{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-dfaca42d6e087253", "name": "Stray `console.log` in TS/JS \u2014 sync-store.js:44", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 sync-store.js:44"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a8fa7b3145647f9e", "name": "Stray `console.log` in TS/JS \u2014 test-regression.js:106", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 test-regression.js:106"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d3dbb22f8d5ebd80", "name": "Stray `console.log` in TS/JS \u2014 vinyl-checker-puppeteer.js:504", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 vinyl-checker-puppeteer.js:504"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9cc98b27535ee2f7", "name": "Stray `console.log` in TS/JS \u2014 goldie.js:2634", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 goldie.js:2634"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eabb43fb15fd5ea5", "name": "Stray `console.log` in TS/JS \u2014 server.js:265", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 server.js:265"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-21111268f186c748", "name": "Stray `console.log` in TS/JS \u2014 chrome-extension/background.js:42", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 chrome-extension/background.js:42"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-268389e3224342f3", "name": "Stray `console.log` in TS/JS \u2014 chrome-extension/sync-window.js:86", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 chrome-extension/sync-window.js:86"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fb94ef3b4da8f352", "name": "Stray `console.log` in TS/JS \u2014 test/matcher.test.js:20", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 test/matcher.test.js:20"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ed31f82503386d9d", "name": "Stray `console.log` in TS/JS \u2014 test/gramaphone.test.js:19", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 test/gramaphone.test.js:19"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5653b9f18da8cde6", "name": "Stray `console.log` in TS/JS \u2014 test/optimizer.test.js:14", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 test/optimizer.test.js:14"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d50bce2986ba1bac", "name": "Stray `console.log` in TS/JS \u2014 test/octopus.test.js:20", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 test/octopus.test.js:20"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8ac5a34b18476d1c", "name": "Stray `console.log` in TS/JS \u2014 test/further.test.js:19", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 test/further.test.js:19"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1a03c2b2367d5d25", "name": "Stray `console.log` in TS/JS \u2014 scripts/validate-video-ids.js:48", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/validate-video-ids.js:48"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be11307a3ecf67a0", "name": "Stray `console.log` in TS/JS \u2014 scripts/discogs-video-sync.js:64", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/discogs-video-sync.js:64"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-525866c7bc16f1dc", "name": "Stray `console.log` in TS/JS \u2014 scripts/vendor-quality-check.js:19", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/vendor-quality-check.js:19"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7b7d2380b73b6ebd", "name": "Stray `console.log` in TS/JS \u2014 lib/shazam-enrichment.js:147", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/shazam-enrichment.js:147"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-016868734380193c", "name": "Stray `console.log` in TS/JS \u2014 lib/youtube-enrichment.js:318", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/youtube-enrichment.js:318"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4fbb8a404ddc0d0f", "name": "Stray `console.log` in TS/JS \u2014 lib/songstats-enrichment.js:185", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/songstats-enrichment.js:185"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8eefaf75ee3f25ce", "name": "Stray `console.log` in TS/JS \u2014 lib/health-monitor.js:41", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/health-monitor.js:41"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d7f2e848f06cdf72", "name": "Stray `console.log` in TS/JS \u2014 lib/optimizer-worker.js:195", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/optimizer-worker.js:195"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d9e633c79c2d08e7", "name": "Stray `console.log` in TS/JS \u2014 lib/scrapers.js:363", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/scrapers.js:363"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6055099b057ccfc7", "name": "Stray `console.log` in TS/JS \u2014 lib/email-alerts.js:96", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/email-alerts.js:96"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8fcccb49c4e8c6dd", "name": "Stray `console.log` in TS/JS \u2014 lib/recommender.js:74", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/recommender.js:74"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9fe76c6ab5fce21a", "name": "Stray `console.log` in TS/JS \u2014 lib/discogs.js:46", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/discogs.js:46"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4129d74b9282ab34", "name": "Stray `console.log` in TS/JS \u2014 lib/pipeline-worker.js:59", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/pipeline-worker.js:59"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f781aad7c13073d8", "name": "Stray `console.log` in TS/JS \u2014 lib/scanner.js:78", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/scanner.js:78"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f858a03e5d393aa3", "name": "Stray `console.log` in TS/JS \u2014 lib/stores/further.js:230", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/stores/further.js:230"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c3bf92ad6f799f6a", "name": "Stray `console.log` in TS/JS \u2014 lib/stores/gramaphone.js:213", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/stores/gramaphone.js:213"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d16f06fdd2cb3028", "name": "Stray `console.log` in TS/JS \u2014 lib/stores/uvs.js:185", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/stores/uvs.js:185"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3032010117356ae1", "name": "Stray `console.log` in TS/JS \u2014 lib/stores/hardwax.js:259", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/stores/hardwax.js:259"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cb9019237622ee85", "name": "Stray `console.log` in TS/JS \u2014 lib/stores/octopus.js:229", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/stores/octopus.js:229"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4e45ac5bfef77d29", "name": "Stray `console.log` in TS/JS \u2014 lib/pipeline-stages/meta-sync.js:37", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/pipeline-stages/meta-sync.js:37"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c552197660d46069", "name": "Stray `console.log` in TS/JS \u2014 lib/pipeline-stages/gem-score.js:23", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/pipeline-stages/gem-score.js:23"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-31a2df0fa5ef9ba9", "name": "Stray `console.log` in TS/JS \u2014 lib/pipeline-stages/wantlist-sync.js:39", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/pipeline-stages/wantlist-sync.js:39"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-16117a5cfcde9b62", "name": "Stray `console.log` in TS/JS \u2014 lib/pipeline-stages/yt-id-search.js:18", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/pipeline-stages/yt-id-search.js:18"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9370bbf0e7c2ff77", "name": "Stray `console.log` in TS/JS \u2014 lib/pipeline-stages/yt-enrich.js:17", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/pipeline-stages/yt-enrich.js:17"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-90cc9541f09d0bf7", "name": "Icon-only button without accessible name \u2014 public/js/app.js:836", "shortDescription": {"text": "Icon-only button without accessible name \u2014 public/js/app.js:836"}, "fullDescription": {"text": "A `<button>` whose only child is a single glyph or symbol needs `title=` or `aria-label=` so screen readers (and tooltips on hover) work.\n\nWhy: P3 in CHECKLIST.md \u2014 icon-only buttons skipped a title.\nRule id: fq.button.no-label"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-650fae4087438542", "name": "Stray `console.log` in TS/JS \u2014 public/js/app.js:970", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 public/js/app.js:970"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-815debb3fee6579f", "name": "Insecure pattern 'direct_innerhtml_assignment' in index.html:621", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in index.html:621"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d9ba55179f90b70e", "name": "Insecure pattern 'cors_wildcard' in goldie.js:2543", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in goldie.js:2543"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-71280d8b7eecd24e", "name": "Insecure pattern 'node_child_process' in server.js:1457", "shortDescription": {"text": "Insecure pattern 'node_child_process' in server.js:1457"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-02a9f6e34806ceb2", "name": "Insecure pattern 'domparser_html_parse' in chrome-extension/sync-window.js:301", "shortDescription": {"text": "Insecure pattern 'domparser_html_parse' in chrome-extension/sync-window.js:301"}, "fullDescription": {"text": "Found a known-risky pattern (domparser_html_parse). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b6ce11b9502b79d6", "name": "Insecure pattern 'exec_used' in scripts/preflight.sh:37", "shortDescription": {"text": "Insecure pattern 'exec_used' in scripts/preflight.sh:37"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c4d17b77c1a280b0", "name": "Insecure pattern 'node_child_process' in lib/mix-resolver.js:436", "shortDescription": {"text": "Insecure pattern 'node_child_process' in lib/mix-resolver.js:436"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7006339a29fc0305", "name": "Insecure pattern 'weak_hash' in lib/oauth.js:80", "shortDescription": {"text": "Insecure pattern 'weak_hash' in lib/oauth.js:80"}, "fullDescription": {"text": "Found a known-risky pattern (weak_hash). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2e78d1bb63111bb4", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/admin.html:270", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/admin.html:270"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e10126f7f21cc4ef", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/js/app.js:393", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/js/app.js:393"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a1edc95c5d123d4c", "name": "Insecure pattern 'insert_adjacent_html' in public/js/app.js:1567", "shortDescription": {"text": "Insecure pattern 'insert_adjacent_html' in public/js/app.js:1567"}, "fullDescription": {"text": "Found a known-risky pattern (insert_adjacent_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1de2b68a437f4f0f", "name": "Very large file: db.js (2902 lines)", "shortDescription": {"text": "Very large file: db.js (2902 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-34e24aceafdd9403", "name": "Very large file: goldie.js (2699 lines)", "shortDescription": {"text": "Very large file: goldie.js (2699 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-01df037d9d35c93e", "name": "Very large file: server.js (4436 lines)", "shortDescription": {"text": "Very large file: server.js (4436 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9fe91e8d0496cea1", "name": "Very large file: lib/mix-resolver.js (1173 lines)", "shortDescription": {"text": "Very large file: lib/mix-resolver.js (1173 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-02ee36a071929825", "name": "Very large file: lib/scrapers.js (987 lines)", "shortDescription": {"text": "Very large file: lib/scrapers.js (987 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9cf885f653715055", "name": "Very large file: lib/scanner.js (2091 lines)", "shortDescription": {"text": "Very large file: lib/scanner.js (2091 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-336e34bc89e42c50", "name": "Very large file: public/js/app.js (8189 lines)", "shortDescription": {"text": "Very large file: public/js/app.js (8189 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea3b5e389d8c9c0f", "name": "Low test-to-source ratio", "shortDescription": {"text": "Low test-to-source ratio"}, "fullDescription": {"text": "6 tests / 52 src (ratio 0.12)."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 264 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 14 placeholder/mock markers across 4 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license, ci. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-505bc666a82f9849", "name": "Agent instruction/config may expose a secret: .claude/settings.local.json", "shortDescription": {"text": "Agent instruction/config may expose a secret: .claude/settings.local.json"}, "fullDescription": {"text": "Agent-facing files are routinely pasted into LLM/tool contexts. Move literal tokens, keys, and passwords into a secret manager or document them as placeholders only."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ecb0d2c55ed6875d", "name": "Agent authority lacks a verifier contract: .claude/settings.local.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/settings.local.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-32571644a2b6231b", "name": "Commented-code block (7 lines) in vinyl-checker-puppeteer.js:520", "shortDescription": {"text": "Commented-code block (7 lines) in vinyl-checker-puppeteer.js:520"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ac30c5b3a5317024", "name": "Commented-code block (5 lines) in goldie.js:1733", "shortDescription": {"text": "Commented-code block (5 lines) in goldie.js:1733"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6976860273001b2b", "name": "Commented-code block (5 lines) in server.js:1385", "shortDescription": {"text": "Commented-code block (5 lines) in server.js:1385"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0fc36f5d74802e09", "name": "Commented-code block (6 lines) in chrome-extension/background.js:127", "shortDescription": {"text": "Commented-code block (6 lines) in chrome-extension/background.js:127"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8a8d2a1a220d7411", "name": "Commented-code block (5 lines) in lib/youtube-enrichment.js:50", "shortDescription": {"text": "Commented-code block (5 lines) in lib/youtube-enrichment.js:50"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-92f0e4d4693470c6", "name": "`fetch()` without try/.catch or AbortSignal \u2014 lib/youtube-enrichment.js:238", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 lib/youtube-enrichment.js:238"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e40bb06643e442e4", "name": "`fetch()` without try/.catch or AbortSignal \u2014 lib/youtube-ingest.js:29", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 lib/youtube-ingest.js:29"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0b5312c82dd84e7e", "name": "Commented-code block (5 lines) in lib/mix-resolver.js:572", "shortDescription": {"text": "Commented-code block (5 lines) in lib/mix-resolver.js:572"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-17814a7e5a06181e", "name": "`fetch()` without try/.catch or AbortSignal \u2014 lib/mix-resolver.js:150", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 lib/mix-resolver.js:150"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0ae9266f0de983dc", "name": "Commented-code block (9 lines) in lib/scrapers.js:43", "shortDescription": {"text": "Commented-code block (9 lines) in lib/scrapers.js:43"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-347803edb8d80fca", "name": "`fetch()` without try/.catch or AbortSignal \u2014 lib/soundcloud.js:26", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 lib/soundcloud.js:26"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e54736dd6dc5df6e", "name": "Commented-code block (5 lines) in lib/scanner.js:26", "shortDescription": {"text": "Commented-code block (5 lines) in lib/scanner.js:26"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6cdd01f0bc209de0", "name": "Commented-code block (5 lines) in lib/stores/further.js:35", "shortDescription": {"text": "Commented-code block (5 lines) in lib/stores/further.js:35"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8b62f19ae76aa68f", "name": "Commented-code block (6 lines) in lib/stores/uvs.js:53", "shortDescription": {"text": "Commented-code block (6 lines) in lib/stores/uvs.js:53"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1b38bd7d37b6c60c", "name": "Commented-code block (6 lines) in lib/stores/octopus.js:59", "shortDescription": {"text": "Commented-code block (6 lines) in lib/stores/octopus.js:59"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cb53573b9012293a", "name": "Commented-code block (6 lines) in lib/stores/shopify.js:39", "shortDescription": {"text": "Commented-code block (6 lines) in lib/stores/shopify.js:39"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c030ed78269e784e", "name": "Commented-code block (5 lines) in public/js/app.js:189", "shortDescription": {"text": "Commented-code block (5 lines) in public/js/app.js:189"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e2152102f04481f3", "name": "`fetch()` without try/.catch or AbortSignal \u2014 public/js/app.js:760", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/js/app.js:760"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5b454b67ecf8c581", "name": "Dangling fetch: GET https://soundcloud.com/ (lib/mix-resolver.js:697)", "shortDescription": {"text": "Dangling fetch: GET https://soundcloud.com/ (lib/mix-resolver.js:697)"}, "fullDescription": {"text": "`lib/mix-resolver.js:697` calls `GET https://soundcloud.com/` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/soundcloud.com`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cdbb5400079c8116", "name": "Unused endpoint: GET /extension", "shortDescription": {"text": "Unused endpoint: GET /extension"}, "fullDescription": {"text": "`server.js` declares `GET /extension` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-562322a28c342d7f", "name": "Unused endpoint: GET /api/auth/status", "shortDescription": {"text": "Unused endpoint: GET /api/auth/status"}, "fullDescription": {"text": "`server.js` declares `GET /api/auth/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-82d9930fba6e382f", "name": "Unused endpoint: GET /api/auth/discogs", "shortDescription": {"text": "Unused endpoint: GET /api/auth/discogs"}, "fullDescription": {"text": "`server.js` declares `GET /api/auth/discogs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6e6485573ef0264a", "name": "Unused endpoint: GET /api/auth/discogs/callback", "shortDescription": {"text": "Unused endpoint: GET /api/auth/discogs/callback"}, "fullDescription": {"text": "`server.js` declares `GET /api/auth/discogs/callback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3d0ca4266fc53792", "name": "Unused endpoint: POST /api/auth/discogs/disconnect", "shortDescription": {"text": "Unused endpoint: POST /api/auth/discogs/disconnect"}, "fullDescription": {"text": "`server.js` declares `POST /api/auth/discogs/disconnect` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-065a7629e7f86caf", "name": "Unused endpoint: GET /api/auth/google", "shortDescription": {"text": "Unused endpoint: GET /api/auth/google"}, "fullDescription": {"text": "`server.js` declares `GET /api/auth/google` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ab9e687c0618f84d", "name": "Unused endpoint: GET /api/auth/google/callback", "shortDescription": {"text": "Unused endpoint: GET /api/auth/google/callback"}, "fullDescription": {"text": "`server.js` declares `GET /api/auth/google/callback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-13e56a1eb740ee97", "name": "Unused endpoint: POST /api/auth/google/disconnect", "shortDescription": {"text": "Unused endpoint: POST /api/auth/google/disconnect"}, "fullDescription": {"text": "`server.js` declares `POST /api/auth/google/disconnect` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1ce88fb2df9e05b8", "name": "Unused endpoint: GET /api/auth/soundcloud", "shortDescription": {"text": "Unused endpoint: GET /api/auth/soundcloud"}, "fullDescription": {"text": "`server.js` declares `GET /api/auth/soundcloud` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f6cc13327b840120", "name": "Unused endpoint: GET /api/auth/soundcloud/callback", "shortDescription": {"text": "Unused endpoint: GET /api/auth/soundcloud/callback"}, "fullDescription": {"text": "`server.js` declares `GET /api/auth/soundcloud/callback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-05e0c61695ba654a", "name": "Unused endpoint: POST /api/auth/soundcloud/disconnect", "shortDescription": {"text": "Unused endpoint: POST /api/auth/soundcloud/disconnect"}, "fullDescription": {"text": "`server.js` declares `POST /api/auth/soundcloud/disconnect` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fb03f586917d1501", "name": "Unused endpoint: POST /api/soundcloud/ingest", "shortDescription": {"text": "Unused endpoint: POST /api/soundcloud/ingest"}, "fullDescription": {"text": "`server.js` declares `POST /api/soundcloud/ingest` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2ddc3b00998a1589", "name": "Unused endpoint: GET /api/soundcloud/status", "shortDescription": {"text": "Unused endpoint: GET /api/soundcloud/status"}, "fullDescription": {"text": "`server.js` declares `GET /api/soundcloud/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e44c5b063d97ec8c", "name": "Unused endpoint: POST /api/youtube/ingest", "shortDescription": {"text": "Unused endpoint: POST /api/youtube/ingest"}, "fullDescription": {"text": "`server.js` declares `POST /api/youtube/ingest` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8f222efc3572ccf8", "name": "Unused endpoint: GET /api/youtube/status", "shortDescription": {"text": "Unused endpoint: GET /api/youtube/status"}, "fullDescription": {"text": "`server.js` declares `GET /api/youtube/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1aa188b3ade54eb5", "name": "Unused endpoint: GET /api/discovery/:username", "shortDescription": {"text": "Unused endpoint: GET /api/discovery/:username"}, "fullDescription": {"text": "`server.js` declares `GET /api/discovery/:username` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3c38c2366ce1f0ee", "name": "Unused endpoint: POST /api/youtube/create-playlist", "shortDescription": {"text": "Unused endpoint: POST /api/youtube/create-playlist"}, "fullDescription": {"text": "`server.js` declares `POST /api/youtube/create-playlist` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be3ff2caa1757ca0", "name": "Unused endpoint: GET /api/reset", "shortDescription": {"text": "Unused endpoint: GET /api/reset"}, "fullDescription": {"text": "`server.js` declares `GET /api/reset` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6b0e7f5976711316", "name": "Unused endpoint: GET /api/session", "shortDescription": {"text": "Unused endpoint: GET /api/session"}, "fullDescription": {"text": "`server.js` declares `GET /api/session` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fcdb619a018a7454", "name": "Unused endpoint: POST /api/session", "shortDescription": {"text": "Unused endpoint: POST /api/session"}, "fullDescription": {"text": "`server.js` declares `POST /api/session` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a10936f69cf3bbb4", "name": "Unused endpoint: POST /api/logout", "shortDescription": {"text": "Unused endpoint: POST /api/logout"}, "fullDescription": {"text": "`server.js` declares `POST /api/logout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-775836f50c0fdf36", "name": "Unused endpoint: GET /api/test-stores", "shortDescription": {"text": "Unused endpoint: GET /api/test-stores"}, "fullDescription": {"text": "`server.js` declares `GET /api/test-stores` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f483bbb4727756d7", "name": "Unused endpoint: GET /api/validate", "shortDescription": {"text": "Unused endpoint: GET /api/validate"}, "fullDescription": {"text": "`server.js` declares `GET /api/validate` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bebeb829c7746471", "name": "Unused endpoint: GET /api/scan/:username", "shortDescription": {"text": "Unused endpoint: GET /api/scan/:username"}, "fullDescription": {"text": "`server.js` declares `GET /api/scan/:username` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d471e840eee40a55", "name": "Unused endpoint: GET /api/results/:username", "shortDescription": {"text": "Unused endpoint: GET /api/results/:username"}, "fullDescription": {"text": "`server.js` declares `GET /api/results/:username` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-438e978ec66fde3a", "name": "Unused endpoint: GET /api/collection/:username", "shortDescription": {"text": "Unused endpoint: GET /api/collection/:username"}, "fullDescription": {"text": "`server.js` declares `GET /api/collection/:username` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2ef9c7f1986f72e9", "name": "Unused endpoint: GET /api/release/:discogs_id", "shortDescription": {"text": "Unused endpoint: GET /api/release/:discogs_id"}, "fullDescription": {"text": "`server.js` declares `GET /api/release/:discogs_id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e0221298a213b912", "name": "Unused endpoint: GET /api/price-history/:discogs_id", "shortDescription": {"text": "Unused endpoint: GET /api/price-history/:discogs_id"}, "fullDescription": {"text": "`server.js` declares `GET /api/price-history/:discogs_id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d4fb8b4f3f45a324", "name": "Unused endpoint: GET /api/history/:discogs_id", "shortDescription": {"text": "Unused endpoint: GET /api/history/:discogs_id"}, "fullDescription": {"text": "`server.js` declares `GET /api/history/:discogs_id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-07b4f403ef8fa198", "name": "Unused endpoint: GET /api/preferences/:username", "shortDescription": {"text": "Unused endpoint: GET /api/preferences/:username"}, "fullDescription": {"text": "`server.js` declares `GET /api/preferences/:username` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8d0af95b76ac04a8", "name": "Unused endpoint: POST /api/preferences/:username", "shortDescription": {"text": "Unused endpoint: POST /api/preferences/:username"}, "fullDescription": {"text": "`server.js` declares `POST /api/preferences/:username` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f262e6c5bc7dcae7", "name": "Unused endpoint: POST /api/optimize/:username", "shortDescription": {"text": "Unused endpoint: POST /api/optimize/:username"}, "fullDescription": {"text": "`server.js` declares `POST /api/optimize/:username` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cc4db14d90efdf9e", "name": "Unused endpoint: GET /api/optimize/job/:jobId", "shortDescription": {"text": "Unused endpoint: GET /api/optimize/job/:jobId"}, "fullDescription": {"text": "`server.js` declares `GET /api/optimize/job/:jobId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a5237a90f012b17c", "name": "Unused endpoint: GET /api/optimize/latest/:username", "shortDescription": {"text": "Unused endpoint: GET /api/optimize/latest/:username"}, "fullDescription": {"text": "`server.js` declares `GET /api/optimize/latest/:username` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea1454ed83525840", "name": "Unused endpoint: GET /api/recommend/:username", "shortDescription": {"text": "Unused endpoint: GET /api/recommend/:username"}, "fullDescription": {"text": "`server.js` declares `GET /api/recommend/:username` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-744b590128b8791e", "name": "Unused endpoint: POST /api/verify", "shortDescription": {"text": "Unused endpoint: POST /api/verify"}, "fullDescription": {"text": "`server.js` declares `POST /api/verify` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-963710f42a2c8219", "name": "Unused endpoint: GET /api/status", "shortDescription": {"text": "Unused endpoint: GET /api/status"}, "fullDescription": {"text": "`server.js` declares `GET /api/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-de520adc97b20cde", "name": "Unused endpoint: GET /api/job-health", "shortDescription": {"text": "Unused endpoint: GET /api/job-health"}, "fullDescription": {"text": "`server.js` declares `GET /api/job-health` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f9e888b9fbdc54a8", "name": "Unused endpoint: POST /api/trigger", "shortDescription": {"text": "Unused endpoint: POST /api/trigger"}, "fullDescription": {"text": "`server.js` declares `POST /api/trigger` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3c5678301beea41b", "name": "Unused endpoint: POST /api/admin/sync-store", "shortDescription": {"text": "Unused endpoint: POST /api/admin/sync-store"}, "fullDescription": {"text": "`server.js` declares `POST /api/admin/sync-store` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a87e60b297cd2de", "name": "Unused endpoint: POST /api/deploy", "shortDescription": {"text": "Unused endpoint: POST /api/deploy"}, "fullDescription": {"text": "`server.js` declares `POST /api/deploy` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-77b7497aae5f2344", "name": "Unused endpoint: GET /api/scan-status/:username", "shortDescription": {"text": "Unused endpoint: GET /api/scan-status/:username"}, "fullDescription": {"text": "`server.js` declares `GET /api/scan-status/:username` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bcb7965ae0468f73", "name": "Unused endpoint: GET /api/meta-sync/:username", "shortDescription": {"text": "Unused endpoint: GET /api/meta-sync/:username"}, "fullDescription": {"text": "`server.js` declares `GET /api/meta-sync/:username` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-201ba901e1ed5458", "name": "Unused endpoint: GET /api/pipeline/status", "shortDescription": {"text": "Unused endpoint: GET /api/pipeline/status"}, "fullDescription": {"text": "`server.js` declares `GET /api/pipeline/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8aca3e9fefe330e7", "name": "Unused endpoint: GET /api/pipeline/log", "shortDescription": {"text": "Unused endpoint: GET /api/pipeline/log"}, "fullDescription": {"text": "`server.js` declares `GET /api/pipeline/log` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bb2eae295b3c1159", "name": "Unused endpoint: POST /api/pipeline/trigger", "shortDescription": {"text": "Unused endpoint: POST /api/pipeline/trigger"}, "fullDescription": {"text": "`server.js` declares `POST /api/pipeline/trigger` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-50de348e375d3b1b", "name": "Unused endpoint: POST /api/wantlist/add", "shortDescription": {"text": "Unused endpoint: POST /api/wantlist/add"}, "fullDescription": {"text": "`server.js` declares `POST /api/wantlist/add` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-99ccc3d032ece5c0", "name": "Unused endpoint: DELETE /api/wantlist/:username/:discogsId", "shortDescription": {"text": "Unused endpoint: DELETE /api/wantlist/:username/:discogsId"}, "fullDescription": {"text": "`server.js` declares `DELETE /api/wantlist/:username/:discogsId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b43579ea2d0c5baf", "name": "Unused endpoint: POST /api/collection/add", "shortDescription": {"text": "Unused endpoint: POST /api/collection/add"}, "fullDescription": {"text": "`server.js` declares `POST /api/collection/add` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-728f7232e1fa4f79", "name": "Unused endpoint: GET /api/digger-recommendations/:username", "shortDescription": {"text": "Unused endpoint: GET /api/digger-recommendations/:username"}, "fullDescription": {"text": "`server.js` declares `GET /api/digger-recommendations/:username` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/19971"}, "properties": {"repository": "solakli/vinyl-checker", "repoUrl": "https://github.com/solakli/vinyl-checker", "branch": "main"}, "results": [{"ruleId": "scanner-dfaca42d6e087253", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 sync-store.js:44"}, "properties": {"repobilityId": "34912ed2b1031c5b", "scanner": "scanner-primary", "fingerprint": "dfaca42d6e087253", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a8fa7b3145647f9e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 test-regression.js:106"}, "properties": {"repobilityId": "f3db45fa42eb4f37", "scanner": "scanner-primary", "fingerprint": "a8fa7b3145647f9e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d3dbb22f8d5ebd80", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 vinyl-checker-puppeteer.js:504"}, "properties": {"repobilityId": "e8a922eee2863741", "scanner": "scanner-primary", "fingerprint": "d3dbb22f8d5ebd80", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9cc98b27535ee2f7", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 goldie.js:2634"}, "properties": {"repobilityId": "4ea608811b98fffa", "scanner": "scanner-primary", "fingerprint": "9cc98b27535ee2f7", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-eabb43fb15fd5ea5", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 server.js:265"}, "properties": {"repobilityId": "a9deebb5fdc93edc", "scanner": "scanner-primary", "fingerprint": "eabb43fb15fd5ea5", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-21111268f186c748", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 chrome-extension/background.js:42"}, "properties": {"repobilityId": "522257b52e9b9f46", "scanner": "scanner-primary", "fingerprint": "21111268f186c748", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-268389e3224342f3", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 chrome-extension/sync-window.js:86"}, "properties": {"repobilityId": "212189020cad5203", "scanner": "scanner-primary", "fingerprint": "268389e3224342f3", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-fb94ef3b4da8f352", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 test/matcher.test.js:20"}, "properties": {"repobilityId": "a951cfbd6c142006", "scanner": "scanner-primary", "fingerprint": "fb94ef3b4da8f352", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ed31f82503386d9d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 test/gramaphone.test.js:19"}, "properties": {"repobilityId": "f130a5ca1be8183c", "scanner": "scanner-primary", "fingerprint": "ed31f82503386d9d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5653b9f18da8cde6", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 test/optimizer.test.js:14"}, "properties": {"repobilityId": "3a3b0df4d4013215", "scanner": "scanner-primary", "fingerprint": "5653b9f18da8cde6", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d50bce2986ba1bac", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 test/octopus.test.js:20"}, "properties": {"repobilityId": "e42576203929af3b", "scanner": "scanner-primary", "fingerprint": "d50bce2986ba1bac", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8ac5a34b18476d1c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 test/further.test.js:19"}, "properties": {"repobilityId": "39f3f351be692e24", "scanner": "scanner-primary", "fingerprint": "8ac5a34b18476d1c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-1a03c2b2367d5d25", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/validate-video-ids.js:48"}, "properties": {"repobilityId": "a92d30fab2985c1e", "scanner": "scanner-primary", "fingerprint": "1a03c2b2367d5d25", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-be11307a3ecf67a0", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/discogs-video-sync.js:64"}, "properties": {"repobilityId": "7d572f559e9f8d6b", "scanner": "scanner-primary", "fingerprint": "be11307a3ecf67a0", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-525866c7bc16f1dc", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/vendor-quality-check.js:19"}, "properties": {"repobilityId": "3b1b963e04d3a3c7", "scanner": "scanner-primary", "fingerprint": "525866c7bc16f1dc", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7b7d2380b73b6ebd", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/shazam-enrichment.js:147"}, "properties": {"repobilityId": "2079ecdf0f5ec988", "scanner": "scanner-primary", "fingerprint": "7b7d2380b73b6ebd", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-016868734380193c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/youtube-enrichment.js:318"}, "properties": {"repobilityId": "db7ee7a83e3432b4", "scanner": "scanner-primary", "fingerprint": "016868734380193c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4fbb8a404ddc0d0f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/songstats-enrichment.js:185"}, "properties": {"repobilityId": "07683577d6cc1d65", "scanner": "scanner-primary", "fingerprint": "4fbb8a404ddc0d0f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8eefaf75ee3f25ce", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/health-monitor.js:41"}, "properties": {"repobilityId": "8c9bd76c55b93aa9", "scanner": "scanner-primary", "fingerprint": "8eefaf75ee3f25ce", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d7f2e848f06cdf72", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/optimizer-worker.js:195"}, "properties": {"repobilityId": "e2dfa8abfbd7b8da", "scanner": "scanner-primary", "fingerprint": "d7f2e848f06cdf72", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d9e633c79c2d08e7", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/scrapers.js:363"}, "properties": {"repobilityId": "b0e02adfcbf24082", "scanner": "scanner-primary", "fingerprint": "d9e633c79c2d08e7", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-6055099b057ccfc7", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/email-alerts.js:96"}, "properties": {"repobilityId": "3676358dc51cdb19", "scanner": "scanner-primary", "fingerprint": "6055099b057ccfc7", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8fcccb49c4e8c6dd", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/recommender.js:74"}, "properties": {"repobilityId": "9a00de088979987f", "scanner": "scanner-primary", "fingerprint": "8fcccb49c4e8c6dd", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9fe76c6ab5fce21a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/discogs.js:46"}, "properties": {"repobilityId": "dd51e472907d92cc", "scanner": "scanner-primary", "fingerprint": "9fe76c6ab5fce21a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4129d74b9282ab34", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/pipeline-worker.js:59"}, "properties": {"repobilityId": "95c31eb008046f44", "scanner": "scanner-primary", "fingerprint": "4129d74b9282ab34", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f781aad7c13073d8", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/scanner.js:78"}, "properties": {"repobilityId": "b62e2571018dfa47", "scanner": "scanner-primary", "fingerprint": "f781aad7c13073d8", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f858a03e5d393aa3", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/stores/further.js:230"}, "properties": {"repobilityId": "063f2f0ba7bb9b0e", "scanner": "scanner-primary", "fingerprint": "f858a03e5d393aa3", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c3bf92ad6f799f6a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/stores/gramaphone.js:213"}, "properties": {"repobilityId": "11030445b72697be", "scanner": "scanner-primary", "fingerprint": "c3bf92ad6f799f6a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d16f06fdd2cb3028", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/stores/uvs.js:185"}, "properties": {"repobilityId": "f93fadcd5973727f", "scanner": "scanner-primary", "fingerprint": "d16f06fdd2cb3028", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3032010117356ae1", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/stores/hardwax.js:259"}, "properties": {"repobilityId": "2f04506162d44737", "scanner": "scanner-primary", "fingerprint": "3032010117356ae1", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-cb9019237622ee85", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/stores/octopus.js:229"}, "properties": {"repobilityId": "548d19c3e5f2dff6", "scanner": "scanner-primary", "fingerprint": "cb9019237622ee85", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4e45ac5bfef77d29", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/pipeline-stages/meta-sync.js:37"}, "properties": {"repobilityId": "cc89044db1336de1", "scanner": "scanner-primary", "fingerprint": "4e45ac5bfef77d29", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c552197660d46069", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/pipeline-stages/gem-score.js:23"}, "properties": {"repobilityId": "56b3e9b5fa1b3957", "scanner": "scanner-primary", "fingerprint": "c552197660d46069", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-31a2df0fa5ef9ba9", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/pipeline-stages/wantlist-sync.js:39"}, "properties": {"repobilityId": "b11f774eeaaf9883", "scanner": "scanner-primary", "fingerprint": "31a2df0fa5ef9ba9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-16117a5cfcde9b62", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/pipeline-stages/yt-id-search.js:18"}, "properties": {"repobilityId": "2dbdbfff535d9511", "scanner": "scanner-primary", "fingerprint": "16117a5cfcde9b62", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9370bbf0e7c2ff77", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/pipeline-stages/yt-enrich.js:17"}, "properties": {"repobilityId": "ae6d3c6aafb5378e", "scanner": "scanner-primary", "fingerprint": "9370bbf0e7c2ff77", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-90cc9541f09d0bf7", "level": "note", "message": {"text": "Icon-only button without accessible name \u2014 public/js/app.js:836"}, "properties": {"repobilityId": "844497b979268973", "scanner": "scanner-primary", "fingerprint": "90cc9541f09d0bf7", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.button.no-label"]}}, {"ruleId": "scanner-650fae4087438542", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 public/js/app.js:970"}, "properties": {"repobilityId": "5bf343aa4978169a", "scanner": "scanner-primary", "fingerprint": "650fae4087438542", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-815debb3fee6579f", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in index.html:621"}, "properties": {"repobilityId": "f91708437a3a5445", "scanner": "scanner-primary", "fingerprint": "815debb3fee6579f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "index.html"}, "region": {"startLine": 621}}}]}, {"ruleId": "scanner-d9ba55179f90b70e", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in goldie.js:2543"}, "properties": {"repobilityId": "6bc63734bacc7622", "scanner": "scanner-primary", "fingerprint": "d9ba55179f90b70e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "goldie.js"}, "region": {"startLine": 2543}}}]}, {"ruleId": "scanner-71280d8b7eecd24e", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in server.js:1457"}, "properties": {"repobilityId": "23f3ba0b6e438ed3", "scanner": "scanner-primary", "fingerprint": "71280d8b7eecd24e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "server.js"}, "region": {"startLine": 1457}}}]}, {"ruleId": "scanner-02a9f6e34806ceb2", "level": "warning", "message": {"text": "Insecure pattern 'domparser_html_parse' in chrome-extension/sync-window.js:301"}, "properties": {"repobilityId": "e9ab851383111071", "scanner": "scanner-primary", "fingerprint": "02a9f6e34806ceb2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "domparser_html_parse"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "chrome-extension/sync-window.js"}, "region": {"startLine": 301}}}]}, {"ruleId": "scanner-b6ce11b9502b79d6", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in scripts/preflight.sh:37"}, "properties": {"repobilityId": "f58facdcaa97f679", "scanner": "scanner-primary", "fingerprint": "b6ce11b9502b79d6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/preflight.sh"}, "region": {"startLine": 37}}}]}, {"ruleId": "scanner-c4d17b77c1a280b0", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in lib/mix-resolver.js:436"}, "properties": {"repobilityId": "d43a7b34d5a3a646", "scanner": "scanner-primary", "fingerprint": "c4d17b77c1a280b0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "lib/mix-resolver.js"}, "region": {"startLine": 436}}}]}, {"ruleId": "scanner-7006339a29fc0305", "level": "warning", "message": {"text": "Insecure pattern 'weak_hash' in lib/oauth.js:80"}, "properties": {"repobilityId": "4978c76b79f61136", "scanner": "scanner-primary", "fingerprint": "7006339a29fc0305", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "weak_hash"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "lib/oauth.js"}, "region": {"startLine": 80}}}]}, {"ruleId": "scanner-2e78d1bb63111bb4", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/admin.html:270"}, "properties": {"repobilityId": "df5203f722eec321", "scanner": "scanner-primary", "fingerprint": "2e78d1bb63111bb4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/admin.html"}, "region": {"startLine": 270}}}]}, {"ruleId": "scanner-e10126f7f21cc4ef", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/js/app.js:393"}, "properties": {"repobilityId": "20ef8ff0d2135a46", "scanner": "scanner-primary", "fingerprint": "e10126f7f21cc4ef", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/js/app.js"}, "region": {"startLine": 393}}}]}, {"ruleId": "scanner-a1edc95c5d123d4c", "level": "warning", "message": {"text": "Insecure pattern 'insert_adjacent_html' in public/js/app.js:1567"}, "properties": {"repobilityId": "078d8b132772047a", "scanner": "scanner-primary", "fingerprint": "a1edc95c5d123d4c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "insert_adjacent_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/js/app.js"}, "region": {"startLine": 1567}}}]}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-1de2b68a437f4f0f", "level": "note", "message": {"text": "Very large file: db.js (2902 lines)"}, "properties": {"repobilityId": "e046e77351c30956", "scanner": "scanner-primary", "fingerprint": "1de2b68a437f4f0f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-34e24aceafdd9403", "level": "note", "message": {"text": "Very large file: goldie.js (2699 lines)"}, "properties": {"repobilityId": "0f0df17cd8b81fd6", "scanner": "scanner-primary", "fingerprint": "34e24aceafdd9403", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-01df037d9d35c93e", "level": "note", "message": {"text": "Very large file: server.js (4436 lines)"}, "properties": {"repobilityId": "1479ba50e708c5c1", "scanner": "scanner-primary", "fingerprint": "01df037d9d35c93e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-9fe91e8d0496cea1", "level": "note", "message": {"text": "Very large file: lib/mix-resolver.js (1173 lines)"}, "properties": {"repobilityId": "4c0dfeea3e429ee1", "scanner": "scanner-primary", "fingerprint": "9fe91e8d0496cea1", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-02ee36a071929825", "level": "note", "message": {"text": "Very large file: lib/scrapers.js (987 lines)"}, "properties": {"repobilityId": "a078bd9a79e91ca1", "scanner": "scanner-primary", "fingerprint": "02ee36a071929825", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-9cf885f653715055", "level": "note", "message": {"text": "Very large file: lib/scanner.js (2091 lines)"}, "properties": {"repobilityId": "77729f7a0c83da4f", "scanner": "scanner-primary", "fingerprint": "9cf885f653715055", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-336e34bc89e42c50", "level": "note", "message": {"text": "Very large file: public/js/app.js (8189 lines)"}, "properties": {"repobilityId": "95bc23e2f7df6e1a", "scanner": "scanner-primary", "fingerprint": "336e34bc89e42c50", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ea3b5e389d8c9c0f", "level": "note", "message": {"text": "Low test-to-source ratio"}, "properties": {"repobilityId": "ef7b2552cc00a375", "scanner": "scanner-primary", "fingerprint": "ea3b5e389d8c9c0f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["tests"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "ee3b1ffcd4569ff4", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "8300a35504549b8b", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "bf22989257ae29fd", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "9fc54535bca9052b", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "e56b2509fce05476", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "6df578a515e2cfa8", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "99f31d91ec0036b3", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "4084a88702b992bd", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-505bc666a82f9849", "level": "error", "message": {"text": "Agent instruction/config may expose a secret: .claude/settings.local.json"}, "properties": {"repobilityId": "777970b0fce0a93b", "scanner": "scanner-primary", "fingerprint": "505bc666a82f9849", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["agent-instructions", "secrets", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/settings.local.json"}, "region": {"startLine": 74}}}]}, {"ruleId": "scanner-ecb0d2c55ed6875d", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/settings.local.json"}, "properties": {"repobilityId": "d8bae33a6d517bf0", "scanner": "scanner-primary", "fingerprint": "ecb0d2c55ed6875d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/settings.local.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-32571644a2b6231b", "level": "none", "message": {"text": "Commented-code block (7 lines) in vinyl-checker-puppeteer.js:520"}, "properties": {"repobilityId": "eb3bfbaff00dc975", "scanner": "scanner-primary", "fingerprint": "32571644a2b6231b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ac30c5b3a5317024", "level": "none", "message": {"text": "Commented-code block (5 lines) in goldie.js:1733"}, "properties": {"repobilityId": "4c48ec3f70245989", "scanner": "scanner-primary", "fingerprint": "ac30c5b3a5317024", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6976860273001b2b", "level": "none", "message": {"text": "Commented-code block (5 lines) in server.js:1385"}, "properties": {"repobilityId": "d42d8a71ba30be85", "scanner": "scanner-primary", "fingerprint": "6976860273001b2b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0fc36f5d74802e09", "level": "none", "message": {"text": "Commented-code block (6 lines) in chrome-extension/background.js:127"}, "properties": {"repobilityId": "e775b6c66d7304ba", "scanner": "scanner-primary", "fingerprint": "0fc36f5d74802e09", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8a8d2a1a220d7411", "level": "none", "message": {"text": "Commented-code block (5 lines) in lib/youtube-enrichment.js:50"}, "properties": {"repobilityId": "cf4b5c60639a844d", "scanner": "scanner-primary", "fingerprint": "8a8d2a1a220d7411", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-92f0e4d4693470c6", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 lib/youtube-enrichment.js:238"}, "properties": {"repobilityId": "fc655d4a079220ce", "scanner": "scanner-primary", "fingerprint": "92f0e4d4693470c6", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-e40bb06643e442e4", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 lib/youtube-ingest.js:29"}, "properties": {"repobilityId": "e238b7eb78e4a826", "scanner": "scanner-primary", "fingerprint": "e40bb06643e442e4", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-0b5312c82dd84e7e", "level": "none", "message": {"text": "Commented-code block (5 lines) in lib/mix-resolver.js:572"}, "properties": {"repobilityId": "c0dfa1bb4fd1e28a", "scanner": "scanner-primary", "fingerprint": "0b5312c82dd84e7e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-17814a7e5a06181e", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 lib/mix-resolver.js:150"}, "properties": {"repobilityId": "d787490af9b18475", "scanner": "scanner-primary", "fingerprint": "17814a7e5a06181e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-0ae9266f0de983dc", "level": "none", "message": {"text": "Commented-code block (9 lines) in lib/scrapers.js:43"}, "properties": {"repobilityId": "bcc139ca0fff5f66", "scanner": "scanner-primary", "fingerprint": "0ae9266f0de983dc", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-347803edb8d80fca", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 lib/soundcloud.js:26"}, "properties": {"repobilityId": "fee1cd1c305bfb5e", "scanner": "scanner-primary", "fingerprint": "347803edb8d80fca", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-e54736dd6dc5df6e", "level": "none", "message": {"text": "Commented-code block (5 lines) in lib/scanner.js:26"}, "properties": {"repobilityId": "60fa55854dacef24", "scanner": "scanner-primary", "fingerprint": "e54736dd6dc5df6e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6cdd01f0bc209de0", "level": "none", "message": {"text": "Commented-code block (5 lines) in lib/stores/further.js:35"}, "properties": {"repobilityId": "2fbbb57708b15626", "scanner": "scanner-primary", "fingerprint": "6cdd01f0bc209de0", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8b62f19ae76aa68f", "level": "none", "message": {"text": "Commented-code block (6 lines) in lib/stores/uvs.js:53"}, "properties": {"repobilityId": "9a08d3fc037e6e22", "scanner": "scanner-primary", "fingerprint": "8b62f19ae76aa68f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1b38bd7d37b6c60c", "level": "none", "message": {"text": "Commented-code block (6 lines) in lib/stores/octopus.js:59"}, "properties": {"repobilityId": "798515d34cc918af", "scanner": "scanner-primary", "fingerprint": "1b38bd7d37b6c60c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-cb53573b9012293a", "level": "none", "message": {"text": "Commented-code block (6 lines) in lib/stores/shopify.js:39"}, "properties": {"repobilityId": "7dc14a614a213b4c", "scanner": "scanner-primary", "fingerprint": "cb53573b9012293a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c030ed78269e784e", "level": "none", "message": {"text": "Commented-code block (5 lines) in public/js/app.js:189"}, "properties": {"repobilityId": "3c61e1e996763a90", "scanner": "scanner-primary", "fingerprint": "c030ed78269e784e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e2152102f04481f3", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/js/app.js:760"}, "properties": {"repobilityId": "e42e4b99ef22196a", "scanner": "scanner-primary", "fingerprint": "e2152102f04481f3", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-5b454b67ecf8c581", "level": "error", "message": {"text": "Dangling fetch: GET https://soundcloud.com/ (lib/mix-resolver.js:697)"}, "properties": {"repobilityId": "e714b77a25cfbf46", "scanner": "scanner-primary", "fingerprint": "5b454b67ecf8c581", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-cdbb5400079c8116", "level": "note", "message": {"text": "Unused endpoint: GET /extension"}, "properties": {"repobilityId": "d682f8cbdd752bdb", "scanner": "scanner-primary", "fingerprint": "cdbb5400079c8116", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-562322a28c342d7f", "level": "note", "message": {"text": "Unused endpoint: GET /api/auth/status"}, "properties": {"repobilityId": "54ec2771a288ca77", "scanner": "scanner-primary", "fingerprint": "562322a28c342d7f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-82d9930fba6e382f", "level": "note", "message": {"text": "Unused endpoint: GET /api/auth/discogs"}, "properties": {"repobilityId": "84e43a7742cce5b2", "scanner": "scanner-primary", "fingerprint": "82d9930fba6e382f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6e6485573ef0264a", "level": "note", "message": {"text": "Unused endpoint: GET /api/auth/discogs/callback"}, "properties": {"repobilityId": "7a53feced624af74", "scanner": "scanner-primary", "fingerprint": "6e6485573ef0264a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3d0ca4266fc53792", "level": "note", "message": {"text": "Unused endpoint: POST /api/auth/discogs/disconnect"}, "properties": {"repobilityId": "be281d9e490008e3", "scanner": "scanner-primary", "fingerprint": "3d0ca4266fc53792", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-065a7629e7f86caf", "level": "note", "message": {"text": "Unused endpoint: GET /api/auth/google"}, "properties": {"repobilityId": "2d9ca1a3b1f4a6c4", "scanner": "scanner-primary", "fingerprint": "065a7629e7f86caf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ab9e687c0618f84d", "level": "note", "message": {"text": "Unused endpoint: GET /api/auth/google/callback"}, "properties": {"repobilityId": "a469564f20267a71", "scanner": "scanner-primary", "fingerprint": "ab9e687c0618f84d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-13e56a1eb740ee97", "level": "note", "message": {"text": "Unused endpoint: POST /api/auth/google/disconnect"}, "properties": {"repobilityId": "155fbdf6de306627", "scanner": "scanner-primary", "fingerprint": "13e56a1eb740ee97", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1ce88fb2df9e05b8", "level": "note", "message": {"text": "Unused endpoint: GET /api/auth/soundcloud"}, "properties": {"repobilityId": "0c9d36866f1cd3fd", "scanner": "scanner-primary", "fingerprint": "1ce88fb2df9e05b8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f6cc13327b840120", "level": "note", "message": {"text": "Unused endpoint: GET /api/auth/soundcloud/callback"}, "properties": {"repobilityId": "a04a9e2ed639cc3d", "scanner": "scanner-primary", "fingerprint": "f6cc13327b840120", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-05e0c61695ba654a", "level": "note", "message": {"text": "Unused endpoint: POST /api/auth/soundcloud/disconnect"}, "properties": {"repobilityId": "2c0cfdc30da80f1a", "scanner": "scanner-primary", "fingerprint": "05e0c61695ba654a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fb03f586917d1501", "level": "note", "message": {"text": "Unused endpoint: POST /api/soundcloud/ingest"}, "properties": {"repobilityId": "543cc471029df5bd", "scanner": "scanner-primary", "fingerprint": "fb03f586917d1501", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2ddc3b00998a1589", "level": "note", "message": {"text": "Unused endpoint: GET /api/soundcloud/status"}, "properties": {"repobilityId": "0553022ae9fe2a0b", "scanner": "scanner-primary", "fingerprint": "2ddc3b00998a1589", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e44c5b063d97ec8c", "level": "note", "message": {"text": "Unused endpoint: POST /api/youtube/ingest"}, "properties": {"repobilityId": "17c3948bbaaf05ac", "scanner": "scanner-primary", "fingerprint": "e44c5b063d97ec8c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8f222efc3572ccf8", "level": "note", "message": {"text": "Unused endpoint: GET /api/youtube/status"}, "properties": {"repobilityId": "a7a007a992f8dbd3", "scanner": "scanner-primary", "fingerprint": "8f222efc3572ccf8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1aa188b3ade54eb5", "level": "note", "message": {"text": "Unused endpoint: GET /api/discovery/:username"}, "properties": {"repobilityId": "298932714deb089a", "scanner": "scanner-primary", "fingerprint": "1aa188b3ade54eb5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3c38c2366ce1f0ee", "level": "note", "message": {"text": "Unused endpoint: POST /api/youtube/create-playlist"}, "properties": {"repobilityId": "f56385fa41f5af25", "scanner": "scanner-primary", "fingerprint": "3c38c2366ce1f0ee", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-be3ff2caa1757ca0", "level": "note", "message": {"text": "Unused endpoint: GET /api/reset"}, "properties": {"repobilityId": "ad64e691bd9e0681", "scanner": "scanner-primary", "fingerprint": "be3ff2caa1757ca0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6b0e7f5976711316", "level": "note", "message": {"text": "Unused endpoint: GET /api/session"}, "properties": {"repobilityId": "bb3ea1ba18e02617", "scanner": "scanner-primary", "fingerprint": "6b0e7f5976711316", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fcdb619a018a7454", "level": "note", "message": {"text": "Unused endpoint: POST /api/session"}, "properties": {"repobilityId": "d25a3a14edd65543", "scanner": "scanner-primary", "fingerprint": "fcdb619a018a7454", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a10936f69cf3bbb4", "level": "note", "message": {"text": "Unused endpoint: POST /api/logout"}, "properties": {"repobilityId": "1488149da6c7b2f0", "scanner": "scanner-primary", "fingerprint": "a10936f69cf3bbb4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-775836f50c0fdf36", "level": "note", "message": {"text": "Unused endpoint: GET /api/test-stores"}, "properties": {"repobilityId": "bd07905d5c3cf236", "scanner": "scanner-primary", "fingerprint": "775836f50c0fdf36", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f483bbb4727756d7", "level": "note", "message": {"text": "Unused endpoint: GET /api/validate"}, "properties": {"repobilityId": "bb46cf519a90a8c9", "scanner": "scanner-primary", "fingerprint": "f483bbb4727756d7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bebeb829c7746471", "level": "note", "message": {"text": "Unused endpoint: GET /api/scan/:username"}, "properties": {"repobilityId": "a88eb1798c11d7b1", "scanner": "scanner-primary", "fingerprint": "bebeb829c7746471", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d471e840eee40a55", "level": "note", "message": {"text": "Unused endpoint: GET /api/results/:username"}, "properties": {"repobilityId": "965b1f9b841c76c9", "scanner": "scanner-primary", "fingerprint": "d471e840eee40a55", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-438e978ec66fde3a", "level": "note", "message": {"text": "Unused endpoint: GET /api/collection/:username"}, "properties": {"repobilityId": "22a4b68638812c0c", "scanner": "scanner-primary", "fingerprint": "438e978ec66fde3a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2ef9c7f1986f72e9", "level": "note", "message": {"text": "Unused endpoint: GET /api/release/:discogs_id"}, "properties": {"repobilityId": "a2c326e892e431d2", "scanner": "scanner-primary", "fingerprint": "2ef9c7f1986f72e9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e0221298a213b912", "level": "note", "message": {"text": "Unused endpoint: GET /api/price-history/:discogs_id"}, "properties": {"repobilityId": "242b882130f8ef80", "scanner": "scanner-primary", "fingerprint": "e0221298a213b912", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d4fb8b4f3f45a324", "level": "note", "message": {"text": "Unused endpoint: GET /api/history/:discogs_id"}, "properties": {"repobilityId": "c08061b084b6de14", "scanner": "scanner-primary", "fingerprint": "d4fb8b4f3f45a324", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-07b4f403ef8fa198", "level": "note", "message": {"text": "Unused endpoint: GET /api/preferences/:username"}, "properties": {"repobilityId": "2b6e2ec5d559bbbb", "scanner": "scanner-primary", "fingerprint": "07b4f403ef8fa198", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8d0af95b76ac04a8", "level": "note", "message": {"text": "Unused endpoint: POST /api/preferences/:username"}, "properties": {"repobilityId": "9f25121edf27f187", "scanner": "scanner-primary", "fingerprint": "8d0af95b76ac04a8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f262e6c5bc7dcae7", "level": "note", "message": {"text": "Unused endpoint: POST /api/optimize/:username"}, "properties": {"repobilityId": "188f6314271ab999", "scanner": "scanner-primary", "fingerprint": "f262e6c5bc7dcae7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cc4db14d90efdf9e", "level": "note", "message": {"text": "Unused endpoint: GET /api/optimize/job/:jobId"}, "properties": {"repobilityId": "5103828cdadcabef", "scanner": "scanner-primary", "fingerprint": "cc4db14d90efdf9e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a5237a90f012b17c", "level": "note", "message": {"text": "Unused endpoint: GET /api/optimize/latest/:username"}, "properties": {"repobilityId": "9d0d3db93c0fe1de", "scanner": "scanner-primary", "fingerprint": "a5237a90f012b17c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ea1454ed83525840", "level": "note", "message": {"text": "Unused endpoint: GET /api/recommend/:username"}, "properties": {"repobilityId": "9d8343a4b9ecf89e", "scanner": "scanner-primary", "fingerprint": "ea1454ed83525840", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-744b590128b8791e", "level": "note", "message": {"text": "Unused endpoint: POST /api/verify"}, "properties": {"repobilityId": "f04a9f309062694c", "scanner": "scanner-primary", "fingerprint": "744b590128b8791e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-963710f42a2c8219", "level": "note", "message": {"text": "Unused endpoint: GET /api/status"}, "properties": {"repobilityId": "fa2554f166d66db7", "scanner": "scanner-primary", "fingerprint": "963710f42a2c8219", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-de520adc97b20cde", "level": "note", "message": {"text": "Unused endpoint: GET /api/job-health"}, "properties": {"repobilityId": "8982b008d4a21fee", "scanner": "scanner-primary", "fingerprint": "de520adc97b20cde", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f9e888b9fbdc54a8", "level": "note", "message": {"text": "Unused endpoint: POST /api/trigger"}, "properties": {"repobilityId": "8b0aea725acf1424", "scanner": "scanner-primary", "fingerprint": "f9e888b9fbdc54a8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3c5678301beea41b", "level": "note", "message": {"text": "Unused endpoint: POST /api/admin/sync-store"}, "properties": {"repobilityId": "76d9809cca062d26", "scanner": "scanner-primary", "fingerprint": "3c5678301beea41b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a87e60b297cd2de", "level": "note", "message": {"text": "Unused endpoint: POST /api/deploy"}, "properties": {"repobilityId": "eaeb198431709fab", "scanner": "scanner-primary", "fingerprint": "7a87e60b297cd2de", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-77b7497aae5f2344", "level": "note", "message": {"text": "Unused endpoint: GET /api/scan-status/:username"}, "properties": {"repobilityId": "b81e925f536c3641", "scanner": "scanner-primary", "fingerprint": "77b7497aae5f2344", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bcb7965ae0468f73", "level": "note", "message": {"text": "Unused endpoint: GET /api/meta-sync/:username"}, "properties": {"repobilityId": "92ba838096a9cc32", "scanner": "scanner-primary", "fingerprint": "bcb7965ae0468f73", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-201ba901e1ed5458", "level": "note", "message": {"text": "Unused endpoint: GET /api/pipeline/status"}, "properties": {"repobilityId": "ead42e1a3d53e7c8", "scanner": "scanner-primary", "fingerprint": "201ba901e1ed5458", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8aca3e9fefe330e7", "level": "note", "message": {"text": "Unused endpoint: GET /api/pipeline/log"}, "properties": {"repobilityId": "05bd7136e455335f", "scanner": "scanner-primary", "fingerprint": "8aca3e9fefe330e7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bb2eae295b3c1159", "level": "note", "message": {"text": "Unused endpoint: POST /api/pipeline/trigger"}, "properties": {"repobilityId": "86fd2cc29889c0ba", "scanner": "scanner-primary", "fingerprint": "bb2eae295b3c1159", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-50de348e375d3b1b", "level": "note", "message": {"text": "Unused endpoint: POST /api/wantlist/add"}, "properties": {"repobilityId": "ea409784aa877a9b", "scanner": "scanner-primary", "fingerprint": "50de348e375d3b1b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-99ccc3d032ece5c0", "level": "note", "message": {"text": "Unused endpoint: DELETE /api/wantlist/:username/:discogsId"}, "properties": {"repobilityId": "55f98ef410760d1a", "scanner": "scanner-primary", "fingerprint": "99ccc3d032ece5c0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b43579ea2d0c5baf", "level": "note", "message": {"text": "Unused endpoint: POST /api/collection/add"}, "properties": {"repobilityId": "2508b733818c9280", "scanner": "scanner-primary", "fingerprint": "b43579ea2d0c5baf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-728f7232e1fa4f79", "level": "note", "message": {"text": "Unused endpoint: GET /api/digger-recommendations/:username"}, "properties": {"repobilityId": "3ddbb4d943d4ca7d", "scanner": "scanner-primary", "fingerprint": "728f7232e1fa4f79", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}