-formats/diff-formats/udiff-comprehensive.test.ts:509", "shortDescription": {"text": "Commented-code block (7 lines) in worker/agents/output-formats/diff-formats/udiff-comprehensive.test.ts:509"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8d84428e51a8b986", "name": "Commented-code block (6 lines) in worker/agents/prompts/designSkills.ts:97", "shortDescription": {"text": "Commented-code block (6 lines) in worker/agents/prompts/designSkills.ts:97"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-916351c80b93409e", "name": "Commented-code block (5 lines) in worker/agents/planning/blueprint.ts:341", "shortDescription": {"text": "Commented-code block (5 lines) in worker/agents/planning/blueprint.ts:341"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7f9e2c06c6376087", "name": "Commented-code block (6 lines) in worker/agents/domain/values/GenerationContext.ts:34", "shortDescription": {"text": "Commented-code block (6 lines) in worker/agents/domain/values/GenerationContext.ts:34"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-00b5383a5ad68213", "name": "Commented-code block (6 lines) in worker/services/code-fixer/index.ts:176", "shortDescription": {"text": "Commented-code block (6 lines) in worker/services/code-fixer/index.ts:176"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cbc17e807200077e", "name": "Commented-code block (6 lines) in worker/services/rate-limit/usageChecker.ts:287", "shortDescription": {"text": "Commented-code block (6 lines) in worker/services/rate-limit/usageChecker.ts:287"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a4a4716369c52c1c", "name": "`fetch()` without try/.catch or AbortSignal \u2014 worker/services/migration/cloudflare-compatibility-checker.ts:274", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/services/migration/cloudflare-compatibility-checker.ts:274"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4b740607ce1e7c6a", "name": "`fetch()` without try/.catch or AbortSignal \u2014 worker/services/oauth/github.ts:62", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/services/oauth/github.ts:62"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ffc43119d20cf1e2", "name": "`fetch()` without try/.catch or AbortSignal \u2014 worker/services/oauth/base.ts:99", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/services/oauth/base.ts:99"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b88fc7eee3a697fd", "name": "`fetch()` without try/.catch or AbortSignal \u2014 worker/services/sandbox/resourceProvisioner.ts:72", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/services/sandbox/resourceProvisioner.ts:72"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4bf3aa2638d69377", "name": "Commented-code block (7 lines) in worker/services/sandbox/sandboxSdkClient.ts:419", "shortDescription": {"text": "Commented-code block (7 lines) in worker/services/sandbox/sandboxSdkClient.ts:419"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b4a5c92fa2bb8b81", "name": "`fetch()` without try/.catch or AbortSignal \u2014 worker/services/sandbox/remoteSandboxService.ts:42", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/services/sandbox/remoteSandboxService.ts:42"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-53f4c1519dc4a5f6", "name": "Commented-code block (5 lines) in worker/services/sandbox/BaseSandboxService.ts:93", "shortDescription": {"text": "Commented-code block (5 lines) in worker/services/sandbox/BaseSandboxService.ts:93"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2db6b71f1d18df18", "name": "`fetch()` without try/.catch or AbortSignal \u2014 worker/services/deployer/api/cloudflare-api.ts:43", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/services/deployer/api/cloudflare-api.ts:43"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-40a11f5f447c1198", "name": "`fetch()` without try/.catch or AbortSignal \u2014 worker/services/aigateway-proxy/controller.ts:186", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/services/aigateway-proxy/controller.ts:186"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-52b18a38526c3534", "name": "`fetch()` without try/.catch or AbortSignal \u2014 container/monitor-cli.test.ts:2492", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 container/monitor-cli.test.ts:2492"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6f938c411f20d3d1", "name": "Commented-code block (6 lines) in src/App.tsx:11", "shortDescription": {"text": "Commented-code block (6 lines) in src/App.tsx:11"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-21744f79279183b2", "name": "Commented-code block (5 lines) in src/components/auth/login-modal.tsx:12", "shortDescription": {"text": "Commented-code block (5 lines) in src/components/auth/login-modal.tsx:12"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5eca11a143145372", "name": "Commented-code block (5 lines) in src/contexts/auth-context.tsx:145", "shortDescription": {"text": "Commented-code block (5 lines) in src/contexts/auth-context.tsx:145"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cf7202474f2a2fbf", "name": "Commented-code block (8 lines) in src/lib/api-client.ts:545", "shortDescription": {"text": "Commented-code block (8 lines) in src/lib/api-client.ts:545"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a31fe86961c9897e", "name": "Commented-code block (11 lines) in src/routes/settings/index.tsx:136", "shortDescription": {"text": "Commented-code block (11 lines) in src/routes/settings/index.tsx:136"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2bd421deb70f3512", "name": "Commented-code block (11 lines) in src/routes/chat/chat.tsx:247", "shortDescription": {"text": "Commented-code block (11 lines) in src/routes/chat/chat.tsx:247"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1e7f989b08e782db", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/routes/chat/mocks/file-mock.ts:223", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/routes/chat/mocks/file-mock.ts:223"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1ab1c967d0f22301", "name": "Commented-code block (7 lines) in src/routes/chat/utils/handle-websocket-message.ts:765", "shortDescription": {"text": "Commented-code block (7 lines) in src/routes/chat/utils/handle-websocket-message.ts:765"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7136d9163cecd930", "name": "Commented-code block (6 lines) in src/routes/chat/components/preview-iframe.tsx:216", "shortDescription": {"text": "Commented-code block (6 lines) in src/routes/chat/components/preview-iframe.tsx:216"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-001b3ff371d37af5", "name": "Commented-code block (13 lines) in src/routes/chat/hooks/use-chat.ts:6", "shortDescription": {"text": "Commented-code block (13 lines) in src/routes/chat/hooks/use-chat.ts:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-59db4a95ef32fef6", "name": "Commented-code block (6 lines) in src/routes/app/index.tsx:219", "shortDescription": {"text": "Commented-code block (6 lines) in src/routes/app/index.tsx:219"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7879703ff6ef75a4", "name": "Legacy-named symbol `ai_request_analyzer_v2` in debug-tools/ai_request_analyzer_v2.py:19", "shortDescription": {"text": "Legacy-named symbol `ai_request_analyzer_v2` in debug-tools/ai_request_analyzer_v2.py:19"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-207b1a4a15d4006b", "name": "`fetch()` without try/.catch or AbortSignal \u2014 debug-tools/test-ai-gateway-analytics.ts:563", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 debug-tools/test-ai-gateway-analytics.ts:563"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-49c98f7cedd9c977", "name": "Near-duplicate function bodies in 4 places", "shortDescription": {"text": "Near-duplicate function bodies in 4 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\ndebug-tools/ai_request_analyzer_v2.py:analyze, debug-tools/ai_request_analyzer_v2.py:analyze, debug-tools/ai_request_analyzer_v2.py:analyze, debug-tools/ai_request_analyzer_v2.py:analyze\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-325e8f5f7a1d76c9", "name": "Dangling fetch: GET http://example.com/api/byop/repositories (tests/integration/controllers/BYOPController.test.ts:35)", "shortDescription": {"text": "Dangling fetch: GET http://example.com/api/byop/repositories (tests/integration/controllers/BYOPController.test.ts:35)"}, "fullDescription": {"text": "`tests/integration/controllers/BYOPController.test.ts:35` calls `GET http://example.com/api/byop/repositories` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/repositories`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-332e543768642f74", "name": "Dangling fetch: GET http://example.com/api/byop/repositories (tests/integration/controllers/BYOPController.test.ts:57)", "shortDescription": {"text": "Dangling fetch: GET http://example.com/api/byop/repositories (tests/integration/controllers/BYOPController.test.ts:57)"}, "fullDescription": {"text": "`tests/integration/controllers/BYOPController.test.ts:57` calls `GET http://example.com/api/byop/repositories` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/repositories`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-34e719cf438b2cff", "name": "Dangling fetch: GET http://example.com/api/byop/repositories (tests/integration/controllers/BYOPController.test.ts:73)", "shortDescription": {"text": "Dangling fetch: GET http://example.com/api/byop/repositories (tests/integration/controllers/BYOPController.test.ts:73)"}, "fullDescription": {"text": "`tests/integration/controllers/BYOPController.test.ts:73` calls `GET http://example.com/api/byop/repositories` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/repositories`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-969db090a2af681f", "name": "Dangling fetch: GET http://example.com/api/byop/repositories (tests/integration/controllers/BYOPController.test.ts:96)", "shortDescription": {"text": "Dangling fetch: GET http://example.com/api/byop/repositories (tests/integration/controllers/BYOPController.test.ts:96)"}, "fullDescription": {"text": "`tests/integration/controllers/BYOPController.test.ts:96` calls `GET http://example.com/api/byop/repositories` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/repositories`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-61a21a29fa4ba623", "name": "Dangling fetch: GET http://example.com/api/byop/repositories (tests/integration/controllers/BYOPController.test.ts:114)", "shortDescription": {"text": "Dangling fetch: GET http://example.com/api/byop/repositories (tests/integration/controllers/BYOPController.test.ts:114)"}, "fullDescription": {"text": "`tests/integration/controllers/BYOPController.test.ts:114` calls `GET http://example.com/api/byop/repositories` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/repositories`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0d668978e22c087d", "name": "Dangling fetch: GET http://example.com/api/byop/repositories (tests/integration/controllers/BYOPController.test.ts:130)", "shortDescription": {"text": "Dangling fetch: GET http://example.com/api/byop/repositories (tests/integration/controllers/BYOPController.test.ts:130)"}, "fullDescription": {"text": "`tests/integration/controllers/BYOPController.test.ts:130` calls `GET http://example.com/api/byop/repositories` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/repositories`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b0d932777eed0425", "name": "Dangling fetch: POST http://example.com/api/byop/import (tests/integration/controllers/BYOPController.test.ts:149)", "shortDescription": {"text": "Dangling fetch: POST http://example.com/api/byop/import (tests/integration/controllers/BYOPController.test.ts:149)"}, "fullDescription": {"text": "`tests/integration/controllers/BYOPController.test.ts:149` calls `POST http://example.com/api/byop/import` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/import`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b3ff73257a9355f0", "name": "Dangling fetch: POST http://example.com/api/byop/import (tests/integration/controllers/BYOPController.test.ts:193)", "shortDescription": {"text": "Dangling fetch: POST http://example.com/api/byop/import (tests/integration/controllers/BYOPController.test.ts:193)"}, "fullDescription": {"text": "`tests/integration/controllers/BYOPController.test.ts:193` calls `POST http://example.com/api/byop/import` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/import`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-025347382519b90a", "name": "Dangling fetch: POST http://example.com/api/byop/import (tests/integration/controllers/BYOPController.test.ts:219)", "shortDescription": {"text": "Dangling fetch: POST http://example.com/api/byop/import (tests/integration/controllers/BYOPController.test.ts:219)"}, "fullDescription": {"text": "`tests/integration/controllers/BYOPController.test.ts:219` calls `POST http://example.com/api/byop/import` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/import`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d1e294b7cd931fe2", "name": "Dangling fetch: POST http://example.com/api/byop/import (tests/integration/controllers/BYOPController.test.ts:239)", "shortDescription": {"text": "Dangling fetch: POST http://example.com/api/byop/import (tests/integration/controllers/BYOPController.test.ts:239)"}, "fullDescription": {"text": "`tests/integration/controllers/BYOPController.test.ts:239` calls `POST http://example.com/api/byop/import` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/import`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-db6e1dd32ad47a50", "name": "Dangling fetch: POST http://example.com/api/byop/import (tests/integration/controllers/BYOPController.test.ts:257)", "shortDescription": {"text": "Dangling fetch: POST http://example.com/api/byop/import (tests/integration/controllers/BYOPController.test.ts:257)"}, "fullDescription": {"text": "`tests/integration/controllers/BYOPController.test.ts:257` calls `POST http://example.com/api/byop/import` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/import`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7f84ec73a132760f", "name": "Dangling fetch: POST http://example.com/api/byop/import (tests/integration/controllers/BYOPController.test.ts:280)", "shortDescription": {"text": "Dangling fetch: POST http://example.com/api/byop/import (tests/integration/controllers/BYOPController.test.ts:280)"}, "fullDescription": {"text": "`tests/integration/controllers/BYOPController.test.ts:280` calls `POST http://example.com/api/byop/import` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/import`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6744f97cb8da5c05", "name": "Dangling fetch: POST http://example.com/api/byop/import (tests/integration/controllers/BYOPController.test.ts:300)", "shortDescription": {"text": "Dangling fetch: POST http://example.com/api/byop/import (tests/integration/controllers/BYOPController.test.ts:300)"}, "fullDescription": {"text": "`tests/integration/controllers/BYOPController.test.ts:300` calls `POST http://example.com/api/byop/import` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/import`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-43b80d5444c9734b", "name": "Dangling fetch: POST http://example.com/api/byop/import (tests/integration/controllers/BYOPController.test.ts:327)", "shortDescription": {"text": "Dangling fetch: POST http://example.com/api/byop/import (tests/integration/controllers/BYOPController.test.ts:327)"}, "fullDescription": {"text": "`tests/integration/controllers/BYOPController.test.ts:327` calls `POST http://example.com/api/byop/import` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/import`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-655e7acdce53e86a", "name": "Dangling fetch: GET http://example.com/api/byop/analysis/${analysisId}/status (tests/integration/controllers/BYOPControl", "shortDescription": {"text": "Dangling fetch: GET http://example.com/api/byop/analysis/${analysisId}/status (tests/integration/controllers/BYOPController.test.ts:343)"}, "fullDescription": {"text": "`tests/integration/controllers/BYOPController.test.ts:343` calls `GET http://example.com/api/byop/analysis/${analysisId}/status` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/analysis/<p>/status`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dc94b606c3fdaf46", "name": "Dangling fetch: GET http://example.com/api/byop/analysis/invalid-id/status (tests/integration/controllers/BYOPController", "shortDescription": {"text": "Dangling fetch: GET http://example.com/api/byop/analysis/invalid-id/status (tests/integration/controllers/BYOPController.test.ts:366)"}, "fullDescription": {"text": "`tests/integration/controllers/BYOPController.test.ts:366` calls `GET http://example.com/api/byop/analysis/invalid-id/status` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/analysis/invalid-id/status`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-64890ab793cbd407", "name": "Dangling fetch: GET http://example.com/api/byop/analysis/some-id/status (tests/integration/controllers/BYOPController.te", "shortDescription": {"text": "Dangling fetch: GET http://example.com/api/byop/analysis/some-id/status (tests/integration/controllers/BYOPController.test.ts:380)"}, "fullDescription": {"text": "`tests/integration/controllers/BYOPController.test.ts:380` calls `GET http://example.com/api/byop/analysis/some-id/status` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/analysis/some-id/status`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5cc0c7c9e5a0ed8f", "name": "Dangling fetch: GET http://example.com/api/byop/analysis/${analysisId}/blueprint (tests/integration/controllers/BYOPCont", "shortDescription": {"text": "Dangling fetch: GET http://example.com/api/byop/analysis/${analysisId}/blueprint (tests/integration/controllers/BYOPController.test.ts:401)"}, "fullDescription": {"text": "`tests/integration/controllers/BYOPController.test.ts:401` calls `GET http://example.com/api/byop/analysis/${analysisId}/blueprint` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/analysis/<p>/blueprint`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-44173e4b438b8c5c", "name": "Dangling fetch: GET http://example.com/api/byop/analysis/${analysisId}/blueprint (tests/integration/controllers/BYOPCont", "shortDescription": {"text": "Dangling fetch: GET http://example.com/api/byop/analysis/${analysisId}/blueprint (tests/integration/controllers/BYOPController.test.ts:420)"}, "fullDescription": {"text": "`tests/integration/controllers/BYOPController.test.ts:420` calls `GET http://example.com/api/byop/analysis/${analysisId}/blueprint` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/analysis/<p>/blueprint`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-87814fe423d4ecb4", "name": "Dangling fetch: GET http://example.com/api/byop/analysis/${analysisId}/blueprint (tests/integration/controllers/BYOPCont", "shortDescription": {"text": "Dangling fetch: GET http://example.com/api/byop/analysis/${analysisId}/blueprint (tests/integration/controllers/BYOPController.test.ts:439)"}, "fullDescription": {"text": "`tests/integration/controllers/BYOPController.test.ts:439` calls `GET http://example.com/api/byop/analysis/${analysisId}/blueprint` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/analysis/<p>/blueprint`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6a9c92e8bd2fdd33", "name": "Dangling fetch: GET http://example.com/api/byop/analysis/${analysisId}/blueprint (tests/integration/controllers/BYOPCont", "shortDescription": {"text": "Dangling fetch: GET http://example.com/api/byop/analysis/${analysisId}/blueprint (tests/integration/controllers/BYOPController.test.ts:465)"}, "fullDescription": {"text": "`tests/integration/controllers/BYOPController.test.ts:465` calls `GET http://example.com/api/byop/analysis/${analysisId}/blueprint` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/analysis/<p>/blueprint`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-27f57aaf053f091e", "name": "Dangling fetch: GET http://example.com/api/byop/repositories (tests/e2e/byop-happy-path.test.ts:63)", "shortDescription": {"text": "Dangling fetch: GET http://example.com/api/byop/repositories (tests/e2e/byop-happy-path.test.ts:63)"}, "fullDescription": {"text": "`tests/e2e/byop-happy-path.test.ts:63` calls `GET http://example.com/api/byop/repositories` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/repositories`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-665a122b3cf85d9c", "name": "Dangling fetch: POST http://example.com/api/byop/import (tests/e2e/byop-happy-path.test.ts:88)", "shortDescription": {"text": "Dangling fetch: POST http://example.com/api/byop/import (tests/e2e/byop-happy-path.test.ts:88)"}, "fullDescription": {"text": "`tests/e2e/byop-happy-path.test.ts:88` calls `POST http://example.com/api/byop/import` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/import`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-67a8816015aa3ed2", "name": "Dangling fetch: GET http://example.com/api/byop/analysis/${analysisId}/status (tests/e2e/byop-happy-path.test.ts:160)", "shortDescription": {"text": "Dangling fetch: GET http://example.com/api/byop/analysis/${analysisId}/status (tests/e2e/byop-happy-path.test.ts:160)"}, "fullDescription": {"text": "`tests/e2e/byop-happy-path.test.ts:160` calls `GET http://example.com/api/byop/analysis/${analysisId}/status` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/analysis/<p>/status`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-082868c09e5cf98e", "name": "Dangling fetch: GET http://example.com/api/byop/analysis/${analysisId}/blueprint (tests/e2e/byop-happy-path.test.ts:189)", "shortDescription": {"text": "Dangling fetch: GET http://example.com/api/byop/analysis/${analysisId}/blueprint (tests/e2e/byop-happy-path.test.ts:189)"}, "fullDescription": {"text": "`tests/e2e/byop-happy-path.test.ts:189` calls `GET http://example.com/api/byop/analysis/${analysisId}/blueprint` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/analysis/<p>/blueprint`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-be1545c032bb1d05", "name": "Dangling fetch: POST http://example.com/api/byop/import (tests/e2e/byop-happy-path.test.ts:256)", "shortDescription": {"text": "Dangling fetch: POST http://example.com/api/byop/import (tests/e2e/byop-happy-path.test.ts:256)"}, "fullDescription": {"text": "`tests/e2e/byop-happy-path.test.ts:256` calls `POST http://example.com/api/byop/import` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/import`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bfb0b7748d510bf2", "name": "Dangling fetch: GET http://example.com/api/byop/analysis/${firstData.analysisId}/blueprint (tests/e2e/byop-happy-path.te", "shortDescription": {"text": "Dangling fetch: GET http://example.com/api/byop/analysis/${firstData.analysisId}/blueprint (tests/e2e/byop-happy-path.test.ts:282)"}, "fullDescription": {"text": "`tests/e2e/byop-happy-path.test.ts:282` calls `GET http://example.com/api/byop/analysis/${firstData.analysisId}/blueprint` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/analysis/<p>/blueprint`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e3302804c6e1b7d6", "name": "Dangling fetch: POST http://example.com/api/byop/import (tests/e2e/byop-happy-path.test.ts:297)", "shortDescription": {"text": "Dangling fetch: POST http://example.com/api/byop/import (tests/e2e/byop-happy-path.test.ts:297)"}, "fullDescription": {"text": "`tests/e2e/byop-happy-path.test.ts:297` calls `POST http://example.com/api/byop/import` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/example.com/api/byop/import`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e880300d9957e246", "name": "Dangling fetch: GET https://api.cloudflare.com/client/v4/user/tokens/verify (scripts/deploy.ts:424)", "shortDescription": {"text": "Dangling fetch: GET https://api.cloudflare.com/client/v4/user/tokens/verify (scripts/deploy.ts:424)"}, "fullDescription": {"text": "`scripts/deploy.ts:424` calls `GET https://api.cloudflare.com/client/v4/user/tokens/verify` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.cloudflare.com/client/v4/user/tokens/verify`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b498b356bf22a832", "name": "Dangling fetch: POST https://api.cloudflare.com/client/v4/user/tokens (scripts/deploy.ts:482)", "shortDescription": {"text": "Dangling fetch: POST https://api.cloudflare.com/client/v4/user/tokens (scripts/deploy.ts:482)"}, "fullDescription": {"text": "`scripts/deploy.ts:482` calls `POST https://api.cloudflare.com/client/v4/user/tokens` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.cloudflare.com/client/v4/user/tokens`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2f873bb2027e6426", "name": "Dangling fetch: GET https://api.cloudflare.com/client/v4/zones?name=${encodeURIComponent(zoneName)} (scripts/deploy.ts:8", "shortDescription": {"text": "Dangling fetch: GET https://api.cloudflare.com/client/v4/zones?name=${encodeURIComponent(zoneName)} (scripts/deploy.ts:856)"}, "fullDescription": {"text": "`scripts/deploy.ts:856` calls `GET https://api.cloudflare.com/client/v4/zones?name=${encodeURIComponent(zoneName)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.cloudflare.com/client/v4/zones`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3bb9deb249972d36", "name": "Dangling fetch: GET https://api.cloudflare.com/client/v4/accounts/${this.config.accountId}/storage/kv/namespaces (script", "shortDescription": {"text": "Dangling fetch: GET https://api.cloudflare.com/client/v4/accounts/${this.config.accountId}/storage/kv/namespaces (scripts/setup.ts:669)"}, "fullDescription": {"text": "`scripts/setup.ts:669` calls `GET https://api.cloudflare.com/client/v4/accounts/${this.config.accountId}/storage/kv/namespaces` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.cloudflare.com/client/v4/accounts/<p>/storage/kv/namespaces`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4fab352b9851d967", "name": "Dangling fetch: POST https://api.cloudflare.com/client/v4/accounts/${this.config.accountId}/storage/kv/namespaces (scrip", "shortDescription": {"text": "Dangling fetch: POST https://api.cloudflare.com/client/v4/accounts/${this.config.accountId}/storage/kv/namespaces (scripts/setup.ts:692)"}, "fullDescription": {"text": "`scripts/setup.ts:692` calls `POST https://api.cloudflare.com/client/v4/accounts/${this.config.accountId}/storage/kv/namespaces` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.cloudflare.com/client/v4/accounts/<p>/storage/kv/namespaces`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c31738605d2b2c28", "name": "Dangling fetch: GET https://api.cloudflare.com/client/v4/accounts/${this.config.accountId}/r2/buckets/${bucketName} (scr", "shortDescription": {"text": "Dangling fetch: GET https://api.cloudflare.com/client/v4/accounts/${this.config.accountId}/r2/buckets/${bucketName} (scripts/setup.ts:803)"}, "fullDescription": {"text": "`scripts/setup.ts:803` calls `GET https://api.cloudflare.com/client/v4/accounts/${this.config.accountId}/r2/buckets/${bucketName}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.cloudflare.com/client/v4/accounts/<p>/r2/buckets/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-355a7d2db148b0b1", "name": "Dangling fetch: POST https://api.cloudflare.com/client/v4/accounts/${this.config.accountId}/r2/buckets (scripts/setup.ts", "shortDescription": {"text": "Dangling fetch: POST https://api.cloudflare.com/client/v4/accounts/${this.config.accountId}/r2/buckets (scripts/setup.ts:820)"}, "fullDescription": {"text": "`scripts/setup.ts:820` calls `POST https://api.cloudflare.com/client/v4/accounts/${this.config.accountId}/r2/buckets` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.cloudflare.com/client/v4/accounts/<p>/r2/buckets`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ac64cc32cf0b5d7d", "name": "Dangling fetch: GET https://api.cloudflare.com/client/v4/user/tokens/verify (scripts/setup.ts:950)", "shortDescription": {"text": "Dangling fetch: GET https://api.cloudflare.com/client/v4/user/tokens/verify (scripts/setup.ts:950)"}, "fullDescription": {"text": "`scripts/setup.ts:950` calls `GET https://api.cloudflare.com/client/v4/user/tokens/verify` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.cloudflare.com/client/v4/user/tokens/verify`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f4821a82dd18dad5", "name": "Dangling fetch: GET https://api.cloudflare.com/client/v4/user/tokens/permission_groups?name=AI%20Gateway (scripts/setup.", "shortDescription": {"text": "Dangling fetch: GET https://api.cloudflare.com/client/v4/user/tokens/permission_groups?name=AI%20Gateway (scripts/setup.ts:971)"}, "fullDescription": {"text": "`scripts/setup.ts:971` calls `GET https://api.cloudflare.com/client/v4/user/tokens/permission_groups?name=AI%20Gateway` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.cloudflare.com/client/v4/user/tokens/permission_groups`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-62dabcbaa4bee4ee", "name": "Dangling fetch: GET https://api.cloudflare.com/client/v4/accounts/${this.config.accountId}/ai-gateway/gateways (scripts/", "shortDescription": {"text": "Dangling fetch: GET https://api.cloudflare.com/client/v4/accounts/${this.config.accountId}/ai-gateway/gateways (scripts/setup.ts:992)"}, "fullDescription": {"text": "`scripts/setup.ts:992` calls `GET https://api.cloudflare.com/client/v4/accounts/${this.config.accountId}/ai-gateway/gateways` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.cloudflare.com/client/v4/accounts/<p>/ai-gateway/gateways`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-be8c14478e2e41d2", "name": "Dangling fetch: POST https://api.cloudflare.com/client/v4/user/tokens (scripts/setup.ts:1038)", "shortDescription": {"text": "Dangling fetch: POST https://api.cloudflare.com/client/v4/user/tokens (scripts/setup.ts:1038)"}, "fullDescription": {"text": "`scripts/setup.ts:1038` calls `POST https://api.cloudflare.com/client/v4/user/tokens` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.cloudflare.com/client/v4/user/tokens`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-54194ee9d16c4532", "name": "Dangling fetch: GET https://api.github.com/user (worker/api/controllers/byop/controller.ts:190)", "shortDescription": {"text": "Dangling fetch: GET https://api.github.com/user (worker/api/controllers/byop/controller.ts:190)"}, "fullDescription": {"text": "`worker/api/controllers/byop/controller.ts:190` calls `GET https://api.github.com/user` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.github.com/user`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-84764ccd9f9e81a0", "name": "Dangling fetch: POST http://analyzer/start (worker/api/controllers/byop/controller.ts:366)", "shortDescription": {"text": "Dangling fetch: POST http://analyzer/start (worker/api/controllers/byop/controller.ts:366)"}, "fullDescription": {"text": "`worker/api/controllers/byop/controller.ts:366` calls `POST http://analyzer/start` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/analyzer/start`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f1c7d3574806b128", "name": "Dangling fetch: GET http://analyzer/state (worker/api/controllers/byop/controller.ts:438)", "shortDescription": {"text": "Dangling fetch: GET http://analyzer/state (worker/api/controllers/byop/controller.ts:438)"}, "fullDescription": {"text": "`worker/api/controllers/byop/controller.ts:438` calls `GET http://analyzer/state` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/analyzer/state`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e848b32dad61caa8", "name": "Dangling fetch: GET http://analyzer/state (worker/api/controllers/byop/controller.ts:474)", "shortDescription": {"text": "Dangling fetch: GET http://analyzer/state (worker/api/controllers/byop/controller.ts:474)"}, "fullDescription": {"text": "`worker/api/controllers/byop/controller.ts:474` calls `GET http://analyzer/state` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/analyzer/state`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2529a64af9c11c7b", "name": "Dangling fetch: GET http://analyzer/state (worker/api/controllers/byop/controller.ts:679)", "shortDescription": {"text": "Dangling fetch: GET http://analyzer/state (worker/api/controllers/byop/controller.ts:679)"}, "fullDescription": {"text": "`worker/api/controllers/byop/controller.ts:679` calls `GET http://analyzer/state` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/analyzer/state`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-78c5ffc08d2b44d8", "name": "Dangling fetch: GET /api/data (worker/agents/operations/PhaseImplementation.ts:199)", "shortDescription": {"text": "Dangling fetch: GET /api/data (worker/agents/operations/PhaseImplementation.ts:199)"}, "fullDescription": {"text": "`worker/agents/operations/PhaseImplementation.ts:199` calls `GET /api/data` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/data`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1783b5ca96412be0", "name": "Dangling fetch: POST https://api.github.com/user/repos (worker/services/github/GitHubService.ts:90)", "shortDescription": {"text": "Dangling fetch: POST https://api.github.com/user/repos (worker/services/github/GitHubService.ts:90)"}, "fullDescription": {"text": "`worker/services/github/GitHubService.ts:90` calls `POST https://api.github.com/user/repos` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.github.com/user/repos`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-69b197c02bdb5966", "name": "Dangling fetch: GET https://api.cloudflare.com/client/v4/accounts (worker/services/cloudflare/CloudflareAccountService.t", "shortDescription": {"text": "Dangling fetch: GET https://api.cloudflare.com/client/v4/accounts (worker/services/cloudflare/CloudflareAccountService.ts:65)"}, "fullDescription": {"text": "`worker/services/cloudflare/CloudflareAccountService.ts:65` calls `GET https://api.cloudflare.com/client/v4/accounts` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.cloudflare.com/client/v4/accounts`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1ad1d1abbb0e168b", "name": "Dangling fetch: GET https://api.cloudflare.com/client/v4/accounts/${accountId}/ai-gateway/gateways (worker/services/clou", "shortDescription": {"text": "Dangling fetch: GET https://api.cloudflare.com/client/v4/accounts/${accountId}/ai-gateway/gateways (worker/services/cloudflare/CloudflareAccountService.ts:103)"}, "fullDescription": {"text": "`worker/services/cloudflare/CloudflareAccountService.ts:103` calls `GET https://api.cloudflare.com/client/v4/accounts/${accountId}/ai-gateway/gateways` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.cloudflare.com/client/v4/accounts/<p>/ai-gateway/gateways`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7ff2242adbd9a360", "name": "Dangling fetch: POST https://api.cloudflare.com/client/v4/accounts/${accountId}/ai-gateway/gateways (worker/services/clo", "shortDescription": {"text": "Dangling fetch: POST https://api.cloudflare.com/client/v4/accounts/${accountId}/ai-gateway/gateways (worker/services/cloudflare/CloudflareAccountService.ts:147)"}, "fullDescription": {"text": "`worker/services/cloudflare/CloudflareAccountService.ts:147` calls `POST https://api.cloudflare.com/client/v4/accounts/${accountId}/ai-gateway/gateways` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.cloudflare.com/client/v4/accounts/<p>/ai-gateway/gateways`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4c05ce4197a9c0a2", "name": "Dangling fetch: GET https://api.cloudflare.com/client/v4/accounts/${accountId}/ai-gateway-billing/credit_balance (worker", "shortDescription": {"text": "Dangling fetch: GET https://api.cloudflare.com/client/v4/accounts/${accountId}/ai-gateway-billing/credit_balance (worker/services/cloudflare/CloudflareAccountService.ts:209)"}, "fullDescription": {"text": "`worker/services/cloudflare/CloudflareAccountService.ts:209` calls `GET https://api.cloudflare.com/client/v4/accounts/${accountId}/ai-gateway-billing/credit_balance` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.cloudflare.com/client/v4/accounts/<p>/ai-gateway-billing/credit_balance`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9be2cf69411c0921", "name": "Dangling fetch: GET http://127.0.0.1:${port}/ (container/process-monitor.ts:1229)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/ (container/process-monitor.ts:1229)"}, "fullDescription": {"text": "`container/process-monitor.ts:1229` calls `GET http://127.0.0.1:${port}/` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-773d4fa01701f3f0", "name": "Dangling fetch: GET /api/apps (src/lib/api-client.ts:437)", "shortDescription": {"text": "Dangling fetch: GET /api/apps (src/lib/api-client.ts:437)"}, "fullDescription": {"text": "`src/lib/api-client.ts:437` calls `GET /api/apps` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/apps`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-307f557e02bf053e", "name": "Dangling fetch: GET /api/apps/recent (src/lib/api-client.ts:444)", "shortDescription": {"text": "Dangling fetch: GET /api/apps/recent (src/lib/api-client.ts:444)"}, "fullDescription": {"text": "`src/lib/api-client.ts:444` calls `GET /api/apps/recent` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/apps/recent`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-94d404e27c0ce4ba", "name": "Dangling fetch: GET /api/apps/favorites (src/lib/api-client.ts:451)", "shortDescription": {"text": "Dangling fetch: GET /api/apps/favorites (src/lib/api-client.ts:451)"}, "fullDescription": {"text": "`src/lib/api-client.ts:451` calls `GET /api/apps/favorites` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/apps/favorites`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7a0a8593d6728db6", "name": "Dangling fetch: POST /api/apps (src/lib/api-client.ts:481)", "shortDescription": {"text": "Dangling fetch: POST /api/apps (src/lib/api-client.ts:481)"}, "fullDescription": {"text": "`src/lib/api-client.ts:481` calls `POST /api/apps` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/apps`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7c8e0ae162028ad1", "name": "Dangling fetch: POST /api/apps/${appId}/favorite (src/lib/api-client.ts:493)", "shortDescription": {"text": "Dangling fetch: POST /api/apps/${appId}/favorite (src/lib/api-client.ts:493)"}, "fullDescription": {"text": "`src/lib/api-client.ts:493` calls `POST /api/apps/${appId}/favorite` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/apps/<p>/favorite`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9c98e2c6d8548f83", "name": "Dangling fetch: PUT /api/apps/${appId}/visibility (src/lib/api-client.ts:505)", "shortDescription": {"text": "Dangling fetch: PUT /api/apps/${appId}/visibility (src/lib/api-client.ts:505)"}, "fullDescription": {"text": "`src/lib/api-client.ts:505` calls `PUT /api/apps/${appId}/visibility` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/apps/<p>/visibility`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a34c808ea78ef29b", "name": "Dangling fetch: GET /api/apps/${appId} (src/lib/api-client.ts:531)", "shortDescription": {"text": "Dangling fetch: GET /api/apps/${appId} (src/lib/api-client.ts:531)"}, "fullDescription": {"text": "`src/lib/api-client.ts:531` calls `GET /api/apps/${appId}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/apps/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4ac4ae7f85579f4a", "name": "Dangling fetch: POST /api/apps/${appId}/star (src/lib/api-client.ts:540)", "shortDescription": {"text": "Dangling fetch: POST /api/apps/${appId}/star (src/lib/api-client.ts:540)"}, "fullDescription": {"text": "`src/lib/api-client.ts:540` calls `POST /api/apps/${appId}/star` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/apps/<p>/star`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eb56fd7b3de61d55", "name": "Dangling fetch: POST /api/apps/${appId}/fork (src/lib/api-client.ts:550)", "shortDescription": {"text": "Dangling fetch: POST /api/apps/${appId}/fork (src/lib/api-client.ts:550)"}, "fullDescription": {"text": "`src/lib/api-client.ts:550` calls `POST /api/apps/${appId}/fork` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/apps/<p>/fork`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-debd76ce1899af1d", "name": "Dangling fetch: GET /api/stats/user (src/lib/api-client.ts:634)", "shortDescription": {"text": "Dangling fetch: GET /api/stats/user (src/lib/api-client.ts:634)"}, "fullDescription": {"text": "`src/lib/api-client.ts:634` calls `GET /api/stats/user` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/stats/user`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-598208cb78a73ba5", "name": "Dangling fetch: GET /api/model-configs (src/lib/api-client.ts:682)", "shortDescription": {"text": "Dangling fetch: GET /api/model-configs (src/lib/api-client.ts:682)"}, "fullDescription": {"text": "`src/lib/api-client.ts:682` calls `GET /api/model-configs` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/model-configs`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3d5e862282292f4c", "name": "Dangling fetch: DELETE /api/model-configs/${agentAction} (src/lib/api-client.ts:709)", "shortDescription": {"text": "Dangling fetch: DELETE /api/model-configs/${agentAction} (src/lib/api-client.ts:709)"}, "fullDescription": {"text": "`src/lib/api-client.ts:709` calls `DELETE /api/model-configs/${agentAction}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/model-configs/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2c433e737c2082ca", "name": "Dangling fetch: POST /api/model-configs/reset-all (src/lib/api-client.ts:775)", "shortDescription": {"text": "Dangling fetch: POST /api/model-configs/reset-all (src/lib/api-client.ts:775)"}, "fullDescription": {"text": "`src/lib/api-client.ts:775` calls `POST /api/model-configs/reset-all` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/model-configs/reset-all`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9ba057a2421c5aff", "name": "Dangling fetch: POST /api/interview (src/lib/api-client.ts:879)", "shortDescription": {"text": "Dangling fetch: POST /api/interview (src/lib/api-client.ts:879)"}, "fullDescription": {"text": "`src/lib/api-client.ts:879` calls `POST /api/interview` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/interview`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-acc24ef35044eeaa", "name": "Dangling fetch: GET /api/interview/${sessionId} (src/lib/api-client.ts:889)", "shortDescription": {"text": "Dangling fetch: GET /api/interview/${sessionId} (src/lib/api-client.ts:889)"}, "fullDescription": {"text": "`src/lib/api-client.ts:889` calls `GET /api/interview/${sessionId}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/interview/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-afc567e8d6f41b36", "name": "Dangling fetch: POST /api/interview/${sessionId}/answer (src/lib/api-client.ts:900)", "shortDescription": {"text": "Dangling fetch: POST /api/interview/${sessionId}/answer (src/lib/api-client.ts:900)"}, "fullDescription": {"text": "`src/lib/api-client.ts:900` calls `POST /api/interview/${sessionId}/answer` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/interview/<p>/answer`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-844f636891fcae0c", "name": "Dangling fetch: POST /api/interview/${sessionId}/finish (src/lib/api-client.ts:910)", "shortDescription": {"text": "Dangling fetch: POST /api/interview/${sessionId}/finish (src/lib/api-client.ts:910)"}, "fullDescription": {"text": "`src/lib/api-client.ts:910` calls `POST /api/interview/${sessionId}/finish` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/interview/<p>/finish`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f291568eb76b1e9e", "name": "Dangling fetch: GET /api/secrets (src/lib/api-client.ts:923)", "shortDescription": {"text": "Dangling fetch: GET /api/secrets (src/lib/api-client.ts:923)"}, "fullDescription": {"text": "`src/lib/api-client.ts:923` calls `GET /api/secrets` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/secrets`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f873c38d74e381ff", "name": "Dangling fetch: POST /api/secrets (src/lib/api-client.ts:937)", "shortDescription": {"text": "Dangling fetch: POST /api/secrets (src/lib/api-client.ts:937)"}, "fullDescription": {"text": "`src/lib/api-client.ts:937` calls `POST /api/secrets` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/secrets`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7f453361868397b1", "name": "Dangling fetch: DELETE /api/secrets/${secretId} (src/lib/api-client.ts:949)", "shortDescription": {"text": "Dangling fetch: DELETE /api/secrets/${secretId} (src/lib/api-client.ts:949)"}, "fullDescription": {"text": "`src/lib/api-client.ts:949` calls `DELETE /api/secrets/${secretId}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/secrets/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ebbca8c4d9eb6072", "name": "Dangling fetch: PATCH /api/secrets/${secretId}/toggle (src/lib/api-client.ts:960)", "shortDescription": {"text": "Dangling fetch: PATCH /api/secrets/${secretId}/toggle (src/lib/api-client.ts:960)"}, "fullDescription": {"text": "`src/lib/api-client.ts:960` calls `PATCH /api/secrets/${secretId}/toggle` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/secrets/<p>/toggle`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-165eb295d4793234", "name": "Dangling fetch: GET /api/auth/sessions (src/lib/api-client.ts:1033)", "shortDescription": {"text": "Dangling fetch: GET /api/auth/sessions (src/lib/api-client.ts:1033)"}, "fullDescription": {"text": "`src/lib/api-client.ts:1033` calls `GET /api/auth/sessions` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/sessions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a60b033f3d48a9cd", "name": "Dangling fetch: DELETE /api/auth/sessions/${sessionId} (src/lib/api-client.ts:1042)", "shortDescription": {"text": "Dangling fetch: DELETE /api/auth/sessions/${sessionId} (src/lib/api-client.ts:1042)"}, "fullDescription": {"text": "`src/lib/api-client.ts:1042` calls `DELETE /api/auth/sessions/${sessionId}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/sessions/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2ea108214a9e40e1", "name": "Dangling fetch: POST /api/auth/api-keys (src/lib/api-client.ts:1074)", "shortDescription": {"text": "Dangling fetch: POST /api/auth/api-keys (src/lib/api-client.ts:1074)"}, "fullDescription": {"text": "`src/lib/api-client.ts:1074` calls `POST /api/auth/api-keys` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/api-keys`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fe8f95d1861fda0b", "name": "Dangling fetch: DELETE /api/auth/api-keys/${keyId} (src/lib/api-client.ts:1091)", "shortDescription": {"text": "Dangling fetch: DELETE /api/auth/api-keys/${keyId} (src/lib/api-client.ts:1091)"}, "fullDescription": {"text": "`src/lib/api-client.ts:1091` calls `DELETE /api/auth/api-keys/${keyId}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/api-keys/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-505c7972a5658275", "name": "Dangling fetch: POST /api/byop/analysis/${analysisId}/start-building (src/lib/api-client.ts:1157)", "shortDescription": {"text": "Dangling fetch: POST /api/byop/analysis/${analysisId}/start-building (src/lib/api-client.ts:1157)"}, "fullDescription": {"text": "`src/lib/api-client.ts:1157` calls `POST /api/byop/analysis/${analysisId}/start-building` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/byop/analysis/<p>/start-building`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6cced232a5409964", "name": "Dangling fetch: POST /api/auth/login (src/lib/api-client.ts:1231)", "shortDescription": {"text": "Dangling fetch: POST /api/auth/login (src/lib/api-client.ts:1231)"}, "fullDescription": {"text": "`src/lib/api-client.ts:1231` calls `POST /api/auth/login` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/login`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0ce7e70c06577c73", "name": "Dangling fetch: POST /api/auth/register (src/lib/api-client.ts:1245)", "shortDescription": {"text": "Dangling fetch: POST /api/auth/register (src/lib/api-client.ts:1245)"}, "fullDescription": {"text": "`src/lib/api-client.ts:1245` calls `POST /api/auth/register` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/register`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-22fe6713b1092fac", "name": "Dangling fetch: POST /api/auth/verify-email (src/lib/api-client.ts:1258)", "shortDescription": {"text": "Dangling fetch: POST /api/auth/verify-email (src/lib/api-client.ts:1258)"}, "fullDescription": {"text": "`src/lib/api-client.ts:1258` calls `POST /api/auth/verify-email` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/verify-email`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9369e2b9111d3b63", "name": "Dangling fetch: POST /api/auth/resend-verification (src/lib/api-client.ts:1270)", "shortDescription": {"text": "Dangling fetch: POST /api/auth/resend-verification (src/lib/api-client.ts:1270)"}, "fullDescription": {"text": "`src/lib/api-client.ts:1270` calls `POST /api/auth/resend-verification` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/resend-verification`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-16532eb83fe8ca9d", "name": "Dangling fetch: GET /api/auth/providers (src/lib/api-client.ts:1306)", "shortDescription": {"text": "Dangling fetch: GET /api/auth/providers (src/lib/api-client.ts:1306)"}, "fullDescription": {"text": "`src/lib/api-client.ts:1306` calls `GET /api/auth/providers` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/providers`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-09ff92ac3044dca0", "name": "Dangling fetch: PUT /api/auth/profile (src/routes/settings/index.tsx:136)", "shortDescription": {"text": "Dangling fetch: PUT /api/auth/profile (src/routes/settings/index.tsx:136)"}, "fullDescription": {"text": "`src/routes/settings/index.tsx:136` calls `PUT /api/auth/profile` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/auth/profile`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b8073f7bf758f6d0", "name": "Unused endpoint: USE /api/*", "shortDescription": {"text": "Unused endpoint: USE /api/*"}, "fullDescription": {"text": "`worker/app.ts` declares `USE /api/*` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f5c922b9512394db", "name": "Unused endpoint: GET /csrf-token", "shortDescription": {"text": "Unused endpoint: GET /csrf-token"}, "fullDescription": {"text": "`worker/api/routes/authRoutes.ts` declares `GET /csrf-token` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e21cf4ee09f7c6a9", "name": "Unused endpoint: GET /providers", "shortDescription": {"text": "Unused endpoint: GET /providers"}, "fullDescription": {"text": "`worker/api/routes/authRoutes.ts` declares `GET /providers` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-304b6f2b403d93f7", "name": "Unused endpoint: POST /register", "shortDescription": {"text": "Unused endpoint: POST /register"}, "fullDescription": {"text": "`worker/api/routes/authRoutes.ts` declares `POST /register` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-618721b912bad1c2", "name": "Unused endpoint: POST /login", "shortDescription": {"text": "Unused endpoint: POST /login"}, "fullDescription": {"text": "`worker/api/routes/authRoutes.ts` declares `POST /login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0c3bb6af93b4422a", "name": "Unused endpoint: POST /verify-email", "shortDescription": {"text": "Unused endpoint: POST /verify-email"}, "fullDescription": {"text": "`worker/api/routes/authRoutes.ts` declares `POST /verify-email` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0afae4bfd1ff1c08", "name": "Unused endpoint: POST /resend-verification", "shortDescription": {"text": "Unused endpoint: POST /resend-verification"}, "fullDescription": {"text": "`worker/api/routes/authRoutes.ts` declares `POST /resend-verification` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e5f899fff8e655a2", "name": "Unused endpoint: GET /check", "shortDescription": {"text": "Unused endpoint: GET /check"}, "fullDescription": {"text": "`worker/api/routes/authRoutes.ts` declares `GET /check` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2595b39638e5c045", "name": "Unused endpoint: GET /profile", "shortDescription": {"text": "Unused endpoint: GET /profile"}, "fullDescription": {"text": "`worker/api/routes/authRoutes.ts` declares `GET /profile` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-911492554a68d0c1", "name": "Unused endpoint: PUT /profile", "shortDescription": {"text": "Unused endpoint: PUT /profile"}, "fullDescription": {"text": "`worker/api/routes/authRoutes.ts` declares `PUT /profile` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-99fc36db98c134ce", "name": "Unused endpoint: POST /logout", "shortDescription": {"text": "Unused endpoint: POST /logout"}, "fullDescription": {"text": "`worker/api/routes/authRoutes.ts` declares `POST /logout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b15d518d538de57d", "name": "Unused endpoint: GET /sessions", "shortDescription": {"text": "Unused endpoint: GET /sessions"}, "fullDescription": {"text": "`worker/api/routes/authRoutes.ts` declares `GET /sessions` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-05b1ac409816dfd9", "name": "Unused endpoint: DELETE /sessions/:sessionId", "shortDescription": {"text": "Unused endpoint: DELETE /sessions/:sessionId"}, "fullDescription": {"text": "`worker/api/routes/authRoutes.ts` declares `DELETE /sessions/:sessionId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c32b4607df0975e2", "name": "Unused endpoint: GET /api-keys", "shortDescription": {"text": "Unused endpoint: GET /api-keys"}, "fullDescription": {"text": "`worker/api/routes/authRoutes.ts` declares `GET /api-keys` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-224cbb7548a6b13c", "name": "Unused endpoint: POST /api-keys", "shortDescription": {"text": "Unused endpoint: POST /api-keys"}, "fullDescription": {"text": "`worker/api/routes/authRoutes.ts` declares `POST /api-keys` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4aa5f1617bc2f39b", "name": "Unused endpoint: DELETE /api-keys/:keyId", "shortDescription": {"text": "Unused endpoint: DELETE /api-keys/:keyId"}, "fullDescription": {"text": "`worker/api/routes/authRoutes.ts` declares `DELETE /api-keys/:keyId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ed8eaae0bc558031", "name": "Unused endpoint: GET /oauth/:provider", "shortDescription": {"text": "Unused endpoint: GET /oauth/:provider"}, "fullDescription": {"text": "`worker/api/routes/authRoutes.ts` declares `GET /oauth/:provider` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a537c245f0127632", "name": "Unused endpoint: GET /callback/:provider", "shortDescription": {"text": "Unused endpoint: GET /callback/:provider"}, "fullDescription": {"text": "`worker/api/routes/authRoutes.ts` declares `GET /callback/:provider` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eb9704c9e7ebf6c2", "name": "Unused endpoint: GET /:id/:file", "shortDescription": {"text": "Unused endpoint: GET /:id/:file"}, "fullDescription": {"text": "`worker/api/routes/imagesRoutes.ts` declares `GET /:id/:file` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7048a5bb2e75bdd1", "name": "Unused endpoint: GET /:file", "shortDescription": {"text": "Unused endpoint: GET /:file"}, "fullDescription": {"text": "`worker/api/routes/imagesRoutes.ts` declares `GET /:file` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-66be2e63e9cbc888", "name": "Unused endpoint: GET /api/user/apps", "shortDescription": {"text": "Unused endpoint: GET /api/user/apps"}, "fullDescription": {"text": "`worker/api/routes/userRoutes.ts` declares `GET /api/user/apps` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dd372090e9e12608", "name": "Unused endpoint: GET /api/user/providers", "shortDescription": {"text": "Unused endpoint: GET /api/user/providers"}, "fullDescription": {"text": "`worker/api/routes/modelProviderRoutes.ts` declares `GET /api/user/providers` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4aa0183417eec9bb", "name": "Unused endpoint: GET /api/user/providers/:id", "shortDescription": {"text": "Unused endpoint: GET /api/user/providers/:id"}, "fullDescription": {"text": "`worker/api/routes/modelProviderRoutes.ts` declares `GET /api/user/providers/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-edef8b247414474d", "name": "Unused endpoint: POST /api/user/providers", "shortDescription": {"text": "Unused endpoint: POST /api/user/providers"}, "fullDescription": {"text": "`worker/api/routes/modelProviderRoutes.ts` declares `POST /api/user/providers` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-84ed732a2d8ac61b", "name": "Unused endpoint: DELETE /api/user/providers/:id", "shortDescription": {"text": "Unused endpoint: DELETE /api/user/providers/:id"}, "fullDescription": {"text": "`worker/api/routes/modelProviderRoutes.ts` declares `DELETE /api/user/providers/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f629f7c8659dc139", "name": "Unused endpoint: POST /api/user/providers/test", "shortDescription": {"text": "Unused endpoint: POST /api/user/providers/test"}, "fullDescription": {"text": "`worker/api/routes/modelProviderRoutes.ts` declares `POST /api/user/providers/test` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a009b1a56794f45", "name": "Unused endpoint: POST /", "shortDescription": {"text": "Unused endpoint: POST /"}, "fullDescription": {"text": "`worker/api/routes/interviewRoutes.ts` declares `POST /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c9c3650dde2516a3", "name": "Unused endpoint: GET /:sessionId", "shortDescription": {"text": "Unused endpoint: GET /:sessionId"}, "fullDescription": {"text": "`worker/api/routes/interviewRoutes.ts` declares `GET /:sessionId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0849f154e68b7cea", "name": "Unused endpoint: POST /:sessionId/answer", "shortDescription": {"text": "Unused endpoint: POST /:sessionId/answer"}, "fullDescription": {"text": "`worker/api/routes/interviewRoutes.ts` declares `POST /:sessionId/answer` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8ae36833cd60a3bb", "name": "Unused endpoint: POST /:sessionId/finish", "shortDescription": {"text": "Unused endpoint: POST /:sessionId/finish"}, "fullDescription": {"text": "`worker/api/routes/interviewRoutes.ts` declares `POST /:sessionId/finish` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`worker/api/routes/statusRoutes.ts` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-19a2092a23c40fef", "name": "Unused endpoint: POST /api/agent", "shortDescription": {"text": "Unused endpoint: POST /api/agent"}, "fullDescription": {"text": "`worker/api/routes/codegenRoutes.ts` declares `POST /api/agent` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2526536f700238c1", "name": "Unused endpoint: GET /api/agent/:agentId/ws", "shortDescription": {"text": "Unused endpoint: GET /api/agent/:agentId/ws"}, "fullDescription": {"text": "`worker/api/routes/codegenRoutes.ts` declares `GET /api/agent/:agentId/ws` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b751fafe8c993414", "name": "Unused endpoint: GET /api/agent/:agentId/connect", "shortDescription": {"text": "Unused endpoint: GET /api/agent/:agentId/connect"}, "fullDescription": {"text": "`worker/api/routes/codegenRoutes.ts` declares `GET /api/agent/:agentId/connect` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-07622488bbb18488", "name": "Unused endpoint: GET /api/agent/:agentId/preview", "shortDescription": {"text": "Unused endpoint: GET /api/agent/:agentId/preview"}, "fullDescription": {"text": "`worker/api/routes/codegenRoutes.ts` declares `GET /api/agent/:agentId/preview` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4756b4c4da7d2088", "name": "Unused endpoint: GET /api/health", "shortDescription": {"text": "Unused endpoint: GET /api/health"}, "fullDescription": {"text": "`worker/api/routes/index.ts` declares `GET /api/health` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6a42c52fea3345b5", "name": "Unused endpoint: GET /public", "shortDescription": {"text": "Unused endpoint: GET /public"}, "fullDescription": {"text": "`worker/api/routes/appRoutes.ts` declares `GET /public` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-955005a6da85f786", "name": "Unused endpoint: GET /recent", "shortDescription": {"text": "Unused endpoint: GET /recent"}, "fullDescription": {"text": "`worker/api/routes/appRoutes.ts` declares `GET /recent` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-290b7834e43f5b66", "name": "Unused endpoint: GET /favorites", "shortDescription": {"text": "Unused endpoint: GET /favorites"}, "fullDescription": {"text": "`worker/api/routes/appRoutes.ts` declares `GET /favorites` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6bd4dac6864b6b2b", "name": "Unused endpoint: POST /:id/star", "shortDescription": {"text": "Unused endpoint: POST /:id/star"}, "fullDescription": {"text": "`worker/api/routes/appRoutes.ts` declares `POST /:id/star` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3496a0fb449a79d0", "name": "Unused endpoint: POST /:id/fork", "shortDescription": {"text": "Unused endpoint: POST /:id/fork"}, "fullDescription": {"text": "`worker/api/routes/appRoutes.ts` declares `POST /:id/fork` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e097518d6e369a4a", "name": "Unused endpoint: POST /:id/favorite", "shortDescription": {"text": "Unused endpoint: POST /:id/favorite"}, "fullDescription": {"text": "`worker/api/routes/appRoutes.ts` declares `POST /:id/favorite` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ca5756175765b49d", "name": "Unused endpoint: GET /:id", "shortDescription": {"text": "Unused endpoint: GET /:id"}, "fullDescription": {"text": "`worker/api/routes/appRoutes.ts` declares `GET /:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2777a966d6b1b552", "name": "Unused endpoint: PUT /:id/visibility", "shortDescription": {"text": "Unused endpoint: PUT /:id/visibility"}, "fullDescription": {"text": "`worker/api/routes/appRoutes.ts` declares `PUT /:id/visibility` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a61c112b611f4bb", "name": "Unused endpoint: DELETE /:id", "shortDescription": {"text": "Unused endpoint: DELETE /:id"}, "fullDescription": {"text": "`worker/api/routes/appRoutes.ts` declares `DELETE /:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f1c22d9e74fd654f", "name": "Unused endpoint: POST /tunnel", "shortDescription": {"text": "Unused endpoint: POST /tunnel"}, "fullDescription": {"text": "`worker/api/routes/sentryRoutes.ts` declares `POST /tunnel` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-10c38a97762e7b8c", "name": "Unused endpoint: GET /repositories", "shortDescription": {"text": "Unused endpoint: GET /repositories"}, "fullDescription": {"text": "`worker/api/routes/byopRoutes.ts` declares `GET /repositories` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be4cb5e3cabcce80", "name": "Unused endpoint: POST /import", "shortDescription": {"text": "Unused endpoint: POST /import"}, "fullDescription": {"text": "`worker/api/routes/byopRoutes.ts` declares `POST /import` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ad6675332dc61eee", "name": "Unused endpoint: GET /analysis/:analysisId/status", "shortDescription": {"text": "Unused endpoint: GET /analysis/:analysisId/status"}, "fullDescription": {"text": "`worker/api/routes/byopRoutes.ts` declares `GET /analysis/:analysisId/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e11fbcad56e8d061", "name": "Unused endpoint: GET /analysis/:analysisId/blueprint", "shortDescription": {"text": "Unused endpoint: GET /analysis/:analysisId/blueprint"}, "fullDescription": {"text": "`worker/api/routes/byopRoutes.ts` declares `GET /analysis/:analysisId/blueprint` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/17650"}, "properties": {"repository": "QuicksilverSlick/dreamforge-cf", "repoUrl": "https://github.com/QuicksilverSlick/dreamforge-cf", "branch": "main"}, "results": [{"ruleId": "scanner-daffa53e5df18fb2", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/helpers/websocket-client.ts:40"}, "properties": {"repobilityId": "042bd101f11fa80a", "scanner": "scanner-primary", "fingerprint": "daffa53e5df18fb2", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b26294d91b5ec62c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e/byop-happy-path.test.ts:59"}, "properties": {"repobilityId": "daf3778c8ac2400a", "scanner": "scanner-primary", "fingerprint": "b26294d91b5ec62c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-82e4fa2ab6479781", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/deploy.ts:123"}, "properties": {"repobilityId": "981745a632ea4a14", "scanner": "scanner-primary", "fingerprint": "82e4fa2ab6479781", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-64a8958e6a27fb59", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/undeploy.ts:95"}, "properties": {"repobilityId": "948596264e72f981", "scanner": "scanner-primary", "fingerprint": "64a8958e6a27fb59", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5e3a8997a73a816d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/copy-landing-pages.ts:42"}, "properties": {"repobilityId": "76e52e89fd0978d1", "scanner": "scanner-primary", "fingerprint": "5e3a8997a73a816d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c33c7881107b5f2a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/setup.ts:63"}, "properties": {"repobilityId": "6b5357ac89817640", "scanner": "scanner-primary", "fingerprint": "c33c7881107b5f2a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f9318a061b0be6ed", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 worker/types/secretsTemplates.ts:189"}, "properties": {"repobilityId": "ab4a2f704a1605c0", "scanner": "scanner-primary", "fingerprint": "f9318a061b0be6ed", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-7706818613e6142e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/middleware/auth/routeAuth.ts:74"}, "properties": {"repobilityId": "59d9d1505e1079f6", "scanner": "scanner-primary", "fingerprint": "7706818613e6142e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ca84bc0d4c0147a9", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/api/controllers/modelConfig/byokHelper.ts:128"}, "properties": {"repobilityId": "38b98b26cf90d5d2", "scanner": "scanner-primary", "fingerprint": "ca84bc0d4c0147a9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-19f45ffe40b6dd76", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 worker/database/services/AuthService.ts:590"}, "properties": {"repobilityId": "89547084b2d45814", "scanner": "scanner-primary", "fingerprint": "19f45ffe40b6dd76", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-790890ada55d38aa", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 worker/agents/prompts.ts:1366"}, "properties": {"repobilityId": "2dcef84b1dffd094", "scanner": "scanner-primary", "fingerprint": "790890ada55d38aa", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-2893918cfd6c4a19", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/agents/prompts.ts:913"}, "properties": {"repobilityId": "a61a0b24b9f449ec", "scanner": "scanner-primary", "fingerprint": "2893918cfd6c4a19", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f56b00ac6f8af067", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/agents/utils/templateCustomizer.ts:106"}, "properties": {"repobilityId": "7d704a75d110a72c", "scanner": "scanner-primary", "fingerprint": "f56b00ac6f8af067", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-1d9c378022cfddd2", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/agents/assistants/realtimeCodeFixer.ts:541"}, "properties": {"repobilityId": "39aeeb7f6cee1567", "scanner": "scanner-primary", "fingerprint": "1d9c378022cfddd2", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-6c34d4887bce5dd4", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/agents/inferutils/infer.ts:139"}, "properties": {"repobilityId": "5c206b4a605d11cc", "scanner": "scanner-primary", "fingerprint": "6c34d4887bce5dd4", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-532a04fe1858ecc8", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/agents/inferutils/schemaFormatters.ts:725"}, "properties": {"repobilityId": "b588cd1b6b6197dc", "scanner": "scanner-primary", "fingerprint": "532a04fe1858ecc8", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-61b34151018c75cf", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/agents/inferutils/core.ts:57"}, "properties": {"repobilityId": "5ed441a562a8bf71", "scanner": "scanner-primary", "fingerprint": "61b34151018c75cf", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4e3446b6d64c43b9", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/agents/services/implementations/FileManager.ts:48"}, "properties": {"repobilityId": "2202c048eaca6fca", "scanner": "scanner-primary", "fingerprint": "4e3446b6d64c43b9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-caa33f2e09faa03b", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 worker/agents/core/smartGeneratorAgent.ts:38"}, "properties": {"repobilityId": "30705def1a454f2b", "scanner": "scanner-primary", "fingerprint": "caa33f2e09faa03b", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-84cbeb03c9ff1f67", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/agents/output-formats/streaming-formats/scof.test.ts:32"}, "properties": {"repobilityId": "4c3f66ca5edb820a", "scanner": "scanner-primary", "fingerprint": "84cbeb03c9ff1f67", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e5403d02d2f1707c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/agents/output-formats/streaming-formats/scof-comprehensive.test.ts:41"}, "properties": {"repobilityId": "844838c26d389f52", "scanner": "scanner-primary", "fingerprint": "e5403d02d2f1707c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-85d120b82ae5bc1b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/agents/output-formats/diff-formats/udiff.test.ts:52"}, "properties": {"repobilityId": "e3dd4ba2055b5abb", "scanner": "scanner-primary", "fingerprint": "85d120b82ae5bc1b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b2f5399421f0b23e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/agents/output-formats/diff-formats/search-replace.test.ts:7"}, "properties": {"repobilityId": "b09e547f3a4ddd1e", "scanner": "scanner-primary", "fingerprint": "b2f5399421f0b23e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b3cf3a3819f0368e", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 worker/agents/output-formats/diff-formats/udiff-comprehensive.test.ts:513"}, "properties": {"repobilityId": "9212dab7699dbc4d", "scanner": "scanner-primary", "fingerprint": "b3cf3a3819f0368e", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-15e3bc00058c8816", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/agents/planning/blueprint.ts:343"}, "properties": {"repobilityId": "2580f63e92840587", "scanner": "scanner-primary", "fingerprint": "15e3bc00058c8816", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-866535c4c51b6c92", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 worker/services/code-fixer/fixers/ts2304.ts:266"}, "properties": {"repobilityId": "aac222f8c9a26d9d", "scanner": "scanner-primary", "fingerprint": "866535c4c51b6c92", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-ba2c69838cd0ffd1", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/services/sandbox/sandboxSdkClient.ts:111"}, "properties": {"repobilityId": "19c30ebe2ea887cf", "scanner": "scanner-primary", "fingerprint": "ba2c69838cd0ffd1", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-384741177fa478d7", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/services/sandbox/factory.ts:8"}, "properties": {"repobilityId": "26f3cdb5857df7cb", "scanner": "scanner-primary", "fingerprint": "384741177fa478d7", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2884d86b0096f2ee", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 worker/services/analysis/CodeAnalysisService.ts:25"}, "properties": {"repobilityId": "c286e9eb2b60fcca", "scanner": "scanner-primary", "fingerprint": "2884d86b0096f2ee", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-3cf75711bb1c2f9e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/services/deployer/api/cloudflare-api.ts:188"}, "properties": {"repobilityId": "ea256bd57fdf3774", "scanner": "scanner-primary", "fingerprint": "3cf75711bb1c2f9e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b984e6eb7e76a39a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 worker/services/aigateway-proxy/controller.ts:11"}, "properties": {"repobilityId": "c234d359dbd7a36c", "scanner": "scanner-primary", "fingerprint": "b984e6eb7e76a39a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9d3fca431d46c638", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 container/process-monitor.ts:418"}, "properties": {"repobilityId": "e9167b735c11da6c", "scanner": "scanner-primary", "fingerprint": "9d3fca431d46c638", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-08982ae27af08089", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 container/cli-tools.ts:119"}, "properties": {"repobilityId": "09263070d0628100", "scanner": "scanner-primary", "fingerprint": "08982ae27af08089", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3875c25029568dd9", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 container/monitor-cli.test.ts:46"}, "properties": {"repobilityId": "b1e58e01f0a74d23", "scanner": "scanner-primary", "fingerprint": "3875c25029568dd9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-94522e0db2cbfb3c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/utils/screenshot.ts:208"}, "properties": {"repobilityId": "09ece3a495e84c4e", "scanner": "scanner-primary", "fingerprint": "94522e0db2cbfb3c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e2e4b14aa96a1177", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/image-attachment-preview.tsx:52"}, "properties": {"repobilityId": "238a0269413e9e5b", "scanner": "scanner-primary", "fingerprint": "e2e4b14aa96a1177", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-2108f3dc50e57438", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/config-card.tsx:198"}, "properties": {"repobilityId": "fa686ec663077da7", "scanner": "scanner-primary", "fingerprint": "2108f3dc50e57438", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-441a8693e61af419", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/layout/app-sidebar.tsx:124"}, "properties": {"repobilityId": "0439dbc617b570d4", "scanner": "scanner-primary", "fingerprint": "441a8693e61af419", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-911cb1a6d68147d0", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/layout/global-header.tsx:72"}, "properties": {"repobilityId": "31c8f8fa854fd559", "scanner": "scanner-primary", "fingerprint": "911cb1a6d68147d0", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-e7253eb8e41b61de", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/shared/AppCard.tsx:284"}, "properties": {"repobilityId": "dfbf1d9723530981", "scanner": "scanner-primary", "fingerprint": "e7253eb8e41b61de", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-6f763ecd975b7d29", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/ui/model-selector.tsx:193"}, "properties": {"repobilityId": "878ecc4095af7377", "scanner": "scanner-primary", "fingerprint": "6f763ecd975b7d29", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-9464c9f335979a74", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/byop/GitHubRepositoryList.tsx:211"}, "properties": {"repobilityId": "65a491c002764ef4", "scanner": "scanner-primary", "fingerprint": "9464c9f335979a74", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-dbfbf747508239ab", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/contexts/limits-context.tsx:72"}, "properties": {"repobilityId": "24e498ec7c4fb3e1", "scanner": "scanner-primary", "fingerprint": "dbfbf747508239ab", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c577488129098711", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/lib/api-client.ts:389"}, "properties": {"repobilityId": "46297b50a0393c47", "scanner": "scanner-primary", "fingerprint": "c577488129098711", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-faa06112a826b491", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 src/routes/home.tsx:42"}, "properties": {"repobilityId": "272a8b89dc75ca58", "scanner": "scanner-primary", "fingerprint": "faa06112a826b491", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-65eee19d76c33991", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/routes/chat/utils/file-state-helpers.ts:58"}, "properties": {"repobilityId": "9852b09b5c298f89", "scanner": "scanner-primary", "fingerprint": "65eee19d76c33991", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-54b488e5c5eed097", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/routes/chat/components/file-explorer.tsx:40"}, "properties": {"repobilityId": "bc62fdd4a1a1b829", "scanner": "scanner-primary", "fingerprint": "54b488e5c5eed097", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-587c56cf5b976309", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/routes/chat/components/debug-panel.tsx:880"}, "properties": {"repobilityId": "98df17b6540aac66", "scanner": "scanner-primary", "fingerprint": "587c56cf5b976309", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-2b0603add96d9b3d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/routes/chat/components/preview-iframe.tsx:72"}, "properties": {"repobilityId": "c63b28fb9b099193", "scanner": "scanner-primary", "fingerprint": "2b0603add96d9b3d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a6879fc2f9da7367", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/routes/chat/components/phase-timeline.tsx:515"}, "properties": {"repobilityId": "d40e35095ac8c731", "scanner": "scanner-primary", "fingerprint": "a6879fc2f9da7367", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-5dda5baf0c533af1", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/routes/app/index.tsx:949"}, "properties": {"repobilityId": "11c727459494ba22", "scanner": "scanner-primary", "fingerprint": "5dda5baf0c533af1", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-139c42f28ade1137", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/hooks/use-byop.ts:88"}, "properties": {"repobilityId": "adec00f064a97340", "scanner": "scanner-primary", "fingerprint": "139c42f28ade1137", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5dc380dc64294cb7", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/features/app/index.ts:49"}, "properties": {"repobilityId": "127b2d88e18f2aca", "scanner": "scanner-primary", "fingerprint": "5dc380dc64294cb7", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-cbdde17da04841dd", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/features/general/index.tsx:44"}, "properties": {"repobilityId": "c6d9d57579f457a4", "scanner": "scanner-primary", "fingerprint": "cbdde17da04841dd", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a27c6be7295a63b0", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/features/presentation/index.tsx:92"}, "properties": {"repobilityId": "35c7ca3acf1b1987", "scanner": "scanner-primary", "fingerprint": "a27c6be7295a63b0", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b65bfe0ff91beb1c", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/presentation/components/PresentationPreview.tsx:169"}, "properties": {"repobilityId": "dcde70dc1406c54d", "scanner": "scanner-primary", "fingerprint": "b65bfe0ff91beb1c", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-d960daa2776ac774", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 debug-tools/test-ai-gateway-analytics.ts:662"}, "properties": {"repobilityId": "346ffd5921622c6f", "scanner": "scanner-primary", "fingerprint": "d960daa2776ac774", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e97a933adab0e294", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/deploy.ts:16"}, "properties": {"repobilityId": "736dc8bf5170df1a", "scanner": "scanner-primary", "fingerprint": "e97a933adab0e294", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/deploy.ts"}, "region": {"startLine": 16}}}]}, {"ruleId": "scanner-78ad42c213bebde5", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/undeploy.ts:21"}, "properties": {"repobilityId": "ebdda791ea97209e", "scanner": "scanner-primary", "fingerprint": "78ad42c213bebde5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/undeploy.ts"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-4e5cfb552a27e762", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/setup.ts:3"}, "properties": {"repobilityId": "9b3db7368ebec43d", "scanner": "scanner-primary", "fingerprint": "4e5cfb552a27e762", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/setup.ts"}, "region": {"startLine": 3}}}]}, {"ruleId": "scanner-452e8cf9be27d924", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in worker/api/controllers/screenshots/controller.ts:172"}, "properties": {"repobilityId": "77e2691d581a0bbd", "scanner": "scanner-primary", "fingerprint": "452e8cf9be27d924", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/api/controllers/screenshots/controller.ts"}, "region": {"startLine": 172}}}]}, {"ruleId": "scanner-8f401f235745b5ff", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in worker/agents/core/codingAgent.ts:800"}, "properties": {"repobilityId": "d0e7dd26fe665bb3", "scanner": "scanner-primary", "fingerprint": "8f401f235745b5ff", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "worker/agents/core/codingAgent.ts"}, "region": {"startLine": 800}}}]}, {"ruleId": "scanner-0cc410e25ffffb4b", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in container/process-monitor.ts:2"}, "properties": {"repobilityId": "06588708fec6b03c", "scanner": "scanner-primary", "fingerprint": "0cc410e25ffffb4b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "container/process-monitor.ts"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-25e154d41d8dba4d", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in container/bun-sqlite.d.ts:14"}, "properties": {"repobilityId": "1b04fe1ca814b818", "scanner": "scanner-primary", "fingerprint": "25e154d41d8dba4d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "container/bun-sqlite.d.ts"}, "region": {"startLine": 14}}}]}, {"ruleId": "scanner-6fc26c9857519a91", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in container/monitor-cli.test.ts:5"}, "properties": {"repobilityId": "de73b0f0cea5ec68", "scanner": "scanner-primary", "fingerprint": "6fc26c9857519a91", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "container/monitor-cli.test.ts"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-e389f4af196fb8dc", "level": "error", "message": {"text": "Possible secret in src/components/auth/login-modal.tsx"}, "properties": {"repobilityId": "ea2e5f4fa8d977eb", "scanner": "scanner-primary", "fingerprint": "e389f4af196fb8dc", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/components/auth/login-modal.tsx"}, "region": {"startLine": 115}}}]}, {"ruleId": "scanner-e389f4af196fb8dc", "level": "error", "message": {"text": "Possible secret in src/components/auth/login-modal.tsx"}, "properties": {"repobilityId": "ea2e5f4fa8d977eb", "scanner": "scanner-primary", "fingerprint": "e389f4af196fb8dc", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/components/auth/login-modal.tsx"}, "region": {"startLine": 117}}}]}, {"ruleId": "scanner-e389f4af196fb8dc", "level": "error", "message": {"text": "Possible secret in src/components/auth/login-modal.tsx"}, "properties": {"repobilityId": "ea2e5f4fa8d977eb", "scanner": "scanner-primary", "fingerprint": "e389f4af196fb8dc", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/components/auth/login-modal.tsx"}, "region": {"startLine": 131}}}]}, {"ruleId": "scanner-73cac6004da3ba33", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in src/lib/api-client.ts:266"}, "properties": {"repobilityId": "0439d037ff4d95a6", "scanner": "scanner-primary", "fingerprint": "73cac6004da3ba33", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lib/api-client.ts"}, "region": {"startLine": 266}}}]}, {"ruleId": "scanner-65c561827a3f3d93", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "66c8c8cbdc7d6c80", "scanner": "scanner-primary", "fingerprint": "65c561827a3f3d93", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy-templates.yml"}, "region": {"startLine": 70}}}]}, {"ruleId": "scanner-65c561827a3f3d93", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "cdbf2266c8ce7f2b", "scanner": "scanner-primary", "fingerprint": "65c561827a3f3d93", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy-templates.yml"}, "region": {"startLine": 77}}}]}, {"ruleId": "scanner-65c561827a3f3d93", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "f3edeb55b1086375", "scanner": "scanner-primary", "fingerprint": "65c561827a3f3d93", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy-templates.yml"}, "region": {"startLine": 83}}}]}, {"ruleId": "scanner-65c561827a3f3d93", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "756d519871c4d8fe", "scanner": "scanner-primary", "fingerprint": "65c561827a3f3d93", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy-templates.yml"}, "region": {"startLine": 88}}}]}, {"ruleId": "scanner-65c561827a3f3d93", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ba3bc84051e45661", "scanner": "scanner-primary", "fingerprint": "65c561827a3f3d93", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy-templates.yml"}, "region": {"startLine": 114}}}]}, {"ruleId": "scanner-1d988a919dff22ba", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "cbe7a020715ca775", "scanner": "scanner-primary", "fingerprint": "1d988a919dff22ba", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/upstream-notifications.yml"}, "region": {"startLine": 19}}}]}, {"ruleId": "scanner-28c4a04bd807da0c", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "2aee2e2d969c7c6b", "scanner": "scanner-primary", "fingerprint": "28c4a04bd807da0c", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy.yml"}, "region": {"startLine": 43}}}]}, {"ruleId": "scanner-28c4a04bd807da0c", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "6bc71594f1f99392", "scanner": "scanner-primary", "fingerprint": "28c4a04bd807da0c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy.yml"}, "region": {"startLine": 46}}}]}, {"ruleId": "scanner-28c4a04bd807da0c", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "bee6b8956e03198c", "scanner": "scanner-primary", "fingerprint": "28c4a04bd807da0c", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy.yml"}, "region": {"startLine": 55}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ae16880318b99912", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 27}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "9e71a599ca1555f0", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 30}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "54c8f1b47dd62535", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 40}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ae16880318b99912", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 57}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "9e71a599ca1555f0", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 60}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "54c8f1b47dd62535", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 65}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ae16880318b99912", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 84}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "9e71a599ca1555f0", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 87}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "54c8f1b47dd62535", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 92}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ae16880318b99912", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 111}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "9e71a599ca1555f0", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 114}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "54c8f1b47dd62535", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 119}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "bd7f3c1c34d83159", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 133}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ae16880318b99912", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 145}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "9e71a599ca1555f0", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 148}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "989a74409a402368", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 157}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "54c8f1b47dd62535", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 162}}}]}, {"ruleId": "scanner-26b9b311e08cf9b3", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "19282a3e6c94e9f4", "scanner": "scanner-primary", "fingerprint": "26b9b311e08cf9b3", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/upstream-sync-manual.yml"}, "region": {"startLine": 38}}}]}, {"ruleId": "scanner-26b9b311e08cf9b3", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "970ac9a5520acbc2", "scanner": "scanner-primary", "fingerprint": "26b9b311e08cf9b3", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/upstream-sync-manual.yml"}, "region": {"startLine": 347}}}]}, {"ruleId": "scanner-0a8684948b726644", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "2805776cf94fc8a3", "scanner": "scanner-primary", "fingerprint": "0a8684948b726644", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/upstream-sync-manual.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9cc0655987a97af2", "level": "note", "message": {"text": "Very large file: scripts/deploy.ts (2131 lines)"}, "properties": {"repobilityId": "ec78a9dc22010f37", "scanner": "scanner-primary", "fingerprint": "9cc0655987a97af2", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-b04992e15589bde0", "level": "note", "message": {"text": "Very large file: scripts/setup.ts (2121 lines)"}, "properties": {"repobilityId": "d233e02e17493471", "scanner": "scanner-primary", "fingerprint": "b04992e15589bde0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-196b806a3bb262d3", "level": "note", "message": {"text": "Very large file: worker/agents/prompts.ts (1502 lines)"}, "properties": {"repobilityId": "256f15d585acade1", "scanner": "scanner-primary", "fingerprint": "196b806a3bb262d3", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-cafe4da8d3aae386", "level": "note", "message": {"text": "Very large file: worker/agents/inferutils/schemaFormatters.ts (1311 lines)"}, "properties": {"repobilityId": "55c4bdf32d388527", "scanner": "scanner-primary", "fingerprint": "cafe4da8d3aae386", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6d0e1ec0d57b212f", "level": "note", "message": {"text": "Very large file: worker/agents/core/simpleGeneratorAgent.ts (2863 lines)"}, "properties": {"repobilityId": "83112b93b09d99ee", "scanner": "scanner-primary", "fingerprint": "6d0e1ec0d57b212f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-a332ff368b948a83", "level": "note", "message": {"text": "Very large file: worker/agents/core/behaviors/base.ts (2398 lines)"}, "properties": {"repobilityId": "e8e409469a1b325f", "scanner": "scanner-primary", "fingerprint": "a332ff368b948a83", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-5896b6d3b21a2338", "level": "note", "message": {"text": "Very large file: worker/services/sandbox/sandboxSdkClient.ts (2919 lines)"}, "properties": {"repobilityId": "c1d6218204976f3a", "scanner": "scanner-primary", "fingerprint": "5896b6d3b21a2338", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-676477bb83db1a0d", "level": "note", "message": {"text": "Very large file: container/monitor-cli.test.ts (3052 lines)"}, "properties": {"repobilityId": "e92e99a9668f267b", "scanner": "scanner-primary", "fingerprint": "676477bb83db1a0d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-8ef8053939e60cf6", "level": "note", "message": {"text": "Very large file: src/routes/settings/index.tsx (1834 lines)"}, "properties": {"repobilityId": "29bba5ccf3cacbad", "scanner": "scanner-primary", "fingerprint": "8ef8053939e60cf6", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-7213b6460487be67", "level": "note", "message": {"text": "Very large file: src/routes/chat/components/debug-panel.tsx (1099 lines)"}, "properties": {"repobilityId": "10e83ee633df3faa", "scanner": "scanner-primary", "fingerprint": "7213b6460487be67", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-c7659ce6e2b0e01f", "level": "note", "message": {"text": "40 TODO/FIXME markers"}, "properties": {"repobilityId": "4b38c118003e07d2", "scanner": "scanner-primary", "fingerprint": "c7659ce6e2b0e01f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["maintenance"]}}, {"ruleId": "scanner-bed23407a409157d", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: container/package.json"}, "properties": {"repobilityId": "ae2a9196cd8742b5", "scanner": "scanner-primary", "fingerprint": "bed23407a409157d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "container/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "3d15350a74d1a48f", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "6052d175ee95ef76", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "70481ea4e590f295", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "d97fa76f35bd428c", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "410c0c8b737df743", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "f24e587aeeb82650", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-478734530777971a", "level": "none", "message": {"text": "Commented-code block (5 lines) in vite.config.ts:18"}, "properties": {"repobilityId": "f04c6afa2b951f4c", "scanner": "scanner-primary", "fingerprint": "478734530777971a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a0cb745fd34cebe1", "level": "none", "message": {"text": "Commented-code block (5 lines) in worker-secrets.d.ts:107"}, "properties": {"repobilityId": "441ac438f1cbb816", "scanner": "scanner-primary", "fingerprint": "a0cb745fd34cebe1", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5eb9522e8f6f1530", "level": "none", "message": {"text": "Commented-code block (6 lines) in drizzle.config.remote.ts:6"}, "properties": {"repobilityId": "76c239915a517b56", "scanner": "scanner-primary", "fingerprint": "5eb9522e8f6f1530", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5c0c4674518104e0", "level": "none", "message": {"text": "Commented-code block (6 lines) in drizzle.config.local.ts:6"}, "properties": {"repobilityId": "bd22d8654f6e5fad", "scanner": "scanner-primary", "fingerprint": "5c0c4674518104e0", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f1414c3634019472", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/copy-landing-pages.ts:19"}, "properties": {"repobilityId": "2d572bbba5719f28", "scanner": "scanner-primary", "fingerprint": "f1414c3634019472", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-77400a26c84ab59a", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/setup.ts:692"}, "properties": {"repobilityId": "025c639984740ba9", "scanner": "scanner-primary", "fingerprint": "77400a26c84ab59a", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-0dfe07e59be37b31", "level": "none", "message": {"text": "Commented-code block (7 lines) in worker/index.ts:221"}, "properties": {"repobilityId": "593ed0c728cabe30", "scanner": "scanner-primary", "fingerprint": "0dfe07e59be37b31", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-463f107c33a44e82", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/index.ts:111"}, "properties": {"repobilityId": "a22bcd86d14991f2", "scanner": "scanner-primary", "fingerprint": "463f107c33a44e82", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-f4f70b98bafbeb40", "level": "none", "message": {"text": "Commented-code block (6 lines) in worker/app.ts:34"}, "properties": {"repobilityId": "af6a512498f99ade", "scanner": "scanner-primary", "fingerprint": "f4f70b98bafbeb40", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4a3b29b039525cfb", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/app.ts:129"}, "properties": {"repobilityId": "5f8165c026f9eb7a", "scanner": "scanner-primary", "fingerprint": "4a3b29b039525cfb", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-2e06af67eff6e159", "level": "none", "message": {"text": "Commented-code block (9 lines) in worker/api/websocketTypes.ts:386"}, "properties": {"repobilityId": "6a90e69892993a79", "scanner": "scanner-primary", "fingerprint": "2e06af67eff6e159", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e1e157a6c3d5646b", "level": "none", "message": {"text": "Commented-code block (5 lines) in worker/api/routes/imagesRoutes.ts:15"}, "properties": {"repobilityId": "a80ace7ec640ff14", "scanner": "scanner-primary", "fingerprint": "e1e157a6c3d5646b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-04d16fa7e7909102", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/api/routes/byopRoutes.ts:66"}, "properties": {"repobilityId": "e1a6c67355afdd67", "scanner": "scanner-primary", "fingerprint": "04d16fa7e7909102", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-14b156d70f1e4afb", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/api/controllers/sentry/tunnelController.ts:66"}, "properties": {"repobilityId": "9f88d2321cde983c", "scanner": "scanner-primary", "fingerprint": "14b156d70f1e4afb", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-fd96f7f9ccc71bab", "level": "none", "message": {"text": "Commented-code block (6 lines) in worker/api/controllers/agent/controller.ts:134"}, "properties": {"repobilityId": "1e5d9cf184eca932", "scanner": "scanner-primary", "fingerprint": "fd96f7f9ccc71bab", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ffba49218ffbe36b", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/api/controllers/agent/controller.ts:286"}, "properties": {"repobilityId": "2e17fb7fa5c761bd", "scanner": "scanner-primary", "fingerprint": "ffba49218ffbe36b", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-baf4d5f81a696acf", "level": "none", "message": {"text": "Commented-code block (10 lines) in worker/api/controllers/screenshots/controller.ts:52"}, "properties": {"repobilityId": "241bb7b922819ca0", "scanner": "scanner-primary", "fingerprint": "baf4d5f81a696acf", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0946ae073ba824cb", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/api/controllers/byop/controller.ts:366"}, "properties": {"repobilityId": "de115e8a65a2e90b", "scanner": "scanner-primary", "fingerprint": "0946ae073ba824cb", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-7568848ad52acb78", "level": "none", "message": {"text": "Commented-code block (5 lines) in worker/api/controllers/appView/controller.ts:116"}, "properties": {"repobilityId": "da8671cbdc8011bb", "scanner": "scanner-primary", "fingerprint": "7568848ad52acb78", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1a61737afd4af148", "level": "none", "message": {"text": "Commented-code block (6 lines) in worker/api/controllers/appView/types.ts:41"}, "properties": {"repobilityId": "8296715dccaf3639", "scanner": "scanner-primary", "fingerprint": "1a61737afd4af148", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6da1e6dde057805d", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/utils/images.ts:112"}, "properties": {"repobilityId": "a67ce9483e754013", "scanner": "scanner-primary", "fingerprint": "6da1e6dde057805d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-c525423ee8cfc394", "level": "none", "message": {"text": "Commented-code block (5 lines) in worker/observability/sentry.ts:34"}, "properties": {"repobilityId": "f907396f88143d33", "scanner": "scanner-primary", "fingerprint": "c525423ee8cfc394", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-64cf2e4805335182", "level": "none", "message": {"text": "Commented-code block (5 lines) in worker/agents/prompts.ts:1285"}, "properties": {"repobilityId": "de454cb69c0e6345", "scanner": "scanner-primary", "fingerprint": "64cf2e4805335182", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2cf2785742d552cc", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/agents/prompts.ts:566"}, "properties": {"repobilityId": "d242353b0c36ed25", "scanner": "scanner-primary", "fingerprint": "2cf2785742d552cc", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-ee37f36e301972eb", "level": "none", "message": {"text": "Commented-code block (6 lines) in worker/agents/constants.ts:78"}, "properties": {"repobilityId": "b35689d21225aa90", "scanner": "scanner-primary", "fingerprint": "ee37f36e301972eb", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d00b2925f1b6178c", "level": "none", "message": {"text": "Commented-code block (17 lines) in worker/agents/operations/PhaseImplementation.ts:304"}, "properties": {"repobilityId": "ba93f7a11bba70e6", "scanner": "scanner-primary", "fingerprint": "d00b2925f1b6178c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3710a4dd2660c84f", "level": "none", "message": {"text": "Commented-code block (6 lines) in worker/agents/operations/ImageGeneration.ts:78"}, "properties": {"repobilityId": "828369847eab4845", "scanner": "scanner-primary", "fingerprint": "3710a4dd2660c84f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5c079bd69c233fd4", "level": "none", "message": {"text": "Commented-code block (6 lines) in worker/agents/operations/SimpleCodeGeneration.ts:10"}, "properties": {"repobilityId": "728e30bd903b69e1", "scanner": "scanner-primary", "fingerprint": "5c079bd69c233fd4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-367f854f186d7cb5", "level": "none", "message": {"text": "Commented-code block (11 lines) in worker/agents/inferutils/config.ts:70"}, "properties": {"repobilityId": "65dc0f8d10f3cd62", "scanner": "scanner-primary", "fingerprint": "367f854f186d7cb5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-47e2ca83c5821ef7", "level": "none", "message": {"text": "Commented-code block (6 lines) in worker/agents/inferutils/schemaFormatters.ts:54"}, "properties": {"repobilityId": "8ce33113fb132442", "scanner": "scanner-primary", "fingerprint": "47e2ca83c5821ef7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d802c7dce1d99800", "level": "none", "message": {"text": "Commented-code block (6 lines) in worker/agents/inferutils/core.ts:178"}, "properties": {"repobilityId": "e109061e84fca72a", "scanner": "scanner-primary", "fingerprint": "d802c7dce1d99800", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1062749f2e3aa946", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/agents/inferutils/imageGeneration.ts:144"}, "properties": {"repobilityId": "cd23d97fae595376", "scanner": "scanner-primary", "fingerprint": "1062749f2e3aa946", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-c509f11fafc0a727", "level": "none", "message": {"text": "Commented-code block (6 lines) in worker/agents/services/implementations/DeploymentManager.ts:108"}, "properties": {"repobilityId": "7e302987796df082", "scanner": "scanner-primary", "fingerprint": "c509f11fafc0a727", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1eda569cd0842355", "level": "none", "message": {"text": "Commented-code block (5 lines) in worker/agents/core/codingAgent.ts:155"}, "properties": {"repobilityId": "c66cf0565319ebac", "scanner": "scanner-primary", "fingerprint": "1eda569cd0842355", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f27507211fc99b08", "level": "none", "message": {"text": "Commented-code block (12 lines) in worker/agents/core/state.ts:171"}, "properties": {"repobilityId": "8faa94657dcd7a3c", "scanner": "scanner-primary", "fingerprint": "f27507211fc99b08", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-63b3be3d821de9f4", "level": "none", "message": {"text": "Commented-code block (7 lines) in worker/agents/core/websocket.ts:227"}, "properties": {"repobilityId": "dec94b96ea2c39b2", "scanner": "scanner-primary", "fingerprint": "63b3be3d821de9f4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-03fcf2e2b0720169", "level": "note", "message": {"text": "Legacy-named symbol `stateWithDeprecated` in worker/agents/core/stateMigration.ts:273"}, "properties": {"repobilityId": "4554df317655e5f2", "scanner": "scanner-primary", "fingerprint": "03fcf2e2b0720169", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-91886f0db1e0759c", "level": "none", "message": {"text": "Commented-code block (5 lines) in worker/agents/core/stateMigration.ts:281"}, "properties": {"repobilityId": "2b0a364b81cb1ee8", "scanner": "scanner-primary", "fingerprint": "91886f0db1e0759c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-cce0caf8b13c1b0e", "level": "none", "message": {"text": "Commented-code block (6 lines) in worker/agents/core/simpleGeneratorAgent.ts:154"}, "properties": {"repobilityId": "1a01dae4569936cc", "scanner": "scanner-primary", "fingerprint": "cce0caf8b13c1b0e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2820793b503d38ba", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/agents/core/simpleGeneratorAgent.ts:2243"}, "properties": {"repobilityId": "2085687d1ece5474", "scanner": "scanner-primary", "fingerprint": "2820793b503d38ba", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-7c3d5ec1577a22c3", "level": "none", "message": {"text": "Commented-code block (5 lines) in worker/agents/core/behaviors/base.ts:516"}, "properties": {"repobilityId": "1b9f9310008bbf8a", "scanner": "scanner-primary", "fingerprint": "7c3d5ec1577a22c3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-34d4c531b88f0e84", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/agents/core/behaviors/base.ts:1772"}, "properties": {"repobilityId": "f1d873465acfea9c", "scanner": "scanner-primary", "fingerprint": "34d4c531b88f0e84", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-2c418cf1638573ed", "level": "none", "message": {"text": "Commented-code block (5 lines) in worker/agents/core/behaviors/agentic.ts:133"}, "properties": {"repobilityId": "22a8d00420232252", "scanner": "scanner-primary", "fingerprint": "2c418cf1638573ed", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7f03383971e1eca8", "level": "none", "message": {"text": "Commented-code block (8 lines) in worker/agents/core/behaviors/phasic.ts:321"}, "properties": {"repobilityId": "dd3b2af54f7eeaaf", "scanner": "scanner-primary", "fingerprint": "7f03383971e1eca8", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-57f75a32de48e1ac", "level": "none", "message": {"text": "Commented-code block (5 lines) in worker/agents/output-formats/streaming-formats/xml-stream.ts:161"}, "properties": {"repobilityId": "230104ea6510ba1f", "scanner": "scanner-primary", "fingerprint": "57f75a32de48e1ac", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b06e37550f479d87", "level": "none", "message": {"text": "Commented-code block (5 lines) in worker/agents/output-formats/streaming-formats/base.ts:18"}, "properties": {"repobilityId": "502fbf6bbfea47d2", "scanner": "scanner-primary", "fingerprint": "b06e37550f479d87", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c5201f1b9501a7cf", "level": "none", "message": {"text": "Commented-code block (7 lines) in worker/agents/output-formats/diff-formats/udiff-comprehensive.test.ts:509"}, "properties": {"repobilityId": "c15e6635a54b2279", "scanner": "scanner-primary", "fingerprint": "c5201f1b9501a7cf", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8d84428e51a8b986", "level": "none", "message": {"text": "Commented-code block (6 lines) in worker/agents/prompts/designSkills.ts:97"}, "properties": {"repobilityId": "3b135cdb1533c8a0", "scanner": "scanner-primary", "fingerprint": "8d84428e51a8b986", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-916351c80b93409e", "level": "none", "message": {"text": "Commented-code block (5 lines) in worker/agents/planning/blueprint.ts:341"}, "properties": {"repobilityId": "1457b5a3f268ca48", "scanner": "scanner-primary", "fingerprint": "916351c80b93409e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7f9e2c06c6376087", "level": "none", "message": {"text": "Commented-code block (6 lines) in worker/agents/domain/values/GenerationContext.ts:34"}, "properties": {"repobilityId": "6baf9ecc3f97deb0", "scanner": "scanner-primary", "fingerprint": "7f9e2c06c6376087", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-00b5383a5ad68213", "level": "none", "message": {"text": "Commented-code block (6 lines) in worker/services/code-fixer/index.ts:176"}, "properties": {"repobilityId": "ccf2ce58175c9541", "scanner": "scanner-primary", "fingerprint": "00b5383a5ad68213", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-cbc17e807200077e", "level": "none", "message": {"text": "Commented-code block (6 lines) in worker/services/rate-limit/usageChecker.ts:287"}, "properties": {"repobilityId": "b6e9c2c20b6f4610", "scanner": "scanner-primary", "fingerprint": "cbc17e807200077e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a4a4716369c52c1c", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/services/migration/cloudflare-compatibility-checker.ts:274"}, "properties": {"repobilityId": "3912f24f5bc251f8", "scanner": "scanner-primary", "fingerprint": "a4a4716369c52c1c", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-4b740607ce1e7c6a", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/services/oauth/github.ts:62"}, "properties": {"repobilityId": "5bcbe7198a26c0f1", "scanner": "scanner-primary", "fingerprint": "4b740607ce1e7c6a", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-ffc43119d20cf1e2", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/services/oauth/base.ts:99"}, "properties": {"repobilityId": "5d80834d20e50503", "scanner": "scanner-primary", "fingerprint": "ffc43119d20cf1e2", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-b88fc7eee3a697fd", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/services/sandbox/resourceProvisioner.ts:72"}, "properties": {"repobilityId": "556b0a8b310a73b9", "scanner": "scanner-primary", "fingerprint": "b88fc7eee3a697fd", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-4bf3aa2638d69377", "level": "none", "message": {"text": "Commented-code block (7 lines) in worker/services/sandbox/sandboxSdkClient.ts:419"}, "properties": {"repobilityId": "11f72a7ed1b9e125", "scanner": "scanner-primary", "fingerprint": "4bf3aa2638d69377", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b4a5c92fa2bb8b81", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/services/sandbox/remoteSandboxService.ts:42"}, "properties": {"repobilityId": "043487a711975121", "scanner": "scanner-primary", "fingerprint": "b4a5c92fa2bb8b81", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-53f4c1519dc4a5f6", "level": "none", "message": {"text": "Commented-code block (5 lines) in worker/services/sandbox/BaseSandboxService.ts:93"}, "properties": {"repobilityId": "e61eae1e460cce46", "scanner": "scanner-primary", "fingerprint": "53f4c1519dc4a5f6", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2db6b71f1d18df18", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/services/deployer/api/cloudflare-api.ts:43"}, "properties": {"repobilityId": "c1427884598815e0", "scanner": "scanner-primary", "fingerprint": "2db6b71f1d18df18", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-40a11f5f447c1198", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 worker/services/aigateway-proxy/controller.ts:186"}, "properties": {"repobilityId": "cacb7f67744eb2c5", "scanner": "scanner-primary", "fingerprint": "40a11f5f447c1198", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-52b18a38526c3534", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 container/monitor-cli.test.ts:2492"}, "properties": {"repobilityId": "5bf2ae240e564e37", "scanner": "scanner-primary", "fingerprint": "52b18a38526c3534", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-6f938c411f20d3d1", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/App.tsx:11"}, "properties": {"repobilityId": "8c4bd7777ed28e96", "scanner": "scanner-primary", "fingerprint": "6f938c411f20d3d1", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-21744f79279183b2", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/components/auth/login-modal.tsx:12"}, "properties": {"repobilityId": "cd044d1ee85e6258", "scanner": "scanner-primary", "fingerprint": "21744f79279183b2", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5eca11a143145372", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/contexts/auth-context.tsx:145"}, "properties": {"repobilityId": "6b91a57bbf51588b", "scanner": "scanner-primary", "fingerprint": "5eca11a143145372", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-cf7202474f2a2fbf", "level": "none", "message": {"text": "Commented-code block (8 lines) in src/lib/api-client.ts:545"}, "properties": {"repobilityId": "6e1114aaff004abe", "scanner": "scanner-primary", "fingerprint": "cf7202474f2a2fbf", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a31fe86961c9897e", "level": "none", "message": {"text": "Commented-code block (11 lines) in src/routes/settings/index.tsx:136"}, "properties": {"repobilityId": "feb629a16d67eade", "scanner": "scanner-primary", "fingerprint": "a31fe86961c9897e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2bd421deb70f3512", "level": "none", "message": {"text": "Commented-code block (11 lines) in src/routes/chat/chat.tsx:247"}, "properties": {"repobilityId": "f4adc4ba0617d0a7", "scanner": "scanner-primary", "fingerprint": "2bd421deb70f3512", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1e7f989b08e782db", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/routes/chat/mocks/file-mock.ts:223"}, "properties": {"repobilityId": "a3a16ee56b112cf8", "scanner": "scanner-primary", "fingerprint": "1e7f989b08e782db", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-1ab1c967d0f22301", "level": "none", "message": {"text": "Commented-code block (7 lines) in src/routes/chat/utils/handle-websocket-message.ts:765"}, "properties": {"repobilityId": "9e2e0acfb4bd44f0", "scanner": "scanner-primary", "fingerprint": "1ab1c967d0f22301", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7136d9163cecd930", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/routes/chat/components/preview-iframe.tsx:216"}, "properties": {"repobilityId": "1fc6c40b5937e20f", "scanner": "scanner-primary", "fingerprint": "7136d9163cecd930", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-001b3ff371d37af5", "level": "none", "message": {"text": "Commented-code block (13 lines) in src/routes/chat/hooks/use-chat.ts:6"}, "properties": {"repobilityId": "6287d842e7d9ab71", "scanner": "scanner-primary", "fingerprint": "001b3ff371d37af5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-59db4a95ef32fef6", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/routes/app/index.tsx:219"}, "properties": {"repobilityId": "1046b43e8d8a55ec", "scanner": "scanner-primary", "fingerprint": "59db4a95ef32fef6", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7879703ff6ef75a4", "level": "note", "message": {"text": "Legacy-named symbol `ai_request_analyzer_v2` in debug-tools/ai_request_analyzer_v2.py:19"}, "properties": {"repobilityId": "3384fe5c7559217d", "scanner": "scanner-primary", "fingerprint": "7879703ff6ef75a4", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-207b1a4a15d4006b", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 debug-tools/test-ai-gateway-analytics.ts:563"}, "properties": {"repobilityId": "01003180c99e7d03", "scanner": "scanner-primary", "fingerprint": "207b1a4a15d4006b", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "76eedc4c783e4919", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-325e8f5f7a1d76c9", "level": "error", "message": {"text": "Dangling fetch: GET http://example.com/api/byop/repositories (tests/integration/controllers/BYOPController.test.ts:35)"}, "properties": {"repobilityId": "0516e40fc46fec9b", "scanner": "scanner-primary", "fingerprint": "325e8f5f7a1d76c9", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-332e543768642f74", "level": "error", "message": {"text": "Dangling fetch: GET http://example.com/api/byop/repositories (tests/integration/controllers/BYOPController.test.ts:57)"}, "properties": {"repobilityId": "e5a2f71b002c4363", "scanner": "scanner-primary", "fingerprint": "332e543768642f74", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-34e719cf438b2cff", "level": "error", "message": {"text": "Dangling fetch: GET http://example.com/api/byop/repositories (tests/integration/controllers/BYOPController.test.ts:73)"}, "properties": {"repobilityId": "9ea6b4038e14459a", "scanner": "scanner-primary", "fingerprint": "34e719cf438b2cff", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-969db090a2af681f", "level": "error", "message": {"text": "Dangling fetch: GET http://example.com/api/byop/repositories (tests/integration/controllers/BYOPController.test.ts:96)"}, "properties": {"repobilityId": "7cd3ff6a88609a10", "scanner": "scanner-primary", "fingerprint": "969db090a2af681f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-61a21a29fa4ba623", "level": "error", "message": {"text": "Dangling fetch: GET http://example.com/api/byop/repositories (tests/integration/controllers/BYOPController.test.ts:114)"}, "properties": {"repobilityId": "41e064ee45f55e18", "scanner": "scanner-primary", "fingerprint": "61a21a29fa4ba623", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-0d668978e22c087d", "level": "error", "message": {"text": "Dangling fetch: GET http://example.com/api/byop/repositories (tests/integration/controllers/BYOPController.test.ts:130)"}, "properties": {"repobilityId": "68b5fafb5373fcf0", "scanner": "scanner-primary", "fingerprint": "0d668978e22c087d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-b0d932777eed0425", "level": "error", "message": {"text": "Dangling fetch: POST http://example.com/api/byop/import (tests/integration/controllers/BYOPController.test.ts:149)"}, "properties": {"repobilityId": "9bd21cecd71b3aec", "scanner": "scanner-primary", "fingerprint": "b0d932777eed0425", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-b3ff73257a9355f0", "level": "error", "message": {"text": "Dangling fetch: POST http://example.com/api/byop/import (tests/integration/controllers/BYOPController.test.ts:193)"}, "properties": {"repobilityId": "61b68e5c43b982d8", "scanner": "scanner-primary", "fingerprint": "b3ff73257a9355f0", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-025347382519b90a", "level": "error", "message": {"text": "Dangling fetch: POST http://example.com/api/byop/import (tests/integration/controllers/BYOPController.test.ts:219)"}, "properties": {"repobilityId": "19ea27d60602e323", "scanner": "scanner-primary", "fingerprint": "025347382519b90a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-d1e294b7cd931fe2", "level": "error", "message": {"text": "Dangling fetch: POST http://example.com/api/byop/import (tests/integration/controllers/BYOPController.test.ts:239)"}, "properties": {"repobilityId": "e2ba0ddedf99be2d", "scanner": "scanner-primary", "fingerprint": "d1e294b7cd931fe2", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-db6e1dd32ad47a50", "level": "error", "message": {"text": "Dangling fetch: POST http://example.com/api/byop/import (tests/integration/controllers/BYOPController.test.ts:257)"}, "properties": {"repobilityId": "e1f3795d2e8c69c4", "scanner": "scanner-primary", "fingerprint": "db6e1dd32ad47a50", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-7f84ec73a132760f", "level": "error", "message": {"text": "Dangling fetch: POST http://example.com/api/byop/import (tests/integration/controllers/BYOPController.test.ts:280)"}, "properties": {"repobilityId": "f79d9c96e8af1e33", "scanner": "scanner-primary", "fingerprint": "7f84ec73a132760f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-6744f97cb8da5c05", "level": "error", "message": {"text": "Dangling fetch: POST http://example.com/api/byop/import (tests/integration/controllers/BYOPController.test.ts:300)"}, "properties": {"repobilityId": "e9c290f1e3131c72", "scanner": "scanner-primary", "fingerprint": "6744f97cb8da5c05", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-43b80d5444c9734b", "level": "error", "message": {"text": "Dangling fetch: POST http://example.com/api/byop/import (tests/integration/controllers/BYOPController.test.ts:327)"}, "properties": {"repobilityId": "0b3626aff5e1e1a3", "scanner": "scanner-primary", "fingerprint": "43b80d5444c9734b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-655e7acdce53e86a", "level": "error", "message": {"text": "Dangling fetch: GET http://example.com/api/byop/analysis/${analysisId}/status (tests/integration/controllers/BYOPController.test.ts:343)"}, "properties": {"repobilityId": "4c7d4ed85acd365c", "scanner": "scanner-primary", "fingerprint": "655e7acdce53e86a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-dc94b606c3fdaf46", "level": "error", "message": {"text": "Dangling fetch: GET http://example.com/api/byop/analysis/invalid-id/status (tests/integration/controllers/BYOPController.test.ts:366)"}, "properties": {"repobilityId": "c9b4b97a61a4a75a", "scanner": "scanner-primary", "fingerprint": "dc94b606c3fdaf46", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-64890ab793cbd407", "level": "error", "message": {"text": "Dangling fetch: GET http://example.com/api/byop/analysis/some-id/status (tests/integration/controllers/BYOPController.test.ts:380)"}, "properties": {"repobilityId": "6f3ba0b2acfaade9", "scanner": "scanner-primary", "fingerprint": "64890ab793cbd407", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-5cc0c7c9e5a0ed8f", "level": "error", "message": {"text": "Dangling fetch: GET http://example.com/api/byop/analysis/${analysisId}/blueprint (tests/integration/controllers/BYOPController.test.ts:401)"}, "properties": {"repobilityId": "7f725122aff7bcc0", "scanner": "scanner-primary", "fingerprint": "5cc0c7c9e5a0ed8f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-44173e4b438b8c5c", "level": "error", "message": {"text": "Dangling fetch: GET http://example.com/api/byop/analysis/${analysisId}/blueprint (tests/integration/controllers/BYOPController.test.ts:420)"}, "properties": {"repobilityId": "69457cc300b9720a", "scanner": "scanner-primary", "fingerprint": "44173e4b438b8c5c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-87814fe423d4ecb4", "level": "error", "message": {"text": "Dangling fetch: GET http://example.com/api/byop/analysis/${analysisId}/blueprint (tests/integration/controllers/BYOPController.test.ts:439)"}, "properties": {"repobilityId": "f5aab1bec7597c44", "scanner": "scanner-primary", "fingerprint": "87814fe423d4ecb4", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-6a9c92e8bd2fdd33", "level": "error", "message": {"text": "Dangling fetch: GET http://example.com/api/byop/analysis/${analysisId}/blueprint (tests/integration/controllers/BYOPController.test.ts:465)"}, "properties": {"repobilityId": "f8cda3876c9cacfc", "scanner": "scanner-primary", "fingerprint": "6a9c92e8bd2fdd33", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-27f57aaf053f091e", "level": "error", "message": {"text": "Dangling fetch: GET http://example.com/api/byop/repositories (tests/e2e/byop-happy-path.test.ts:63)"}, "properties": {"repobilityId": "e0de4523883f70a7", "scanner": "scanner-primary", "fingerprint": "27f57aaf053f091e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-665a122b3cf85d9c", "level": "error", "message": {"text": "Dangling fetch: POST http://example.com/api/byop/import (tests/e2e/byop-happy-path.test.ts:88)"}, "properties": {"repobilityId": "c0938e4ace97d2f9", "scanner": "scanner-primary", "fingerprint": "665a122b3cf85d9c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-67a8816015aa3ed2", "level": "error", "message": {"text": "Dangling fetch: GET http://example.com/api/byop/analysis/${analysisId}/status (tests/e2e/byop-happy-path.test.ts:160)"}, "properties": {"repobilityId": "70194aa290dadebb", "scanner": "scanner-primary", "fingerprint": "67a8816015aa3ed2", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-082868c09e5cf98e", "level": "error", "message": {"text": "Dangling fetch: GET http://example.com/api/byop/analysis/${analysisId}/blueprint (tests/e2e/byop-happy-path.test.ts:189)"}, "properties": {"repobilityId": "c1b8b2e56148cd37", "scanner": "scanner-primary", "fingerprint": "082868c09e5cf98e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-be1545c032bb1d05", "level": "error", "message": {"text": "Dangling fetch: POST http://example.com/api/byop/import (tests/e2e/byop-happy-path.test.ts:256)"}, "properties": {"repobilityId": "4990dac269ee79ac", "scanner": "scanner-primary", "fingerprint": "be1545c032bb1d05", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-bfb0b7748d510bf2", "level": "error", "message": {"text": "Dangling fetch: GET http://example.com/api/byop/analysis/${firstData.analysisId}/blueprint (tests/e2e/byop-happy-path.test.ts:282)"}, "properties": {"repobilityId": "69ef2b5d103d9f13", "scanner": "scanner-primary", "fingerprint": "bfb0b7748d510bf2", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-e3302804c6e1b7d6", "level": "error", "message": {"text": "Dangling fetch: POST http://example.com/api/byop/import (tests/e2e/byop-happy-path.test.ts:297)"}, "properties": {"repobilityId": "c3c71d0e507ddf7e", "scanner": "scanner-primary", "fingerprint": "e3302804c6e1b7d6", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-e880300d9957e246", "level": "error", "message": {"text": "Dangling fetch: GET https://api.cloudflare.com/client/v4/user/tokens/verify (scripts/deploy.ts:424)"}, "properties": {"repobilityId": "1c19420438583572", "scanner": "scanner-primary", "fingerprint": "e880300d9957e246", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-b498b356bf22a832", "level": "error", "message": {"text": "Dangling fetch: POST https://api.cloudflare.com/client/v4/user/tokens (scripts/deploy.ts:482)"}, "properties": {"repobilityId": "4d40afd42dcd42e9", "scanner": "scanner-primary", "fingerprint": "b498b356bf22a832", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-2f873bb2027e6426", "level": "error", "message": {"text": "Dangling fetch: GET https://api.cloudflare.com/client/v4/zones?name=${encodeURIComponent(zoneName)} (scripts/deploy.ts:856)"}, "properties": {"repobilityId": "4159592eae5cad15", "scanner": "scanner-primary", "fingerprint": "2f873bb2027e6426", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-3bb9deb249972d36", "level": "error", "message": {"text": "Dangling fetch: GET https://api.cloudflare.com/client/v4/accounts/${this.config.accountId}/storage/kv/namespaces (scripts/setup.ts:669)"}, "properties": {"repobilityId": "af7d922f769f1f82", "scanner": "scanner-primary", "fingerprint": "3bb9deb249972d36", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-4fab352b9851d967", "level": "error", "message": {"text": "Dangling fetch: POST https://api.cloudflare.com/client/v4/accounts/${this.config.accountId}/storage/kv/namespaces (scripts/setup.ts:692)"}, "properties": {"repobilityId": "da566b8ae479136e", "scanner": "scanner-primary", "fingerprint": "4fab352b9851d967", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-c31738605d2b2c28", "level": "error", "message": {"text": "Dangling fetch: GET https://api.cloudflare.com/client/v4/accounts/${this.config.accountId}/r2/buckets/${bucketName} (scripts/setup.ts:803)"}, "properties": {"repobilityId": "c02206c1d5f12812", "scanner": "scanner-primary", "fingerprint": "c31738605d2b2c28", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-355a7d2db148b0b1", "level": "error", "message": {"text": "Dangling fetch: POST https://api.cloudflare.com/client/v4/accounts/${this.config.accountId}/r2/buckets (scripts/setup.ts:820)"}, "properties": {"repobilityId": "12c6bfc8f0d5202f", "scanner": "scanner-primary", "fingerprint": "355a7d2db148b0b1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-ac64cc32cf0b5d7d", "level": "error", "message": {"text": "Dangling fetch: GET https://api.cloudflare.com/client/v4/user/tokens/verify (scripts/setup.ts:950)"}, "properties": {"repobilityId": "6702f62167326c79", "scanner": "scanner-primary", "fingerprint": "ac64cc32cf0b5d7d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-f4821a82dd18dad5", "level": "error", "message": {"text": "Dangling fetch: GET https://api.cloudflare.com/client/v4/user/tokens/permission_groups?name=AI%20Gateway (scripts/setup.ts:971)"}, "properties": {"repobilityId": "3d5f6add2fd491ec", "scanner": "scanner-primary", "fingerprint": "f4821a82dd18dad5", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-62dabcbaa4bee4ee", "level": "error", "message": {"text": "Dangling fetch: GET https://api.cloudflare.com/client/v4/accounts/${this.config.accountId}/ai-gateway/gateways (scripts/setup.ts:992)"}, "properties": {"repobilityId": "738a727ce1012b40", "scanner": "scanner-primary", "fingerprint": "62dabcbaa4bee4ee", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-be8c14478e2e41d2", "level": "error", "message": {"text": "Dangling fetch: POST https://api.cloudflare.com/client/v4/user/tokens (scripts/setup.ts:1038)"}, "properties": {"repobilityId": "9608988eb3cd1827", "scanner": "scanner-primary", "fingerprint": "be8c14478e2e41d2", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-54194ee9d16c4532", "level": "error", "message": {"text": "Dangling fetch: GET https://api.github.com/user (worker/api/controllers/byop/controller.ts:190)"}, "properties": {"repobilityId": "806078d3074422d8", "scanner": "scanner-primary", "fingerprint": "54194ee9d16c4532", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-84764ccd9f9e81a0", "level": "error", "message": {"text": "Dangling fetch: POST http://analyzer/start (worker/api/controllers/byop/controller.ts:366)"}, "properties": {"repobilityId": "765e5cf1e435df90", "scanner": "scanner-primary", "fingerprint": "84764ccd9f9e81a0", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-f1c7d3574806b128", "level": "error", "message": {"text": "Dangling fetch: GET http://analyzer/state (worker/api/controllers/byop/controller.ts:438)"}, "properties": {"repobilityId": "6ddaec490ee1b2f4", "scanner": "scanner-primary", "fingerprint": "f1c7d3574806b128", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-e848b32dad61caa8", "level": "error", "message": {"text": "Dangling fetch: GET http://analyzer/state (worker/api/controllers/byop/controller.ts:474)"}, "properties": {"repobilityId": "e6be0a0112dbac80", "scanner": "scanner-primary", "fingerprint": "e848b32dad61caa8", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-2529a64af9c11c7b", "level": "error", "message": {"text": "Dangling fetch: GET http://analyzer/state (worker/api/controllers/byop/controller.ts:679)"}, "properties": {"repobilityId": "46425f38c61c0db1", "scanner": "scanner-primary", "fingerprint": "2529a64af9c11c7b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-78c5ffc08d2b44d8", "level": "error", "message": {"text": "Dangling fetch: GET /api/data (worker/agents/operations/PhaseImplementation.ts:199)"}, "properties": {"repobilityId": "da12d3537fbde58a", "scanner": "scanner-primary", "fingerprint": "78c5ffc08d2b44d8", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-1783b5ca96412be0", "level": "error", "message": {"text": "Dangling fetch: POST https://api.github.com/user/repos (worker/services/github/GitHubService.ts:90)"}, "properties": {"repobilityId": "c9dcda6999bfeb3c", "scanner": "scanner-primary", "fingerprint": "1783b5ca96412be0", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-69b197c02bdb5966", "level": "error", "message": {"text": "Dangling fetch: GET https://api.cloudflare.com/client/v4/accounts (worker/services/cloudflare/CloudflareAccountService.ts:65)"}, "properties": {"repobilityId": "ea4085d55ed23a7c", "scanner": "scanner-primary", "fingerprint": "69b197c02bdb5966", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-1ad1d1abbb0e168b", "level": "error", "message": {"text": "Dangling fetch: GET https://api.cloudflare.com/client/v4/accounts/${accountId}/ai-gateway/gateways (worker/services/cloudflare/CloudflareAccountService.ts:103)"}, "properties": {"repobilityId": "47c94ea60b973e7e", "scanner": "scanner-primary", "fingerprint": "1ad1d1abbb0e168b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-7ff2242adbd9a360", "level": "error", "message": {"text": "Dangling fetch: POST https://api.cloudflare.com/client/v4/accounts/${accountId}/ai-gateway/gateways (worker/services/cloudflare/CloudflareAccountService.ts:147)"}, "properties": {"repobilityId": "80bc4d6ded34f136", "scanner": "scanner-primary", "fingerprint": "7ff2242adbd9a360", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-4c05ce4197a9c0a2", "level": "error", "message": {"text": "Dangling fetch: GET https://api.cloudflare.com/client/v4/accounts/${accountId}/ai-gateway-billing/credit_balance (worker/services/cloudflare/CloudflareAccountService.ts:209)"}, "properties": {"repobilityId": "9eee812a8b395122", "scanner": "scanner-primary", "fingerprint": "4c05ce4197a9c0a2", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-9be2cf69411c0921", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/ (container/process-monitor.ts:1229)"}, "properties": {"repobilityId": "6ddd3a0aa3d3aa7d", "scanner": "scanner-primary", "fingerprint": "9be2cf69411c0921", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-773d4fa01701f3f0", "level": "error", "message": {"text": "Dangling fetch: GET /api/apps (src/lib/api-client.ts:437)"}, "properties": {"repobilityId": "d4e7c95c6654ba92", "scanner": "scanner-primary", "fingerprint": "773d4fa01701f3f0", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-307f557e02bf053e", "level": "error", "message": {"text": "Dangling fetch: GET /api/apps/recent (src/lib/api-client.ts:444)"}, "properties": {"repobilityId": "9bb49af4cf78139f", "scanner": "scanner-primary", "fingerprint": "307f557e02bf053e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-94d404e27c0ce4ba", "level": "error", "message": {"text": "Dangling fetch: GET /api/apps/favorites (src/lib/api-client.ts:451)"}, "properties": {"repobilityId": "13f832c370cc0a65", "scanner": "scanner-primary", "fingerprint": "94d404e27c0ce4ba", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-7a0a8593d6728db6", "level": "error", "message": {"text": "Dangling fetch: POST /api/apps (src/lib/api-client.ts:481)"}, "properties": {"repobilityId": "b478a822639163c9", "scanner": "scanner-primary", "fingerprint": "7a0a8593d6728db6", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-7c8e0ae162028ad1", "level": "error", "message": {"text": "Dangling fetch: POST /api/apps/${appId}/favorite (src/lib/api-client.ts:493)"}, "properties": {"repobilityId": "47f4c4a2308f696b", "scanner": "scanner-primary", "fingerprint": "7c8e0ae162028ad1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-9c98e2c6d8548f83", "level": "error", "message": {"text": "Dangling fetch: PUT /api/apps/${appId}/visibility (src/lib/api-client.ts:505)"}, "properties": {"repobilityId": "524e79a34f2492fc", "scanner": "scanner-primary", "fingerprint": "9c98e2c6d8548f83", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-a34c808ea78ef29b", "level": "error", "message": {"text": "Dangling fetch: GET /api/apps/${appId} (src/lib/api-client.ts:531)"}, "properties": {"repobilityId": "39204b09ad533812", "scanner": "scanner-primary", "fingerprint": "a34c808ea78ef29b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-4ac4ae7f85579f4a", "level": "error", "message": {"text": "Dangling fetch: POST /api/apps/${appId}/star (src/lib/api-client.ts:540)"}, "properties": {"repobilityId": "8d6df69eba431e7b", "scanner": "scanner-primary", "fingerprint": "4ac4ae7f85579f4a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-eb56fd7b3de61d55", "level": "error", "message": {"text": "Dangling fetch: POST /api/apps/${appId}/fork (src/lib/api-client.ts:550)"}, "properties": {"repobilityId": "a4609f6282c17192", "scanner": "scanner-primary", "fingerprint": "eb56fd7b3de61d55", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-debd76ce1899af1d", "level": "error", "message": {"text": "Dangling fetch: GET /api/stats/user (src/lib/api-client.ts:634)"}, "properties": {"repobilityId": "c57b60ae57bb686f", "scanner": "scanner-primary", "fingerprint": "debd76ce1899af1d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-598208cb78a73ba5", "level": "error", "message": {"text": "Dangling fetch: GET /api/model-configs (src/lib/api-client.ts:682)"}, "properties": {"repobilityId": "cbe8d3927fd642f5", "scanner": "scanner-primary", "fingerprint": "598208cb78a73ba5", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-3d5e862282292f4c", "level": "error", "message": {"text": "Dangling fetch: DELETE /api/model-configs/${agentAction} (src/lib/api-client.ts:709)"}, "properties": {"repobilityId": "2eec349b210e9c56", "scanner": "scanner-primary", "fingerprint": "3d5e862282292f4c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-2c433e737c2082ca", "level": "error", "message": {"text": "Dangling fetch: POST /api/model-configs/reset-all (src/lib/api-client.ts:775)"}, "properties": {"repobilityId": "7815e3591ac6af40", "scanner": "scanner-primary", "fingerprint": "2c433e737c2082ca", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-9ba057a2421c5aff", "level": "error", "message": {"text": "Dangling fetch: POST /api/interview (src/lib/api-client.ts:879)"}, "properties": {"repobilityId": "399d1dea7bd34821", "scanner": "scanner-primary", "fingerprint": "9ba057a2421c5aff", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-acc24ef35044eeaa", "level": "error", "message": {"text": "Dangling fetch: GET /api/interview/${sessionId} (src/lib/api-client.ts:889)"}, "properties": {"repobilityId": "13c6d8912a11cf19", "scanner": "scanner-primary", "fingerprint": "acc24ef35044eeaa", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-afc567e8d6f41b36", "level": "error", "message": {"text": "Dangling fetch: POST /api/interview/${sessionId}/answer (src/lib/api-client.ts:900)"}, "properties": {"repobilityId": "3374f509c0956eb3", "scanner": "scanner-primary", "fingerprint": "afc567e8d6f41b36", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-844f636891fcae0c", "level": "error", "message": {"text": "Dangling fetch: POST /api/interview/${sessionId}/finish (src/lib/api-client.ts:910)"}, "properties": {"repobilityId": "0e79e0580332b183", "scanner": "scanner-primary", "fingerprint": "844f636891fcae0c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-f291568eb76b1e9e", "level": "error", "message": {"text": "Dangling fetch: GET /api/secrets (src/lib/api-client.ts:923)"}, "properties": {"repobilityId": "dfd4ea3972f0ff06", "scanner": "scanner-primary", "fingerprint": "f291568eb76b1e9e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-f873c38d74e381ff", "level": "error", "message": {"text": "Dangling fetch: POST /api/secrets (src/lib/api-client.ts:937)"}, "properties": {"repobilityId": "7981bf5c5963d857", "scanner": "scanner-primary", "fingerprint": "f873c38d74e381ff", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-7f453361868397b1", "level": "error", "message": {"text": "Dangling fetch: DELETE /api/secrets/${secretId} (src/lib/api-client.ts:949)"}, "properties": {"repobilityId": "fd6693b1cc90450c", "scanner": "scanner-primary", "fingerprint": "7f453361868397b1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-ebbca8c4d9eb6072", "level": "error", "message": {"text": "Dangling fetch: PATCH /api/secrets/${secretId}/toggle (src/lib/api-client.ts:960)"}, "properties": {"repobilityId": "5ad3e982171d074c", "scanner": "scanner-primary", "fingerprint": "ebbca8c4d9eb6072", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-165eb295d4793234", "level": "error", "message": {"text": "Dangling fetch: GET /api/auth/sessions (src/lib/api-client.ts:1033)"}, "properties": {"repobilityId": "ee9c741833aa349b", "scanner": "scanner-primary", "fingerprint": "165eb295d4793234", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-a60b033f3d48a9cd", "level": "error", "message": {"text": "Dangling fetch: DELETE /api/auth/sessions/${sessionId} (src/lib/api-client.ts:1042)"}, "properties": {"repobilityId": "63c793988e8d0812", "scanner": "scanner-primary", "fingerprint": "a60b033f3d48a9cd", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-2ea108214a9e40e1", "level": "error", "message": {"text": "Dangling fetch: POST /api/auth/api-keys (src/lib/api-client.ts:1074)"}, "properties": {"repobilityId": "9da8503779909e11", "scanner": "scanner-primary", "fingerprint": "2ea108214a9e40e1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-fe8f95d1861fda0b", "level": "error", "message": {"text": "Dangling fetch: DELETE /api/auth/api-keys/${keyId} (src/lib/api-client.ts:1091)"}, "properties": {"repobilityId": "43ff0ddb46cb0182", "scanner": "scanner-primary", "fingerprint": "fe8f95d1861fda0b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-505c7972a5658275", "level": "error", "message": {"text": "Dangling fetch: POST /api/byop/analysis/${analysisId}/start-building (src/lib/api-client.ts:1157)"}, "properties": {"repobilityId": "ef020cabf053648b", "scanner": "scanner-primary", "fingerprint": "505c7972a5658275", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-6cced232a5409964", "level": "error", "message": {"text": "Dangling fetch: POST /api/auth/login (src/lib/api-client.ts:1231)"}, "properties": {"repobilityId": "f5043b11a66896d7", "scanner": "scanner-primary", "fingerprint": "6cced232a5409964", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-0ce7e70c06577c73", "level": "error", "message": {"text": "Dangling fetch: POST /api/auth/register (src/lib/api-client.ts:1245)"}, "properties": {"repobilityId": "1bbf7be104859f80", "scanner": "scanner-primary", "fingerprint": "0ce7e70c06577c73", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-22fe6713b1092fac", "level": "error", "message": {"text": "Dangling fetch: POST /api/auth/verify-email (src/lib/api-client.ts:1258)"}, "properties": {"repobilityId": "71f353a7916fbcb9", "scanner": "scanner-primary", "fingerprint": "22fe6713b1092fac", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-9369e2b9111d3b63", "level": "error", "message": {"text": "Dangling fetch: POST /api/auth/resend-verification (src/lib/api-client.ts:1270)"}, "properties": {"repobilityId": "85ee19f91ae6740a", "scanner": "scanner-primary", "fingerprint": "9369e2b9111d3b63", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-16532eb83fe8ca9d", "level": "error", "message": {"text": "Dangling fetch: GET /api/auth/providers (src/lib/api-client.ts:1306)"}, "properties": {"repobilityId": "4f9891aa0a94cea5", "scanner": "scanner-primary", "fingerprint": "16532eb83fe8ca9d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-09ff92ac3044dca0", "level": "error", "message": {"text": "Dangling fetch: PUT /api/auth/profile (src/routes/settings/index.tsx:136)"}, "properties": {"repobilityId": "7d8a409f2bc6d431", "scanner": "scanner-primary", "fingerprint": "09ff92ac3044dca0", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-b8073f7bf758f6d0", "level": "note", "message": {"text": "Unused endpoint: USE /api/*"}, "properties": {"repobilityId": "1e7eac0f9d8e0662", "scanner": "scanner-primary", "fingerprint": "b8073f7bf758f6d0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f5c922b9512394db", "level": "note", "message": {"text": "Unused endpoint: GET /csrf-token"}, "properties": {"repobilityId": "acbe8a807f36a9de", "scanner": "scanner-primary", "fingerprint": "f5c922b9512394db", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e21cf4ee09f7c6a9", "level": "note", "message": {"text": "Unused endpoint: GET /providers"}, "properties": {"repobilityId": "aab277883317c8ca", "scanner": "scanner-primary", "fingerprint": "e21cf4ee09f7c6a9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-304b6f2b403d93f7", "level": "note", "message": {"text": "Unused endpoint: POST /register"}, "properties": {"repobilityId": "0f66afd1a9761d6a", "scanner": "scanner-primary", "fingerprint": "304b6f2b403d93f7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-618721b912bad1c2", "level": "note", "message": {"text": "Unused endpoint: POST /login"}, "properties": {"repobilityId": "a5aa251ed8839689", "scanner": "scanner-primary", "fingerprint": "618721b912bad1c2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0c3bb6af93b4422a", "level": "note", "message": {"text": "Unused endpoint: POST /verify-email"}, "properties": {"repobilityId": "f6527a1e5d8309a1", "scanner": "scanner-primary", "fingerprint": "0c3bb6af93b4422a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0afae4bfd1ff1c08", "level": "note", "message": {"text": "Unused endpoint: POST /resend-verification"}, "properties": {"repobilityId": "ac4b2c89c9e087f0", "scanner": "scanner-primary", "fingerprint": "0afae4bfd1ff1c08", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e5f899fff8e655a2", "level": "note", "message": {"text": "Unused endpoint: GET /check"}, "properties": {"repobilityId": "86219041ce8c689f", "scanner": "scanner-primary", "fingerprint": "e5f899fff8e655a2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2595b39638e5c045", "level": "note", "message": {"text": "Unused endpoint: GET /profile"}, "properties": {"repobilityId": "b9b58a0682fbbedb", "scanner": "scanner-primary", "fingerprint": "2595b39638e5c045", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-911492554a68d0c1", "level": "note", "message": {"text": "Unused endpoint: PUT /profile"}, "properties": {"repobilityId": "cffc43a7f2e31439", "scanner": "scanner-primary", "fingerprint": "911492554a68d0c1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-99fc36db98c134ce", "level": "note", "message": {"text": "Unused endpoint: POST /logout"}, "properties": {"repobilityId": "520439471d860f02", "scanner": "scanner-primary", "fingerprint": "99fc36db98c134ce", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b15d518d538de57d", "level": "note", "message": {"text": "Unused endpoint: GET /sessions"}, "properties": {"repobilityId": "b445355bbfdac206", "scanner": "scanner-primary", "fingerprint": "b15d518d538de57d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-05b1ac409816dfd9", "level": "note", "message": {"text": "Unused endpoint: DELETE /sessions/:sessionId"}, "properties": {"repobilityId": "f5b939ac5ee65f3f", "scanner": "scanner-primary", "fingerprint": "05b1ac409816dfd9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c32b4607df0975e2", "level": "note", "message": {"text": "Unused endpoint: GET /api-keys"}, "properties": {"repobilityId": "cb71af46378cdac4", "scanner": "scanner-primary", "fingerprint": "c32b4607df0975e2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-224cbb7548a6b13c", "level": "note", "message": {"text": "Unused endpoint: POST /api-keys"}, "properties": {"repobilityId": "35702a09f9f411b0", "scanner": "scanner-primary", "fingerprint": "224cbb7548a6b13c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4aa5f1617bc2f39b", "level": "note", "message": {"text": "Unused endpoint: DELETE /api-keys/:keyId"}, "properties": {"repobilityId": "36279a5208a4e34c", "scanner": "scanner-primary", "fingerprint": "4aa5f1617bc2f39b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ed8eaae0bc558031", "level": "note", "message": {"text": "Unused endpoint: GET /oauth/:provider"}, "properties": {"repobilityId": "5b96e6203737b13f", "scanner": "scanner-primary", "fingerprint": "ed8eaae0bc558031", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a537c245f0127632", "level": "note", "message": {"text": "Unused endpoint: GET /callback/:provider"}, "properties": {"repobilityId": "c9414b54b01e452d", "scanner": "scanner-primary", "fingerprint": "a537c245f0127632", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-eb9704c9e7ebf6c2", "level": "note", "message": {"text": "Unused endpoint: GET /:id/:file"}, "properties": {"repobilityId": "7509eaee295812ad", "scanner": "scanner-primary", "fingerprint": "eb9704c9e7ebf6c2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7048a5bb2e75bdd1", "level": "note", "message": {"text": "Unused endpoint: GET /:file"}, "properties": {"repobilityId": "094232cc7d1cbb06", "scanner": "scanner-primary", "fingerprint": "7048a5bb2e75bdd1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-66be2e63e9cbc888", "level": "note", "message": {"text": "Unused endpoint: GET /api/user/apps"}, "properties": {"repobilityId": "815c775e49899210", "scanner": "scanner-primary", "fingerprint": "66be2e63e9cbc888", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dd372090e9e12608", "level": "note", "message": {"text": "Unused endpoint: GET /api/user/providers"}, "properties": {"repobilityId": "78d416374d5b229b", "scanner": "scanner-primary", "fingerprint": "dd372090e9e12608", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4aa0183417eec9bb", "level": "note", "message": {"text": "Unused endpoint: GET /api/user/providers/:id"}, "properties": {"repobilityId": "d5c8142b84b98049", "scanner": "scanner-primary", "fingerprint": "4aa0183417eec9bb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-edef8b247414474d", "level": "note", "message": {"text": "Unused endpoint: POST /api/user/providers"}, "properties": {"repobilityId": "90507e3cb0ee7aed", "scanner": "scanner-primary", "fingerprint": "edef8b247414474d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-84ed732a2d8ac61b", "level": "note", "message": {"text": "Unused endpoint: DELETE /api/user/providers/:id"}, "properties": {"repobilityId": "110514318f56d718", "scanner": "scanner-primary", "fingerprint": "84ed732a2d8ac61b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f629f7c8659dc139", "level": "note", "message": {"text": "Unused endpoint: POST /api/user/providers/test"}, "properties": {"repobilityId": "ced398df196104bf", "scanner": "scanner-primary", "fingerprint": "f629f7c8659dc139", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a009b1a56794f45", "level": "note", "message": {"text": "Unused endpoint: POST /"}, "properties": {"repobilityId": "0c4e02f49826844d", "scanner": "scanner-primary", "fingerprint": "7a009b1a56794f45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c9c3650dde2516a3", "level": "note", "message": {"text": "Unused endpoint: GET /:sessionId"}, "properties": {"repobilityId": "d2bb431aefc65430", "scanner": "scanner-primary", "fingerprint": "c9c3650dde2516a3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0849f154e68b7cea", "level": "note", "message": {"text": "Unused endpoint: POST /:sessionId/answer"}, "properties": {"repobilityId": "7f549ed958e7f6b3", "scanner": "scanner-primary", "fingerprint": "0849f154e68b7cea", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8ae36833cd60a3bb", "level": "note", "message": {"text": "Unused endpoint: POST /:sessionId/finish"}, "properties": {"repobilityId": "f56ae70d3c312793", "scanner": "scanner-primary", "fingerprint": "8ae36833cd60a3bb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "62c4f252b75e8242", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-19a2092a23c40fef", "level": "note", "message": {"text": "Unused endpoint: POST /api/agent"}, "properties": {"repobilityId": "91e5eccdbaadb992", "scanner": "scanner-primary", "fingerprint": "19a2092a23c40fef", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2526536f700238c1", "level": "note", "message": {"text": "Unused endpoint: GET /api/agent/:agentId/ws"}, "properties": {"repobilityId": "7c1d268f14c89e41", "scanner": "scanner-primary", "fingerprint": "2526536f700238c1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b751fafe8c993414", "level": "note", "message": {"text": "Unused endpoint: GET /api/agent/:agentId/connect"}, "properties": {"repobilityId": "f721d1abfdc14c46", "scanner": "scanner-primary", "fingerprint": "b751fafe8c993414", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-07622488bbb18488", "level": "note", "message": {"text": "Unused endpoint: GET /api/agent/:agentId/preview"}, "properties": {"repobilityId": "8aa60c2115244cd5", "scanner": "scanner-primary", "fingerprint": "07622488bbb18488", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4756b4c4da7d2088", "level": "note", "message": {"text": "Unused endpoint: GET /api/health"}, "properties": {"repobilityId": "8c52542868bdd5c9", "scanner": "scanner-primary", "fingerprint": "4756b4c4da7d2088", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6a42c52fea3345b5", "level": "note", "message": {"text": "Unused endpoint: GET /public"}, "properties": {"repobilityId": "c042f68280e95507", "scanner": "scanner-primary", "fingerprint": "6a42c52fea3345b5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-955005a6da85f786", "level": "note", "message": {"text": "Unused endpoint: GET /recent"}, "properties": {"repobilityId": "113ee3303d4b3b6b", "scanner": "scanner-primary", "fingerprint": "955005a6da85f786", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-290b7834e43f5b66", "level": "note", "message": {"text": "Unused endpoint: GET /favorites"}, "properties": {"repobilityId": "13141af6bf038f39", "scanner": "scanner-primary", "fingerprint": "290b7834e43f5b66", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6bd4dac6864b6b2b", "level": "note", "message": {"text": "Unused endpoint: POST /:id/star"}, "properties": {"repobilityId": "d0753245713ed842", "scanner": "scanner-primary", "fingerprint": "6bd4dac6864b6b2b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3496a0fb449a79d0", "level": "note", "message": {"text": "Unused endpoint: POST /:id/fork"}, "properties": {"repobilityId": "2ca08c2b5d83ed19", "scanner": "scanner-primary", "fingerprint": "3496a0fb449a79d0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e097518d6e369a4a", "level": "note", "message": {"text": "Unused endpoint: POST /:id/favorite"}, "properties": {"repobilityId": "b33959cebf7dcb87", "scanner": "scanner-primary", "fingerprint": "e097518d6e369a4a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ca5756175765b49d", "level": "note", "message": {"text": "Unused endpoint: GET /:id"}, "properties": {"repobilityId": "e03ab8b75628613f", "scanner": "scanner-primary", "fingerprint": "ca5756175765b49d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2777a966d6b1b552", "level": "note", "message": {"text": "Unused endpoint: PUT /:id/visibility"}, "properties": {"repobilityId": "8013b47a19bf5806", "scanner": "scanner-primary", "fingerprint": "2777a966d6b1b552", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a61c112b611f4bb", "level": "note", "message": {"text": "Unused endpoint: DELETE /:id"}, "properties": {"repobilityId": "0923c9bc472c3520", "scanner": "scanner-primary", "fingerprint": "7a61c112b611f4bb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f1c22d9e74fd654f", "level": "note", "message": {"text": "Unused endpoint: POST /tunnel"}, "properties": {"repobilityId": "9165e067554fce66", "scanner": "scanner-primary", "fingerprint": "f1c22d9e74fd654f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-10c38a97762e7b8c", "level": "note", "message": {"text": "Unused endpoint: GET /repositories"}, "properties": {"repobilityId": "36d1db47ae4ea356", "scanner": "scanner-primary", "fingerprint": "10c38a97762e7b8c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-be4cb5e3cabcce80", "level": "note", "message": {"text": "Unused endpoint: POST /import"}, "properties": {"repobilityId": "daf1363479c4a639", "scanner": "scanner-primary", "fingerprint": "be4cb5e3cabcce80", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ad6675332dc61eee", "level": "note", "message": {"text": "Unused endpoint: GET /analysis/:analysisId/status"}, "properties": {"repobilityId": "7bd58fd4e62028fe", "scanner": "scanner-primary", "fingerprint": "ad6675332dc61eee", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e11fbcad56e8d061", "level": "note", "message": {"text": "Unused endpoint: GET /analysis/:analysisId/blueprint"}, "properties": {"repobilityId": "ce05817aeb7c1ffb", "scanner": "scanner-primary", "fingerprint": "e11fbcad56e8d061", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}