{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-a7a3187aca4d52c4", "name": "Stray `console.log` in TS/JS \u2014 activate-gam.js:27", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 activate-gam.js:27"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6a70434164e7cde0", "name": "Stray `console.log` in TS/JS \u2014 test-connections.js:5", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 test-connections.js:5"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2eb06b69f9fe7b54", "name": "Stray `console.log` in TS/JS \u2014 test-criar.js:28", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 test-criar.js:28"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-658fb3e31251322f", "name": "Stray `console.log` in TS/JS \u2014 run-sync.js:10", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 run-sync.js:10"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cd3446e032cbb585", "name": "Stray `console.log` in TS/JS \u2014 test-upload.js:28", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 test-upload.js:28"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-38b41aeb2e388d9e", "name": "Stray `console.log` in TS/JS \u2014 server.js:232", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 server.js:232"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-85c55e1f0a2faa6f", "name": "Stray `console.log` in TS/JS \u2014 diagnose-gam.js:45", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 diagnose-gam.js:45"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-edc03358e7bfe038", "name": "Stray `console.log` in TS/JS \u2014 scripts/diag-db.js:10", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/diag-db.js:10"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4fc758435dfa8f7b", "name": "Stray `console.log` in TS/JS \u2014 scripts/test-db-query.js:29", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-db-query.js:29"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5adba104bf724515", "name": "Stray `console.log` in TS/JS \u2014 scripts/test-gam-columns.js:7", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-gam-columns.js:7"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d0baf9a4c777f0d7", "name": "Stray `console.log` in TS/JS \u2014 scripts/diag-meta.js:57", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/diag-meta.js:57"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0b9aab1c3277c2c9", "name": "Stray `console.log` in TS/JS \u2014 scripts/audit-full.js:17", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/audit-full.js:17"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b5ae7c17151b06dc", "name": "Stray `console.log` in TS/JS \u2014 scripts/migrate-fase2.js:54", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/migrate-fase2.js:54"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-81c112ca6c792fd3", "name": "Stray `console.log` in TS/JS \u2014 scripts/setup-db.js:56", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/setup-db.js:56"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e6686b7b9fc357ee", "name": "Stray `console.log` in TS/JS \u2014 scripts/diag-gam.js:60", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/diag-gam.js:60"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dfedf0d47eff560f", "name": "Stray `console.log` in TS/JS \u2014 scripts/diag-bm2.js:10", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/diag-bm2.js:10"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0e85641eca5e8b49", "name": "Stray `console.log` in TS/JS \u2014 scripts/fetch-meta-locales.js:41", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/fetch-meta-locales.js:41"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5cc7b6ad9f96756a", "name": "Stray `console.log` in TS/JS \u2014 scripts/generate-icons.js:27", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/generate-icons.js:27"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d313036ddb8258ca", "name": "Stray `console.log` in TS/JS \u2014 scripts/audit.js:17", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/audit.js:17"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3794d8b5a0c827a3", "name": "Stray `console.log` in TS/JS \u2014 scripts/migrate-bms.js:21", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/migrate-bms.js:21"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e6f5b358d41c078d", "name": "Stray `console.log` in TS/JS \u2014 scripts/test-gam-utm.js:54", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-gam-utm.js:54"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8a836f35532a70ed", "name": "Stray `console.log` in TS/JS \u2014 scripts/diag-cross.js:89", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/diag-cross.js:89"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-88662809321e359f", "name": "Stray `console.log` in TS/JS \u2014 scripts/test-meta-today.js:9", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-meta-today.js:9"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-47827f45fa3eb647", "name": "Stray `console.log` in TS/JS \u2014 scripts/test-gam-csv.js:57", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-gam-csv.js:57"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-41e7707754b807f1", "name": "TODO/FIXME marker in shipping code \u2014 src/app/api/orcamento-status/route.js:135", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 src/app/api/orcamento-status/route.js:135"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3bc5f8528311cccb", "name": "Stray `console.log` in TS/JS \u2014 src/app/api/orcamento-status/route.js:100", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/app/api/orcamento-status/route.js:100"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1ee0a017285a6eed", "name": "Stray `console.log` in TS/JS \u2014 src/app/api/drilldown/route.js:51", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/app/api/drilldown/route.js:51"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-95b7adf9909b3757", "name": "Stray `console.log` in TS/JS \u2014 src/app/api/reports-gam/route.js:231", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/app/api/reports-gam/route.js:231"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3abf253a3bc49849", "name": "Stray `console.log` in TS/JS \u2014 src/app/api/campaigns/route.js:70", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/app/api/campaigns/route.js:70"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ed94cd0a9402d440", "name": "Stray `console.log` in TS/JS \u2014 src/app/api/meta-resources/route.js:146", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/app/api/meta-resources/route.js:146"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-921c657ceaa2054b", "name": "Stray `console.log` in TS/JS \u2014 src/lib/scheduler.js:7", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/lib/scheduler.js:7"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5f4fcea586dccf1e", "name": "Stray `console.log` in TS/JS \u2014 src/lib/sync.js:302", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/lib/sync.js:302"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d3c5dcebe225f17e", "name": "Stray `console.log` in TS/JS \u2014 src/lib/gam.js:809", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/lib/gam.js:809"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1eec825d5106e708", "name": "Stray `console.log` in TS/JS \u2014 src/lib/parser.js:140", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/lib/parser.js:140"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6da7f41377bc344c", "name": "Stray `console.log` in TS/JS \u2014 src/services/exchange.service.js:38", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/services/exchange.service.js:38"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f374079dd7846ea2", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/mobile.html:609", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/mobile.html:609"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-041689749b707c76", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/dashboard.html:2566", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/dashboard.html:2566"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2953bcd1c72b6b25", "name": "Insecure pattern 'insert_adjacent_html' in public/dashboard.html:6107", "shortDescription": {"text": "Insecure pattern 'insert_adjacent_html' in public/dashboard.html:6107"}, "fullDescription": {"text": "Found a known-risky pattern (insert_adjacent_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-616c6f5751ba6f0f", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/index.html:803", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/index.html:803"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e23e1456938e3899", "name": "Very large file: src/lib/sync.js (1158 lines)", "shortDescription": {"text": "Very large file: src/lib/sync.js (1158 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea3b5e389d8c9c0f", "name": "Low test-to-source ratio", "shortDescription": {"text": "Low test-to-source ratio"}, "fullDescription": {"text": "8 tests / 56 src (ratio 0.14)."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 399 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci, tests. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d816990841bee20b", "name": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/diag-db.js:167", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/diag-db.js:167"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e686b02a7efbdd45", "name": "`fetch()` without try/.catch or AbortSignal \u2014 public/js/api.js:5", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/js/api.js:5"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-319e66a630e14977", "name": "2 env vars used in code but missing from .env.example", "shortDescription": {"text": "2 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `JWT_SECRET`, `PORT`. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9bcb70b126fdea44", "name": "Dangling fetch: GET https://graph.facebook.com/v19.0/${account} (test-connections.js:13)", "shortDescription": {"text": "Dangling fetch: GET https://graph.facebook.com/v19.0/${account} (test-connections.js:13)"}, "fullDescription": {"text": "`test-connections.js:13` calls `GET https://graph.facebook.com/v19.0/${account}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/graph.facebook.com/v19.0/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d94f3f8e95aa578e", "name": "Dangling fetch: POST https://ads.google.com/apis/ads/publisher/${GAM_VERSION}/NetworkService (test-connections.js:78)", "shortDescription": {"text": "Dangling fetch: POST https://ads.google.com/apis/ads/publisher/${GAM_VERSION}/NetworkService (test-connections.js:78)"}, "fullDescription": {"text": "`test-connections.js:78` calls `POST https://ads.google.com/apis/ads/publisher/${GAM_VERSION}/NetworkService` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/ads.google.com/apis/ads/publisher/<p>/networkservice`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-92914f34750a6b83", "name": "Dangling fetch: POST https://ads.google.com/apis/ads/publisher/${GAM_VERSION}/ReportService (test-connections.js:154)", "shortDescription": {"text": "Dangling fetch: POST https://ads.google.com/apis/ads/publisher/${GAM_VERSION}/ReportService (test-connections.js:154)"}, "fullDescription": {"text": "`test-connections.js:154` calls `POST https://ads.google.com/apis/ads/publisher/${GAM_VERSION}/ReportService` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/ads.google.com/apis/ads/publisher/<p>/reportservice`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1e7b83b6c221eb15", "name": "Dangling fetch: GET https://admanager.googleapis.com/v1/networks (diagnose-gam.js:97)", "shortDescription": {"text": "Dangling fetch: GET https://admanager.googleapis.com/v1/networks (diagnose-gam.js:97)"}, "fullDescription": {"text": "`diagnose-gam.js:97` calls `GET https://admanager.googleapis.com/v1/networks` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/admanager.googleapis.com/v1/networks`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9c4d9787eb70850e", "name": "Dangling fetch: GET https://admanager.googleapis.com/v1/networks/${TARGET_NETWORK} (diagnose-gam.js:111)", "shortDescription": {"text": "Dangling fetch: GET https://admanager.googleapis.com/v1/networks/${TARGET_NETWORK} (diagnose-gam.js:111)"}, "fullDescription": {"text": "`diagnose-gam.js:111` calls `GET https://admanager.googleapis.com/v1/networks/${TARGET_NETWORK}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/admanager.googleapis.com/v1/networks/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b00703921471cc17", "name": "Dangling fetch: GET https://graph.facebook.com/v19.0/${account} (scripts/diag-bm2.js:14)", "shortDescription": {"text": "Dangling fetch: GET https://graph.facebook.com/v19.0/${account} (scripts/diag-bm2.js:14)"}, "fullDescription": {"text": "`scripts/diag-bm2.js:14` calls `GET https://graph.facebook.com/v19.0/${account}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/graph.facebook.com/v19.0/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6947ae66ca95b815", "name": "Dangling fetch: GET https://graph.facebook.com/v19.0/${account}/insights (scripts/diag-bm2.js:24)", "shortDescription": {"text": "Dangling fetch: GET https://graph.facebook.com/v19.0/${account}/insights (scripts/diag-bm2.js:24)"}, "fullDescription": {"text": "`scripts/diag-bm2.js:24` calls `GET https://graph.facebook.com/v19.0/${account}/insights` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/graph.facebook.com/v19.0/<p>/insights`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9db095f9c962517f", "name": "Dangling fetch: GET https://graph.facebook.com/v19.0/${ACCOUNT}/insights (scripts/audit.js:104)", "shortDescription": {"text": "Dangling fetch: GET https://graph.facebook.com/v19.0/${ACCOUNT}/insights (scripts/audit.js:104)"}, "fullDescription": {"text": "`scripts/audit.js:104` calls `GET https://graph.facebook.com/v19.0/${ACCOUNT}/insights` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/graph.facebook.com/v19.0/<p>/insights`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-668f0b06820174f9", "name": "Dangling fetch: GET https://graph.facebook.com/v19.0/${accountId} (scripts/migrate-bms.js:10)", "shortDescription": {"text": "Dangling fetch: GET https://graph.facebook.com/v19.0/${accountId} (scripts/migrate-bms.js:10)"}, "fullDescription": {"text": "`scripts/migrate-bms.js:10` calls `GET https://graph.facebook.com/v19.0/${accountId}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/graph.facebook.com/v19.0/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ade742661470d516", "name": "Dangling fetch: POST https://ads.google.com/apis/ads/publisher/v202505/ReportService (scripts/test-gam-utm.js:49)", "shortDescription": {"text": "Dangling fetch: POST https://ads.google.com/apis/ads/publisher/v202505/ReportService (scripts/test-gam-utm.js:49)"}, "fullDescription": {"text": "`scripts/test-gam-utm.js:49` calls `POST https://ads.google.com/apis/ads/publisher/v202505/ReportService` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/ads.google.com/apis/ads/publisher/v202505/reportservice`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3905a28d072f58dd", "name": "Dangling fetch: GET https://graph.facebook.com/v19.0/${account}/insights (scripts/test-meta-today.js:14)", "shortDescription": {"text": "Dangling fetch: GET https://graph.facebook.com/v19.0/${account}/insights (scripts/test-meta-today.js:14)"}, "fullDescription": {"text": "`scripts/test-meta-today.js:14` calls `GET https://graph.facebook.com/v19.0/${account}/insights` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/graph.facebook.com/v19.0/<p>/insights`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c715a78ec4321fd7", "name": "Dangling fetch: GET https://graph.facebook.com/v19.0/${account}/campaigns (scripts/test-meta-today.js:27)", "shortDescription": {"text": "Dangling fetch: GET https://graph.facebook.com/v19.0/${account}/campaigns (scripts/test-meta-today.js:27)"}, "fullDescription": {"text": "`scripts/test-meta-today.js:27` calls `GET https://graph.facebook.com/v19.0/${account}/campaigns` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/graph.facebook.com/v19.0/<p>/campaigns`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-26244fe52e64e03e", "name": "Dangling fetch: GET https://graph.facebook.com/v19.0/${account}/insights (scripts/test-meta-today.js:39)", "shortDescription": {"text": "Dangling fetch: GET https://graph.facebook.com/v19.0/${account}/insights (scripts/test-meta-today.js:39)"}, "fullDescription": {"text": "`scripts/test-meta-today.js:39` calls `GET https://graph.facebook.com/v19.0/${account}/insights` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/graph.facebook.com/v19.0/<p>/insights`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ac8bb48f79546cfd", "name": "Dangling fetch: GET https://admanager.googleapis.com/v1/networks (src/lib/gam.js:385)", "shortDescription": {"text": "Dangling fetch: GET https://admanager.googleapis.com/v1/networks (src/lib/gam.js:385)"}, "fullDescription": {"text": "`src/lib/gam.js:385` calls `GET https://admanager.googleapis.com/v1/networks` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/admanager.googleapis.com/v1/networks`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b33ae9045c0f5b26", "name": "Dangling fetch: GET https://economia.awesomeapi.com.br/json/last/USD-BRL (src/services/exchange.service.js:13)", "shortDescription": {"text": "Dangling fetch: GET https://economia.awesomeapi.com.br/json/last/USD-BRL (src/services/exchange.service.js:13)"}, "fullDescription": {"text": "`src/services/exchange.service.js:13` calls `GET https://economia.awesomeapi.com.br/json/last/USD-BRL` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/economia.awesomeapi.com.br/json/last/usd-brl`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b3b8eb95237166df", "name": "Dangling fetch: GET https://api.exchangerate-api.com/v4/latest/USD (src/services/exchange.service.js:19)", "shortDescription": {"text": "Dangling fetch: GET https://api.exchangerate-api.com/v4/latest/USD (src/services/exchange.service.js:19)"}, "fullDescription": {"text": "`src/services/exchange.service.js:19` calls `GET https://api.exchangerate-api.com/v4/latest/USD` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/api.exchangerate-api.com/v4/latest/usd`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4dcd5251ac43500f", "name": "Dangling fetch: GET https://economia.awesomeapi.com.br/json/last/USD-BRL (src/services/exchange.service.js:59)", "shortDescription": {"text": "Dangling fetch: GET https://economia.awesomeapi.com.br/json/last/USD-BRL (src/services/exchange.service.js:59)"}, "fullDescription": {"text": "`src/services/exchange.service.js:59` calls `GET https://economia.awesomeapi.com.br/json/last/USD-BRL` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/economia.awesomeapi.com.br/json/last/usd-brl`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d7716bbccf06fd33", "name": "Dangling fetch: GET https://api.exchangerate-api.com/v4/latest/USD (src/services/exchange.service.js:66)", "shortDescription": {"text": "Dangling fetch: GET https://api.exchangerate-api.com/v4/latest/USD (src/services/exchange.service.js:66)"}, "fullDescription": {"text": "`src/services/exchange.service.js:66` calls `GET https://api.exchangerate-api.com/v4/latest/USD` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/api.exchangerate-api.com/v4/latest/usd`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-741da11a250343e2", "name": "Unused endpoint: GET /privacidade", "shortDescription": {"text": "Unused endpoint: GET /privacidade"}, "fullDescription": {"text": "`server.js` declares `GET /privacidade` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`server.js` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-16d386462dfb8a22", "name": "Unused endpoint: GET /dashboard.html", "shortDescription": {"text": "Unused endpoint: GET /dashboard.html"}, "fullDescription": {"text": "`server.js` declares `GET /dashboard.html` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be1fc5ec702d9282", "name": "Unused endpoint: GET /mobile", "shortDescription": {"text": "Unused endpoint: GET /mobile"}, "fullDescription": {"text": "`server.js` declares `GET /mobile` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d218b99cb402d54e", "name": "Unused endpoint: GET /lib/chart.umd.min.js", "shortDescription": {"text": "Unused endpoint: GET /lib/chart.umd.min.js"}, "fullDescription": {"text": "`server.js` declares `GET /lib/chart.umd.min.js` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd55aa0818a7c897", "name": "Unused endpoint: POST /api/auth/login", "shortDescription": {"text": "Unused endpoint: POST /api/auth/login"}, "fullDescription": {"text": "`server.js` declares `POST /api/auth/login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d5a39262ac205120", "name": "Unused endpoint: POST /api/auth/logout", "shortDescription": {"text": "Unused endpoint: POST /api/auth/logout"}, "fullDescription": {"text": "`server.js` declares `POST /api/auth/logout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ee4aa5ddab88c9dc", "name": "Unused endpoint: GET /api/auth/me", "shortDescription": {"text": "Unused endpoint: GET /api/auth/me"}, "fullDescription": {"text": "`server.js` declares `GET /api/auth/me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-30ebd8b02a460b20", "name": "Unused endpoint: GET /api/metrics", "shortDescription": {"text": "Unused endpoint: GET /api/metrics"}, "fullDescription": {"text": "`server.js` declares `GET /api/metrics` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0d99e6b89d636be3", "name": "Unused endpoint: POST /api/insights", "shortDescription": {"text": "Unused endpoint: POST /api/insights"}, "fullDescription": {"text": "`server.js` declares `POST /api/insights` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-87f7ca9628364786", "name": "Unused endpoint: GET /api/overview", "shortDescription": {"text": "Unused endpoint: GET /api/overview"}, "fullDescription": {"text": "`server.js` declares `GET /api/overview` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8fdf3f6802d65e7b", "name": "Unused endpoint: GET /api/orcamento-status", "shortDescription": {"text": "Unused endpoint: GET /api/orcamento-status"}, "fullDescription": {"text": "`server.js` declares `GET /api/orcamento-status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6ae92428b89c54b8", "name": "Unused endpoint: GET /api/dashboard", "shortDescription": {"text": "Unused endpoint: GET /api/dashboard"}, "fullDescription": {"text": "`server.js` declares `GET /api/dashboard` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ae318ee7589859e3", "name": "Unused endpoint: GET /api/reports-gam", "shortDescription": {"text": "Unused endpoint: GET /api/reports-gam"}, "fullDescription": {"text": "`server.js` declares `GET /api/reports-gam` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ba2fff617bf7d128", "name": "Unused endpoint: GET /api/gam-status", "shortDescription": {"text": "Unused endpoint: GET /api/gam-status"}, "fullDescription": {"text": "`server.js` declares `GET /api/gam-status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-472c2ab6e3d1920f", "name": "Unused endpoint: GET /api/intraday", "shortDescription": {"text": "Unused endpoint: GET /api/intraday"}, "fullDescription": {"text": "`server.js` declares `GET /api/intraday` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d5a4b79289554f96", "name": "Unused endpoint: POST /api/relatorios/custom", "shortDescription": {"text": "Unused endpoint: POST /api/relatorios/custom"}, "fullDescription": {"text": "`server.js` declares `POST /api/relatorios/custom` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c59bbfe1bc947e4d", "name": "Unused endpoint: GET /api/contas", "shortDescription": {"text": "Unused endpoint: GET /api/contas"}, "fullDescription": {"text": "`server.js` declares `GET /api/contas` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9c87f9725bfd25b9", "name": "Unused endpoint: POST /api/contas", "shortDescription": {"text": "Unused endpoint: POST /api/contas"}, "fullDescription": {"text": "`server.js` declares `POST /api/contas` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f12545ccb0a174ca", "name": "Unused endpoint: PUT /api/contas/:id", "shortDescription": {"text": "Unused endpoint: PUT /api/contas/:id"}, "fullDescription": {"text": "`server.js` declares `PUT /api/contas/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-52f274c94db53289", "name": "Unused endpoint: DELETE /api/contas/:id", "shortDescription": {"text": "Unused endpoint: DELETE /api/contas/:id"}, "fullDescription": {"text": "`server.js` declares `DELETE /api/contas/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-94e27785a0756fef", "name": "Unused endpoint: POST /api/contas/testar", "shortDescription": {"text": "Unused endpoint: POST /api/contas/testar"}, "fullDescription": {"text": "`server.js` declares `POST /api/contas/testar` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-86c28ddf7b02f56e", "name": "Unused endpoint: POST /api/contas/:id/testar", "shortDescription": {"text": "Unused endpoint: POST /api/contas/:id/testar"}, "fullDescription": {"text": "`server.js` declares `POST /api/contas/:id/testar` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1e0aa6f6d9e42c82", "name": "Unused endpoint: POST /api/contas/:id/imposto", "shortDescription": {"text": "Unused endpoint: POST /api/contas/:id/imposto"}, "fullDescription": {"text": "`server.js` declares `POST /api/contas/:id/imposto` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ed252cbea96182b6", "name": "Unused endpoint: POST /api/admin/recalcular-imposto", "shortDescription": {"text": "Unused endpoint: POST /api/admin/recalcular-imposto"}, "fullDescription": {"text": "`server.js` declares `POST /api/admin/recalcular-imposto` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8c9f550ca5c0875e", "name": "Unused endpoint: GET /api/paginas", "shortDescription": {"text": "Unused endpoint: GET /api/paginas"}, "fullDescription": {"text": "`server.js` declares `GET /api/paginas` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-814c2d0d0d70f6c5", "name": "Unused endpoint: POST /api/paginas/sync", "shortDescription": {"text": "Unused endpoint: POST /api/paginas/sync"}, "fullDescription": {"text": "`server.js` declares `POST /api/paginas/sync` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1ac431dd8b3242e4", "name": "Unused endpoint: GET /api/historico-campanhas/ultimo-numero", "shortDescription": {"text": "Unused endpoint: GET /api/historico-campanhas/ultimo-numero"}, "fullDescription": {"text": "`server.js` declares `GET /api/historico-campanhas/ultimo-numero` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-97f0428048d16cb0", "name": "Unused endpoint: GET /api/dominios", "shortDescription": {"text": "Unused endpoint: GET /api/dominios"}, "fullDescription": {"text": "`server.js` declares `GET /api/dominios` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f007b64f830f7c80", "name": "Unused endpoint: POST /api/dominios", "shortDescription": {"text": "Unused endpoint: POST /api/dominios"}, "fullDescription": {"text": "`server.js` declares `POST /api/dominios` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f4f9d4ce22b18941", "name": "Unused endpoint: GET /api/dominios/pendentes", "shortDescription": {"text": "Unused endpoint: GET /api/dominios/pendentes"}, "fullDescription": {"text": "`server.js` declares `GET /api/dominios/pendentes` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-281bf80b988937bc", "name": "Unused endpoint: POST /api/dominios/aprovar", "shortDescription": {"text": "Unused endpoint: POST /api/dominios/aprovar"}, "fullDescription": {"text": "`server.js` declares `POST /api/dominios/aprovar` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8807873abf70f42f", "name": "Unused endpoint: GET /api/metas", "shortDescription": {"text": "Unused endpoint: GET /api/metas"}, "fullDescription": {"text": "`server.js` declares `GET /api/metas` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d44ba3660310511c", "name": "Unused endpoint: POST /api/metas", "shortDescription": {"text": "Unused endpoint: POST /api/metas"}, "fullDescription": {"text": "`server.js` declares `POST /api/metas` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0a8a93035bc479a8", "name": "Unused endpoint: PUT /api/metas/:id", "shortDescription": {"text": "Unused endpoint: PUT /api/metas/:id"}, "fullDescription": {"text": "`server.js` declares `PUT /api/metas/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-273d23872876f2b6", "name": "Unused endpoint: DELETE /api/metas/:id", "shortDescription": {"text": "Unused endpoint: DELETE /api/metas/:id"}, "fullDescription": {"text": "`server.js` declares `DELETE /api/metas/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a1a8550737127ec7", "name": "Unused endpoint: GET /api/notificacoes", "shortDescription": {"text": "Unused endpoint: GET /api/notificacoes"}, "fullDescription": {"text": "`server.js` declares `GET /api/notificacoes` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6fe3188f1f1c32d3", "name": "Unused endpoint: POST /api/notificacoes/:id/marcar-lida", "shortDescription": {"text": "Unused endpoint: POST /api/notificacoes/:id/marcar-lida"}, "fullDescription": {"text": "`server.js` declares `POST /api/notificacoes/:id/marcar-lida` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8a55f016901c988a", "name": "Unused endpoint: POST /api/notificacoes/marcar-todas-lidas", "shortDescription": {"text": "Unused endpoint: POST /api/notificacoes/marcar-todas-lidas"}, "fullDescription": {"text": "`server.js` declares `POST /api/notificacoes/marcar-todas-lidas` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9a87ad959d96703e", "name": "Unused endpoint: GET /api/utms", "shortDescription": {"text": "Unused endpoint: GET /api/utms"}, "fullDescription": {"text": "`server.js` declares `GET /api/utms` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1b05483d9fb19c34", "name": "Unused endpoint: GET /api/utms/conjuntos-ativos", "shortDescription": {"text": "Unused endpoint: GET /api/utms/conjuntos-ativos"}, "fullDescription": {"text": "`server.js` declares `GET /api/utms/conjuntos-ativos` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a6a346d0112923c0", "name": "Unused endpoint: GET /api/drilldown/:utm", "shortDescription": {"text": "Unused endpoint: GET /api/drilldown/:utm"}, "fullDescription": {"text": "`server.js` declares `GET /api/drilldown/:utm` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-88491d73c88c6cf5", "name": "Unused endpoint: GET /api/otimizacoes/tipos-acao", "shortDescription": {"text": "Unused endpoint: GET /api/otimizacoes/tipos-acao"}, "fullDescription": {"text": "`server.js` declares `GET /api/otimizacoes/tipos-acao` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cd3076a74c88f048", "name": "Unused endpoint: POST /api/otimizacoes/tipos-acao", "shortDescription": {"text": "Unused endpoint: POST /api/otimizacoes/tipos-acao"}, "fullDescription": {"text": "`server.js` declares `POST /api/otimizacoes/tipos-acao` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-399bad1f8df9181e", "name": "Unused endpoint: PUT /api/otimizacoes/tipos-acao/:id", "shortDescription": {"text": "Unused endpoint: PUT /api/otimizacoes/tipos-acao/:id"}, "fullDescription": {"text": "`server.js` declares `PUT /api/otimizacoes/tipos-acao/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-61e46125eeafbe4b", "name": "Unused endpoint: DELETE /api/otimizacoes/tipos-acao/:id", "shortDescription": {"text": "Unused endpoint: DELETE /api/otimizacoes/tipos-acao/:id"}, "fullDescription": {"text": "`server.js` declares `DELETE /api/otimizacoes/tipos-acao/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3b9e3c16a37e369e", "name": "Unused endpoint: GET /api/otimizacoes/preview", "shortDescription": {"text": "Unused endpoint: GET /api/otimizacoes/preview"}, "fullDescription": {"text": "`server.js` declares `GET /api/otimizacoes/preview` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-38305752d4c6bd84", "name": "Unused endpoint: GET /api/otimizacoes/snapshot-preview", "shortDescription": {"text": "Unused endpoint: GET /api/otimizacoes/snapshot-preview"}, "fullDescription": {"text": "`server.js` declares `GET /api/otimizacoes/snapshot-preview` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f855e5e4a51361e0", "name": "Unused endpoint: GET /api/otimizacoes/revisar", "shortDescription": {"text": "Unused endpoint: GET /api/otimizacoes/revisar"}, "fullDescription": {"text": "`server.js` declares `GET /api/otimizacoes/revisar` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4be40d3fd9ca5595", "name": "Unused endpoint: GET /api/otimizacoes/pendentes-por-utm", "shortDescription": {"text": "Unused endpoint: GET /api/otimizacoes/pendentes-por-utm"}, "fullDescription": {"text": "`server.js` declares `GET /api/otimizacoes/pendentes-por-utm` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/23694"}, "properties": {"repository": "zorionmidias-oss/media-intelligence", "repoUrl": "https://github.com/zorionmidias-oss/media-intelligence", "branch": "main"}, "results": [{"ruleId": "scanner-a7a3187aca4d52c4", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 activate-gam.js:27"}, "properties": {"repobilityId": "43972be2f183cc4e", "scanner": "scanner-primary", "fingerprint": "a7a3187aca4d52c4", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-6a70434164e7cde0", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 test-connections.js:5"}, "properties": {"repobilityId": "45a0a7c48f722857", "scanner": "scanner-primary", "fingerprint": "6a70434164e7cde0", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2eb06b69f9fe7b54", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 test-criar.js:28"}, "properties": {"repobilityId": "6619d6c0b606c27a", "scanner": "scanner-primary", "fingerprint": "2eb06b69f9fe7b54", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-658fb3e31251322f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 run-sync.js:10"}, "properties": {"repobilityId": "f6d15d4c8e07820c", "scanner": "scanner-primary", "fingerprint": "658fb3e31251322f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-cd3446e032cbb585", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 test-upload.js:28"}, "properties": {"repobilityId": "764594396883a38f", "scanner": "scanner-primary", "fingerprint": "cd3446e032cbb585", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-38b41aeb2e388d9e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 server.js:232"}, "properties": {"repobilityId": "a9deebb5fdc93edc", "scanner": "scanner-primary", "fingerprint": "38b41aeb2e388d9e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-85c55e1f0a2faa6f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 diagnose-gam.js:45"}, "properties": {"repobilityId": "1ef0364fe2a5d238", "scanner": "scanner-primary", "fingerprint": "85c55e1f0a2faa6f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-edc03358e7bfe038", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/diag-db.js:10"}, "properties": {"repobilityId": "23e14fac1887ca7e", "scanner": "scanner-primary", "fingerprint": "edc03358e7bfe038", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4fc758435dfa8f7b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-db-query.js:29"}, "properties": {"repobilityId": "5e519c73df67ddd9", "scanner": "scanner-primary", "fingerprint": "4fc758435dfa8f7b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5adba104bf724515", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-gam-columns.js:7"}, "properties": {"repobilityId": "829f0dcc2a24168c", "scanner": "scanner-primary", "fingerprint": "5adba104bf724515", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d0baf9a4c777f0d7", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/diag-meta.js:57"}, "properties": {"repobilityId": "964efb21e67fb9ea", "scanner": "scanner-primary", "fingerprint": "d0baf9a4c777f0d7", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0b9aab1c3277c2c9", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/audit-full.js:17"}, "properties": {"repobilityId": "4bd95d4495f6241a", "scanner": "scanner-primary", "fingerprint": "0b9aab1c3277c2c9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b5ae7c17151b06dc", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/migrate-fase2.js:54"}, "properties": {"repobilityId": "53db19d99d35a574", "scanner": "scanner-primary", "fingerprint": "b5ae7c17151b06dc", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-81c112ca6c792fd3", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/setup-db.js:56"}, "properties": {"repobilityId": "14fb2a7199ff27f0", "scanner": "scanner-primary", "fingerprint": "81c112ca6c792fd3", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e6686b7b9fc357ee", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/diag-gam.js:60"}, "properties": {"repobilityId": "24bef6322ccb6da6", "scanner": "scanner-primary", "fingerprint": "e6686b7b9fc357ee", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-dfedf0d47eff560f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/diag-bm2.js:10"}, "properties": {"repobilityId": "4d4fe970d93b79cf", "scanner": "scanner-primary", "fingerprint": "dfedf0d47eff560f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0e85641eca5e8b49", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/fetch-meta-locales.js:41"}, "properties": {"repobilityId": "526840f5fb701240", "scanner": "scanner-primary", "fingerprint": "0e85641eca5e8b49", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5cc7b6ad9f96756a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/generate-icons.js:27"}, "properties": {"repobilityId": "50ac322bf6978bfe", "scanner": "scanner-primary", "fingerprint": "5cc7b6ad9f96756a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d313036ddb8258ca", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/audit.js:17"}, "properties": {"repobilityId": "3b49ce1cb3a69c10", "scanner": "scanner-primary", "fingerprint": "d313036ddb8258ca", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3794d8b5a0c827a3", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/migrate-bms.js:21"}, "properties": {"repobilityId": "5a3b4e029409cce0", "scanner": "scanner-primary", "fingerprint": "3794d8b5a0c827a3", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e6f5b358d41c078d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-gam-utm.js:54"}, "properties": {"repobilityId": "a8b069a4be49b5d6", "scanner": "scanner-primary", "fingerprint": "e6f5b358d41c078d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8a836f35532a70ed", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/diag-cross.js:89"}, "properties": {"repobilityId": "120ac70ad396cc49", "scanner": "scanner-primary", "fingerprint": "8a836f35532a70ed", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-88662809321e359f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-meta-today.js:9"}, "properties": {"repobilityId": "0ad6ebd405f5be86", "scanner": "scanner-primary", "fingerprint": "88662809321e359f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-47827f45fa3eb647", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-gam-csv.js:57"}, "properties": {"repobilityId": "667525399ca3e66b", "scanner": "scanner-primary", "fingerprint": "47827f45fa3eb647", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-41e7707754b807f1", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 src/app/api/orcamento-status/route.js:135"}, "properties": {"repobilityId": "05195791ba7e9413", "scanner": "scanner-primary", "fingerprint": "41e7707754b807f1", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-3bc5f8528311cccb", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/app/api/orcamento-status/route.js:100"}, "properties": {"repobilityId": "e29675b3266cfe43", "scanner": "scanner-primary", "fingerprint": "3bc5f8528311cccb", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-1ee0a017285a6eed", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/app/api/drilldown/route.js:51"}, "properties": {"repobilityId": "92acebd109e80d4b", "scanner": "scanner-primary", "fingerprint": "1ee0a017285a6eed", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-95b7adf9909b3757", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/app/api/reports-gam/route.js:231"}, "properties": {"repobilityId": "bb5bd7bf0bc39211", "scanner": "scanner-primary", "fingerprint": "95b7adf9909b3757", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3abf253a3bc49849", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/app/api/campaigns/route.js:70"}, "properties": {"repobilityId": "b70d81bf24bd29d0", "scanner": "scanner-primary", "fingerprint": "3abf253a3bc49849", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ed94cd0a9402d440", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/app/api/meta-resources/route.js:146"}, "properties": {"repobilityId": "393cf9443c19f590", "scanner": "scanner-primary", "fingerprint": "ed94cd0a9402d440", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-921c657ceaa2054b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/lib/scheduler.js:7"}, "properties": {"repobilityId": "6065b8f869c75f22", "scanner": "scanner-primary", "fingerprint": "921c657ceaa2054b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5f4fcea586dccf1e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/lib/sync.js:302"}, "properties": {"repobilityId": "334a04d31f1dd218", "scanner": "scanner-primary", "fingerprint": "5f4fcea586dccf1e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d3c5dcebe225f17e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/lib/gam.js:809"}, "properties": {"repobilityId": "8a0ad003ccfe215c", "scanner": "scanner-primary", "fingerprint": "d3c5dcebe225f17e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-1eec825d5106e708", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/lib/parser.js:140"}, "properties": {"repobilityId": "464f3b36ab4b3069", "scanner": "scanner-primary", "fingerprint": "1eec825d5106e708", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-6da7f41377bc344c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/services/exchange.service.js:38"}, "properties": {"repobilityId": "86dfdce29516cb47", "scanner": "scanner-primary", "fingerprint": "6da7f41377bc344c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f374079dd7846ea2", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/mobile.html:609"}, "properties": {"repobilityId": "8bfbe1859dc248fd", "scanner": "scanner-primary", "fingerprint": "f374079dd7846ea2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/mobile.html"}, "region": {"startLine": 609}}}]}, {"ruleId": "scanner-041689749b707c76", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/dashboard.html:2566"}, "properties": {"repobilityId": "547954c10b03e6e3", "scanner": "scanner-primary", "fingerprint": "041689749b707c76", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/dashboard.html"}, "region": {"startLine": 2566}}}]}, {"ruleId": "scanner-2953bcd1c72b6b25", "level": "warning", "message": {"text": "Insecure pattern 'insert_adjacent_html' in public/dashboard.html:6107"}, "properties": {"repobilityId": "af814e0c066ca9f0", "scanner": "scanner-primary", "fingerprint": "2953bcd1c72b6b25", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "insert_adjacent_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/dashboard.html"}, "region": {"startLine": 6107}}}]}, {"ruleId": "scanner-616c6f5751ba6f0f", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/index.html:803"}, "properties": {"repobilityId": "fcd975cc51168fca", "scanner": "scanner-primary", "fingerprint": "616c6f5751ba6f0f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/index.html"}, "region": {"startLine": 803}}}]}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-e23e1456938e3899", "level": "note", "message": {"text": "Very large file: src/lib/sync.js (1158 lines)"}, "properties": {"repobilityId": "80a8e499c63ff4ac", "scanner": "scanner-primary", "fingerprint": "e23e1456938e3899", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ea3b5e389d8c9c0f", "level": "note", "message": {"text": "Low test-to-source ratio"}, "properties": {"repobilityId": "ef7b2552cc00a375", "scanner": "scanner-primary", "fingerprint": "ea3b5e389d8c9c0f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["tests"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "d96713ef880fb795", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "9b6441265a49e452", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "warning", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "6d2f3c56fa22e44a", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "040285dd30e23b28", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "d8e93a6555c8f375", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-d816990841bee20b", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/diag-db.js:167"}, "properties": {"repobilityId": "bbe4f4c345094a5e", "scanner": "scanner-primary", "fingerprint": "d816990841bee20b", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-e686b02a7efbdd45", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/js/api.js:5"}, "properties": {"repobilityId": "47f47eb0b6c0047b", "scanner": "scanner-primary", "fingerprint": "e686b02a7efbdd45", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-319e66a630e14977", "level": "none", "message": {"text": "2 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "d838d1fc5d8231c9", "scanner": "scanner-primary", "fingerprint": "319e66a630e14977", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-9bcb70b126fdea44", "level": "error", "message": {"text": "Dangling fetch: GET https://graph.facebook.com/v19.0/${account} (test-connections.js:13)"}, "properties": {"repobilityId": "6324a4d5d341cf42", "scanner": "scanner-primary", "fingerprint": "9bcb70b126fdea44", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-d94f3f8e95aa578e", "level": "error", "message": {"text": "Dangling fetch: POST https://ads.google.com/apis/ads/publisher/${GAM_VERSION}/NetworkService (test-connections.js:78)"}, "properties": {"repobilityId": "cc0f7d99713bd28c", "scanner": "scanner-primary", "fingerprint": "d94f3f8e95aa578e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-92914f34750a6b83", "level": "error", "message": {"text": "Dangling fetch: POST https://ads.google.com/apis/ads/publisher/${GAM_VERSION}/ReportService (test-connections.js:154)"}, "properties": {"repobilityId": "bab057f012268f67", "scanner": "scanner-primary", "fingerprint": "92914f34750a6b83", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-1e7b83b6c221eb15", "level": "error", "message": {"text": "Dangling fetch: GET https://admanager.googleapis.com/v1/networks (diagnose-gam.js:97)"}, "properties": {"repobilityId": "b81e1d5da53c3a8e", "scanner": "scanner-primary", "fingerprint": "1e7b83b6c221eb15", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-9c4d9787eb70850e", "level": "error", "message": {"text": "Dangling fetch: GET https://admanager.googleapis.com/v1/networks/${TARGET_NETWORK} (diagnose-gam.js:111)"}, "properties": {"repobilityId": "5ac1870ef53ff371", "scanner": "scanner-primary", "fingerprint": "9c4d9787eb70850e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-b00703921471cc17", "level": "error", "message": {"text": "Dangling fetch: GET https://graph.facebook.com/v19.0/${account} (scripts/diag-bm2.js:14)"}, "properties": {"repobilityId": "ee2d02522c2c7988", "scanner": "scanner-primary", "fingerprint": "b00703921471cc17", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-6947ae66ca95b815", "level": "error", "message": {"text": "Dangling fetch: GET https://graph.facebook.com/v19.0/${account}/insights (scripts/diag-bm2.js:24)"}, "properties": {"repobilityId": "f8cc3c805056d930", "scanner": "scanner-primary", "fingerprint": "6947ae66ca95b815", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-9db095f9c962517f", "level": "error", "message": {"text": "Dangling fetch: GET https://graph.facebook.com/v19.0/${ACCOUNT}/insights (scripts/audit.js:104)"}, "properties": {"repobilityId": "6ffddf1cec9c126a", "scanner": "scanner-primary", "fingerprint": "9db095f9c962517f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-668f0b06820174f9", "level": "error", "message": {"text": "Dangling fetch: GET https://graph.facebook.com/v19.0/${accountId} (scripts/migrate-bms.js:10)"}, "properties": {"repobilityId": "825c2893d261d0fe", "scanner": "scanner-primary", "fingerprint": "668f0b06820174f9", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-ade742661470d516", "level": "error", "message": {"text": "Dangling fetch: POST https://ads.google.com/apis/ads/publisher/v202505/ReportService (scripts/test-gam-utm.js:49)"}, "properties": {"repobilityId": "7aae1715e9629cff", "scanner": "scanner-primary", "fingerprint": "ade742661470d516", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-3905a28d072f58dd", "level": "error", "message": {"text": "Dangling fetch: GET https://graph.facebook.com/v19.0/${account}/insights (scripts/test-meta-today.js:14)"}, "properties": {"repobilityId": "2550a8d0e0ce6086", "scanner": "scanner-primary", "fingerprint": "3905a28d072f58dd", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-c715a78ec4321fd7", "level": "error", "message": {"text": "Dangling fetch: GET https://graph.facebook.com/v19.0/${account}/campaigns (scripts/test-meta-today.js:27)"}, "properties": {"repobilityId": "9d2c6a53cc1b38f3", "scanner": "scanner-primary", "fingerprint": "c715a78ec4321fd7", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-26244fe52e64e03e", "level": "error", "message": {"text": "Dangling fetch: GET https://graph.facebook.com/v19.0/${account}/insights (scripts/test-meta-today.js:39)"}, "properties": {"repobilityId": "9ecad2f461a931be", "scanner": "scanner-primary", "fingerprint": "26244fe52e64e03e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-ac8bb48f79546cfd", "level": "error", "message": {"text": "Dangling fetch: GET https://admanager.googleapis.com/v1/networks (src/lib/gam.js:385)"}, "properties": {"repobilityId": "9361e50e11dc5bba", "scanner": "scanner-primary", "fingerprint": "ac8bb48f79546cfd", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-b33ae9045c0f5b26", "level": "error", "message": {"text": "Dangling fetch: GET https://economia.awesomeapi.com.br/json/last/USD-BRL (src/services/exchange.service.js:13)"}, "properties": {"repobilityId": "9c799011e167f703", "scanner": "scanner-primary", "fingerprint": "b33ae9045c0f5b26", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-b3b8eb95237166df", "level": "error", "message": {"text": "Dangling fetch: GET https://api.exchangerate-api.com/v4/latest/USD (src/services/exchange.service.js:19)"}, "properties": {"repobilityId": "f28a90e39fbd8377", "scanner": "scanner-primary", "fingerprint": "b3b8eb95237166df", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-4dcd5251ac43500f", "level": "error", "message": {"text": "Dangling fetch: GET https://economia.awesomeapi.com.br/json/last/USD-BRL (src/services/exchange.service.js:59)"}, "properties": {"repobilityId": "94f6bbe2210471df", "scanner": "scanner-primary", "fingerprint": "4dcd5251ac43500f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-d7716bbccf06fd33", "level": "error", "message": {"text": "Dangling fetch: GET https://api.exchangerate-api.com/v4/latest/USD (src/services/exchange.service.js:66)"}, "properties": {"repobilityId": "4f077afbdf1fbdaf", "scanner": "scanner-primary", "fingerprint": "d7716bbccf06fd33", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-741da11a250343e2", "level": "note", "message": {"text": "Unused endpoint: GET /privacidade"}, "properties": {"repobilityId": "4aa044ff5f86fa25", "scanner": "scanner-primary", "fingerprint": "741da11a250343e2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "9b883326e67da4e4", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-16d386462dfb8a22", "level": "note", "message": {"text": "Unused endpoint: GET /dashboard.html"}, "properties": {"repobilityId": "d8fc1b385c1d8036", "scanner": "scanner-primary", "fingerprint": "16d386462dfb8a22", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-be1fc5ec702d9282", "level": "note", "message": {"text": "Unused endpoint: GET /mobile"}, "properties": {"repobilityId": "f02167ade28e402c", "scanner": "scanner-primary", "fingerprint": "be1fc5ec702d9282", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d218b99cb402d54e", "level": "note", "message": {"text": "Unused endpoint: GET /lib/chart.umd.min.js"}, "properties": {"repobilityId": "927dcb4e3bcca6c7", "scanner": "scanner-primary", "fingerprint": "d218b99cb402d54e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd55aa0818a7c897", "level": "note", "message": {"text": "Unused endpoint: POST /api/auth/login"}, "properties": {"repobilityId": "4b2c3310a7f2d8f2", "scanner": "scanner-primary", "fingerprint": "fd55aa0818a7c897", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d5a39262ac205120", "level": "note", "message": {"text": "Unused endpoint: POST /api/auth/logout"}, "properties": {"repobilityId": "aa3173c3593ae21d", "scanner": "scanner-primary", "fingerprint": "d5a39262ac205120", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ee4aa5ddab88c9dc", "level": "note", "message": {"text": "Unused endpoint: GET /api/auth/me"}, "properties": {"repobilityId": "0fc801facb986854", "scanner": "scanner-primary", "fingerprint": "ee4aa5ddab88c9dc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-30ebd8b02a460b20", "level": "note", "message": {"text": "Unused endpoint: GET /api/metrics"}, "properties": {"repobilityId": "97a22043e91cf9f8", "scanner": "scanner-primary", "fingerprint": "30ebd8b02a460b20", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0d99e6b89d636be3", "level": "note", "message": {"text": "Unused endpoint: POST /api/insights"}, "properties": {"repobilityId": "ea4dc7c42ff924d2", "scanner": "scanner-primary", "fingerprint": "0d99e6b89d636be3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-87f7ca9628364786", "level": "note", "message": {"text": "Unused endpoint: GET /api/overview"}, "properties": {"repobilityId": "86592444d33bd2d6", "scanner": "scanner-primary", "fingerprint": "87f7ca9628364786", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8fdf3f6802d65e7b", "level": "note", "message": {"text": "Unused endpoint: GET /api/orcamento-status"}, "properties": {"repobilityId": "6185890ced812f04", "scanner": "scanner-primary", "fingerprint": "8fdf3f6802d65e7b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6ae92428b89c54b8", "level": "note", "message": {"text": "Unused endpoint: GET /api/dashboard"}, "properties": {"repobilityId": "463453d8c0ef0d9c", "scanner": "scanner-primary", "fingerprint": "6ae92428b89c54b8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ae318ee7589859e3", "level": "note", "message": {"text": "Unused endpoint: GET /api/reports-gam"}, "properties": {"repobilityId": "4175495aab410e8e", "scanner": "scanner-primary", "fingerprint": "ae318ee7589859e3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ba2fff617bf7d128", "level": "note", "message": {"text": "Unused endpoint: GET /api/gam-status"}, "properties": {"repobilityId": "7ee93d8b5046369a", "scanner": "scanner-primary", "fingerprint": "ba2fff617bf7d128", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-472c2ab6e3d1920f", "level": "note", "message": {"text": "Unused endpoint: GET /api/intraday"}, "properties": {"repobilityId": "dd7c76d6c277c6c5", "scanner": "scanner-primary", "fingerprint": "472c2ab6e3d1920f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d5a4b79289554f96", "level": "note", "message": {"text": "Unused endpoint: POST /api/relatorios/custom"}, "properties": {"repobilityId": "aabc8175131f9951", "scanner": "scanner-primary", "fingerprint": "d5a4b79289554f96", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c59bbfe1bc947e4d", "level": "note", "message": {"text": "Unused endpoint: GET /api/contas"}, "properties": {"repobilityId": "8c26ddf6409d3655", "scanner": "scanner-primary", "fingerprint": "c59bbfe1bc947e4d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9c87f9725bfd25b9", "level": "note", "message": {"text": "Unused endpoint: POST /api/contas"}, "properties": {"repobilityId": "8ab47cf5590bb97d", "scanner": "scanner-primary", "fingerprint": "9c87f9725bfd25b9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f12545ccb0a174ca", "level": "note", "message": {"text": "Unused endpoint: PUT /api/contas/:id"}, "properties": {"repobilityId": "f16b263ce0687c85", "scanner": "scanner-primary", "fingerprint": "f12545ccb0a174ca", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-52f274c94db53289", "level": "note", "message": {"text": "Unused endpoint: DELETE /api/contas/:id"}, "properties": {"repobilityId": "4676923c3fd37653", "scanner": "scanner-primary", "fingerprint": "52f274c94db53289", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-94e27785a0756fef", "level": "note", "message": {"text": "Unused endpoint: POST /api/contas/testar"}, "properties": {"repobilityId": "2418eb6902e2b9a6", "scanner": "scanner-primary", "fingerprint": "94e27785a0756fef", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-86c28ddf7b02f56e", "level": "note", "message": {"text": "Unused endpoint: POST /api/contas/:id/testar"}, "properties": {"repobilityId": "db6012ab1964127c", "scanner": "scanner-primary", "fingerprint": "86c28ddf7b02f56e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1e0aa6f6d9e42c82", "level": "note", "message": {"text": "Unused endpoint: POST /api/contas/:id/imposto"}, "properties": {"repobilityId": "b0ae6598ea3e51b4", "scanner": "scanner-primary", "fingerprint": "1e0aa6f6d9e42c82", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ed252cbea96182b6", "level": "note", "message": {"text": "Unused endpoint: POST /api/admin/recalcular-imposto"}, "properties": {"repobilityId": "26fe39ddfa1b7cbf", "scanner": "scanner-primary", "fingerprint": "ed252cbea96182b6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8c9f550ca5c0875e", "level": "note", "message": {"text": "Unused endpoint: GET /api/paginas"}, "properties": {"repobilityId": "e51ce92b8e9c007a", "scanner": "scanner-primary", "fingerprint": "8c9f550ca5c0875e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-814c2d0d0d70f6c5", "level": "note", "message": {"text": "Unused endpoint: POST /api/paginas/sync"}, "properties": {"repobilityId": "1a36b5ca2b580700", "scanner": "scanner-primary", "fingerprint": "814c2d0d0d70f6c5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1ac431dd8b3242e4", "level": "note", "message": {"text": "Unused endpoint: GET /api/historico-campanhas/ultimo-numero"}, "properties": {"repobilityId": "d7227caca2710f6e", "scanner": "scanner-primary", "fingerprint": "1ac431dd8b3242e4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-97f0428048d16cb0", "level": "note", "message": {"text": "Unused endpoint: GET /api/dominios"}, "properties": {"repobilityId": "4950a11f810ccf27", "scanner": "scanner-primary", "fingerprint": "97f0428048d16cb0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f007b64f830f7c80", "level": "note", "message": {"text": "Unused endpoint: POST /api/dominios"}, "properties": {"repobilityId": "1efb3bf73f5eb876", "scanner": "scanner-primary", "fingerprint": "f007b64f830f7c80", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f4f9d4ce22b18941", "level": "note", "message": {"text": "Unused endpoint: GET /api/dominios/pendentes"}, "properties": {"repobilityId": "82eb9b8c9bc21fd2", "scanner": "scanner-primary", "fingerprint": "f4f9d4ce22b18941", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-281bf80b988937bc", "level": "note", "message": {"text": "Unused endpoint: POST /api/dominios/aprovar"}, "properties": {"repobilityId": "208a29f4e7bb0285", "scanner": "scanner-primary", "fingerprint": "281bf80b988937bc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8807873abf70f42f", "level": "note", "message": {"text": "Unused endpoint: GET /api/metas"}, "properties": {"repobilityId": "3bab79949df0249d", "scanner": "scanner-primary", "fingerprint": "8807873abf70f42f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d44ba3660310511c", "level": "note", "message": {"text": "Unused endpoint: POST /api/metas"}, "properties": {"repobilityId": "aac062ba25fcdb38", "scanner": "scanner-primary", "fingerprint": "d44ba3660310511c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0a8a93035bc479a8", "level": "note", "message": {"text": "Unused endpoint: PUT /api/metas/:id"}, "properties": {"repobilityId": "fe2b451b3963f661", "scanner": "scanner-primary", "fingerprint": "0a8a93035bc479a8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-273d23872876f2b6", "level": "note", "message": {"text": "Unused endpoint: DELETE /api/metas/:id"}, "properties": {"repobilityId": "c614d129905a1e10", "scanner": "scanner-primary", "fingerprint": "273d23872876f2b6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a1a8550737127ec7", "level": "note", "message": {"text": "Unused endpoint: GET /api/notificacoes"}, "properties": {"repobilityId": "a28ae011814dc65c", "scanner": "scanner-primary", "fingerprint": "a1a8550737127ec7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6fe3188f1f1c32d3", "level": "note", "message": {"text": "Unused endpoint: POST /api/notificacoes/:id/marcar-lida"}, "properties": {"repobilityId": "a52f814f2cf8526d", "scanner": "scanner-primary", "fingerprint": "6fe3188f1f1c32d3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8a55f016901c988a", "level": "note", "message": {"text": "Unused endpoint: POST /api/notificacoes/marcar-todas-lidas"}, "properties": {"repobilityId": "caad2fdf363b5350", "scanner": "scanner-primary", "fingerprint": "8a55f016901c988a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9a87ad959d96703e", "level": "note", "message": {"text": "Unused endpoint: GET /api/utms"}, "properties": {"repobilityId": "5b9aa8348b63f655", "scanner": "scanner-primary", "fingerprint": "9a87ad959d96703e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1b05483d9fb19c34", "level": "note", "message": {"text": "Unused endpoint: GET /api/utms/conjuntos-ativos"}, "properties": {"repobilityId": "cf0d62c1998c1242", "scanner": "scanner-primary", "fingerprint": "1b05483d9fb19c34", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a6a346d0112923c0", "level": "note", "message": {"text": "Unused endpoint: GET /api/drilldown/:utm"}, "properties": {"repobilityId": "a3255ca2d6ae6961", "scanner": "scanner-primary", "fingerprint": "a6a346d0112923c0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-88491d73c88c6cf5", "level": "note", "message": {"text": "Unused endpoint: GET /api/otimizacoes/tipos-acao"}, "properties": {"repobilityId": "c34a58b6d6bafb2c", "scanner": "scanner-primary", "fingerprint": "88491d73c88c6cf5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cd3076a74c88f048", "level": "note", "message": {"text": "Unused endpoint: POST /api/otimizacoes/tipos-acao"}, "properties": {"repobilityId": "a4aead8a026b6558", "scanner": "scanner-primary", "fingerprint": "cd3076a74c88f048", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-399bad1f8df9181e", "level": "note", "message": {"text": "Unused endpoint: PUT /api/otimizacoes/tipos-acao/:id"}, "properties": {"repobilityId": "8ec59616663840b2", "scanner": "scanner-primary", "fingerprint": "399bad1f8df9181e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-61e46125eeafbe4b", "level": "note", "message": {"text": "Unused endpoint: DELETE /api/otimizacoes/tipos-acao/:id"}, "properties": {"repobilityId": "12ef00947a858193", "scanner": "scanner-primary", "fingerprint": "61e46125eeafbe4b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3b9e3c16a37e369e", "level": "note", "message": {"text": "Unused endpoint: GET /api/otimizacoes/preview"}, "properties": {"repobilityId": "d4c9be50ed392d7c", "scanner": "scanner-primary", "fingerprint": "3b9e3c16a37e369e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-38305752d4c6bd84", "level": "note", "message": {"text": "Unused endpoint: GET /api/otimizacoes/snapshot-preview"}, "properties": {"repobilityId": "4123110ce67fcb53", "scanner": "scanner-primary", "fingerprint": "38305752d4c6bd84", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f855e5e4a51361e0", "level": "note", "message": {"text": "Unused endpoint: GET /api/otimizacoes/revisar"}, "properties": {"repobilityId": "579ab6ab3ff5fb03", "scanner": "scanner-primary", "fingerprint": "f855e5e4a51361e0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4be40d3fd9ca5595", "level": "note", "message": {"text": "Unused endpoint: GET /api/otimizacoes/pendentes-por-utm"}, "properties": {"repobilityId": "a026ad51648f545e", "scanner": "scanner-primary", "fingerprint": "4be40d3fd9ca5595", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}