{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-d2665c6a15a1a1bf", "name": "`truncate` class without `title=` for hover reveal \u2014 components/layout/sidebar.tsx:402", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 components/layout/sidebar.tsx:402"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f0fac85fbc1af251", "name": "`truncate` class without `title=` for hover reveal \u2014 components/layout/university-switcher.tsx:83", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 components/layout/university-switcher.tsx:83"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-35c1d6c1a9bd1064", "name": "`truncate` class without `title=` for hover reveal \u2014 components/layout/page-header.tsx:33", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 components/layout/page-header.tsx:33"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e3b547553e3191c5", "name": "Stray `console.log` in TS/JS \u2014 components/auth/auth-provider.tsx:61", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 components/auth/auth-provider.tsx:61"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d459e9df3ea144dc", "name": "`truncate` class without `title=` for hover reveal \u2014 components/ui/date-time-picker.tsx:112", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 components/ui/date-time-picker.tsx:112"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bae8373f45d18879", "name": "`truncate` class without `title=` for hover reveal \u2014 components/ui/file-upload.tsx:159", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 components/ui/file-upload.tsx:159"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a8d50d28e320d941", "name": "`truncate` class without `title=` for hover reveal \u2014 components/universities/UniversityAppearanceModal.tsx:212", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 components/universities/UniversityAppearanceModal.tsx:212"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3111078097806e3d", "name": "`truncate` class without `title=` for hover reveal \u2014 components/courses/course-calendar-tab.tsx:404", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 components/courses/course-calendar-tab.tsx:404"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-eb8ee31ffcd0bed6", "name": "Stray `console.log` in TS/JS \u2014 app/api/auth/login/route.ts:26", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 app/api/auth/login/route.ts:26"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fe41762a4c77d324", "name": "`truncate` class without `title=` for hover reveal \u2014 app/(dashboard)/analytics/page.tsx:485", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/(dashboard)/analytics/page.tsx:485"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2a910ba338dfe144", "name": "TODO/FIXME marker in shipping code \u2014 app/(dashboard)/admin/page.tsx:1", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 app/(dashboard)/admin/page.tsx:1"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2842a63efa67d3dc", "name": "`truncate` class without `title=` for hover reveal \u2014 app/(dashboard)/admin/permissions/page.tsx:189", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/(dashboard)/admin/permissions/page.tsx:189"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1da42d364316fa31", "name": "`truncate` class without `title=` for hover reveal \u2014 app/(dashboard)/modules/[id]/page.tsx:1462", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/(dashboard)/modules/[id]/page.tsx:1462"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-99487c29c912c274", "name": "`truncate` class without `title=` for hover reveal \u2014 app/(dashboard)/universities/page.tsx:65", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/(dashboard)/universities/page.tsx:65"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-dc87613836d3d18a", "name": "`truncate` class without `title=` for hover reveal \u2014 app/(dashboard)/professor-agent/page.tsx:307", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/(dashboard)/professor-agent/page.tsx:307"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-48b441a61ba3e33c", "name": "`truncate` class without `title=` for hover reveal \u2014 app/(dashboard)/tutorials/page.tsx:629", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/(dashboard)/tutorials/page.tsx:629"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-85825508514152d5", "name": "Stray `console.log` in TS/JS \u2014 app/(auth)/signup/page.tsx:139", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 app/(auth)/signup/page.tsx:139"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-44f43b1e6821159e", "name": "Stray `console.log` in TS/JS \u2014 lib/api.ts:304", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/api.ts:304"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-206b557dd2430ac5", "name": "Stray `console.log` in TS/JS \u2014 lib/utils.ts:477", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/utils.ts:477"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-195438e9cf126016", "name": "Insecure pattern 'local_storage_auth_token' in components/auth/auth-provider.tsx:188", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in components/auth/auth-provider.tsx:188"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-28c5ab92f4e2338d", "name": "Insecure pattern 'local_storage_auth_token' in lib/api.ts:178", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in lib/api.ts:178"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5d5062490e378be8", "name": "Insecure pattern 'local_storage_auth_token' in lib/auth.ts:56", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in lib/auth.ts:56"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8f4c232b4aa78fc9", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-77166cbd46fcd8e4", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-27924aa79fa4a517", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-de53ac274e5b4ecf", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-37716d9c0a33ad5c", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9c4a9d9220527b75", "name": "Very large file: app/(dashboard)/modules/[id]/page.tsx (2332 lines)", "shortDescription": {"text": "Very large file: app/(dashboard)/modules/[id]/page.tsx (2332 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-442b196257b02a42", "name": "Very large file: app/(dashboard)/courses/[id]/page.tsx (1636 lines)", "shortDescription": {"text": "Very large file: app/(dashboard)/courses/[id]/page.tsx (1636 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a26e0b4cb3849170", "name": "Very large file: lib/api.ts (1637 lines)", "shortDescription": {"text": "Very large file: lib/api.ts (1637 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "0 test file(s) for 136 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 18 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 211 placeholder/mock markers across 50 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-11825279136b53a3", "name": "CI is configured but no tests are detected", "shortDescription": {"text": "CI is configured but no tests are detected"}, "fullDescription": {"text": "A CI pipeline exists, but the scan found no test files to gate. Opus labeled this generated-code pattern as config theater: release machinery exists, but it has little behavioral signal."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, tests. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license, tests. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2c83f1d87dbe51ff", "name": "Legacy-named symbol `include_deprecated` in components/modules/ai-model-selector.tsx:44", "shortDescription": {"text": "Legacy-named symbol `include_deprecated` in components/modules/ai-model-selector.tsx:44"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3d6bbe3688edaa68", "name": "`fetch()` without try/.catch or AbortSignal \u2014 app/api/auth/login/route.ts:75", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 app/api/auth/login/route.ts:75"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-da06276ee326cfba", "name": "Legacy-named symbol `isDeprecated` in app/(dashboard)/models/page.tsx:69", "shortDescription": {"text": "Legacy-named symbol `isDeprecated` in app/(dashboard)/models/page.tsx:69"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7f53365b48ee1172", "name": "Commented-code block (5 lines) in app/(dashboard)/universities/[id]/page.tsx:89", "shortDescription": {"text": "Commented-code block (5 lines) in app/(dashboard)/universities/[id]/page.tsx:89"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-384d3498f31b8a90", "name": "Legacy-named symbol `include_deprecated` in lib/api.ts:745", "shortDescription": {"text": "Legacy-named symbol `include_deprecated` in lib/api.ts:745"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4731554d3d68af8e", "name": "`fetch()` without try/.catch or AbortSignal \u2014 lib/api.ts:217", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 lib/api.ts:217"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8143a345715bd45d", "name": "Legacy-named symbol `isDeprecated` in lib/types.ts:316", "shortDescription": {"text": "Legacy-named symbol `isDeprecated` in lib/types.ts:316"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e86c9bdfeba13961", "name": "Dangling fetch: POST /api/auth/login (lib/api.ts:455)", "shortDescription": {"text": "Dangling fetch: POST /api/auth/login (lib/api.ts:455)"}, "fullDescription": {"text": "`lib/api.ts:455` calls `POST /api/auth/login` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/auth/login`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2837b059a20cb7bf", "name": "Dangling fetch: GET /api/permissions (lib/api.ts:1535)", "shortDescription": {"text": "Dangling fetch: GET /api/permissions (lib/api.ts:1535)"}, "fullDescription": {"text": "`lib/api.ts:1535` calls `GET /api/permissions` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/permissions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0336f7f4b6ec9181", "name": "Dangling fetch: GET /api/permissions/roles/${role} (lib/api.ts:1539)", "shortDescription": {"text": "Dangling fetch: GET /api/permissions/roles/${role} (lib/api.ts:1539)"}, "fullDescription": {"text": "`lib/api.ts:1539` calls `GET /api/permissions/roles/${role}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/permissions/roles/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-99e745011b6dfadd", "name": "Dangling fetch: GET /api/permissions/users/${userId}/extra (lib/api.ts:1543)", "shortDescription": {"text": "Dangling fetch: GET /api/permissions/users/${userId}/extra (lib/api.ts:1543)"}, "fullDescription": {"text": "`lib/api.ts:1543` calls `GET /api/permissions/users/${userId}/extra` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/permissions/users/<p>/extra`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5ea9f531d278bd24", "name": "Dangling fetch: PUT /api/permissions/users/${userId} (lib/api.ts:1547)", "shortDescription": {"text": "Dangling fetch: PUT /api/permissions/users/${userId} (lib/api.ts:1547)"}, "fullDescription": {"text": "`lib/api.ts:1547` calls `PUT /api/permissions/users/${userId}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/permissions/users/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-76b17b7b92800d4b", "name": "Dangling fetch: POST /api/permissions (lib/api.ts:1554)", "shortDescription": {"text": "Dangling fetch: POST /api/permissions (lib/api.ts:1554)"}, "fullDescription": {"text": "`lib/api.ts:1554` calls `POST /api/permissions` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/permissions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dea783528240f94d", "name": "Dangling fetch: PUT /api/permissions/${id} (lib/api.ts:1561)", "shortDescription": {"text": "Dangling fetch: PUT /api/permissions/${id} (lib/api.ts:1561)"}, "fullDescription": {"text": "`lib/api.ts:1561` calls `PUT /api/permissions/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/permissions/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-657b8ae1b15a2f6e", "name": "Dangling fetch: DELETE /api/permissions/${id} (lib/api.ts:1568)", "shortDescription": {"text": "Dangling fetch: DELETE /api/permissions/${id} (lib/api.ts:1568)"}, "fullDescription": {"text": "`lib/api.ts:1568` calls `DELETE /api/permissions/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/permissions/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-360e4d1f582fed0b", "name": "Dangling fetch: GET https://viacep.com.br/ws/${cleanCEP}/json/ (lib/utils.ts:496)", "shortDescription": {"text": "Dangling fetch: GET https://viacep.com.br/ws/${cleanCEP}/json/ (lib/utils.ts:496)"}, "fullDescription": {"text": "`lib/utils.ts:496` calls `GET https://viacep.com.br/ws/${cleanCEP}/json/` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/viacep.com.br/ws/<p>/json`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2d67c4be403afb88", "name": "Unused endpoint: POST /api/auth/password-reset-request", "shortDescription": {"text": "Unused endpoint: POST /api/auth/password-reset-request"}, "fullDescription": {"text": "`lib/api.ts` declares `POST /api/auth/password-reset-request` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fcafb84e94667528", "name": "Unused endpoint: POST /api/auth/password-reset", "shortDescription": {"text": "Unused endpoint: POST /api/auth/password-reset"}, "fullDescription": {"text": "`lib/api.ts` declares `POST /api/auth/password-reset` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1ce62746afa9022a", "name": "Unused endpoint: PUT /api/auth/me/password", "shortDescription": {"text": "Unused endpoint: PUT /api/auth/me/password"}, "fullDescription": {"text": "`lib/api.ts` declares `PUT /api/auth/me/password` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ee4aa5ddab88c9dc", "name": "Unused endpoint: GET /api/auth/me", "shortDescription": {"text": "Unused endpoint: GET /api/auth/me"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/auth/me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dab7c8fe051d4c01", "name": "Unused endpoint: PUT /api/auth/me", "shortDescription": {"text": "Unused endpoint: PUT /api/auth/me"}, "fullDescription": {"text": "`lib/api.ts` declares `PUT /api/auth/me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0c5de195ac15d60d", "name": "Unused endpoint: GET /api/universities/", "shortDescription": {"text": "Unused endpoint: GET /api/universities/"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/universities/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1461f370d1aecc0e", "name": "Unused endpoint: POST /api/universities/", "shortDescription": {"text": "Unused endpoint: POST /api/universities/"}, "fullDescription": {"text": "`lib/api.ts` declares `POST /api/universities/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-edaa0be17d70101b", "name": "Unused endpoint: GET /api/courses/", "shortDescription": {"text": "Unused endpoint: GET /api/courses/"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/courses/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1dacd69505026c92", "name": "Unused endpoint: POST /api/courses/", "shortDescription": {"text": "Unused endpoint: POST /api/courses/"}, "fullDescription": {"text": "`lib/api.ts` declares `POST /api/courses/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a7912d8e8fce9543", "name": "Unused endpoint: GET /api/modules/", "shortDescription": {"text": "Unused endpoint: GET /api/modules/"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/modules/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-12a020fe0743cd34", "name": "Unused endpoint: POST /api/modules/", "shortDescription": {"text": "Unused endpoint: POST /api/modules/"}, "fullDescription": {"text": "`lib/api.ts` declares `POST /api/modules/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bcb6689d2aa56e16", "name": "Unused endpoint: POST /api/quiz-upload-jobs", "shortDescription": {"text": "Unused endpoint: POST /api/quiz-upload-jobs"}, "fullDescription": {"text": "`lib/api.ts` declares `POST /api/quiz-upload-jobs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-07eb5bba53e9db79", "name": "Unused endpoint: GET /api/assignments", "shortDescription": {"text": "Unused endpoint: GET /api/assignments"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/assignments` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6940d60c9c754e19", "name": "Unused endpoint: POST /api/assignments", "shortDescription": {"text": "Unused endpoint: POST /api/assignments"}, "fullDescription": {"text": "`lib/api.ts` declares `POST /api/assignments` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-11a75b776846ebbb", "name": "Unused endpoint: GET /api/grading-jobs", "shortDescription": {"text": "Unused endpoint: GET /api/grading-jobs"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/grading-jobs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c9ea39eda4b5cff1", "name": "Unused endpoint: POST /api/grading-jobs", "shortDescription": {"text": "Unused endpoint: POST /api/grading-jobs"}, "fullDescription": {"text": "`lib/api.ts` declares `POST /api/grading-jobs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d96ed5b2791381a3", "name": "Unused endpoint: GET /api/quiz-upload-jobs", "shortDescription": {"text": "Unused endpoint: GET /api/quiz-upload-jobs"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/quiz-upload-jobs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-af6d1b4b379762e6", "name": "Unused endpoint: GET /api/ai-models/", "shortDescription": {"text": "Unused endpoint: GET /api/ai-models/"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/ai-models/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4520139023886ab6", "name": "Unused endpoint: POST /api/ai-models/", "shortDescription": {"text": "Unused endpoint: POST /api/ai-models/"}, "fullDescription": {"text": "`lib/api.ts` declares `POST /api/ai-models/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-894c4cda6d8939a4", "name": "Unused endpoint: GET /api/files/", "shortDescription": {"text": "Unused endpoint: GET /api/files/"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/files/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-da6f6e57d14fe732", "name": "Unused endpoint: POST /api/files", "shortDescription": {"text": "Unused endpoint: POST /api/files"}, "fullDescription": {"text": "`lib/api.ts` declares `POST /api/files` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-de68d1932d6fb401", "name": "Unused endpoint: POST /api/videos/youtube", "shortDescription": {"text": "Unused endpoint: POST /api/videos/youtube"}, "fullDescription": {"text": "`lib/api.ts` declares `POST /api/videos/youtube` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d3686ad3114afa63", "name": "Unused endpoint: GET /api/students/", "shortDescription": {"text": "Unused endpoint: GET /api/students/"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/students/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7ffcb06e89bd5018", "name": "Unused endpoint: POST /api/students/", "shortDescription": {"text": "Unused endpoint: POST /api/students/"}, "fullDescription": {"text": "`lib/api.ts` declares `POST /api/students/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d86e275e949f5ddf", "name": "Unused endpoint: POST /api/students/import", "shortDescription": {"text": "Unused endpoint: POST /api/students/import"}, "fullDescription": {"text": "`lib/api.ts` declares `POST /api/students/import` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eeb6c934ecb04d18", "name": "Unused endpoint: POST /api/students/mass-unenroll", "shortDescription": {"text": "Unused endpoint: POST /api/students/mass-unenroll"}, "fullDescription": {"text": "`lib/api.ts` declares `POST /api/students/mass-unenroll` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-256930c405a82be4", "name": "Unused endpoint: GET /api/students/import-jobs", "shortDescription": {"text": "Unused endpoint: GET /api/students/import-jobs"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/students/import-jobs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c7d5da02541079bd", "name": "Unused endpoint: GET /api/moduleaccesstokens/", "shortDescription": {"text": "Unused endpoint: GET /api/moduleaccesstokens/"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/moduleaccesstokens/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-974be31c12faf204", "name": "Unused endpoint: POST /api/moduleaccesstokens/", "shortDescription": {"text": "Unused endpoint: POST /api/moduleaccesstokens/"}, "fullDescription": {"text": "`lib/api.ts` declares `POST /api/moduleaccesstokens/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-57d849d42233b624", "name": "Unused endpoint: GET /api/super-admin/stats", "shortDescription": {"text": "Unused endpoint: GET /api/super-admin/stats"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/super-admin/stats` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2471f40c603de2c0", "name": "Unused endpoint: GET /api/super-admin/universities/all", "shortDescription": {"text": "Unused endpoint: GET /api/super-admin/universities/all"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/super-admin/universities/all` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bb013decb25d4c16", "name": "Unused endpoint: GET /api/professoragents/my-agent", "shortDescription": {"text": "Unused endpoint: GET /api/professoragents/my-agent"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/professoragents/my-agent` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-12ffd42265266ecb", "name": "Unused endpoint: GET /api/professoragents", "shortDescription": {"text": "Unused endpoint: GET /api/professoragents"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/professoragents` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b3e6d2a529958ab0", "name": "Unused endpoint: POST /api/professoragents", "shortDescription": {"text": "Unused endpoint: POST /api/professoragents"}, "fullDescription": {"text": "`lib/api.ts` declares `POST /api/professoragents` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1206e6f5aa904b18", "name": "Unused endpoint: GET /api/professoragents/by-professor", "shortDescription": {"text": "Unused endpoint: GET /api/professoragents/by-professor"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/professoragents/by-professor` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd95d4b4658275fd", "name": "Unused endpoint: POST /api/tutor/ask", "shortDescription": {"text": "Unused endpoint: POST /api/tutor/ask"}, "fullDescription": {"text": "`lib/api.ts` declares `POST /api/tutor/ask` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b8d951f209482345", "name": "Unused endpoint: GET /api/analytics/dashboard/summary", "shortDescription": {"text": "Unused endpoint: GET /api/analytics/dashboard/summary"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/analytics/dashboard/summary` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9aec847203e2fbd5", "name": "Unused endpoint: GET /api/analytics/dashboard/unified", "shortDescription": {"text": "Unused endpoint: GET /api/analytics/dashboard/unified"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/analytics/dashboard/unified` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c35841989b020b67", "name": "Unused endpoint: GET /api/analytics/costs/detailed", "shortDescription": {"text": "Unused endpoint: GET /api/analytics/costs/detailed"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/analytics/costs/detailed` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c35df423c69bb137", "name": "Unused endpoint: GET /api/analytics/costs/today", "shortDescription": {"text": "Unused endpoint: GET /api/analytics/costs/today"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/analytics/costs/today` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5e503e59bb91ab72", "name": "Unused endpoint: GET /api/analytics/usage/today", "shortDescription": {"text": "Unused endpoint: GET /api/analytics/usage/today"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/analytics/usage/today` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3e462f74b7778bd6", "name": "Unused endpoint: GET /api/analytics/usage/trends", "shortDescription": {"text": "Unused endpoint: GET /api/analytics/usage/trends"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/analytics/usage/trends` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4efc3c4c806fe80a", "name": "Unused endpoint: GET /api/analytics/usage/hourly", "shortDescription": {"text": "Unused endpoint: GET /api/analytics/usage/hourly"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/analytics/usage/hourly` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-14bfbde4f6be66cc", "name": "Unused endpoint: GET /api/analytics/students/top-active", "shortDescription": {"text": "Unused endpoint: GET /api/analytics/students/top-active"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/analytics/students/top-active` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d641f4a0b7e91ce0", "name": "Unused endpoint: GET /api/analytics/performance/response-quality", "shortDescription": {"text": "Unused endpoint: GET /api/analytics/performance/response-quality"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/analytics/performance/response-quality` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-40b08adde8ffc2f1", "name": "Unused endpoint: GET /api/analytics/engagement/conversations", "shortDescription": {"text": "Unused endpoint: GET /api/analytics/engagement/conversations"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/analytics/engagement/conversations` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6238c7847532e2a6", "name": "Unused endpoint: GET /api/analytics/modules/compare", "shortDescription": {"text": "Unused endpoint: GET /api/analytics/modules/compare"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/analytics/modules/compare` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7ac9cdfe90c885ba", "name": "Unused endpoint: GET /api/analytics/questions/frequently-asked", "shortDescription": {"text": "Unused endpoint: GET /api/analytics/questions/frequently-asked"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/analytics/questions/frequently-asked` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-826e743fba637af7", "name": "Unused endpoint: GET /api/audit-logs", "shortDescription": {"text": "Unused endpoint: GET /api/audit-logs"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/audit-logs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9e1d379cca9c6ecb", "name": "Unused endpoint: GET /api/provider-keys/", "shortDescription": {"text": "Unused endpoint: GET /api/provider-keys/"}, "fullDescription": {"text": "`lib/api.ts` declares `GET /api/provider-keys/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/21741"}, "properties": {"repository": "tutoria-chat/tutoria-ui", "repoUrl": "https://github.com/tutoria-chat/tutoria-ui", "branch": "main"}, "results": [{"ruleId": "scanner-d2665c6a15a1a1bf", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 components/layout/sidebar.tsx:402"}, "properties": {"repobilityId": "4b530623029c8aef", "scanner": "scanner-primary", "fingerprint": "d2665c6a15a1a1bf", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-f0fac85fbc1af251", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 components/layout/university-switcher.tsx:83"}, "properties": {"repobilityId": "32f310b70e3530ce", "scanner": "scanner-primary", "fingerprint": "f0fac85fbc1af251", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-35c1d6c1a9bd1064", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 components/layout/page-header.tsx:33"}, "properties": {"repobilityId": "d93adac1d50de09d", "scanner": "scanner-primary", "fingerprint": "35c1d6c1a9bd1064", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-e3b547553e3191c5", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 components/auth/auth-provider.tsx:61"}, "properties": {"repobilityId": "0ea1fcdb84709e4a", "scanner": "scanner-primary", "fingerprint": "e3b547553e3191c5", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d459e9df3ea144dc", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 components/ui/date-time-picker.tsx:112"}, "properties": {"repobilityId": "fc4b2e309e7b1187", "scanner": "scanner-primary", "fingerprint": "d459e9df3ea144dc", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-bae8373f45d18879", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 components/ui/file-upload.tsx:159"}, "properties": {"repobilityId": "bedab110b1e87469", "scanner": "scanner-primary", "fingerprint": "bae8373f45d18879", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-a8d50d28e320d941", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 components/universities/UniversityAppearanceModal.tsx:212"}, "properties": {"repobilityId": "9c3f9f9da865211b", "scanner": "scanner-primary", "fingerprint": "a8d50d28e320d941", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-3111078097806e3d", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 components/courses/course-calendar-tab.tsx:404"}, "properties": {"repobilityId": "c4c95fd3c7e9aed2", "scanner": "scanner-primary", "fingerprint": "3111078097806e3d", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-eb8ee31ffcd0bed6", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 app/api/auth/login/route.ts:26"}, "properties": {"repobilityId": "6186c9c9e7d34e8b", "scanner": "scanner-primary", "fingerprint": "eb8ee31ffcd0bed6", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-fe41762a4c77d324", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/(dashboard)/analytics/page.tsx:485"}, "properties": {"repobilityId": "f9e97030278722b1", "scanner": "scanner-primary", "fingerprint": "fe41762a4c77d324", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-2a910ba338dfe144", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 app/(dashboard)/admin/page.tsx:1"}, "properties": {"repobilityId": "ca6b401385491773", "scanner": "scanner-primary", "fingerprint": "2a910ba338dfe144", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-2842a63efa67d3dc", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/(dashboard)/admin/permissions/page.tsx:189"}, "properties": {"repobilityId": "2154aaa1a1e14e8b", "scanner": "scanner-primary", "fingerprint": "2842a63efa67d3dc", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-1da42d364316fa31", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/(dashboard)/modules/[id]/page.tsx:1462"}, "properties": {"repobilityId": "a5da6fb8d86cc3b2", "scanner": "scanner-primary", "fingerprint": "1da42d364316fa31", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-99487c29c912c274", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/(dashboard)/universities/page.tsx:65"}, "properties": {"repobilityId": "dbfb054a3c42f34d", "scanner": "scanner-primary", "fingerprint": "99487c29c912c274", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-dc87613836d3d18a", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/(dashboard)/professor-agent/page.tsx:307"}, "properties": {"repobilityId": "25c0edbbaddea142", "scanner": "scanner-primary", "fingerprint": "dc87613836d3d18a", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-48b441a61ba3e33c", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/(dashboard)/tutorials/page.tsx:629"}, "properties": {"repobilityId": "23323b089d176c2a", "scanner": "scanner-primary", "fingerprint": "48b441a61ba3e33c", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-85825508514152d5", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 app/(auth)/signup/page.tsx:139"}, "properties": {"repobilityId": "056a57aac689fe4a", "scanner": "scanner-primary", "fingerprint": "85825508514152d5", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-44f43b1e6821159e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/api.ts:304"}, "properties": {"repobilityId": "9893fced4a0811f8", "scanner": "scanner-primary", "fingerprint": "44f43b1e6821159e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-206b557dd2430ac5", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/utils.ts:477"}, "properties": {"repobilityId": "54500f9d22efb212", "scanner": "scanner-primary", "fingerprint": "206b557dd2430ac5", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-195438e9cf126016", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in components/auth/auth-provider.tsx:188"}, "properties": {"repobilityId": "482dd47fe336d791", "scanner": "scanner-primary", "fingerprint": "195438e9cf126016", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "components/auth/auth-provider.tsx"}, "region": {"startLine": 188}}}]}, {"ruleId": "scanner-28c5ab92f4e2338d", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in lib/api.ts:178"}, "properties": {"repobilityId": "9046f3185ba041be", "scanner": "scanner-primary", "fingerprint": "28c5ab92f4e2338d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "lib/api.ts"}, "region": {"startLine": 178}}}]}, {"ruleId": "scanner-5d5062490e378be8", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in lib/auth.ts:56"}, "properties": {"repobilityId": "4266c6756b1403ef", "scanner": "scanner-primary", "fingerprint": "5d5062490e378be8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "lib/auth.ts"}, "region": {"startLine": 56}}}]}, {"ruleId": "scanner-8f4c232b4aa78fc9", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "979e3b58c19faf5e", "scanner": "scanner-primary", "fingerprint": "8f4c232b4aa78fc9", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/claude-code-review.yml"}, "region": {"startLine": 30}}}]}, {"ruleId": "scanner-8f4c232b4aa78fc9", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "7572d8d133564421", "scanner": "scanner-primary", "fingerprint": "8f4c232b4aa78fc9", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/claude-code-review.yml"}, "region": {"startLine": 36}}}]}, {"ruleId": "scanner-77166cbd46fcd8e4", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "50f3b563ffac10e9", "scanner": "scanner-primary", "fingerprint": "77166cbd46fcd8e4", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/claude-code-review.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ae16880318b99912", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 16}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "989a74409a402368", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 19}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ae16880318b99912", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 41}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "989a74409a402368", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 44}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "bd7f3c1c34d83159", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 58}}}]}, {"ruleId": "scanner-de53ac274e5b4ecf", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "02600186fc092bd4", "scanner": "scanner-primary", "fingerprint": "de53ac274e5b4ecf", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/claude.yml"}, "region": {"startLine": 29}}}]}, {"ruleId": "scanner-de53ac274e5b4ecf", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "8ead6a2c2bfe167b", "scanner": "scanner-primary", "fingerprint": "de53ac274e5b4ecf", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/claude.yml"}, "region": {"startLine": 35}}}]}, {"ruleId": "scanner-37716d9c0a33ad5c", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "abfb5752158cf655", "scanner": "scanner-primary", "fingerprint": "37716d9c0a33ad5c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/claude.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9c4a9d9220527b75", "level": "note", "message": {"text": "Very large file: app/(dashboard)/modules/[id]/page.tsx (2332 lines)"}, "properties": {"repobilityId": "37e9479b33d815cb", "scanner": "scanner-primary", "fingerprint": "9c4a9d9220527b75", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-442b196257b02a42", "level": "note", "message": {"text": "Very large file: app/(dashboard)/courses/[id]/page.tsx (1636 lines)"}, "properties": {"repobilityId": "f94409df41dc6538", "scanner": "scanner-primary", "fingerprint": "442b196257b02a42", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-a26e0b4cb3849170", "level": "note", "message": {"text": "Very large file: lib/api.ts (1637 lines)"}, "properties": {"repobilityId": "1926d29fda5f6adf", "scanner": "scanner-primary", "fingerprint": "a26e0b4cb3849170", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "11bc761ca910b5f1", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "01680ef04015c07c", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "72f0864fa07f56b0", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "f4ab3d0366ff602b", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-11825279136b53a3", "level": "warning", "message": {"text": "CI is configured but no tests are detected"}, "properties": {"repobilityId": "7d84b9bdf387e6c3", "scanner": "scanner-primary", "fingerprint": "11825279136b53a3", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "ci", "config-theater", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "908bc4b6a0191a90", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "76cb7f9780df5f25", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "5c2c20a1d39a9243", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "976a4bea1e9e303a", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-2c83f1d87dbe51ff", "level": "note", "message": {"text": "Legacy-named symbol `include_deprecated` in components/modules/ai-model-selector.tsx:44"}, "properties": {"repobilityId": "29e450b78e0937f8", "scanner": "scanner-primary", "fingerprint": "2c83f1d87dbe51ff", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-3d6bbe3688edaa68", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 app/api/auth/login/route.ts:75"}, "properties": {"repobilityId": "038eb7c0bf976711", "scanner": "scanner-primary", "fingerprint": "3d6bbe3688edaa68", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-da06276ee326cfba", "level": "note", "message": {"text": "Legacy-named symbol `isDeprecated` in app/(dashboard)/models/page.tsx:69"}, "properties": {"repobilityId": "7a188e1b557d1890", "scanner": "scanner-primary", "fingerprint": "da06276ee326cfba", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-7f53365b48ee1172", "level": "none", "message": {"text": "Commented-code block (5 lines) in app/(dashboard)/universities/[id]/page.tsx:89"}, "properties": {"repobilityId": "c4b12ac24ba041c2", "scanner": "scanner-primary", "fingerprint": "7f53365b48ee1172", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-384d3498f31b8a90", "level": "note", "message": {"text": "Legacy-named symbol `include_deprecated` in lib/api.ts:745"}, "properties": {"repobilityId": "a0b0ff3a16f43b8f", "scanner": "scanner-primary", "fingerprint": "384d3498f31b8a90", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-4731554d3d68af8e", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 lib/api.ts:217"}, "properties": {"repobilityId": "c525aaf6ab45208d", "scanner": "scanner-primary", "fingerprint": "4731554d3d68af8e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-8143a345715bd45d", "level": "note", "message": {"text": "Legacy-named symbol `isDeprecated` in lib/types.ts:316"}, "properties": {"repobilityId": "b5f360a3a726bdb0", "scanner": "scanner-primary", "fingerprint": "8143a345715bd45d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-e86c9bdfeba13961", "level": "error", "message": {"text": "Dangling fetch: POST /api/auth/login (lib/api.ts:455)"}, "properties": {"repobilityId": "676bf34006e2531d", "scanner": "scanner-primary", "fingerprint": "e86c9bdfeba13961", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-2837b059a20cb7bf", "level": "error", "message": {"text": "Dangling fetch: GET /api/permissions (lib/api.ts:1535)"}, "properties": {"repobilityId": "c2045edace90eb1e", "scanner": "scanner-primary", "fingerprint": "2837b059a20cb7bf", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-0336f7f4b6ec9181", "level": "error", "message": {"text": "Dangling fetch: GET /api/permissions/roles/${role} (lib/api.ts:1539)"}, "properties": {"repobilityId": "88354bcd6ab23c6f", "scanner": "scanner-primary", "fingerprint": "0336f7f4b6ec9181", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-99e745011b6dfadd", "level": "error", "message": {"text": "Dangling fetch: GET /api/permissions/users/${userId}/extra (lib/api.ts:1543)"}, "properties": {"repobilityId": "4c125a6326ed9909", "scanner": "scanner-primary", "fingerprint": "99e745011b6dfadd", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-5ea9f531d278bd24", "level": "error", "message": {"text": "Dangling fetch: PUT /api/permissions/users/${userId} (lib/api.ts:1547)"}, "properties": {"repobilityId": "49f668b7c4e0833b", "scanner": "scanner-primary", "fingerprint": "5ea9f531d278bd24", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-76b17b7b92800d4b", "level": "error", "message": {"text": "Dangling fetch: POST /api/permissions (lib/api.ts:1554)"}, "properties": {"repobilityId": "ab1cc60e9b23b327", "scanner": "scanner-primary", "fingerprint": "76b17b7b92800d4b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-dea783528240f94d", "level": "error", "message": {"text": "Dangling fetch: PUT /api/permissions/${id} (lib/api.ts:1561)"}, "properties": {"repobilityId": "d2f4f256eb6befde", "scanner": "scanner-primary", "fingerprint": "dea783528240f94d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-657b8ae1b15a2f6e", "level": "error", "message": {"text": "Dangling fetch: DELETE /api/permissions/${id} (lib/api.ts:1568)"}, "properties": {"repobilityId": "71152861b4b2fd75", "scanner": "scanner-primary", "fingerprint": "657b8ae1b15a2f6e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-360e4d1f582fed0b", "level": "error", "message": {"text": "Dangling fetch: GET https://viacep.com.br/ws/${cleanCEP}/json/ (lib/utils.ts:496)"}, "properties": {"repobilityId": "7543504b1589d42b", "scanner": "scanner-primary", "fingerprint": "360e4d1f582fed0b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-2d67c4be403afb88", "level": "note", "message": {"text": "Unused endpoint: POST /api/auth/password-reset-request"}, "properties": {"repobilityId": "3cc764bef5784969", "scanner": "scanner-primary", "fingerprint": "2d67c4be403afb88", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fcafb84e94667528", "level": "note", "message": {"text": "Unused endpoint: POST /api/auth/password-reset"}, "properties": {"repobilityId": "34909171d2ad5d16", "scanner": "scanner-primary", "fingerprint": "fcafb84e94667528", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1ce62746afa9022a", "level": "note", "message": {"text": "Unused endpoint: PUT /api/auth/me/password"}, "properties": {"repobilityId": "0bd6bd776fb020cd", "scanner": "scanner-primary", "fingerprint": "1ce62746afa9022a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ee4aa5ddab88c9dc", "level": "note", "message": {"text": "Unused endpoint: GET /api/auth/me"}, "properties": {"repobilityId": "ef93c5e4fa8d2bd0", "scanner": "scanner-primary", "fingerprint": "ee4aa5ddab88c9dc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dab7c8fe051d4c01", "level": "note", "message": {"text": "Unused endpoint: PUT /api/auth/me"}, "properties": {"repobilityId": "e663420d5cff5aaa", "scanner": "scanner-primary", "fingerprint": "dab7c8fe051d4c01", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0c5de195ac15d60d", "level": "note", "message": {"text": "Unused endpoint: GET /api/universities/"}, "properties": {"repobilityId": "74103f3fbfaf8507", "scanner": "scanner-primary", "fingerprint": "0c5de195ac15d60d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1461f370d1aecc0e", "level": "note", "message": {"text": "Unused endpoint: POST /api/universities/"}, "properties": {"repobilityId": "1bd09ec612ddbe59", "scanner": "scanner-primary", "fingerprint": "1461f370d1aecc0e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-edaa0be17d70101b", "level": "note", "message": {"text": "Unused endpoint: GET /api/courses/"}, "properties": {"repobilityId": "710ab8c616fe5979", "scanner": "scanner-primary", "fingerprint": "edaa0be17d70101b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1dacd69505026c92", "level": "note", "message": {"text": "Unused endpoint: POST /api/courses/"}, "properties": {"repobilityId": "43c5ae44480032fc", "scanner": "scanner-primary", "fingerprint": "1dacd69505026c92", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a7912d8e8fce9543", "level": "note", "message": {"text": "Unused endpoint: GET /api/modules/"}, "properties": {"repobilityId": "305c2f326cd1f940", "scanner": "scanner-primary", "fingerprint": "a7912d8e8fce9543", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-12a020fe0743cd34", "level": "note", "message": {"text": "Unused endpoint: POST /api/modules/"}, "properties": {"repobilityId": "23b733a3de67eb2e", "scanner": "scanner-primary", "fingerprint": "12a020fe0743cd34", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bcb6689d2aa56e16", "level": "note", "message": {"text": "Unused endpoint: POST /api/quiz-upload-jobs"}, "properties": {"repobilityId": "ad0a44a0845a42af", "scanner": "scanner-primary", "fingerprint": "bcb6689d2aa56e16", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-07eb5bba53e9db79", "level": "note", "message": {"text": "Unused endpoint: GET /api/assignments"}, "properties": {"repobilityId": "69d36f16fe98b69f", "scanner": "scanner-primary", "fingerprint": "07eb5bba53e9db79", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6940d60c9c754e19", "level": "note", "message": {"text": "Unused endpoint: POST /api/assignments"}, "properties": {"repobilityId": "0ff28603927664c4", "scanner": "scanner-primary", "fingerprint": "6940d60c9c754e19", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-11a75b776846ebbb", "level": "note", "message": {"text": "Unused endpoint: GET /api/grading-jobs"}, "properties": {"repobilityId": "d89c73d29a9f4410", "scanner": "scanner-primary", "fingerprint": "11a75b776846ebbb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c9ea39eda4b5cff1", "level": "note", "message": {"text": "Unused endpoint: POST /api/grading-jobs"}, "properties": {"repobilityId": "54010b334d9b1b8c", "scanner": "scanner-primary", "fingerprint": "c9ea39eda4b5cff1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d96ed5b2791381a3", "level": "note", "message": {"text": "Unused endpoint: GET /api/quiz-upload-jobs"}, "properties": {"repobilityId": "b286e3d01b395525", "scanner": "scanner-primary", "fingerprint": "d96ed5b2791381a3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-af6d1b4b379762e6", "level": "note", "message": {"text": "Unused endpoint: GET /api/ai-models/"}, "properties": {"repobilityId": "3d39d7d56a443832", "scanner": "scanner-primary", "fingerprint": "af6d1b4b379762e6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4520139023886ab6", "level": "note", "message": {"text": "Unused endpoint: POST /api/ai-models/"}, "properties": {"repobilityId": "d26254e3357b83e0", "scanner": "scanner-primary", "fingerprint": "4520139023886ab6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-894c4cda6d8939a4", "level": "note", "message": {"text": "Unused endpoint: GET /api/files/"}, "properties": {"repobilityId": "77fa598652006f11", "scanner": "scanner-primary", "fingerprint": "894c4cda6d8939a4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-da6f6e57d14fe732", "level": "note", "message": {"text": "Unused endpoint: POST /api/files"}, "properties": {"repobilityId": "c3bc7652ddb87942", "scanner": "scanner-primary", "fingerprint": "da6f6e57d14fe732", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-de68d1932d6fb401", "level": "note", "message": {"text": "Unused endpoint: POST /api/videos/youtube"}, "properties": {"repobilityId": "5285ded0adb9df8d", "scanner": "scanner-primary", "fingerprint": "de68d1932d6fb401", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d3686ad3114afa63", "level": "note", "message": {"text": "Unused endpoint: GET /api/students/"}, "properties": {"repobilityId": "55c8aaf43ad715cc", "scanner": "scanner-primary", "fingerprint": "d3686ad3114afa63", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7ffcb06e89bd5018", "level": "note", "message": {"text": "Unused endpoint: POST /api/students/"}, "properties": {"repobilityId": "3b43cffb801802b7", "scanner": "scanner-primary", "fingerprint": "7ffcb06e89bd5018", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d86e275e949f5ddf", "level": "note", "message": {"text": "Unused endpoint: POST /api/students/import"}, "properties": {"repobilityId": "3e1cefee7e00978c", "scanner": "scanner-primary", "fingerprint": "d86e275e949f5ddf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-eeb6c934ecb04d18", "level": "note", "message": {"text": "Unused endpoint: POST /api/students/mass-unenroll"}, "properties": {"repobilityId": "50514829e4c9578e", "scanner": "scanner-primary", "fingerprint": "eeb6c934ecb04d18", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-256930c405a82be4", "level": "note", "message": {"text": "Unused endpoint: GET /api/students/import-jobs"}, "properties": {"repobilityId": "9e20d3356d10b200", "scanner": "scanner-primary", "fingerprint": "256930c405a82be4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c7d5da02541079bd", "level": "note", "message": {"text": "Unused endpoint: GET /api/moduleaccesstokens/"}, "properties": {"repobilityId": "f95e1e9938924c4f", "scanner": "scanner-primary", "fingerprint": "c7d5da02541079bd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-974be31c12faf204", "level": "note", "message": {"text": "Unused endpoint: POST /api/moduleaccesstokens/"}, "properties": {"repobilityId": "b640dbdfaa22ef9f", "scanner": "scanner-primary", "fingerprint": "974be31c12faf204", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-57d849d42233b624", "level": "note", "message": {"text": "Unused endpoint: GET /api/super-admin/stats"}, "properties": {"repobilityId": "fd63931f43d901d7", "scanner": "scanner-primary", "fingerprint": "57d849d42233b624", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2471f40c603de2c0", "level": "note", "message": {"text": "Unused endpoint: GET /api/super-admin/universities/all"}, "properties": {"repobilityId": "bbea44464d3931ab", "scanner": "scanner-primary", "fingerprint": "2471f40c603de2c0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bb013decb25d4c16", "level": "note", "message": {"text": "Unused endpoint: GET /api/professoragents/my-agent"}, "properties": {"repobilityId": "b535f71b8870dcb1", "scanner": "scanner-primary", "fingerprint": "bb013decb25d4c16", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-12ffd42265266ecb", "level": "note", "message": {"text": "Unused endpoint: GET /api/professoragents"}, "properties": {"repobilityId": "fc30507e7b923a57", "scanner": "scanner-primary", "fingerprint": "12ffd42265266ecb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b3e6d2a529958ab0", "level": "note", "message": {"text": "Unused endpoint: POST /api/professoragents"}, "properties": {"repobilityId": "b8fff95146af564b", "scanner": "scanner-primary", "fingerprint": "b3e6d2a529958ab0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1206e6f5aa904b18", "level": "note", "message": {"text": "Unused endpoint: GET /api/professoragents/by-professor"}, "properties": {"repobilityId": "3c71ec72a18c536b", "scanner": "scanner-primary", "fingerprint": "1206e6f5aa904b18", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd95d4b4658275fd", "level": "note", "message": {"text": "Unused endpoint: POST /api/tutor/ask"}, "properties": {"repobilityId": "807524a25dc81bef", "scanner": "scanner-primary", "fingerprint": "fd95d4b4658275fd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b8d951f209482345", "level": "note", "message": {"text": "Unused endpoint: GET /api/analytics/dashboard/summary"}, "properties": {"repobilityId": "610e463560a15726", "scanner": "scanner-primary", "fingerprint": "b8d951f209482345", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9aec847203e2fbd5", "level": "note", "message": {"text": "Unused endpoint: GET /api/analytics/dashboard/unified"}, "properties": {"repobilityId": "f3da7fa1399d78fe", "scanner": "scanner-primary", "fingerprint": "9aec847203e2fbd5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c35841989b020b67", "level": "note", "message": {"text": "Unused endpoint: GET /api/analytics/costs/detailed"}, "properties": {"repobilityId": "a7f02eb541e504ce", "scanner": "scanner-primary", "fingerprint": "c35841989b020b67", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c35df423c69bb137", "level": "note", "message": {"text": "Unused endpoint: GET /api/analytics/costs/today"}, "properties": {"repobilityId": "b6be71ef90056134", "scanner": "scanner-primary", "fingerprint": "c35df423c69bb137", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5e503e59bb91ab72", "level": "note", "message": {"text": "Unused endpoint: GET /api/analytics/usage/today"}, "properties": {"repobilityId": "d13aa2fb27be4cfc", "scanner": "scanner-primary", "fingerprint": "5e503e59bb91ab72", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3e462f74b7778bd6", "level": "note", "message": {"text": "Unused endpoint: GET /api/analytics/usage/trends"}, "properties": {"repobilityId": "bf6b3aac9e3365ba", "scanner": "scanner-primary", "fingerprint": "3e462f74b7778bd6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4efc3c4c806fe80a", "level": "note", "message": {"text": "Unused endpoint: GET /api/analytics/usage/hourly"}, "properties": {"repobilityId": "dee53d8618a0ef28", "scanner": "scanner-primary", "fingerprint": "4efc3c4c806fe80a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-14bfbde4f6be66cc", "level": "note", "message": {"text": "Unused endpoint: GET /api/analytics/students/top-active"}, "properties": {"repobilityId": "334a5c936df1d555", "scanner": "scanner-primary", "fingerprint": "14bfbde4f6be66cc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d641f4a0b7e91ce0", "level": "note", "message": {"text": "Unused endpoint: GET /api/analytics/performance/response-quality"}, "properties": {"repobilityId": "ef8de7620c06e31b", "scanner": "scanner-primary", "fingerprint": "d641f4a0b7e91ce0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-40b08adde8ffc2f1", "level": "note", "message": {"text": "Unused endpoint: GET /api/analytics/engagement/conversations"}, "properties": {"repobilityId": "eb5dccb08528371f", "scanner": "scanner-primary", "fingerprint": "40b08adde8ffc2f1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6238c7847532e2a6", "level": "note", "message": {"text": "Unused endpoint: GET /api/analytics/modules/compare"}, "properties": {"repobilityId": "487a4f180253afa2", "scanner": "scanner-primary", "fingerprint": "6238c7847532e2a6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7ac9cdfe90c885ba", "level": "note", "message": {"text": "Unused endpoint: GET /api/analytics/questions/frequently-asked"}, "properties": {"repobilityId": "067bdcb789b4dfb2", "scanner": "scanner-primary", "fingerprint": "7ac9cdfe90c885ba", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-826e743fba637af7", "level": "note", "message": {"text": "Unused endpoint: GET /api/audit-logs"}, "properties": {"repobilityId": "169d7be80bfebeea", "scanner": "scanner-primary", "fingerprint": "826e743fba637af7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9e1d379cca9c6ecb", "level": "note", "message": {"text": "Unused endpoint: GET /api/provider-keys/"}, "properties": {"repobilityId": "b6856d354ced4d6c", "scanner": "scanner-primary", "fingerprint": "9e1d379cca9c6ecb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}