{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-801a438a4026e8c9", "name": "Possibly dead Python function: filesystem_entry", "shortDescription": {"text": "Possibly dead Python function: filesystem_entry"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3b2f82613b19f595", "name": "Possibly dead Python function: stl_sidecar_job", "shortDescription": {"text": "Possibly dead Python function: stl_sidecar_job"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1f839487a1f31ac9", "name": "Possibly dead Python function: three_mf_sidecar_job", "shortDescription": {"text": "Possibly dead Python function: three_mf_sidecar_job"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d39ccb379db7cb1", "name": "Possibly dead Python function: native_glb_sidecar_job", "shortDescription": {"text": "Possibly dead Python function: native_glb_sidecar_job"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-52a24af4448a5beb", "name": "Possibly dead Python function: export_glb_with_topology", "shortDescription": {"text": "Possibly dead Python function: export_glb_with_topology"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b464cabb33b0040f", "name": "Possibly dead Python function: generate_step", "shortDescription": {"text": "Possibly dead Python function: generate_step"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-58f2f49890604364", "name": "Possibly dead Python function: run_tool_cli", "shortDescription": {"text": "Possibly dead Python function: run_tool_cli"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-58dc6cb4797b705f", "name": "Possibly dead Python function: add_module", "shortDescription": {"text": "Possibly dead Python function: add_module"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-50aad615a3c89617", "name": "Possibly dead Python function: datum", "shortDescription": {"text": "Possibly dead Python function: datum"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2df8ce3e913da2ed", "name": "Possibly dead Python function: linear_frame", "shortDescription": {"text": "Possibly dead Python function: linear_frame"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c1633c1179838748", "name": "Possibly dead Python function: cylindrical_frame", "shortDescription": {"text": "Possibly dead Python function: cylindrical_frame"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6b64ba91091a9627", "name": "Possibly dead Python function: ball_frame", "shortDescription": {"text": "Possibly dead Python function: ball_frame"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5c973fb6709065d5", "name": "Possibly dead Python function: scene_occurrence_prototype_shape", "shortDescription": {"text": "Possibly dead Python function: scene_occurrence_prototype_shape"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4baad11d752b106a", "name": "Possibly dead Python function: export_assembly_step_from_payload", "shortDescription": {"text": "Possibly dead Python function: export_assembly_step_from_payload"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4d08e5a9a0ef9001", "name": "Possibly dead Python function: export_assembly_step_scene_from_payload", "shortDescription": {"text": "Possibly dead Python function: export_assembly_step_scene_from_payload"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e7ba1cca5a9e84a2", "name": "Possibly dead Python function: find_source_by_source_ref", "shortDescription": {"text": "Possibly dead Python function: find_source_by_source_ref"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-585c086153d32b64", "name": "Possibly dead Python function: artifact_path_for_step_path", "shortDescription": {"text": "Possibly dead Python function: artifact_path_for_step_path"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f499d52f1549ba1c", "name": "Possibly dead Python function: hidden_artifact_path_for_step_path", "shortDescription": {"text": "Possibly dead Python function: hidden_artifact_path_for_step_path"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-06be3fcc7f825ff8", "name": "Possibly dead Python function: read_dxf_text_to_cad_metadata", "shortDescription": {"text": "Possibly dead Python function: read_dxf_text_to_cad_metadata"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea0964f92f6a1903", "name": "Possibly dead Python function: step_path_from_target", "shortDescription": {"text": "Possibly dead Python function: step_path_from_target"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-81e1aac71034557c", "name": "Possibly dead Python function: aligned_view_name_for_facts", "shortDescription": {"text": "Possibly dead Python function: aligned_view_name_for_facts"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6d19f26d0a622140", "name": "Possibly dead Python function: assert_bbox_coordinate", "shortDescription": {"text": "Possibly dead Python function: assert_bbox_coordinate"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-45fff68b74c04f43", "name": "Possibly dead Python function: assert_bbox_span", "shortDescription": {"text": "Possibly dead Python function: assert_bbox_span"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-00d33bf21a468617", "name": "Possibly dead Python function: assert_selector_count", "shortDescription": {"text": "Possibly dead Python function: assert_selector_count"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-744faeeb3a216877", "name": "Possibly dead Python function: filesystem_entry", "shortDescription": {"text": "Possibly dead Python function: filesystem_entry"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8ee5cdc359cfadd2", "name": "Possibly dead Python function: stl_sidecar_job", "shortDescription": {"text": "Possibly dead Python function: stl_sidecar_job"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-30ce8d12e5c6b74b", "name": "Possibly dead Python function: three_mf_sidecar_job", "shortDescription": {"text": "Possibly dead Python function: three_mf_sidecar_job"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-20272da6ebb4fa85", "name": "Truncated text has no discoverable full-value affordance \u2014 docs/src/components/site-header-client.tsx:90", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 docs/src/components/site-header-client.tsx:90"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-c594b4709ee37a5f", "name": "Truncated text has no discoverable full-value affordance \u2014 docs/src/components/hero-step-render.tsx:450", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 docs/src/components/hero-step-render.tsx:450"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-ae58ab928e12eed6", "name": "Truncated text has no discoverable full-value affordance \u2014 docs/src/app/page.tsx:173", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 docs/src/app/page.tsx:173"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-35bae8747aede9d3", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 docs/src/app/layout.tsx:112", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 docs/src/app/layout.tsx:112"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-d4836252d4a8dcef", "name": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/CadRenderPane.js:747", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/CadRenderPane.js:747"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-d705eab42b5e26cc", "name": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/GcodeFileSheet.js:377", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/GcodeFileSheet.js:377"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-bea6970525fd7add", "name": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/StepFileSheet.js:1196", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/StepFileSheet.js:1196"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-27fc6299aa297722", "name": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/CadWorkspaceAssemblyIn", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/CadWorkspaceAssemblyInspectPill.js:43"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-187c1fce19ce6903", "name": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/UrdfFileSheet.js:777", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/UrdfFileSheet.js:777"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-27c60554d27c2c35", "name": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/FileSheet.js:129", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/FileSheet.js:129"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-df3d32b920c1106b", "name": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/ThemeSettingsPopover.j", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/ThemeSettingsPopover.js:529"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-01bbd90a60cc5162", "name": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/AssemblyContextMenuIte", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/AssemblyContextMenuItems.js:2"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-6070f5f13b556ae3", "name": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/FileViewerSidebar.js:4", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/FileViewerSidebar.js:413"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-c1a521ff29b80eb3", "name": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/CadWorkspaceTopBar.js:", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/CadWorkspaceTopBar.js:220"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-f35e778a24e8ca03", "name": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/FileAccessContextMenu.", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/FileAccessContextMenu.jsx:26"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-ebd2ce81103f2aa1", "name": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/CadWorkspaceHome.js:21", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/CadWorkspaceHome.js:212"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-d6a7161b12f829b1", "name": "TODO/FIXME marker in shipping code \u2014 skills/cad/scripts/snapshot/runtime/snapshot-render.js:4085", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 skills/cad/scripts/snapshot/runtime/snapshot-render.js:4085"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-4febd6f286fe69e9", "name": "React Flow edge with `label=` but no project-wide edge-label CSS override \u2014 skills/cad/scripts/snapshot/runtime/snapshot", "shortDescription": {"text": "React Flow edge with `label=` but no project-wide edge-label CSS override \u2014 skills/cad/scripts/snapshot/runtime/snapshot-render.js:4168"}, "fullDescription": {"text": "React Flow edge labels render with a white rectangle behind the text by default, which scatters bright boxes across a dark canvas. Either drop the label, or override `.react-flow__edge-textbg` and `.react-flow__edge-text` in your stylesheet.\n\nWhy: P-H in CHECKLIST.md \u2014 vendor edge labels bleed white through a dark canvas.\nRule id: fq.edge-label.no-bg"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-514468e534103108", "name": "TODO/FIXME marker in shipping code \u2014 plugins/cad/skills/cad/scripts/snapshot/runtime/snapshot-render.js:4085", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 plugins/cad/skills/cad/scripts/snapshot/runtime/snapshot-render.js:4085"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-04889c09cbea4369", "name": "React Flow edge with `label=` but no project-wide edge-label CSS override \u2014 plugins/cad/skills/cad/scripts/snapshot/runt", "shortDescription": {"text": "React Flow edge with `label=` but no project-wide edge-label CSS override \u2014 plugins/cad/skills/cad/scripts/snapshot/runtime/snapshot-render.js:4168"}, "fullDescription": {"text": "React Flow edge labels render with a white rectangle behind the text by default, which scatters bright boxes across a dark canvas. Either drop the label, or override `.react-flow__edge-textbg` and `.react-flow__edge-text` in your stylesheet.\n\nWhy: P-H in CHECKLIST.md \u2014 vendor edge labels bleed white through a dark canvas.\nRule id: fq.edge-label.no-bg"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-8ee775eeb3a69289", "name": "use defused xml \u2014 packages/cadpy/src/cadpy/threemf.py:8", "shortDescription": {"text": "use defused xml \u2014 packages/cadpy/src/cadpy/threemf.py:8"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-608148875f420a8b", "name": "use defused xml \u2014 plugins/cad/skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/context.py:5", "shortDescription": {"text": "use defused xml \u2014 plugins/cad/skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/context.py:5"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-a48e8cea1ac1fda4", "name": "use defused xml \u2014 plugins/cad/skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/moveit_py.py:10", "shortDescription": {"text": "use defused xml \u2014 plugins/cad/skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/moveit_py.py:10"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-e3740b0469f7ecb1", "name": "insecure hash algorithm sha1 \u2014 plugins/cad/skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/moveit_py.py:3", "shortDescription": {"text": "insecure hash algorithm sha1 \u2014 plugins/cad/skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/moveit_py.py:349"}, "fullDescription": {"text": "Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead.\n\nRule: python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1\nSeverity: WARNING\nOWASP: A03:2017 - Sensitive Data Exposure, A02:2021 - Cryptographic Failures, A04:2025 - Cryptographic Failures\nCWE: CWE-327: Use of a Broken or Risky Cryptographic Algorithm\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.75}}, {"id": "scanner-97d22d4e1855c57a", "name": "use defused xml \u2014 plugins/cad/skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/srdf_source.py:7", "shortDescription": {"text": "use defused xml \u2014 plugins/cad/skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/srdf_source.py:7"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-94849e62e90118f8", "name": "use defused xml \u2014 plugins/cad/skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/threemf.py:8", "shortDescription": {"text": "use defused xml \u2014 plugins/cad/skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/threemf.py:8"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-f754e2bc78fca771", "name": "use defused xml \u2014 plugins/cad/skills/cad/scripts/packages/cadpy/src/cadpy/threemf.py:8", "shortDescription": {"text": "use defused xml \u2014 plugins/cad/skills/cad/scripts/packages/cadpy/src/cadpy/threemf.py:8"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-d6b50f3743ab16c0", "name": "use defused xml \u2014 plugins/cad/skills/dxf/scripts/packages/cadpy/src/cadpy/threemf.py:8", "shortDescription": {"text": "use defused xml \u2014 plugins/cad/skills/dxf/scripts/packages/cadpy/src/cadpy/threemf.py:8"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-e96db416354fe883", "name": "use defused xml \u2014 plugins/cad/skills/sdf/scripts/sdf/builder.py:5", "shortDescription": {"text": "use defused xml \u2014 plugins/cad/skills/sdf/scripts/sdf/builder.py:5"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-741b4cc4e0c4a36c", "name": "use defused xml \u2014 plugins/cad/skills/sdf/scripts/sdf/cli.py:10", "shortDescription": {"text": "use defused xml \u2014 plugins/cad/skills/sdf/scripts/sdf/cli.py:10"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-f60dbcf60ec2cc43", "name": "use defused xml \u2014 plugins/cad/skills/sdf/scripts/sdf/source.py:6", "shortDescription": {"text": "use defused xml \u2014 plugins/cad/skills/sdf/scripts/sdf/source.py:6"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-01797895b6d7a1dd", "name": "use defused xml \u2014 plugins/cad/skills/sdf/scripts/sdf/validation.py:8", "shortDescription": {"text": "use defused xml \u2014 plugins/cad/skills/sdf/scripts/sdf/validation.py:8"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-754e5d05f15dd0a4", "name": "use defused xml \u2014 plugins/cad/skills/srdf/scripts/srdf/cli.py:13", "shortDescription": {"text": "use defused xml \u2014 plugins/cad/skills/srdf/scripts/srdf/cli.py:13"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-146c75e599a2118b", "name": "use defused xml \u2014 plugins/cad/skills/srdf/scripts/srdf/source.py:7", "shortDescription": {"text": "use defused xml \u2014 plugins/cad/skills/srdf/scripts/srdf/source.py:7"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-248f2401ebddf63c", "name": "dynamic urllib use detected \u2014 plugins/cad/skills/step-parts/scripts/download_step_part.py:66", "shortDescription": {"text": "dynamic urllib use detected \u2014 plugins/cad/skills/step-parts/scripts/download_step_part.py:66"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A01:2017 - Injection\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-80946d7729644b23", "name": "use defused xml \u2014 plugins/cad/skills/urdf/scripts/urdf/cli.py:10", "shortDescription": {"text": "use defused xml \u2014 plugins/cad/skills/urdf/scripts/urdf/cli.py:10"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-d9cdd170dc5de26a", "name": "use defused xml \u2014 plugins/cad/skills/urdf/scripts/urdf/source.py:9", "shortDescription": {"text": "use defused xml \u2014 plugins/cad/skills/urdf/scripts/urdf/source.py:9"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-bad5b23962f91958", "name": "use defused xml \u2014 skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/context.py:5", "shortDescription": {"text": "use defused xml \u2014 skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/context.py:5"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-2232e72a81efeb84", "name": "use defused xml \u2014 skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/moveit_py.py:10", "shortDescription": {"text": "use defused xml \u2014 skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/moveit_py.py:10"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-36ce26864b5bec73", "name": "insecure hash algorithm sha1 \u2014 skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/moveit_py.py:349", "shortDescription": {"text": "insecure hash algorithm sha1 \u2014 skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/moveit_py.py:349"}, "fullDescription": {"text": "Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead.\n\nRule: python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1\nSeverity: WARNING\nOWASP: A03:2017 - Sensitive Data Exposure, A02:2021 - Cryptographic Failures, A04:2025 - Cryptographic Failures\nCWE: CWE-327: Use of a Broken or Risky Cryptographic Algorithm\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.75}}, {"id": "scanner-a9e1a262e78709af", "name": "use defused xml \u2014 skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/srdf_source.py:7", "shortDescription": {"text": "use defused xml \u2014 skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/srdf_source.py:7"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-3de0b9c3515e5970", "name": "use defused xml \u2014 skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/threemf.py:8", "shortDescription": {"text": "use defused xml \u2014 skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/threemf.py:8"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-e496cf0be99b08ad", "name": "use defused xml \u2014 skills/cad/scripts/packages/cadpy/src/cadpy/threemf.py:8", "shortDescription": {"text": "use defused xml \u2014 skills/cad/scripts/packages/cadpy/src/cadpy/threemf.py:8"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-6f25deaafcfae363", "name": "use defused xml \u2014 skills/dxf/scripts/packages/cadpy/src/cadpy/threemf.py:8", "shortDescription": {"text": "use defused xml \u2014 skills/dxf/scripts/packages/cadpy/src/cadpy/threemf.py:8"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-052b8454a04f47b7", "name": "use defused xml \u2014 skills/sdf/scripts/sdf/builder.py:5", "shortDescription": {"text": "use defused xml \u2014 skills/sdf/scripts/sdf/builder.py:5"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-87e6b38572fa93f2", "name": "use defused xml \u2014 skills/sdf/scripts/sdf/cli.py:10", "shortDescription": {"text": "use defused xml \u2014 skills/sdf/scripts/sdf/cli.py:10"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-b558413d2d416dfd", "name": "use defused xml \u2014 skills/sdf/scripts/sdf/source.py:6", "shortDescription": {"text": "use defused xml \u2014 skills/sdf/scripts/sdf/source.py:6"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-c257663d7ddeef7f", "name": "use defused xml \u2014 skills/sdf/scripts/sdf/validation.py:8", "shortDescription": {"text": "use defused xml \u2014 skills/sdf/scripts/sdf/validation.py:8"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-96f888e1feef39fa", "name": "use defused xml \u2014 skills/srdf/scripts/srdf/cli.py:13", "shortDescription": {"text": "use defused xml \u2014 skills/srdf/scripts/srdf/cli.py:13"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-d7e47986a1aa8043", "name": "use defused xml \u2014 skills/srdf/scripts/srdf/source.py:7", "shortDescription": {"text": "use defused xml \u2014 skills/srdf/scripts/srdf/source.py:7"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-fe244dfbe1b2989a", "name": "dynamic urllib use detected \u2014 skills/step-parts/scripts/download_step_part.py:66", "shortDescription": {"text": "dynamic urllib use detected \u2014 skills/step-parts/scripts/download_step_part.py:66"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A01:2017 - Injection\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-67f8debd8d5feec3", "name": "use defused xml \u2014 skills/urdf/scripts/urdf/cli.py:10", "shortDescription": {"text": "use defused xml \u2014 skills/urdf/scripts/urdf/cli.py:10"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-ffb3990aa4594350", "name": "use defused xml \u2014 skills/urdf/scripts/urdf/source.py:9", "shortDescription": {"text": "use defused xml \u2014 skills/urdf/scripts/urdf/source.py:9"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-2d1e32eba17690c7", "name": "use defused xml \u2014 viewer/moveit2_server/moveit2_server/context.py:5", "shortDescription": {"text": "use defused xml \u2014 viewer/moveit2_server/moveit2_server/context.py:5"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-df72bd4d6cdde7d3", "name": "use defused xml \u2014 viewer/moveit2_server/moveit2_server/moveit_py.py:10", "shortDescription": {"text": "use defused xml \u2014 viewer/moveit2_server/moveit2_server/moveit_py.py:10"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-62a8c31bdb3e06cc", "name": "insecure hash algorithm sha1 \u2014 viewer/moveit2_server/moveit2_server/moveit_py.py:349", "shortDescription": {"text": "insecure hash algorithm sha1 \u2014 viewer/moveit2_server/moveit2_server/moveit_py.py:349"}, "fullDescription": {"text": "Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead.\n\nRule: python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1\nSeverity: WARNING\nOWASP: A03:2017 - Sensitive Data Exposure, A02:2021 - Cryptographic Failures, A04:2025 - Cryptographic Failures\nCWE: CWE-327: Use of a Broken or Risky Cryptographic Algorithm\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.75}}, {"id": "scanner-d0b9b74331ba8d40", "name": "use defused xml \u2014 viewer/moveit2_server/moveit2_server/srdf_source.py:7", "shortDescription": {"text": "use defused xml \u2014 viewer/moveit2_server/moveit2_server/srdf_source.py:7"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-bd9ef2832ad8fe97", "name": "use defused xml \u2014 viewer/packages/cadpy/src/cadpy/threemf.py:8", "shortDescription": {"text": "use defused xml \u2014 viewer/packages/cadpy/src/cadpy/threemf.py:8"}, "fullDescription": {"text": "The Python documentation recommends using `defusedxml` instead of `xml` because the native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak confidential data and \"XML bombs\" can cause denial of service.\n\nRule: python.lang.security.use-defused-xml.use-defused-xml\nSeverity: ERROR\nOWASP: A04:2017 - XML External Entities (XXE), A05:2021 - Security Misconfiguration, A02:2025 - Security Misconfiguration\nCWE: CWE-611: Improper Restriction of XML External Entity Reference\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-9a2434d148b9caf4", "name": "CVE-2026-49356: @babel/core 7.29.0 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-49356: @babel/core 7.29.0 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "@babel/core: @babel/core: Arbitrary file read via sourceMappingURL comment\n\nBabel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. Using @babel/core to compile maliciously crafted code can allow an attacker to read any source map from the system that is running Babel, if the attacker controls the input source code, can read the output source code, and knows the path of the source map file that they want to read. This vulnerability is fixed in 8.0.0-rc.6 an\n\nPackage: @babel/core\nInstalled: 7.29.0\nFixed in: 8.0.0-rc.6, 7.29.6\nSeverity: LOW\nFix: Upgrade @babel/core to 8.0.0-rc.6, 7.29.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-654c5dd1b30545b2", "name": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.14 \u2014 docs/package-lock.json", "shortDescription": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.14 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nThe same as the `hono` core [Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)](https://github.com/honojs/hono/security/advisories/GHSA-wwfh-h76j-fc44).\n\n### Summary\n\nOn Windows hosts, an encoded backslash (`%5C`) in the request path decodes to `\\`, which the Windows path resolver treats as a separator. `serve-static` then resolves a single URL segment such as `admin\\secret.txt` into a nested file under the root and serves it, letting an attacker read static files meant t\n\nPackage: @hono/node-server\nInstalled: 1.19.14\nFixed in: 2.0.5\nSeverity: MEDIUM\nFix: Upgrade @hono/node-server to 2.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b7b827e365307352", "name": "CVE-2026-12590: body-parser 2.2.2 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "body-parser: body-parser: Denial of Service via invalid limit option\n\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars\n\nPackage: body-parser\nInstalled: 2.2.2\nFixed in: 1.20.6, 2.3.0\nSeverity: LOW\nFix: Upgrade body-parser to 1.20.6, 2.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-00206968cd20871e", "name": "CVE-2026-13149: brace-expansion 5.0.6 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-13149: brace-expansion 5.0.6 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity\n\nbrace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.\n\nPackage: brace-expansion\nInstalled: 5.0.6\nFixed in: 5.0.7, 1.1.16, 2.1.2\nSeverity: HIGH\nFix: Upgrade brace-expansion to 5.0.7, 1.1.16, 2.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7c4a3af7f35cbc05", "name": "CVE-2026-13676: fast-uri 3.1.2 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-13676: fast-uri 3.1.2 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization\n\nfast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) befo\n\nPackage: fast-uri\nInstalled: 3.1.2\nFixed in: 4.0.1, 3.1.3, 2.4.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 4.0.1, 3.1.3, 2.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-983a1d4642a4fef9", "name": "CVE-2026-16221: fast-uri 3.1.2 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-16221: fast-uri 3.1.2 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x  ...\n\nImpact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use f\n\nPackage: fast-uri\nInstalled: 3.1.2\nFixed in: 2.4.3, 3.1.4, 4.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 2.4.3, 3.1.4, 4.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-870cf85ddb8b813b", "name": "CVE-2026-54290: hono 4.12.18 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-54290: hono 4.12.18 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, with credentials: true and no explicit origin (the default wildcard), the CORS Middleware reflects the request's Origin and sends Access-Control-Allow-Credentials: true. Any site can then make credentialed cross-origin requests and read the responses, exposing cookie-authenticated endpoints to arbitrary origins. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.12.18\nFixed in: 4.12.25\nSeverity: HIGH\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-efe5d2fc749ffad0", "name": "CVE-2026-47673: hono 4.12.18 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-47673: hono 4.12.18 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "Hono: JWT middleware accepts any Authorization scheme, not only Bearer\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk middlewares do not verify that the Authorization header value uses theBearer scheme. Any two-part header value \u2014 regardless of the scheme name in the first position \u2014 proceeds to JWT verification. A request presenting a valid JWT under a non-Bearer scheme identifier (such as Basic or Token) is authenticated identically to a correctly formed Bearer request. This vulnerability is\n\nPackage: hono\nInstalled: 4.12.18\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2b90eb7928403027", "name": "CVE-2026-47674: hono 4.12.18 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-47674: hono 4.12.18 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 \n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restriction middleware (hono/ip-restriction) compares incoming IP addresses against configured deny and allow rules using string equality after partial normalization. Non-canonical IPv6 representations of an address already listed in a static rule \u2014 such as compressed forms, explicit-zero forms, or hex-notation IPv4-mapped addresses \u2014 do not match the normalized rule entry, causing the \n\nPackage: hono\nInstalled: 4.12.18\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bfef8f28b67a2c39", "name": "CVE-2026-47675: hono 4.12.18 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-47675: hono 4.12.18 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() function in hono/cookie validates domain and path options against characters that corrupt Set-Cookie header syntax (;, \\r, \\n), but does not apply the same validation to sameSite and priority. An application that passes user-controlled input into either option may produce a Set-Cookie response header containing attacker-chosen additional attributes. This vulnerability is fixed \n\nPackage: hono\nInstalled: 4.12.18\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7e4bca48cc6cc429", "name": "CVE-2026-47676: hono 4.12.18 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-47676: hono 4.12.18 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() strips the mount prefix from the incoming request path using the raw URL pathname, while route matching is performed against the percent-decoded path. This inconsistency causes the prefix to be stripped at the wrong position when the path contains percent-encoded multi-byte characters, resulting in the mounted sub-application receiving an incorrect path. This vulnerability is fixed\n\nPackage: hono\nInstalled: 4.12.18\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e111e9ab2c2d4938", "name": "CVE-2026-54286: hono 4.12.18 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-54286: hono 4.12.18 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts, an encoded backslash (%5C) in the request path decodes to \\, which the Windows path resolver treats as a separator. serve-static then resolves a single URL segment such as admin\\secret.txt into a nested file under the root and serves it, letting an attacker read static files meant to be protected behind prefix-mounted middleware. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.12.18\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b40cde31aac7a80e", "name": "CVE-2026-54287: hono 4.12.18 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-54287: hono 4.12.18 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, the ALB single-header response and the VPC Lattice v2 response join multiple Set-Cookie headers into one comma-separated value. Because commas also appear inside cookie attributes (for example Expires dates), clients cannot split the value back into individual cookies and silently drop or misparse them. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.12.18\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-65553d3ded92db4c", "name": "CVE-2026-54288: hono 4.12.18 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-54288: hono 4.12.18 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit Middleware trusts the request's Content-Length header to decide whether a body is within the limit. On AWS Lambda (API Gateway v1/v2, ALB, VPC Lattice, and Lambda@Edge) the body is delivered fully buffered and the adapter builds the request with the client-declared Content-Length, which need not match the actual payload. A client can declare a tiny Content-Length while sending a\n\nPackage: hono\nInstalled: 4.12.18\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-38bba986831ade9c", "name": "CVE-2026-54289: hono 4.12.18 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-54289: hono 4.12.18 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda@Edge, CloudFront delivers a request header that appears more than once as several separate entries. The adapter writes each value with Headers.set instead of Headers.append, so every value overwrites the previous one and only the last reaches the application. Repeated request headers such as X-Forwarded-For, Forwarded, and Via are silently truncated to a single value. Request mid\n\nPackage: hono\nInstalled: 4.12.18\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8341ef5f0736a269", "name": "CVE-2026-59895: hono 4.12.18 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-59895: hono 4.12.18 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values used in a JSX class attribute during server-side rendering to break out of the attribute and inject arbitrary markup. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.12.18\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c8f0c6fb47510e4c", "name": "CVE-2026-59896: hono 4.12.18 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-59896: hono 4.12.18 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "hono/jsx does not isolate context per request, leading to cross-request data disclosure\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/jsx did not isolate context values per request during server-side rendering, allowing createContext, useContext, jsxRenderer, or useRequestContext data from a different in-flight request to be used after an await in an async component. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.12.18\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9c01e8ea89057944", "name": "CVE-2026-59897: hono 4.12.18 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-59897: hono 4.12.18 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request header value because it de-duplicates values using a substring comparison instead of an exact match, so middleware or application logic that depends on the complete X-Forwarded-For chain, rate limiting, audit logging, or proxy-chain validation can receive incomplete data. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.12.18\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-51bb941c82b607dd", "name": "CVE-2026-59869: js-yaml 4.1.1 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-59869: js-yaml 4.1.1 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML documents\n\njs-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.\n\nPackage: js-yaml\nInstalled: 4.1.1\nFixed in: 3.15.0, 4.3.0\nSeverity: HIGH\nFix: Upgrade js-yaml to 3.15.0, 4.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a503bb72aab73e90", "name": "CVE-2026-53550: js-yaml 4.1.1 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-53550: js-yaml 4.1.1 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML merge keys\n\njs-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and can block a Node.js worker/event loop for seconds with a relatively small payload (tens of KB), resulting in denial of service. The issue is in merge handling inside lib/loader.js. This vulnerabil\n\nPackage: js-yaml\nInstalled: 4.1.1\nFixed in: 4.2.0, 3.15.0\nSeverity: MEDIUM\nFix: Upgrade js-yaml to 4.2.0, 3.15.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6b58aba3aaf01edf", "name": "CVE-2026-64641: next 16.2.6 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-64641: next 16.2.6 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "Next.js: Denial of Service in App Router using Server Actions\n\n## Impact\n\nCrafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process.\n\n## Workarounds\n\nNo workaround exists besides upgrading. Applications using Pages Router or not using Server Actions are not vulnerable.\n\nPackage: next\nInstalled: 16.2.6\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1aa8757a0398139d", "name": "CVE-2026-64642: next 16.2.6 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-64642: next 16.2.6 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale\n\n## Impact\n\nCrafted requests targeting Next.js applications using App Router built with Turbopack and a **single** entry in `config.i18n.locales` can bypass middleware/proxy based authentication.\n\n## Workarounds\n\nIf you cannot upgrade immediately, enforce authorization in the page's server-side data path instead of relying solely on middleware.\n\nPackage: next\nInstalled: 16.2.6\nFixed in: 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-578d0d3fcdb87a6a", "name": "CVE-2026-64645: next 16.2.6 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-64645: next 16.2.6 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname\n\n## Impact\n\nA `rewrites()` or `redirects()` rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's\u00a0hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A `redirects()` rule configured this way is vulnerable to an Open Redirect.\n\nThis affects any destination that puts a dynamic segmen\n\nPackage: next\nInstalled: 16.2.6\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-30bf89802c5ff263", "name": "CVE-2026-64649: next 16.2.6 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-64649: next 16.2.6 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in Server Actions on custom servers\n\n## Impact\n\nWhen a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker's request to control Host-associated headers. In some configurations, it's also possible to obtain internal values that weaken middleware/proxy authorization.\n\nApplications that use Server Actions are affected when the incoming host header is not fixed to a trusted value. This typically occurs\n\nPackage: next\nInstalled: 16.2.6\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c52eee3491b91888", "name": "CVE-2026-64643: next 16.2.6 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-64643: next 16.2.6 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "Next.js: Unauthenticated disclosure of internal Server Function endpoints\n\n## Impact\n\nIn Next.js applications using App Router, Server Actions (`use server`) or `use cache` endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used.\n\nServer Action IDs can be disclosed to unauthenticated users via publicly served client artifacts (for example, static chunks containing action references).\n\nAffected users are applications using App Router + Server Actions.  \n\nBy itself, this disclosure is typically a recon/enumeration primi\n\nPackage: next\nInstalled: 16.2.6\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-97defb3b621efc6b", "name": "CVE-2026-64644: next 16.2.6 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-64644: next 16.2.6 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "Next.js: Denial of Service in the Image Optimization API using SVGs\n\n### Impact\n\nWhen self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in  `/_next/image` endpoints.\n\n- If you are using `config.images.remotePatterns`, only the patterns in that array are impacted.\n- If you are using `config.images.unoptimized: true`, you are NOT impacted.\n- If you are using `config.images.loader: 'custom'`\n\nPackage: next\nInstalled: 16.2.6\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ed134a1e649884cb", "name": "CVE-2026-64646: next 16.2.6 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-64646: next 16.2.6 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "Next.js: Unbounded Server Action payload in Edge runtime\n\n## Impact\n\nRequests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime\n\n## Workarounds\n\nIf you cannot upgrade, ensure your hosting provider limits the request's body size. 5 MiB should be allowed at max by your hosting provider.\n\nPackage: next\nInstalled: 16.2.6\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-83011e5698f40eec", "name": "CVE-2026-64647: next 16.2.6 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-64647: next 16.2.6 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis is only an issue when receiving request bodies with a content type charset other than UTF-8. For example, the UTF-16 byte sequences for `\uc083\uc083` and `\uc104\uc104` in the request body would share the same cache.\n\n##\n\nPackage: next\nInstalled: 16.2.6\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2760c1623f229234", "name": "CVE-2026-64648: next 16.2.6 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-64648: next 16.2.6 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis only applies to `fetch` calls with a request that has a different init than the one passed to `fetch`.\nSafe: `fetch(new Request(init), init)`\nUnsafe: `fetch(new Request(init), aDifferentInit)`\n\n## Work\n\nPackage: next\nInstalled: 16.2.6\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b2b7c5551ca6f9c9", "name": "CVE-2026-8723: qs 6.15.1 \u2014 docs/package-lock.json", "shortDescription": {"text": "CVE-2026-8723: qs 6.15.1 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "### Summary    `qs.stringify` throws `TypeError` when called with `arr ...\n\n### Summary\n\n\n\n`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).\n\n\n\n### Details\n\n\n\nIn the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encoder before joining:\n\n\n\n```js\n\n\n\nobj = utils.maybeMap(obj, encoder);\n\n\n\n```\n\n\n\n`utils.encode` (`lib/uti\n\nPackage: qs\nInstalled: 6.15.1\nFixed in: 6.15.2\nSeverity: MEDIUM\nFix: Upgrade qs to 6.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f6a2bbde51594faa", "name": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 docs/package-lock.json", "shortDescription": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 docs/package-lock.json"}, "fullDescription": {"text": "sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591\n\n### Impact\n\nA number of vulnerabilities, two rated as \"High\" severity using CVSSv4, have been discovered and fixed in the upstream libvips dependency.\n\nThose processing untrusted input with versions of sharp prior to 0.35.0 are affected.\n\n### Patches\n\n#### Using prebuilt binaries provided by sharp?\n\nMost people rely on the prebuilt binaries provided by sharp.\n\nPlease upgrade sharp to the latest version, currently 0.35.3, which provides libvips 8.18.3.\n\n#### Using a globally-installed libvips?\n\nP\n\nPackage: sharp\nInstalled: 0.34.5\nFixed in: 0.35.0\nSeverity: HIGH\nFix: Upgrade sharp to 0.35.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8121075e5e96682b", "name": "CVE-2026-12151: undici 6.26.0 \u2014 viewer/package-lock.json", "shortDescription": {"text": "CVE-2026-12151: undici 6.26.0 \u2014 viewer/package-lock.json"}, "fullDescription": {"text": "undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames\n\nImpact:\nThe undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service.\n\nAffected applications are those using the undici WebSocket client\n\nPackage: undici\nInstalled: 6.26.0\nFixed in: 6.27.0, 7.28.0, 8.5.0\nSeverity: HIGH\nFix: Upgrade undici to 6.27.0, 7.28.0, 8.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-42d78536b39df07a", "name": "CVE-2026-9679: undici 6.26.0 \u2014 viewer/package-lock.json", "shortDescription": {"text": "CVE-2026-9679: undici 6.26.0 \u2014 viewer/package-lock.json"}, "fullDescription": {"text": "undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding\n\nImpact:\nundici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like %0D%0A, %00, %3B, and %3D into their literal byte equivalents. RFC 6265 \u00a75.4 does not specify any decoding and browsers do not decode either.\n\nApplications that parse a Set-Cookie header and then forward the parsed value into a response header (proxies, middleware, SSR frameworks) become vulnerable to HTTP response header injection: an attacker-controlled upstream can inj\n\nPackage: undici\nInstalled: 6.26.0\nFixed in: 6.27.0, 7.28.0, 8.5.0\nSeverity: MEDIUM\nFix: Upgrade undici to 6.27.0, 7.28.0, 8.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cb26403d68aab7f7", "name": "CVE-2026-11525: undici 6.26.0 \u2014 viewer/package-lock.json", "shortDescription": {"text": "CVE-2026-11525: undici 6.26.0 \u2014 viewer/package-lock.json"}, "fullDescription": {"text": "undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header\n\nImpact:\nWhen undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact match specified by RFC 6265. Non-spec values are silently mapped to one of the three standard tokens. For example, SameSite=NoneOfYourBusiness is parsed as None (the most permissive setting), and SameSite=StrictLax is parsed as Lax (a downgrade from Strict).\n\nAffected applications are those that consume Set-Cookie header\n\nPackage: undici\nInstalled: 6.26.0\nFixed in: 6.27.0, 7.28.0, 8.5.0\nSeverity: LOW\nFix: Upgrade undici to 6.27.0, 7.28.0, 8.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2ae28684ad9c413b", "name": "CVE-2026-6733: undici 6.26.0 \u2014 viewer/package-lock.json", "shortDescription": {"text": "CVE-2026-6733: undici 6.26.0 \u2014 viewer/package-lock.json"}, "fullDescription": {"text": "undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery.\n\nImpact:\nUndici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests.\n\nThis requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-ali\n\nPackage: undici\nInstalled: 6.26.0\nFixed in: 6.27.0, 7.28.0, 8.5.0\nSeverity: LOW\nFix: Upgrade undici to 6.27.0, 7.28.0, 8.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1ddec8c719cdd4e9", "name": "Agent authority lacks a verifier contract: skills/gcode/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: skills/gcode/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6e09d06bd056fd8d", "name": "Agent authority lacks a verifier contract: skills/cad-viewer/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: skills/cad-viewer/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8997f5d83ba2bba0", "name": "Agent authority lacks a verifier contract: skills/sdf/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: skills/sdf/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9679f5699b22a59", "name": "Agent authority lacks a verifier contract: skills/srdf/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: skills/srdf/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4476f2e17cd090e3", "name": "Agent authority lacks a verifier contract: plugins/cad/skills/gcode/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: plugins/cad/skills/gcode/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7683eadb7104dd40", "name": "Agent authority lacks a verifier contract: plugins/cad/skills/cad-viewer/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: plugins/cad/skills/cad-viewer/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6851dc8667a26fd7", "name": "Agent authority lacks a verifier contract: plugins/cad/skills/sdf/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: plugins/cad/skills/sdf/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-454aa15226806f31", "name": "Agent authority lacks a verifier contract: plugins/cad/skills/srdf/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: plugins/cad/skills/srdf/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e725d2ab884fbd49", "name": "Multiple root agent instruction files without precedence", "shortDescription": {"text": "Multiple root agent instruction files without precedence"}, "fullDescription": {"text": "The repo has multiple top-level AI-coder instruction files. Without precedence rules, different agents may follow different policies."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-82a5961ce9bab681", "name": "SkillSpector AST4 (behavioral-ast) in skills/bambu-labs/scripts/bambu_lan_print.py", "shortDescription": {"text": "SkillSpector AST4 (behavioral-ast) in skills/bambu-labs/scripts/bambu_lan_print.py"}, "fullDescription": {"text": "result = subprocess.run(command, check=False, capture_output=True, text=True)\n\nsubprocess module calls execute external commands. Without careful input validation, this enables command injection.\n\nSkill: bambu-labs\nRule: AST4  Category: behavioral-ast\nSeverity: MEDIUM  Confidence: 0.60\n\nRemediation: Use subprocess.run() with shell=False and an explicit argument list. Validate all inputs and avoid passing user-controlled data to commands."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.6}}, {"id": "scanner-446dfef84e6e4c28", "name": "SkillSpector AST7 (behavioral-ast) in skills/bambu-labs/scripts/bambu_lan_print.py", "shortDescription": {"text": "SkillSpector AST7 (behavioral-ast) in skills/bambu-labs/scripts/bambu_lan_print.py"}, "fullDescription": {"text": "if hasattr(args, attr) and not getattr(args, attr, \"\") and entry.get(key):\n\nDynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.\n\nSkill: bambu-labs\nRule: AST7  Category: behavioral-ast\nSeverity: LOW  Confidence: 0.50\n\nRemediation: Replace dynamic getattr() with explicit attribute access or a dictionary lookup with an allowlist of permitted attributes."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.5}}, {"id": "scanner-56ea5beb3aa6ef2c", "name": "SkillSpector LP3 (mcp-least-priv) in skills/bambu-labs/SKILL.md", "shortDescription": {"text": "SkillSpector LP3 (mcp-least-priv) in skills/bambu-labs/SKILL.md"}, "fullDescription": {"text": "MCP Least Privilege\n\nWithout declared permissions the skill's intent is opaque and cannot be validated.\n\nSkill: bambu-labs\nRule: LP3  Category: mcp-least-priv\nSeverity: MEDIUM  Confidence: 0.70\n\nRemediation: Add a 'permissions' field to SKILL.md listing the capabilities this skill requires."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-f1367926d0b0fbb0", "name": "SkillSpector EA3 (excessive-agency) in skills/bambu-labs/LICENSE", "shortDescription": {"text": "SkillSpector EA3 (excessive-agency) in skills/bambu-labs/LICENSE"}, "fullDescription": {"text": "NOT LIMITED TO\n\nSkill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.\n\nSkill: bambu-labs\nRule: EA3  Category: excessive-agency\nSeverity: LOW  Confidence: 0.70\n\nRemediation: Limit the skill's scope to its documented purpose. Remove instructions that enable the agent to perform actions outside its stated functionality."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.7}}, {"id": "scanner-0d21a494ae06e5c2", "name": "SkillSpector OH1 (output-handling) in skills/bambu-labs/scripts/bambu_lan_print.py", "shortDescription": {"text": "SkillSpector OH1 (output-handling) in skills/bambu-labs/scripts/bambu_lan_print.py"}, "fullDescription": {"text": "subprocess.run(command, check=False, capture_output\n\nModel output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.\n\nSkill: bambu-labs\nRule: OH1  Category: output-handling\nSeverity: HIGH  Confidence: 0.95\n\nRemediation: Validate and sanitize all model output before using it in downstream contexts. Use parameterized queries for SQL, shell quoting for commands, and HTML encoding for web output."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.95}}, {"id": "scanner-0430798f1d4ae1f1", "name": "SkillSpector P1 (prompt-injection) in skills/bambu-labs/SKILL.md", "shortDescription": {"text": "SkillSpector P1 (prompt-injection) in skills/bambu-labs/SKILL.md"}, "fullDescription": {"text": "Enable Developer Mode\n\nThis pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.\n\nSkill: bambu-labs\nRule: P1  Category: prompt-injection\nSeverity: HIGH  Confidence: 0.70\n\nRemediation: Remove or rewrite any text that instructs the agent to ignore prompts, override safety rules, or trust unverified content. Ensure skill content cannot be injected to alter agent behavior."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.7}}, {"id": "scanner-b976fbebcf8b0043", "name": "SkillSpector P1 (prompt-injection) in skills/bambu-labs/references/new-printer-onboarding.md", "shortDescription": {"text": "SkillSpector P1 (prompt-injection) in skills/bambu-labs/references/new-printer-onboarding.md"}, "fullDescription": {"text": "Enable Developer Mode\n\nThis pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.\n\nSkill: bambu-labs\nRule: P1  Category: prompt-injection\nSeverity: HIGH  Confidence: 0.70\n\nRemediation: Remove or rewrite any text that instructs the agent to ignore prompts, override safety rules, or trust unverified content. Ensure skill content cannot be injected to alter agent behavior."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.7}}, {"id": "scanner-f2d6c610bf9f12df", "name": "SkillSpector AST7 (behavioral-ast) in skills/cad/scripts/packages/cadpy/src/cadpy/assembly.py", "shortDescription": {"text": "SkillSpector AST7 (behavioral-ast) in skills/cad/scripts/packages/cadpy/src/cadpy/assembly.py"}, "fullDescription": {"text": "joint_cls = getattr(build123d, joint_type)\n\nDynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.\n\nSkill: cad\nRule: AST7  Category: behavioral-ast\nSeverity: LOW  Confidence: 0.50\n\nRemediation: Replace dynamic getattr() with explicit attribute access or a dictionary lookup with an allowlist of permitted attributes."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.5}}, {"id": "scanner-1e518561bdc488bb", "name": "SkillSpector AST7 (behavioral-ast) in skills/cad/scripts/packages/cadpy/src/cadpy/generation.py", "shortDescription": {"text": "SkillSpector AST7 (behavioral-ast) in skills/cad/scripts/packages/cadpy/src/cadpy/generation.py"}, "fullDescription": {"text": "generator = getattr(module, generator_name, None)\n\nDynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.\n\nSkill: cad\nRule: AST7  Category: behavioral-ast\nSeverity: LOW  Confidence: 0.50\n\nRemediation: Replace dynamic getattr() with explicit attribute access or a dictionary lookup with an allowlist of permitted attributes."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.5}}, {"id": "scanner-76f20f656e1511f7", "name": "SkillSpector AST7 (behavioral-ast) in skills/cad/scripts/packages/cadpy/src/cadpy/step_scene.py", "shortDescription": {"text": "SkillSpector AST7 (behavioral-ast) in skills/cad/scripts/packages/cadpy/src/cadpy/step_scene.py"}, "fullDescription": {"text": "mode = getattr(reader, mode_name, None)\n\nDynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.\n\nSkill: cad\nRule: AST7  Category: behavioral-ast\nSeverity: LOW  Confidence: 0.50\n\nRemediation: Replace dynamic getattr() with explicit attribute access or a dictionary lookup with an allowlist of permitted attributes."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.5}}, {"id": "scanner-5b002377515a2528", "name": "SkillSpector LP3 (mcp-least-priv) in skills/cad/SKILL.md", "shortDescription": {"text": "SkillSpector LP3 (mcp-least-priv) in skills/cad/SKILL.md"}, "fullDescription": {"text": "MCP Least Privilege\n\nWithout declared permissions the skill's intent is opaque and cannot be validated.\n\nSkill: cad\nRule: LP3  Category: mcp-least-priv\nSeverity: MEDIUM  Confidence: 0.70\n\nRemediation: Add a 'permissions' field to SKILL.md listing the capabilities this skill requires."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-ac2176b96122d24e", "name": "SkillSpector EA3 (excessive-agency) in skills/cad/LICENSE", "shortDescription": {"text": "SkillSpector EA3 (excessive-agency) in skills/cad/LICENSE"}, "fullDescription": {"text": "NOT LIMITED TO\n\nSkill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.\n\nSkill: cad\nRule: EA3  Category: excessive-agency\nSeverity: LOW  Confidence: 0.70\n\nRemediation: Limit the skill's scope to its documented purpose. Remove instructions that enable the agent to perform actions outside its stated functionality."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.7}}, {"id": "scanner-3368b0beff5c900d", "name": "SkillSpector EA2 (excessive-agency) in skills/cad/references/cad-brief.md", "shortDescription": {"text": "SkillSpector EA2 (excessive-agency) in skills/cad/references/cad-brief.md"}, "fullDescription": {"text": "do not ask the user\n\nSkill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.\n\nSkill: cad\nRule: EA2  Category: excessive-agency\nSeverity: MEDIUM  Confidence: 0.80\n\nRemediation: Add human-in-the-loop confirmation for destructive, irreversible, or high-impact operations. Never auto-execute commands that modify files, send data, or alter system state."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-6471fc7fa114d165", "name": "SkillSpector EA4 (excessive-agency) in skills/cad/scripts/packages/cadpy/src/cadpy/generation_status.py", "shortDescription": {"text": "SkillSpector EA4 (excessive-agency) in skills/cad/scripts/packages/cadpy/src/cadpy/generation_status.py"}, "fullDescription": {"text": "timeout=0\n\nSkill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.\n\nSkill: cad\nRule: EA4  Category: excessive-agency\nSeverity: MEDIUM  Confidence: 0.75\n\nRemediation: Set explicit rate limits, timeouts, and resource quotas for API calls, file operations, and compute. Implement circuit breakers for runaway loops."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.75}}, {"id": "scanner-3496198c4972df9b", "name": "SkillSpector PE3 (priv-esc) in skills/cad/scripts/packages/cadpy/src/cadpy/catalog.py", "shortDescription": {"text": "SkillSpector PE3 (priv-esc) in skills/cad/scripts/packages/cadpy/src/cadpy/catalog.py"}, "fullDescription": {"text": ".env\"\n\nCode accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.\n\nSkill: cad\nRule: PE3  Category: priv-esc\nSeverity: HIGH  Confidence: 0.60\n\nRemediation: Remove references to credential paths. Use environment variables or secrets managers. For docs, use placeholder paths (e.g., /path/to/config). Never load .env or token files in production code paths."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.6}}, {"id": "scanner-8f8a929f4c09cc87", "name": "SkillSpector SC1 (supply-chain) in skills/cad/requirements.txt", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in skills/cad/requirements.txt"}, "fullDescription": {"text": "playwright\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: cad\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.60\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.6}}, {"id": "scanner-2fafb6ded4a7031e", "name": "SkillSpector SC4 (supply-chain) in skills/cad/scripts/packages/cadpy/pyproject.toml", "shortDescription": {"text": "SkillSpector SC4 (supply-chain) in skills/cad/scripts/packages/cadpy/pyproject.toml"}, "fullDescription": {"text": "requires-python\n\nDependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.\n\nSkill: cad\nRule: SC4  Category: supply-chain\nSeverity: HIGH  Confidence: 0.80\n\nRemediation: Update the dependency to a patched version that addresses the known CVE. Check OSV (osv.dev) or NVD for details on the vulnerability."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.8}}, {"id": "scanner-e637c415447867e4", "name": "Run SkillSpector's LLM-backed analysis in your own pipeline", "shortDescription": {"text": "Run SkillSpector's LLM-backed analysis in your own pipeline"}, "fullDescription": {"text": "Repobility ran SkillSpector's static rules server-side. The deeper LLM-backed analyzers \u2014 tool-poisoning (TP*), semantic security discovery (SSD*), developer-intent mismatch (SDI*) \u2014 are meant to run on YOUR machine with YOUR model; repobility never sends your code to an LLM. Recipe:\n\n# 1. Install SkillSpector in your own isolated env\npipx install \"skillspector @ git+https://github.com/NVIDIA/SkillSpector.git\"\n\n# 2. Point it at YOUR LLM pipeline (pick one) - your code stays on your machine\nexport SKILLSPECTOR_PROVIDER=anthropic && export ANTHROPIC_API_KEY=sk-ant-...\n# export SKILLSPECTOR_PROVIDER=openai   && export OPENAI_API_KEY=sk-...\n# export SKILLSPECTOR_PROVIDER=openai OPENAI_API_KEY=ollama OPENAI_BASE_URL=http://localhost:11434/v1 SKILLSPECTOR_MODEL=llama3.1:8b\n# export SKILLSPECTOR_PROVIDER=nv_build && export NVIDIA_INFERENCE_KEY=nvapi-...\n\n# 3. Run the LLM-backed scan per skill (omit --no-llm to enable the LLM analyzers)\nskillspector scan skills/bambu-labs --format sarif --outp"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cf89f0aa75d843d8", "name": "Insecure pattern 'dangerous_innerhtml' in docs/src/app/layout.tsx:112", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in docs/src/app/layout.tsx:112"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-3ea6f1676018915f", "name": "Insecure pattern 'node_child_process' in viewer/scripts/start-agent-viewer.mjs:2", "shortDescription": {"text": "Insecure pattern 'node_child_process' in viewer/scripts/start-agent-viewer.mjs:2"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-152826cd4c1d9b79", "name": "Insecure pattern 'node_child_process' in skills/implicit-cad/scripts/export.mjs:2", "shortDescription": {"text": "Insecure pattern 'node_child_process' in skills/implicit-cad/scripts/export.mjs:2"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-c4f3debab76441f8", "name": "Insecure pattern 'node_child_process' in plugins/cad/skills/implicit-cad/scripts/export.mjs:2", "shortDescription": {"text": "Insecure pattern 'node_child_process' in plugins/cad/skills/implicit-cad/scripts/export.mjs:2"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7efbda965f283c17", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-902782b3d73e83c7", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-46c644c6227e4d4a", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1838a141491ce38c", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-de39ac9e5cbf2f3d", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-25e2699bb316c8bb", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a6508654f974a260", "name": "Very large file: tests/python/skills/cad/cadpy/test_generation.py (2691 lines)", "shortDescription": {"text": "Very large file: tests/python/skills/cad/cadpy/test_generation.py (2691 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4c64e55796dc96cd", "name": "Very large file: viewer/packages/implicitjs/src/common/themeSettings.js (1717 lines)", "shortDescription": {"text": "Very large file: viewer/packages/implicitjs/src/common/themeSettings.js (1717 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-170a2ecf138ea84c", "name": "Very large file: viewer/packages/implicitjs/src/lib/implicitCad/render.js (1966 lines)", "shortDescription": {"text": "Very large file: viewer/packages/implicitjs/src/lib/implicitCad/render.js (1966 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa1481e55e3fad0b", "name": "Very large file: viewer/packages/cadpy/src/cadpy/generation.py (2351 lines)", "shortDescription": {"text": "Very large file: viewer/packages/cadpy/src/cadpy/generation.py (2351 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-124ba8bf3c8dd41d", "name": "Very large file: viewer/packages/cadpy/src/cadpy/assembly_composition.py (1269 lines)", "shortDescription": {"text": "Very large file: viewer/packages/cadpy/src/cadpy/assembly_composition.py (1269 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e2aca858fc2ac90d", "name": "Very large file: viewer/packages/cadpy/src/cadpy/step_scene.py (2626 lines)", "shortDescription": {"text": "Very large file: viewer/packages/cadpy/src/cadpy/step_scene.py (2626 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8768c4820189b7cc", "name": "Very large file: viewer/packages/cadjs/src/common/cadScene.js (2203 lines)", "shortDescription": {"text": "Very large file: viewer/packages/cadjs/src/common/cadScene.js (2203 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-15b90e80e537fda3", "name": "Very large file: viewer/packages/cadjs/src/common/themeSettings.js (1688 lines)", "shortDescription": {"text": "Very large file: viewer/packages/cadjs/src/common/themeSettings.js (1688 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-435be0071336741c", "name": "Very large file: viewer/src/client/components/CadViewer.js (4793 lines)", "shortDescription": {"text": "Very large file: viewer/src/client/components/CadViewer.js (4793 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fb1885d70fe51d47", "name": "Very large file: viewer/src/client/components/CadWorkspace.js (9109 lines)", "shortDescription": {"text": "Very large file: viewer/src/client/components/CadWorkspace.js (9109 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6e75f95f099f9591", "name": "Very large file: viewer/src/client/components/viewer/hooks/useViewerPicking.js (1422 lines)", "shortDescription": {"text": "Very large file: viewer/src/client/components/viewer/hooks/useViewerPicking.js (1422 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ab7a16bbaed7d1d4", "name": "Very large file: viewer/src/client/components/workbench/StepFileSheet.js (1702 lines)", "shortDescription": {"text": "Very large file: viewer/src/client/components/workbench/StepFileSheet.js (1702 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f6343683cdeac37e", "name": "Very large file: viewer/src/client/components/workbench/ThemeSettingsPopover.js (2438 lines)", "shortDescription": {"text": "Very large file: viewer/src/client/components/workbench/ThemeSettingsPopover.js (2438 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d6a2abbf4e908024", "name": "Very large file: viewer/src/client/workbench/sidebar.test.js (2339 lines)", "shortDescription": {"text": "Very large file: viewer/src/client/workbench/sidebar.test.js (2339 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-12d4bb3111539653", "name": "Very large file: packages/implicitjs/src/common/themeSettings.js (1717 lines)", "shortDescription": {"text": "Very large file: packages/implicitjs/src/common/themeSettings.js (1717 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8df87a654993863a", "name": "Very large file: packages/implicitjs/src/lib/implicitCad/render.js (1966 lines)", "shortDescription": {"text": "Very large file: packages/implicitjs/src/lib/implicitCad/render.js (1966 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8e5708095bd6e43b", "name": "Very large file: packages/cadpy/src/cadpy/generation.py (2351 lines)", "shortDescription": {"text": "Very large file: packages/cadpy/src/cadpy/generation.py (2351 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-de12f40332065f3c", "name": "Very large file: packages/cadpy/src/cadpy/assembly_composition.py (1269 lines)", "shortDescription": {"text": "Very large file: packages/cadpy/src/cadpy/assembly_composition.py (1269 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ceb7842db8055be4", "name": "Very large file: packages/cadpy/src/cadpy/step_scene.py (2626 lines)", "shortDescription": {"text": "Very large file: packages/cadpy/src/cadpy/step_scene.py (2626 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5271ba38c42aea2c", "name": "Very large file: packages/cadjs/src/common/cadScene.js (2203 lines)", "shortDescription": {"text": "Very large file: packages/cadjs/src/common/cadScene.js (2203 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4a3a06b0da47872e", "name": "Very large file: packages/cadjs/src/common/themeSettings.js (1688 lines)", "shortDescription": {"text": "Very large file: packages/cadjs/src/common/themeSettings.js (1688 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3586ee1c277f02f7", "name": "Very large file: skills/bambu-labs/scripts/bambu_lan_print.py (1771 lines)", "shortDescription": {"text": "Very large file: skills/bambu-labs/scripts/bambu_lan_print.py (1771 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-289cf415e665db42", "name": "Very large file: skills/cad-viewer/scripts/viewer/packages/implicitjs/src/common/themeSettings.js (1717 lines)", "shortDescription": {"text": "Very large file: skills/cad-viewer/scripts/viewer/packages/implicitjs/src/common/themeSettings.js (1717 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-917f44a7e0020d51", "name": "Very large file: skills/cad-viewer/scripts/viewer/packages/implicitjs/src/lib/implicitCad/render.js (1966 lines)", "shortDescription": {"text": "Very large file: skills/cad-viewer/scripts/viewer/packages/implicitjs/src/lib/implicitCad/render.js (1966 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b7ae46ea17dadcfa", "name": "Very large file: skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/generation.py (2351 lines)", "shortDescription": {"text": "Very large file: skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/generation.py (2351 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4c0236823a1fa6aa", "name": "Very large file: skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/assembly_composition.py (1269 lines)", "shortDescription": {"text": "Very large file: skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/assembly_composition.py (1269 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0e74cafcc8ff6cde", "name": "Very large file: skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/step_scene.py (2626 lines)", "shortDescription": {"text": "Very large file: skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/step_scene.py (2626 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7d602eaebfd371eb", "name": "Very large file: skills/cad-viewer/scripts/viewer/packages/cadjs/src/common/cadScene.js (2203 lines)", "shortDescription": {"text": "Very large file: skills/cad-viewer/scripts/viewer/packages/cadjs/src/common/cadScene.js (2203 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e2667b787a2a6e44", "name": "Very large file: skills/cad-viewer/scripts/viewer/packages/cadjs/src/common/themeSettings.js (1688 lines)", "shortDescription": {"text": "Very large file: skills/cad-viewer/scripts/viewer/packages/cadjs/src/common/themeSettings.js (1688 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-55ce51fbf1f60847", "name": "Very large file: skills/dxf/scripts/packages/cadpy/src/cadpy/generation.py (2351 lines)", "shortDescription": {"text": "Very large file: skills/dxf/scripts/packages/cadpy/src/cadpy/generation.py (2351 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-466aff75171e01d6", "name": "Very large file: skills/dxf/scripts/packages/cadpy/src/cadpy/assembly_composition.py (1269 lines)", "shortDescription": {"text": "Very large file: skills/dxf/scripts/packages/cadpy/src/cadpy/assembly_composition.py (1269 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8f01973a96acab13", "name": "Very large file: skills/dxf/scripts/packages/cadpy/src/cadpy/step_scene.py (2626 lines)", "shortDescription": {"text": "Very large file: skills/dxf/scripts/packages/cadpy/src/cadpy/step_scene.py (2626 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d3c2b00b6e41866b", "name": "Very large file: skills/cad/scripts/packages/cadpy/src/cadpy/generation.py (2351 lines)", "shortDescription": {"text": "Very large file: skills/cad/scripts/packages/cadpy/src/cadpy/generation.py (2351 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fb46b65256203ab8", "name": "Very large file: skills/cad/scripts/packages/cadpy/src/cadpy/assembly_composition.py (1269 lines)", "shortDescription": {"text": "Very large file: skills/cad/scripts/packages/cadpy/src/cadpy/assembly_composition.py (1269 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ee5700d2aec5094d", "name": "Very large file: skills/cad/scripts/packages/cadpy/src/cadpy/step_scene.py (2626 lines)", "shortDescription": {"text": "Very large file: skills/cad/scripts/packages/cadpy/src/cadpy/step_scene.py (2626 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a70c095fecf45001", "name": "Very large file: skills/cad/scripts/snapshot/runtime/snapshot-render.js (4168 lines)", "shortDescription": {"text": "Very large file: skills/cad/scripts/snapshot/runtime/snapshot-render.js (4168 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a0f2e847920a2567", "name": "Very large file: skills/implicit-cad/scripts/packages/implicitjs/src/common/themeSettings.js (1717 lines)", "shortDescription": {"text": "Very large file: skills/implicit-cad/scripts/packages/implicitjs/src/common/themeSettings.js (1717 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4aa39507b6f379e5", "name": "Very large file: skills/implicit-cad/scripts/packages/implicitjs/src/lib/implicitCad/render.js (1966 lines)", "shortDescription": {"text": "Very large file: skills/implicit-cad/scripts/packages/implicitjs/src/lib/implicitCad/render.js (1966 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d8a6c7663679573f", "name": "Very large file: plugins/cad/skills/bambu-labs/scripts/bambu_lan_print.py (1771 lines)", "shortDescription": {"text": "Very large file: plugins/cad/skills/bambu-labs/scripts/bambu_lan_print.py (1771 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-95f0070981bf3195", "name": "Very large file: plugins/cad/skills/cad-viewer/scripts/viewer/packages/implicitjs/src/common/themeSettings.js (1717 line", "shortDescription": {"text": "Very large file: plugins/cad/skills/cad-viewer/scripts/viewer/packages/implicitjs/src/common/themeSettings.js (1717 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3e389137eaa4783d", "name": "Very large file: plugins/cad/skills/cad-viewer/scripts/viewer/packages/implicitjs/src/lib/implicitCad/render.js (1966 li", "shortDescription": {"text": "Very large file: plugins/cad/skills/cad-viewer/scripts/viewer/packages/implicitjs/src/lib/implicitCad/render.js (1966 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-780f3f6f2bb8a3cb", "name": "Very large file: plugins/cad/skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/generation.py (2351 lines)", "shortDescription": {"text": "Very large file: plugins/cad/skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/generation.py (2351 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bdd6c2402ad60472", "name": "Very large file: plugins/cad/skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/assembly_composition.py (1269 lin", "shortDescription": {"text": "Very large file: plugins/cad/skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/assembly_composition.py (1269 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7972c48ce431fef2", "name": "Very large file: plugins/cad/skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/step_scene.py (2626 lines)", "shortDescription": {"text": "Very large file: plugins/cad/skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/step_scene.py (2626 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-685a1f827540aae8", "name": "Very large file: plugins/cad/skills/cad-viewer/scripts/viewer/packages/cadjs/src/common/cadScene.js (2203 lines)", "shortDescription": {"text": "Very large file: plugins/cad/skills/cad-viewer/scripts/viewer/packages/cadjs/src/common/cadScene.js (2203 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-21235ac67d58e7a5", "name": "Very large file: plugins/cad/skills/cad-viewer/scripts/viewer/packages/cadjs/src/common/themeSettings.js (1688 lines)", "shortDescription": {"text": "Very large file: plugins/cad/skills/cad-viewer/scripts/viewer/packages/cadjs/src/common/themeSettings.js (1688 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-02d4a7e0ee2b6372", "name": "Very large file: plugins/cad/skills/dxf/scripts/packages/cadpy/src/cadpy/generation.py (2351 lines)", "shortDescription": {"text": "Very large file: plugins/cad/skills/dxf/scripts/packages/cadpy/src/cadpy/generation.py (2351 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5768b4eb4039b050", "name": "Very large file: plugins/cad/skills/dxf/scripts/packages/cadpy/src/cadpy/assembly_composition.py (1269 lines)", "shortDescription": {"text": "Very large file: plugins/cad/skills/dxf/scripts/packages/cadpy/src/cadpy/assembly_composition.py (1269 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-60a4917bbefdc336", "name": "Very large file: plugins/cad/skills/dxf/scripts/packages/cadpy/src/cadpy/step_scene.py (2626 lines)", "shortDescription": {"text": "Very large file: plugins/cad/skills/dxf/scripts/packages/cadpy/src/cadpy/step_scene.py (2626 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-da96ce28c8b3ef1e", "name": "Very large file: plugins/cad/skills/cad/scripts/packages/cadpy/src/cadpy/generation.py (2351 lines)", "shortDescription": {"text": "Very large file: plugins/cad/skills/cad/scripts/packages/cadpy/src/cadpy/generation.py (2351 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c6fb838c41c4aa6e", "name": "Very large file: plugins/cad/skills/cad/scripts/packages/cadpy/src/cadpy/assembly_composition.py (1269 lines)", "shortDescription": {"text": "Very large file: plugins/cad/skills/cad/scripts/packages/cadpy/src/cadpy/assembly_composition.py (1269 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1db9bf5946c60148", "name": "Very large file: plugins/cad/skills/cad/scripts/packages/cadpy/src/cadpy/step_scene.py (2626 lines)", "shortDescription": {"text": "Very large file: plugins/cad/skills/cad/scripts/packages/cadpy/src/cadpy/step_scene.py (2626 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-18d59ee0655479fc", "name": "Very large file: plugins/cad/skills/cad/scripts/snapshot/runtime/snapshot-render.js (4168 lines)", "shortDescription": {"text": "Very large file: plugins/cad/skills/cad/scripts/snapshot/runtime/snapshot-render.js (4168 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5652350ece16f478", "name": "Very large file: plugins/cad/skills/implicit-cad/scripts/packages/implicitjs/src/common/themeSettings.js (1717 lines)", "shortDescription": {"text": "Very large file: plugins/cad/skills/implicit-cad/scripts/packages/implicitjs/src/common/themeSettings.js (1717 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-19624b341bb374ae", "name": "Very large file: plugins/cad/skills/implicit-cad/scripts/packages/implicitjs/src/lib/implicitCad/render.js (1966 lines)", "shortDescription": {"text": "Very large file: plugins/cad/skills/implicit-cad/scripts/packages/implicitjs/src/lib/implicitCad/render.js (1966 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea3b5e389d8c9c0f", "name": "Low test-to-source ratio", "shortDescription": {"text": "Low test-to-source ratio"}, "fullDescription": {"text": "190 tests / 1017 src (ratio 0.19)."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 171 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-06a39bd4b787b4e0", "name": "Legacy-named symbol `final_joint_values_legacy` in viewer/moveit2_server/moveit2_server/moveit_py.py:571", "shortDescription": {"text": "Legacy-named symbol `final_joint_values_legacy` in viewer/moveit2_server/moveit2_server/moveit_py.py:571"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ce89f17357f8ebc2", "name": "Fire-and-forget `fetch()` has no rejection handler \u2014 viewer/src/client/components/CadWorkspace.js:1746", "shortDescription": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 viewer/src/client/components/CadWorkspace.js:1746"}, "fullDescription": {"text": "This fetch result is neither awaited, returned, assigned, nor followed by `.catch(...)`. A network failure can therefore become an unhandled promise rejection. Await/return the promise or attach an explicit rejection handler."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-c9221aa13cee5e9f", "name": "Fire-and-forget `fetch()` has no rejection handler \u2014 viewer/src/client/components/workbench/CadWorkspaceTopBar.js:834", "shortDescription": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 viewer/src/client/components/workbench/CadWorkspaceTopBar.js:834"}, "fullDescription": {"text": "This fetch result is neither awaited, returned, assigned, nor followed by `.catch(...)`. A network failure can therefore become an unhandled promise rejection. Await/return the promise or attach an explicit rejection handler."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-08313ad176f50327", "name": "Network/subprocess call without timeout or try/except \u2014 skills/bambu-labs/scripts/bambu_lan_print.py:580", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 skills/bambu-labs/scripts/bambu_lan_print.py:580"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-7904709fc9ad867d", "name": "Network/subprocess call without timeout or try/except \u2014 skills/gcode/scripts/gcode_tool.py:528", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 skills/gcode/scripts/gcode_tool.py:528"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-12b9fe356b6f0553", "name": "Legacy-named symbol `final_joint_values_legacy` in skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/moveit", "shortDescription": {"text": "Legacy-named symbol `final_joint_values_legacy` in skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/moveit_py.py:571"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d20f4c07e3088c4", "name": "Network/subprocess call without timeout or try/except \u2014 plugins/cad/skills/bambu-labs/scripts/bambu_lan_print.py:580", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 plugins/cad/skills/bambu-labs/scripts/bambu_lan_print.py:580"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-1c0c4372b6aaecfe", "name": "Network/subprocess call without timeout or try/except \u2014 plugins/cad/skills/gcode/scripts/gcode_tool.py:528", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 plugins/cad/skills/gcode/scripts/gcode_tool.py:528"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-d49b34c6024a9039", "name": "Legacy-named symbol `final_joint_values_legacy` in plugins/cad/skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_s", "shortDescription": {"text": "Legacy-named symbol `final_joint_values_legacy` in plugins/cad/skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/moveit_py.py:571"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-51dbf90b6ad9e4e9", "name": "28 env vars used in code but missing from .env.example", "shortDescription": {"text": "28 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `BAMBOX_BIN`, `BAMBU_STUDIO_BIN`, `BLOB_READ_WRITE_TOKEN`, `BLOB_STORE_ID`, `CAD_PYTHON`, `CAD_PYTHONPATH`, `DEV`, `DISCORD_URL` + 20 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be46ea126aa5d8dc", "name": "Near-duplicate function bodies in 3 places", "shortDescription": {"text": "Near-duplicate function bodies in 3 places"}, "fullDescription": {"text": "Functions with the same substantial AST body hash:\nviewer/moveit2_server/moveit2_server/protocol.py:49:normalize_quat_xyzw, skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/protocol.py:49:normalize_quat_xyzw, plugins/cad/skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/protocol.py:49:normalize_quat_xyzw\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-02525d39071dd2c7", "name": "Near-duplicate function bodies in 5 places", "shortDescription": {"text": "Near-duplicate function bodies in 5 places"}, "fullDescription": {"text": "Functions with the same substantial AST body hash:\nviewer/moveit2_server/moveit2_server/srdf_source.py:73:read_srdf_source, skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/srdf_source.py:73:read_srdf_source, skills/srdf/scripts/srdf/source.py:80:read_srdf_source, plugins/cad/skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/srdf_source.py:73:read_srdf_source\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-76a2f6818267a9a8", "name": "Near-duplicate function bodies in 8 places", "shortDescription": {"text": "Near-duplicate function bodies in 8 places"}, "fullDescription": {"text": "Functions with the same substantial AST body hash:\nviewer/packages/cadpy/src/cadpy/assembly_flatten.py:52:filesystem_entry, packages/cadpy/src/cadpy/assembly_flatten.py:52:filesystem_entry, skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/assembly_flatten.py:52:filesystem_entry, skills/dxf/scripts/packages/cadpy/src/cadpy/assembly_flatten.py:52:filesystem_entry\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fcd88a91331f7152", "name": "Vulnerable dependency next 16.2.6: GHSA-4633-3j49-mh5q", "shortDescription": {"text": "Vulnerable dependency next 16.2.6: GHSA-4633-3j49-mh5q"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.6` (resolved in `docs/package-lock.json`) is affected by GHSA-4633-3j49-mh5q (aka CVE-2026-64647).\n\nNext.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\nAliases: CVE-2026-64647\nAdvisory: https://osv.dev/vulnerability/GHSA-4633-3j49-mh5q\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-80eab56388ed30be", "name": "Vulnerable dependency next 16.2.6: GHSA-4c39-4ccg-62r3", "shortDescription": {"text": "Vulnerable dependency next 16.2.6: GHSA-4c39-4ccg-62r3"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.6` (resolved in `docs/package-lock.json`) is affected by GHSA-4c39-4ccg-62r3 (aka CVE-2026-64646).\n\nNext.js: Unbounded Server Action payload in Edge runtime\n\nAliases: CVE-2026-64646\nAdvisory: https://osv.dev/vulnerability/GHSA-4c39-4ccg-62r3\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e1e683399882b8ec", "name": "Vulnerable dependency next 16.2.6: GHSA-68g3-v927-f742", "shortDescription": {"text": "Vulnerable dependency next 16.2.6: GHSA-68g3-v927-f742"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.6` (resolved in `docs/package-lock.json`) is affected by GHSA-68g3-v927-f742 (aka CVE-2026-64648).\n\nNext.js: Cache confusion of response bodies for requests with bodies\n\nAliases: CVE-2026-64648\nAdvisory: https://osv.dev/vulnerability/GHSA-68g3-v927-f742\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6ab6bca6566112d2", "name": "Vulnerable dependency next 16.2.6: GHSA-6gpp-xcg3-4w24", "shortDescription": {"text": "Vulnerable dependency next 16.2.6: GHSA-6gpp-xcg3-4w24"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.6` (resolved in `docs/package-lock.json`) is affected by GHSA-6gpp-xcg3-4w24 (aka CVE-2026-64642).\n\nNext.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale\n\nAliases: CVE-2026-64642\nAdvisory: https://osv.dev/vulnerability/GHSA-6gpp-xcg3-4w24\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-94f3890042c63abc", "name": "Vulnerable dependency next 16.2.6: GHSA-89xv-2m56-2m9x", "shortDescription": {"text": "Vulnerable dependency next 16.2.6: GHSA-89xv-2m56-2m9x"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.6` (resolved in `docs/package-lock.json`) is affected by GHSA-89xv-2m56-2m9x (aka CVE-2026-64649).\n\nNext.js: Server-Side Request Forgery in Server Actions on custom servers\n\nAliases: CVE-2026-64649\nAdvisory: https://osv.dev/vulnerability/GHSA-89xv-2m56-2m9x\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6b662c7a3d2e19cb", "name": "Vulnerable dependency next 16.2.6: GHSA-955p-x3mx-jcvp", "shortDescription": {"text": "Vulnerable dependency next 16.2.6: GHSA-955p-x3mx-jcvp"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.6` (resolved in `docs/package-lock.json`) is affected by GHSA-955p-x3mx-jcvp (aka CVE-2026-64643).\n\nNext.js: Unauthenticated disclosure of internal Server Function endpoints\n\nAliases: CVE-2026-64643\nAdvisory: https://osv.dev/vulnerability/GHSA-955p-x3mx-jcvp\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e62d23b157c9a09d", "name": "Vulnerable dependency next 16.2.6: GHSA-m99w-x7hq-7vfj", "shortDescription": {"text": "Vulnerable dependency next 16.2.6: GHSA-m99w-x7hq-7vfj"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.6` (resolved in `docs/package-lock.json`) is affected by GHSA-m99w-x7hq-7vfj.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-m99w-x7hq-7vfj\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9d1d446ac129f3ea", "name": "Vulnerable dependency next 16.2.6: GHSA-p9j2-gv94-2wf4", "shortDescription": {"text": "Vulnerable dependency next 16.2.6: GHSA-p9j2-gv94-2wf4"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.6` (resolved in `docs/package-lock.json`) is affected by GHSA-p9j2-gv94-2wf4.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-p9j2-gv94-2wf4\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a1284fe66dbb33d2", "name": "Vulnerable dependency next 16.2.6: GHSA-q8wf-6r8g-63ch", "shortDescription": {"text": "Vulnerable dependency next 16.2.6: GHSA-q8wf-6r8g-63ch"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.6` (resolved in `docs/package-lock.json`) is affected by GHSA-q8wf-6r8g-63ch.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q8wf-6r8g-63ch\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea7d421f6b7b4f8e", "name": "Vulnerable dependency vite 7.3.2: GHSA-fx2h-pf6j-xcff", "shortDescription": {"text": "Vulnerable dependency vite 7.3.2: GHSA-fx2h-pf6j-xcff"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `7.3.2` (resolved in `viewer/package-lock.json`) is affected by GHSA-fx2h-pf6j-xcff (aka CVE-2026-53571).\n\nvite: `server.fs.deny` bypass on Windows alternate paths\n\nAliases: CVE-2026-53571\nAdvisory: https://osv.dev/vulnerability/GHSA-fx2h-pf6j-xcff\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-e5eafff954911c18", "name": "Vulnerable dependency vite 7.3.2: GHSA-v6wh-96g9-6wx3", "shortDescription": {"text": "Vulnerable dependency vite 7.3.2: GHSA-v6wh-96g9-6wx3"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `7.3.2` (resolved in `viewer/package-lock.json`) is affected by GHSA-v6wh-96g9-6wx3.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-v6wh-96g9-6wx3\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-a6c08e5a91b069c1", "name": "Vulnerable dependency @babel/core 7.29.0: GHSA-4x5r-pxfx-6jf8", "shortDescription": {"text": "Vulnerable dependency @babel/core 7.29.0: GHSA-4x5r-pxfx-6jf8"}, "fullDescription": {"text": "OSV.dev reports `@babel/core` at version `7.29.0` (resolved in `docs/package-lock.json`) is affected by GHSA-4x5r-pxfx-6jf8 (aka CVE-2026-49356).\nNote: `@babel/core` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\n@babel/core: Arbitrary File Read via sourceMappingURL Comment\n\nAliases: CVE-2026-49356\nAdvisory: https://osv.dev/vulnerability/GHSA-4x5r-pxfx-6jf8\nFix: upgrade `@babel/core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-6d8a804adf77ba47", "name": "Vulnerable dependency @hono/node-server 1.19.14: GHSA-frvp-7c67-39w9", "shortDescription": {"text": "Vulnerable dependency @hono/node-server 1.19.14: GHSA-frvp-7c67-39w9"}, "fullDescription": {"text": "OSV.dev reports `@hono/node-server` at version `1.19.14` (resolved in `docs/package-lock.json`) is affected by GHSA-frvp-7c67-39w9.\nNote: `@hono/node-server` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNode.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nAdvisory: https://osv.dev/vulnerability/GHSA-frvp-7c67-39w9\nFix: upgrade `@hono/node-server` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-b4c6a6664d1c8fd9", "name": "Vulnerable dependency brace-expansion 5.0.6: GHSA-3jxr-9vmj-r5cp", "shortDescription": {"text": "Vulnerable dependency brace-expansion 5.0.6: GHSA-3jxr-9vmj-r5cp"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `5.0.6` (resolved in `docs/package-lock.json`) is affected by GHSA-3jxr-9vmj-r5cp (aka CVE-2026-13149).\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbrace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups\n\nAliases: CVE-2026-13149\nAdvisory: https://osv.dev/vulnerability/GHSA-3jxr-9vmj-r5cp\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-9c11d20bbac49914", "name": "Vulnerable dependency body-parser 2.2.2: GHSA-v422-hmwv-36x6", "shortDescription": {"text": "Vulnerable dependency body-parser 2.2.2: GHSA-v422-hmwv-36x6"}, "fullDescription": {"text": "OSV.dev reports `body-parser` at version `2.2.2` (resolved in `docs/package-lock.json`) is affected by GHSA-v422-hmwv-36x6.\nNote: `body-parser` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-v422-hmwv-36x6\nFix: upgrade `body-parser` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-4db38ba4a1720c6f", "name": "Vulnerable dependency brace-expansion 1.1.14: GHSA-3jxr-9vmj-r5cp", "shortDescription": {"text": "Vulnerable dependency brace-expansion 1.1.14: GHSA-3jxr-9vmj-r5cp"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `1.1.14` (resolved in `docs/package-lock.json`) is affected by GHSA-3jxr-9vmj-r5cp (aka CVE-2026-13149).\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbrace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups\n\nAliases: CVE-2026-13149\nAdvisory: https://osv.dev/vulnerability/GHSA-3jxr-9vmj-r5cp\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-d715a24db302912b", "name": "Vulnerable dependency fast-uri 3.1.2: GHSA-4c8g-83qw-93j6", "shortDescription": {"text": "Vulnerable dependency fast-uri 3.1.2: GHSA-4c8g-83qw-93j6"}, "fullDescription": {"text": "OSV.dev reports `fast-uri` at version `3.1.2` (resolved in `docs/package-lock.json`) is affected by GHSA-4c8g-83qw-93j6 (aka CVE-2026-13676).\nNote: `fast-uri` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nfast-uri vulnerable to host confusion via failed IDN canonicalization\n\nAliases: CVE-2026-13676\nAdvisory: https://osv.dev/vulnerability/GHSA-4c8g-83qw-93j6\nFix: upgrade `fast-uri` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-2de1735eb417ad38", "name": "Vulnerable dependency fast-uri 3.1.2: GHSA-v2hh-gcrm-f6hx", "shortDescription": {"text": "Vulnerable dependency fast-uri 3.1.2: GHSA-v2hh-gcrm-f6hx"}, "fullDescription": {"text": "OSV.dev reports `fast-uri` at version `3.1.2` (resolved in `docs/package-lock.json`) is affected by GHSA-v2hh-gcrm-f6hx.\nNote: `fast-uri` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-v2hh-gcrm-f6hx\nFix: upgrade `fast-uri` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-4a897fa1c54a1f18", "name": "Vulnerable dependency hono 4.12.18: GHSA-2gcr-mfcq-wcc3", "shortDescription": {"text": "Vulnerable dependency hono 4.12.18: GHSA-2gcr-mfcq-wcc3"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.18` (resolved in `docs/package-lock.json`) is affected by GHSA-2gcr-mfcq-wcc3 (aka CVE-2026-47676).\nNote: `hono` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nHono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths\n\nAliases: CVE-2026-47676\nAdvisory: https://osv.dev/vulnerability/GHSA-2gcr-mfcq-wcc3\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-5ecca733bf9aa8ea", "name": "Vulnerable dependency hono 4.12.18: GHSA-3hrh-pfw6-9m5x", "shortDescription": {"text": "Vulnerable dependency hono 4.12.18: GHSA-3hrh-pfw6-9m5x"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.18` (resolved in `docs/package-lock.json`) is affected by GHSA-3hrh-pfw6-9m5x (aka CVE-2026-47675).\nNote: `hono` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nHono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection\n\nAliases: CVE-2026-47675\nAdvisory: https://osv.dev/vulnerability/GHSA-3hrh-pfw6-9m5x\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-e453f92995f3b230", "name": "Vulnerable dependency hono 4.12.18: GHSA-88fw-hqm2-52qc", "shortDescription": {"text": "Vulnerable dependency hono 4.12.18: GHSA-88fw-hqm2-52qc"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.18` (resolved in `docs/package-lock.json`) is affected by GHSA-88fw-hqm2-52qc (aka CVE-2026-54290).\nNote: `hono` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nhono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard\n\nAliases: CVE-2026-54290\nAdvisory: https://osv.dev/vulnerability/GHSA-88fw-hqm2-52qc\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-49a1c53717ada9dc", "name": "Vulnerable dependency hono 4.12.18: GHSA-f577-qrjj-4474", "shortDescription": {"text": "Vulnerable dependency hono 4.12.18: GHSA-f577-qrjj-4474"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.18` (resolved in `docs/package-lock.json`) is affected by GHSA-f577-qrjj-4474 (aka CVE-2026-47673).\nNote: `hono` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nHono: JWT middleware accepts any Authorization scheme, not only Bearer\n\nAliases: CVE-2026-47673\nAdvisory: https://osv.dev/vulnerability/GHSA-f577-qrjj-4474\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-40c3422ea68dfc3c", "name": "Vulnerable dependency hono 4.12.18: GHSA-hvrm-45r6-mjfj", "shortDescription": {"text": "Vulnerable dependency hono 4.12.18: GHSA-hvrm-45r6-mjfj"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.18` (resolved in `docs/package-lock.json`) is affected by GHSA-hvrm-45r6-mjfj (aka CVE-2026-59896).\nNote: `hono` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nhono/jsx does not isolate context per request, leading to cross-request data disclosure\n\nAliases: CVE-2026-59896\nAdvisory: https://osv.dev/vulnerability/GHSA-hvrm-45r6-mjfj\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-27ab2b4ac9df19be", "name": "Vulnerable dependency hono 4.12.18: GHSA-j6c9-x7qj-28xf", "shortDescription": {"text": "Vulnerable dependency hono 4.12.18: GHSA-j6c9-x7qj-28xf"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.18` (resolved in `docs/package-lock.json`) is affected by GHSA-j6c9-x7qj-28xf (aka CVE-2026-54287).\nNote: `hono` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nhono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice\n\nAliases: CVE-2026-54287\nAdvisory: https://osv.dev/vulnerability/GHSA-j6c9-x7qj-28xf\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-da48c9f20491ca11", "name": "Vulnerable dependency hono 4.12.18: GHSA-rv63-4mwf-qqc2", "shortDescription": {"text": "Vulnerable dependency hono 4.12.18: GHSA-rv63-4mwf-qqc2"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.18` (resolved in `docs/package-lock.json`) is affected by GHSA-rv63-4mwf-qqc2.\nNote: `hono` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-rv63-4mwf-qqc2\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-e30e4930c54d98ae", "name": "Vulnerable dependency hono 4.12.18: GHSA-w62v-xxxg-mg59", "shortDescription": {"text": "Vulnerable dependency hono 4.12.18: GHSA-w62v-xxxg-mg59"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.18` (resolved in `docs/package-lock.json`) is affected by GHSA-w62v-xxxg-mg59.\nNote: `hono` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w62v-xxxg-mg59\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-a7a76ffb56ac0eec", "name": "Vulnerable dependency hono 4.12.18: GHSA-wgpf-jwqj-8h8p", "shortDescription": {"text": "Vulnerable dependency hono 4.12.18: GHSA-wgpf-jwqj-8h8p"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.18` (resolved in `docs/package-lock.json`) is affected by GHSA-wgpf-jwqj-8h8p.\nNote: `hono` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wgpf-jwqj-8h8p\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-b8b9a587bf2c1ef5", "name": "Vulnerable dependency hono 4.12.18: GHSA-wwfh-h76j-fc44", "shortDescription": {"text": "Vulnerable dependency hono 4.12.18: GHSA-wwfh-h76j-fc44"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.18` (resolved in `docs/package-lock.json`) is affected by GHSA-wwfh-h76j-fc44.\nNote: `hono` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wwfh-h76j-fc44\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-bc66d4a10f6c12ce", "name": "Vulnerable dependency hono 4.12.18: GHSA-xgm2-5f3f-mvvc", "shortDescription": {"text": "Vulnerable dependency hono 4.12.18: GHSA-xgm2-5f3f-mvvc"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.18` (resolved in `docs/package-lock.json`) is affected by GHSA-xgm2-5f3f-mvvc.\nNote: `hono` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xgm2-5f3f-mvvc\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-de487e03ef8324a9", "name": "Vulnerable dependency hono 4.12.18: GHSA-xrhx-7g5j-rcj5", "shortDescription": {"text": "Vulnerable dependency hono 4.12.18: GHSA-xrhx-7g5j-rcj5"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.12.18` (resolved in `docs/package-lock.json`) is affected by GHSA-xrhx-7g5j-rcj5.\nNote: `hono` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xrhx-7g5j-rcj5\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-0fd75dc417cf8964", "name": "Dependency react-dom is a major version behind", "shortDescription": {"text": "Dependency react-dom is a major version behind"}, "fullDescription": {"text": "`react-dom` is pinned at `18.3.1` in `viewer/package.json` while the latest release on the npm registry is `19.2.8` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `react-dom` to `19.2.8`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-cdacbe3b9cec2a0f", "name": "Dependency react is a major version behind", "shortDescription": {"text": "Dependency react is a major version behind"}, "fullDescription": {"text": "`react` is pinned at `18.3.1` in `viewer/package.json` while the latest release on the npm registry is `19.2.8` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `react` to `19.2.8`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-979034ad6535a75c", "name": "Dangling fetch: POST /__cad/implicit-export?file=${encodeURIComponent(fileRef)}&format=${encodeURIComponent(exportFormat", "shortDescription": {"text": "Dangling fetch: POST /__cad/implicit-export?file=${encodeURIComponent(fileRef)}&format=${encodeURIComponent(exportFormat)} (viewer/src/client/workbench/implicitExport.js:34)"}, "fullDescription": {"text": "`viewer/src/client/workbench/implicitExport.js:34` calls `POST /__cad/implicit-export?file=${encodeURIComponent(fileRef)}&format=${encodeURIComponent(exportFormat)}` but no backend route in the scanned graph matches that path. The path appears development/example-only, so verify its custom dev server or proxy registration.\n\nTool: fetch\nNormalized path used for matching: `/__cad/implicit-export`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-7f2f781df81936ce", "name": "6 backend endpoints not called by scanned frontend", "shortDescription": {"text": "6 backend endpoints not called by scanned frontend"}, "fullDescription": {"text": "No scanned frontend call matched these backend routes. Sample: ANY /api/cad/reveal, ANY /api/cad/download, ANY /api/cad/server, ANY /api/cad/catalog, ANY /api/hero-step, ANY /api/hero-step-module. This is fine when endpoints serve external clients (mobile apps, SDKs, third-party integrations, server-side webhooks). Otherwise document consumers or remove dead routes."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/30787"}, "properties": {"repository": "earthtojake/text-to-cad", "repoUrl": "https://github.com/earthtojake/text-to-cad", "branch": "main"}, "results": [{"ruleId": "scanner-801a438a4026e8c9", "level": "note", "message": {"text": "Possibly dead Python function: filesystem_entry"}, "properties": {"repobilityId": "2e2c9d08c0ae225d", "scanner": "scanner-primary", "fingerprint": "801a438a4026e8c9", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/assembly_flatten.py:52"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3b2f82613b19f595", "level": "note", "message": {"text": "Possibly dead Python function: stl_sidecar_job"}, "properties": {"repobilityId": "cd74157259a95731", "scanner": "scanner-primary", "fingerprint": "3b2f82613b19f595", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/generation.py:1757"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1f839487a1f31ac9", "level": "note", "message": {"text": "Possibly dead Python function: three_mf_sidecar_job"}, "properties": {"repobilityId": "9a356796b3380a39", "scanner": "scanner-primary", "fingerprint": "1f839487a1f31ac9", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/generation.py:1763"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2d39ccb379db7cb1", "level": "note", "message": {"text": "Possibly dead Python function: native_glb_sidecar_job"}, "properties": {"repobilityId": "85a15d189cff542b", "scanner": "scanner-primary", "fingerprint": "2d39ccb379db7cb1", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/generation.py:1775"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-52a24af4448a5beb", "level": "note", "message": {"text": "Possibly dead Python function: export_glb_with_topology"}, "properties": {"repobilityId": "1c56c44601ab897a", "scanner": "scanner-primary", "fingerprint": "52a24af4448a5beb", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/generation.py:1788"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b464cabb33b0040f", "level": "note", "message": {"text": "Possibly dead Python function: generate_step"}, "properties": {"repobilityId": "ad8312e84ffa9d42", "scanner": "scanner-primary", "fingerprint": "b464cabb33b0040f", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/generation.py:2242"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-58f2f49890604364", "level": "note", "message": {"text": "Possibly dead Python function: run_tool_cli"}, "properties": {"repobilityId": "7529fabe47ddef95", "scanner": "scanner-primary", "fingerprint": "58f2f49890604364", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/generation.py:2310"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-58dc6cb4797b705f", "level": "note", "message": {"text": "Possibly dead Python function: add_module"}, "properties": {"repobilityId": "9ab86a65f06ea5cd", "scanner": "scanner-primary", "fingerprint": "58dc6cb4797b705f", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/assembly.py:116"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-50aad615a3c89617", "level": "note", "message": {"text": "Possibly dead Python function: datum"}, "properties": {"repobilityId": "a19bd1afca960c42", "scanner": "scanner-primary", "fingerprint": "50aad615a3c89617", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/assembly.py:132"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2df8ce3e913da2ed", "level": "note", "message": {"text": "Possibly dead Python function: linear_frame"}, "properties": {"repobilityId": "992e748e1413f4c0", "scanner": "scanner-primary", "fingerprint": "2df8ce3e913da2ed", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/assembly.py:147"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c1633c1179838748", "level": "note", "message": {"text": "Possibly dead Python function: cylindrical_frame"}, "properties": {"repobilityId": "ecc636c7fcef5749", "scanner": "scanner-primary", "fingerprint": "c1633c1179838748", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/assembly.py:150"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6b64ba91091a9627", "level": "note", "message": {"text": "Possibly dead Python function: ball_frame"}, "properties": {"repobilityId": "5a5393a8712d1490", "scanner": "scanner-primary", "fingerprint": "6b64ba91091a9627", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/assembly.py:153"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5c973fb6709065d5", "level": "note", "message": {"text": "Possibly dead Python function: scene_occurrence_prototype_shape"}, "properties": {"repobilityId": "e3d56cc78b1a1087", "scanner": "scanner-primary", "fingerprint": "5c973fb6709065d5", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/step_scene.py:1455"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4baad11d752b106a", "level": "note", "message": {"text": "Possibly dead Python function: export_assembly_step_from_payload"}, "properties": {"repobilityId": "3ab6951d2a3c1d5a", "scanner": "scanner-primary", "fingerprint": "4baad11d752b106a", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/assembly_export.py:951"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4d08e5a9a0ef9001", "level": "note", "message": {"text": "Possibly dead Python function: export_assembly_step_scene_from_payload"}, "properties": {"repobilityId": "f6354482b4c2cceb", "scanner": "scanner-primary", "fingerprint": "4d08e5a9a0ef9001", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/assembly_export.py:963"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e7ba1cca5a9e84a2", "level": "note", "message": {"text": "Possibly dead Python function: find_source_by_source_ref"}, "properties": {"repobilityId": "3e7e1568a50039ca", "scanner": "scanner-primary", "fingerprint": "e7ba1cca5a9e84a2", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/catalog.py:192"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-585c086153d32b64", "level": "note", "message": {"text": "Possibly dead Python function: artifact_path_for_step_path"}, "properties": {"repobilityId": "0fe783b128941f23", "scanner": "scanner-primary", "fingerprint": "585c086153d32b64", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/catalog.py:261"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f499d52f1549ba1c", "level": "note", "message": {"text": "Possibly dead Python function: hidden_artifact_path_for_step_path"}, "properties": {"repobilityId": "f693e6c707a1a094", "scanner": "scanner-primary", "fingerprint": "f499d52f1549ba1c", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/catalog.py:265"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-06be3fcc7f825ff8", "level": "note", "message": {"text": "Possibly dead Python function: read_dxf_text_to_cad_metadata"}, "properties": {"repobilityId": "267e4da3ffb982d7", "scanner": "scanner-primary", "fingerprint": "06be3fcc7f825ff8", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/file_metadata.py:42"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ea0964f92f6a1903", "level": "note", "message": {"text": "Possibly dead Python function: step_path_from_target"}, "properties": {"repobilityId": "dac2acd09716d533", "scanner": "scanner-primary", "fingerprint": "ea0964f92f6a1903", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/step_targets.py:122"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-81e1aac71034557c", "level": "note", "message": {"text": "Possibly dead Python function: aligned_view_name_for_facts"}, "properties": {"repobilityId": "eb7a6f72ff0c85aa", "scanner": "scanner-primary", "fingerprint": "81e1aac71034557c", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/analysis.py:658"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6d19f26d0a622140", "level": "note", "message": {"text": "Possibly dead Python function: assert_bbox_coordinate"}, "properties": {"repobilityId": "b39e1e64d9df4582", "scanner": "scanner-primary", "fingerprint": "6d19f26d0a622140", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/validators.py:50"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-45fff68b74c04f43", "level": "note", "message": {"text": "Possibly dead Python function: assert_bbox_span"}, "properties": {"repobilityId": "6399ad816edfd84f", "scanner": "scanner-primary", "fingerprint": "45fff68b74c04f43", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/validators.py:63"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-00d33bf21a468617", "level": "note", "message": {"text": "Possibly dead Python function: assert_selector_count"}, "properties": {"repobilityId": "6fe1f366291210d7", "scanner": "scanner-primary", "fingerprint": "00d33bf21a468617", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/validators.py:90"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-744faeeb3a216877", "level": "note", "message": {"text": "Possibly dead Python function: filesystem_entry"}, "properties": {"repobilityId": "2e2c9d08c0ae225d", "scanner": "scanner-primary", "fingerprint": "744faeeb3a216877", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/cadpy/src/cadpy/assembly_flatten.py:52"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8ee5cdc359cfadd2", "level": "note", "message": {"text": "Possibly dead Python function: stl_sidecar_job"}, "properties": {"repobilityId": "cd74157259a95731", "scanner": "scanner-primary", "fingerprint": "8ee5cdc359cfadd2", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/cadpy/src/cadpy/generation.py:1757"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-30ce8d12e5c6b74b", "level": "note", "message": {"text": "Possibly dead Python function: three_mf_sidecar_job"}, "properties": {"repobilityId": "9a356796b3380a39", "scanner": "scanner-primary", "fingerprint": "30ce8d12e5c6b74b", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/cadpy/src/cadpy/generation.py:1763"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-20272da6ebb4fa85", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 docs/src/components/site-header-client.tsx:90"}, "properties": {"repobilityId": "e4e7287b6f84abef", "scanner": "scanner-primary", "fingerprint": "20272da6ebb4fa85", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/src/components/site-header-client.tsx"}, "region": {"startLine": 90}}}]}, {"ruleId": "scanner-c594b4709ee37a5f", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 docs/src/components/hero-step-render.tsx:450"}, "properties": {"repobilityId": "1297959cb3ded025", "scanner": "scanner-primary", "fingerprint": "c594b4709ee37a5f", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/src/components/hero-step-render.tsx"}, "region": {"startLine": 450}}}]}, {"ruleId": "scanner-ae58ab928e12eed6", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 docs/src/app/page.tsx:173"}, "properties": {"repobilityId": "e88c286493a3e20d", "scanner": "scanner-primary", "fingerprint": "ae58ab928e12eed6", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/src/app/page.tsx"}, "region": {"startLine": 173}}}]}, {"ruleId": "scanner-35bae8747aede9d3", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 docs/src/app/layout.tsx:112"}, "properties": {"repobilityId": "e2d724fafc8b8379", "scanner": "scanner-primary", "fingerprint": "35bae8747aede9d3", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/src/app/layout.tsx"}, "region": {"startLine": 112}}}]}, {"ruleId": "scanner-d4836252d4a8dcef", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/CadRenderPane.js:747"}, "properties": {"repobilityId": "69081161d35b826f", "scanner": "scanner-primary", "fingerprint": "d4836252d4a8dcef", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/src/client/components/workbench/CadRenderPane.js"}, "region": {"startLine": 747}}}]}, {"ruleId": "scanner-d705eab42b5e26cc", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/GcodeFileSheet.js:377"}, "properties": {"repobilityId": "449695ce81e3583e", "scanner": "scanner-primary", "fingerprint": "d705eab42b5e26cc", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/src/client/components/workbench/GcodeFileSheet.js"}, "region": {"startLine": 377}}}]}, {"ruleId": "scanner-bea6970525fd7add", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/StepFileSheet.js:1196"}, "properties": {"repobilityId": "4ceb41b375148279", "scanner": "scanner-primary", "fingerprint": "bea6970525fd7add", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/src/client/components/workbench/StepFileSheet.js"}, "region": {"startLine": 1196}}}]}, {"ruleId": "scanner-27fc6299aa297722", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/CadWorkspaceAssemblyInspectPill.js:43"}, "properties": {"repobilityId": "896a4bd01411ddfd", "scanner": "scanner-primary", "fingerprint": "27fc6299aa297722", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/src/client/components/workbench/CadWorkspaceAssemblyInspectPill.js"}, "region": {"startLine": 43}}}]}, {"ruleId": "scanner-187c1fce19ce6903", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/UrdfFileSheet.js:777"}, "properties": {"repobilityId": "a47c4ffaa8aca28e", "scanner": "scanner-primary", "fingerprint": "187c1fce19ce6903", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/src/client/components/workbench/UrdfFileSheet.js"}, "region": {"startLine": 777}}}]}, {"ruleId": "scanner-27c60554d27c2c35", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/FileSheet.js:129"}, "properties": {"repobilityId": "825a74af33d90ccf", "scanner": "scanner-primary", "fingerprint": "27c60554d27c2c35", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/src/client/components/workbench/FileSheet.js"}, "region": {"startLine": 129}}}]}, {"ruleId": "scanner-df3d32b920c1106b", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/ThemeSettingsPopover.js:529"}, "properties": {"repobilityId": "dfd6460321592e93", "scanner": "scanner-primary", "fingerprint": "df3d32b920c1106b", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/src/client/components/workbench/ThemeSettingsPopover.js"}, "region": {"startLine": 529}}}]}, {"ruleId": "scanner-01bbd90a60cc5162", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/AssemblyContextMenuItems.js:2"}, "properties": {"repobilityId": "97be104bde76d120", "scanner": "scanner-primary", "fingerprint": "01bbd90a60cc5162", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/src/client/components/workbench/AssemblyContextMenuItems.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-6070f5f13b556ae3", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/FileViewerSidebar.js:413"}, "properties": {"repobilityId": "c95f6b387f05a2de", "scanner": "scanner-primary", "fingerprint": "6070f5f13b556ae3", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/src/client/components/workbench/FileViewerSidebar.js"}, "region": {"startLine": 413}}}]}, {"ruleId": "scanner-c1a521ff29b80eb3", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/CadWorkspaceTopBar.js:220"}, "properties": {"repobilityId": "9e209efee1c91073", "scanner": "scanner-primary", "fingerprint": "c1a521ff29b80eb3", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/src/client/components/workbench/CadWorkspaceTopBar.js"}, "region": {"startLine": 220}}}]}, {"ruleId": "scanner-f35e778a24e8ca03", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/FileAccessContextMenu.jsx:26"}, "properties": {"repobilityId": "fd4ba59d9e3d159d", "scanner": "scanner-primary", "fingerprint": "f35e778a24e8ca03", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/src/client/components/workbench/FileAccessContextMenu.jsx"}, "region": {"startLine": 26}}}]}, {"ruleId": "scanner-ebd2ce81103f2aa1", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 viewer/src/client/components/workbench/CadWorkspaceHome.js:212"}, "properties": {"repobilityId": "23dbc11a782a195f", "scanner": "scanner-primary", "fingerprint": "ebd2ce81103f2aa1", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/src/client/components/workbench/CadWorkspaceHome.js"}, "region": {"startLine": 212}}}]}, {"ruleId": "scanner-d6a7161b12f829b1", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 skills/cad/scripts/snapshot/runtime/snapshot-render.js:4085"}, "properties": {"repobilityId": "23e95d1c57573647", "scanner": "scanner-primary", "fingerprint": "d6a7161b12f829b1", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/cad/scripts/snapshot/runtime/snapshot-render.js"}, "region": {"startLine": 4085}}}]}, {"ruleId": "scanner-4febd6f286fe69e9", "level": "note", "message": {"text": "React Flow edge with `label=` but no project-wide edge-label CSS override \u2014 skills/cad/scripts/snapshot/runtime/snapshot-render.js:4168"}, "properties": {"repobilityId": "03b6633a9f35e713", "scanner": "scanner-primary", "fingerprint": "4febd6f286fe69e9", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.edge-label.no-bg"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/cad/scripts/snapshot/runtime/snapshot-render.js"}, "region": {"startLine": 4168}}}]}, {"ruleId": "scanner-514468e534103108", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 plugins/cad/skills/cad/scripts/snapshot/runtime/snapshot-render.js:4085"}, "properties": {"repobilityId": "4de5d59c50fd8c42", "scanner": "scanner-primary", "fingerprint": "514468e534103108", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/cad/scripts/snapshot/runtime/snapshot-render.js"}, "region": {"startLine": 4085}}}]}, {"ruleId": "scanner-04889c09cbea4369", "level": "note", "message": {"text": "React Flow edge with `label=` but no project-wide edge-label CSS override \u2014 plugins/cad/skills/cad/scripts/snapshot/runtime/snapshot-render.js:4168"}, "properties": {"repobilityId": "394c82ea8dcfae78", "scanner": "scanner-primary", "fingerprint": "04889c09cbea4369", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.edge-label.no-bg"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/cad/scripts/snapshot/runtime/snapshot-render.js"}, "region": {"startLine": 4168}}}]}, {"ruleId": "scanner-8ee775eeb3a69289", "level": "warning", "message": {"text": "use defused xml \u2014 packages/cadpy/src/cadpy/threemf.py:8"}, "properties": {"repobilityId": "e3fb2e20bedc8e8b", "scanner": "scanner-primary", "fingerprint": "8ee775eeb3a69289", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/cadpy/src/cadpy/threemf.py"}, "region": {"startLine": 8}}}]}, {"ruleId": "scanner-608148875f420a8b", "level": "warning", "message": {"text": "use defused xml \u2014 plugins/cad/skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/context.py:5"}, "properties": {"repobilityId": "f8279570fbc2355c", "scanner": "scanner-primary", "fingerprint": "608148875f420a8b", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/context.py"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-a48e8cea1ac1fda4", "level": "warning", "message": {"text": "use defused xml \u2014 plugins/cad/skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/moveit_py.py:10"}, "properties": {"repobilityId": "20da549edb702cd5", "scanner": "scanner-primary", "fingerprint": "a48e8cea1ac1fda4", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/moveit_py.py"}, "region": {"startLine": 10}}}]}, {"ruleId": "scanner-e3740b0469f7ecb1", "level": "warning", "message": {"text": "insecure hash algorithm sha1 \u2014 plugins/cad/skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/moveit_py.py:349"}, "properties": {"repobilityId": "149f2500b535addd", "scanner": "scanner-primary", "fingerprint": "e3740b0469f7ecb1", "layer": "security", "severity": "medium", "confidence": 0.75, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/moveit_py.py"}, "region": {"startLine": 349}}}]}, {"ruleId": "scanner-97d22d4e1855c57a", "level": "warning", "message": {"text": "use defused xml \u2014 plugins/cad/skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/srdf_source.py:7"}, "properties": {"repobilityId": "181232c83f3da497", "scanner": "scanner-primary", "fingerprint": "97d22d4e1855c57a", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/srdf_source.py"}, "region": {"startLine": 7}}}]}, {"ruleId": "scanner-94849e62e90118f8", "level": "warning", "message": {"text": "use defused xml \u2014 plugins/cad/skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/threemf.py:8"}, "properties": {"repobilityId": "fbefc30d69f2d7f3", "scanner": "scanner-primary", "fingerprint": "94849e62e90118f8", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/threemf.py"}, "region": {"startLine": 8}}}]}, {"ruleId": "scanner-f754e2bc78fca771", "level": "warning", "message": {"text": "use defused xml \u2014 plugins/cad/skills/cad/scripts/packages/cadpy/src/cadpy/threemf.py:8"}, "properties": {"repobilityId": "c18b905e25510db6", "scanner": "scanner-primary", "fingerprint": "f754e2bc78fca771", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/cad/scripts/packages/cadpy/src/cadpy/threemf.py"}, "region": {"startLine": 8}}}]}, {"ruleId": "scanner-d6b50f3743ab16c0", "level": "warning", "message": {"text": "use defused xml \u2014 plugins/cad/skills/dxf/scripts/packages/cadpy/src/cadpy/threemf.py:8"}, "properties": {"repobilityId": "8fd7d6e86d6aad39", "scanner": "scanner-primary", "fingerprint": "d6b50f3743ab16c0", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/dxf/scripts/packages/cadpy/src/cadpy/threemf.py"}, "region": {"startLine": 8}}}]}, {"ruleId": "scanner-e96db416354fe883", "level": "warning", "message": {"text": "use defused xml \u2014 plugins/cad/skills/sdf/scripts/sdf/builder.py:5"}, "properties": {"repobilityId": "804dd2f53711ea76", "scanner": "scanner-primary", "fingerprint": "e96db416354fe883", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/sdf/scripts/sdf/builder.py"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-741b4cc4e0c4a36c", "level": "warning", "message": {"text": "use defused xml \u2014 plugins/cad/skills/sdf/scripts/sdf/cli.py:10"}, "properties": {"repobilityId": "1d4be2a38a927fd7", "scanner": "scanner-primary", "fingerprint": "741b4cc4e0c4a36c", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/sdf/scripts/sdf/cli.py"}, "region": {"startLine": 10}}}]}, {"ruleId": "scanner-f60dbcf60ec2cc43", "level": "warning", "message": {"text": "use defused xml \u2014 plugins/cad/skills/sdf/scripts/sdf/source.py:6"}, "properties": {"repobilityId": "5039b06b899b68de", "scanner": "scanner-primary", "fingerprint": "f60dbcf60ec2cc43", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/sdf/scripts/sdf/source.py"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-01797895b6d7a1dd", "level": "warning", "message": {"text": "use defused xml \u2014 plugins/cad/skills/sdf/scripts/sdf/validation.py:8"}, "properties": {"repobilityId": "8f8c7e4b9bce628b", "scanner": "scanner-primary", "fingerprint": "01797895b6d7a1dd", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/sdf/scripts/sdf/validation.py"}, "region": {"startLine": 8}}}]}, {"ruleId": "scanner-754e5d05f15dd0a4", "level": "warning", "message": {"text": "use defused xml \u2014 plugins/cad/skills/srdf/scripts/srdf/cli.py:13"}, "properties": {"repobilityId": "7e69c9e8d8b2975d", "scanner": "scanner-primary", "fingerprint": "754e5d05f15dd0a4", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/srdf/scripts/srdf/cli.py"}, "region": {"startLine": 13}}}]}, {"ruleId": "scanner-146c75e599a2118b", "level": "warning", "message": {"text": "use defused xml \u2014 plugins/cad/skills/srdf/scripts/srdf/source.py:7"}, "properties": {"repobilityId": "43f6f076bb8d58ce", "scanner": "scanner-primary", "fingerprint": "146c75e599a2118b", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/srdf/scripts/srdf/source.py"}, "region": {"startLine": 7}}}]}, {"ruleId": "scanner-248f2401ebddf63c", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 plugins/cad/skills/step-parts/scripts/download_step_part.py:66"}, "properties": {"repobilityId": "a67ac135b239ce7d", "scanner": "scanner-primary", "fingerprint": "248f2401ebddf63c", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/step-parts/scripts/download_step_part.py"}, "region": {"startLine": 66}}}]}, {"ruleId": "scanner-80946d7729644b23", "level": "warning", "message": {"text": "use defused xml \u2014 plugins/cad/skills/urdf/scripts/urdf/cli.py:10"}, "properties": {"repobilityId": "df1947295f346d85", "scanner": "scanner-primary", "fingerprint": "80946d7729644b23", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/urdf/scripts/urdf/cli.py"}, "region": {"startLine": 10}}}]}, {"ruleId": "scanner-d9cdd170dc5de26a", "level": "warning", "message": {"text": "use defused xml \u2014 plugins/cad/skills/urdf/scripts/urdf/source.py:9"}, "properties": {"repobilityId": "167ab22d26304288", "scanner": "scanner-primary", "fingerprint": "d9cdd170dc5de26a", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/urdf/scripts/urdf/source.py"}, "region": {"startLine": 9}}}]}, {"ruleId": "scanner-bad5b23962f91958", "level": "warning", "message": {"text": "use defused xml \u2014 skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/context.py:5"}, "properties": {"repobilityId": "57f96f415266f8ad", "scanner": "scanner-primary", "fingerprint": "bad5b23962f91958", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/context.py"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-2232e72a81efeb84", "level": "warning", "message": {"text": "use defused xml \u2014 skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/moveit_py.py:10"}, "properties": {"repobilityId": "866b875583a1ec50", "scanner": "scanner-primary", "fingerprint": "2232e72a81efeb84", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/moveit_py.py"}, "region": {"startLine": 10}}}]}, {"ruleId": "scanner-36ce26864b5bec73", "level": "warning", "message": {"text": "insecure hash algorithm sha1 \u2014 skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/moveit_py.py:349"}, "properties": {"repobilityId": "996389c9aa73f53e", "scanner": "scanner-primary", "fingerprint": "36ce26864b5bec73", "layer": "security", "severity": "medium", "confidence": 0.75, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/moveit_py.py"}, "region": {"startLine": 349}}}]}, {"ruleId": "scanner-a9e1a262e78709af", "level": "warning", "message": {"text": "use defused xml \u2014 skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/srdf_source.py:7"}, "properties": {"repobilityId": "0954e16315985252", "scanner": "scanner-primary", "fingerprint": "a9e1a262e78709af", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/srdf_source.py"}, "region": {"startLine": 7}}}]}, {"ruleId": "scanner-3de0b9c3515e5970", "level": "warning", "message": {"text": "use defused xml \u2014 skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/threemf.py:8"}, "properties": {"repobilityId": "b2a7e3a81af5ac16", "scanner": "scanner-primary", "fingerprint": "3de0b9c3515e5970", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/threemf.py"}, "region": {"startLine": 8}}}]}, {"ruleId": "scanner-e496cf0be99b08ad", "level": "warning", "message": {"text": "use defused xml \u2014 skills/cad/scripts/packages/cadpy/src/cadpy/threemf.py:8"}, "properties": {"repobilityId": "0048ca67b4a723b8", "scanner": "scanner-primary", "fingerprint": "e496cf0be99b08ad", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/cad/scripts/packages/cadpy/src/cadpy/threemf.py"}, "region": {"startLine": 8}}}]}, {"ruleId": "scanner-6f25deaafcfae363", "level": "warning", "message": {"text": "use defused xml \u2014 skills/dxf/scripts/packages/cadpy/src/cadpy/threemf.py:8"}, "properties": {"repobilityId": "b90c06dd6c3b4138", "scanner": "scanner-primary", "fingerprint": "6f25deaafcfae363", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/dxf/scripts/packages/cadpy/src/cadpy/threemf.py"}, "region": {"startLine": 8}}}]}, {"ruleId": "scanner-052b8454a04f47b7", "level": "warning", "message": {"text": "use defused xml \u2014 skills/sdf/scripts/sdf/builder.py:5"}, "properties": {"repobilityId": "9642a9452283909b", "scanner": "scanner-primary", "fingerprint": "052b8454a04f47b7", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/sdf/scripts/sdf/builder.py"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-87e6b38572fa93f2", "level": "warning", "message": {"text": "use defused xml \u2014 skills/sdf/scripts/sdf/cli.py:10"}, "properties": {"repobilityId": "90db07610f17045a", "scanner": "scanner-primary", "fingerprint": "87e6b38572fa93f2", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/sdf/scripts/sdf/cli.py"}, "region": {"startLine": 10}}}]}, {"ruleId": "scanner-b558413d2d416dfd", "level": "warning", "message": {"text": "use defused xml \u2014 skills/sdf/scripts/sdf/source.py:6"}, "properties": {"repobilityId": "bf61d040467bb155", "scanner": "scanner-primary", "fingerprint": "b558413d2d416dfd", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/sdf/scripts/sdf/source.py"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-c257663d7ddeef7f", "level": "warning", "message": {"text": "use defused xml \u2014 skills/sdf/scripts/sdf/validation.py:8"}, "properties": {"repobilityId": "70868ff5d76330b6", "scanner": "scanner-primary", "fingerprint": "c257663d7ddeef7f", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/sdf/scripts/sdf/validation.py"}, "region": {"startLine": 8}}}]}, {"ruleId": "scanner-96f888e1feef39fa", "level": "warning", "message": {"text": "use defused xml \u2014 skills/srdf/scripts/srdf/cli.py:13"}, "properties": {"repobilityId": "2a42efa10d973152", "scanner": "scanner-primary", "fingerprint": "96f888e1feef39fa", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/srdf/scripts/srdf/cli.py"}, "region": {"startLine": 13}}}]}, {"ruleId": "scanner-d7e47986a1aa8043", "level": "warning", "message": {"text": "use defused xml \u2014 skills/srdf/scripts/srdf/source.py:7"}, "properties": {"repobilityId": "8e10851769352a80", "scanner": "scanner-primary", "fingerprint": "d7e47986a1aa8043", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/srdf/scripts/srdf/source.py"}, "region": {"startLine": 7}}}]}, {"ruleId": "scanner-fe244dfbe1b2989a", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 skills/step-parts/scripts/download_step_part.py:66"}, "properties": {"repobilityId": "dc28e83daea89317", "scanner": "scanner-primary", "fingerprint": "fe244dfbe1b2989a", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/step-parts/scripts/download_step_part.py"}, "region": {"startLine": 66}}}]}, {"ruleId": "scanner-67f8debd8d5feec3", "level": "warning", "message": {"text": "use defused xml \u2014 skills/urdf/scripts/urdf/cli.py:10"}, "properties": {"repobilityId": "dbb35cdeb0871a1f", "scanner": "scanner-primary", "fingerprint": "67f8debd8d5feec3", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/urdf/scripts/urdf/cli.py"}, "region": {"startLine": 10}}}]}, {"ruleId": "scanner-ffb3990aa4594350", "level": "warning", "message": {"text": "use defused xml \u2014 skills/urdf/scripts/urdf/source.py:9"}, "properties": {"repobilityId": "9eebb5f750464c76", "scanner": "scanner-primary", "fingerprint": "ffb3990aa4594350", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/urdf/scripts/urdf/source.py"}, "region": {"startLine": 9}}}]}, {"ruleId": "scanner-2d1e32eba17690c7", "level": "warning", "message": {"text": "use defused xml \u2014 viewer/moveit2_server/moveit2_server/context.py:5"}, "properties": {"repobilityId": "75028b7b20120f65", "scanner": "scanner-primary", "fingerprint": "2d1e32eba17690c7", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/moveit2_server/moveit2_server/context.py"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-df72bd4d6cdde7d3", "level": "warning", "message": {"text": "use defused xml \u2014 viewer/moveit2_server/moveit2_server/moveit_py.py:10"}, "properties": {"repobilityId": "fb0394c48167ef92", "scanner": "scanner-primary", "fingerprint": "df72bd4d6cdde7d3", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/moveit2_server/moveit2_server/moveit_py.py"}, "region": {"startLine": 10}}}]}, {"ruleId": "scanner-62a8c31bdb3e06cc", "level": "warning", "message": {"text": "insecure hash algorithm sha1 \u2014 viewer/moveit2_server/moveit2_server/moveit_py.py:349"}, "properties": {"repobilityId": "cf2eb404d3739a3f", "scanner": "scanner-primary", "fingerprint": "62a8c31bdb3e06cc", "layer": "security", "severity": "medium", "confidence": 0.75, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/moveit2_server/moveit2_server/moveit_py.py"}, "region": {"startLine": 349}}}]}, {"ruleId": "scanner-d0b9b74331ba8d40", "level": "warning", "message": {"text": "use defused xml \u2014 viewer/moveit2_server/moveit2_server/srdf_source.py:7"}, "properties": {"repobilityId": "02996c69cddcebb3", "scanner": "scanner-primary", "fingerprint": "d0b9b74331ba8d40", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/moveit2_server/moveit2_server/srdf_source.py"}, "region": {"startLine": 7}}}]}, {"ruleId": "scanner-bd9ef2832ad8fe97", "level": "warning", "message": {"text": "use defused xml \u2014 viewer/packages/cadpy/src/cadpy/threemf.py:8"}, "properties": {"repobilityId": "b103caeaef4316c8", "scanner": "scanner-primary", "fingerprint": "bd9ef2832ad8fe97", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/packages/cadpy/src/cadpy/threemf.py"}, "region": {"startLine": 8}}}]}, {"ruleId": "scanner-9a2434d148b9caf4", "level": "note", "message": {"text": "CVE-2026-49356: @babel/core 7.29.0 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "8bf45e8d6c87b7ad", "scanner": "scanner-primary", "fingerprint": "9a2434d148b9caf4", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49356"]}}, {"ruleId": "scanner-654c5dd1b30545b2", "level": "warning", "message": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.14 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "d5f0a5e7b7ddcf43", "scanner": "scanner-primary", "fingerprint": "654c5dd1b30545b2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-frvp-7c67-39w9"]}}, {"ruleId": "scanner-b7b827e365307352", "level": "note", "message": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "ff1614c01b16c98d", "scanner": "scanner-primary", "fingerprint": "b7b827e365307352", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12590"]}}, {"ruleId": "scanner-00206968cd20871e", "level": "error", "message": {"text": "CVE-2026-13149: brace-expansion 5.0.6 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "440b8b8da6148d6c", "scanner": "scanner-primary", "fingerprint": "00206968cd20871e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13149"]}}, {"ruleId": "scanner-7c4a3af7f35cbc05", "level": "error", "message": {"text": "CVE-2026-13676: fast-uri 3.1.2 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "35cb5ec8cde2fd99", "scanner": "scanner-primary", "fingerprint": "7c4a3af7f35cbc05", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13676"]}}, {"ruleId": "scanner-983a1d4642a4fef9", "level": "error", "message": {"text": "CVE-2026-16221: fast-uri 3.1.2 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "61651f59f81e0ed5", "scanner": "scanner-primary", "fingerprint": "983a1d4642a4fef9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-16221"]}}, {"ruleId": "scanner-870cf85ddb8b813b", "level": "error", "message": {"text": "CVE-2026-54290: hono 4.12.18 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "ef8373c07630c07b", "scanner": "scanner-primary", "fingerprint": "870cf85ddb8b813b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54290"]}}, {"ruleId": "scanner-efe5d2fc749ffad0", "level": "warning", "message": {"text": "CVE-2026-47673: hono 4.12.18 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "a5799508f854cec8", "scanner": "scanner-primary", "fingerprint": "efe5d2fc749ffad0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47673"]}}, {"ruleId": "scanner-2b90eb7928403027", "level": "warning", "message": {"text": "CVE-2026-47674: hono 4.12.18 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "bde892d5d5e05d70", "scanner": "scanner-primary", "fingerprint": "2b90eb7928403027", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47674"]}}, {"ruleId": "scanner-bfef8f28b67a2c39", "level": "warning", "message": {"text": "CVE-2026-47675: hono 4.12.18 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "d9cbfee84002c268", "scanner": "scanner-primary", "fingerprint": "bfef8f28b67a2c39", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47675"]}}, {"ruleId": "scanner-7e4bca48cc6cc429", "level": "warning", "message": {"text": "CVE-2026-47676: hono 4.12.18 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "51b2d271bb4d4252", "scanner": "scanner-primary", "fingerprint": "7e4bca48cc6cc429", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47676"]}}, {"ruleId": "scanner-e111e9ab2c2d4938", "level": "warning", "message": {"text": "CVE-2026-54286: hono 4.12.18 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "8f1dce03a680cf69", "scanner": "scanner-primary", "fingerprint": "e111e9ab2c2d4938", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54286"]}}, {"ruleId": "scanner-b40cde31aac7a80e", "level": "warning", "message": {"text": "CVE-2026-54287: hono 4.12.18 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "c9d789a03929fc75", "scanner": "scanner-primary", "fingerprint": "b40cde31aac7a80e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54287"]}}, {"ruleId": "scanner-65553d3ded92db4c", "level": "warning", "message": {"text": "CVE-2026-54288: hono 4.12.18 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "e64771fd8fcb83c7", "scanner": "scanner-primary", "fingerprint": "65553d3ded92db4c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54288"]}}, {"ruleId": "scanner-38bba986831ade9c", "level": "warning", "message": {"text": "CVE-2026-54289: hono 4.12.18 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "6ba3af6c2b25d114", "scanner": "scanner-primary", "fingerprint": "38bba986831ade9c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54289"]}}, {"ruleId": "scanner-8341ef5f0736a269", "level": "warning", "message": {"text": "CVE-2026-59895: hono 4.12.18 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "faad5bf66e697563", "scanner": "scanner-primary", "fingerprint": "8341ef5f0736a269", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59895"]}}, {"ruleId": "scanner-c8f0c6fb47510e4c", "level": "warning", "message": {"text": "CVE-2026-59896: hono 4.12.18 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "92b52831f411d477", "scanner": "scanner-primary", "fingerprint": "c8f0c6fb47510e4c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59896"]}}, {"ruleId": "scanner-9c01e8ea89057944", "level": "warning", "message": {"text": "CVE-2026-59897: hono 4.12.18 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "3812bb5a85367557", "scanner": "scanner-primary", "fingerprint": "9c01e8ea89057944", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59897"]}}, {"ruleId": "scanner-51bb941c82b607dd", "level": "error", "message": {"text": "CVE-2026-59869: js-yaml 4.1.1 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "f21fa0e5f5440cb0", "scanner": "scanner-primary", "fingerprint": "51bb941c82b607dd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59869"]}}, {"ruleId": "scanner-a503bb72aab73e90", "level": "warning", "message": {"text": "CVE-2026-53550: js-yaml 4.1.1 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "edb514e63fba8659", "scanner": "scanner-primary", "fingerprint": "a503bb72aab73e90", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53550"]}}, {"ruleId": "scanner-6b58aba3aaf01edf", "level": "error", "message": {"text": "CVE-2026-64641: next 16.2.6 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "ffd97c054de915bd", "scanner": "scanner-primary", "fingerprint": "6b58aba3aaf01edf", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64641"]}}, {"ruleId": "scanner-1aa8757a0398139d", "level": "error", "message": {"text": "CVE-2026-64642: next 16.2.6 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "20506610fa86c1fd", "scanner": "scanner-primary", "fingerprint": "1aa8757a0398139d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64642"]}}, {"ruleId": "scanner-578d0d3fcdb87a6a", "level": "error", "message": {"text": "CVE-2026-64645: next 16.2.6 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "22c34cb5ff7202fa", "scanner": "scanner-primary", "fingerprint": "578d0d3fcdb87a6a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64645"]}}, {"ruleId": "scanner-30bf89802c5ff263", "level": "error", "message": {"text": "CVE-2026-64649: next 16.2.6 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "89d8bdfb4a6ea0a6", "scanner": "scanner-primary", "fingerprint": "30bf89802c5ff263", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64649"]}}, {"ruleId": "scanner-c52eee3491b91888", "level": "warning", "message": {"text": "CVE-2026-64643: next 16.2.6 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "4a34558c5dd40eec", "scanner": "scanner-primary", "fingerprint": "c52eee3491b91888", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64643"]}}, {"ruleId": "scanner-97defb3b621efc6b", "level": "warning", "message": {"text": "CVE-2026-64644: next 16.2.6 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "05b4aeb5fd92f4e4", "scanner": "scanner-primary", "fingerprint": "97defb3b621efc6b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64644"]}}, {"ruleId": "scanner-ed134a1e649884cb", "level": "warning", "message": {"text": "CVE-2026-64646: next 16.2.6 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "c9d15344d4887081", "scanner": "scanner-primary", "fingerprint": "ed134a1e649884cb", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64646"]}}, {"ruleId": "scanner-83011e5698f40eec", "level": "warning", "message": {"text": "CVE-2026-64647: next 16.2.6 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "f2592018d177c8fa", "scanner": "scanner-primary", "fingerprint": "83011e5698f40eec", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64647"]}}, {"ruleId": "scanner-2760c1623f229234", "level": "warning", "message": {"text": "CVE-2026-64648: next 16.2.6 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "a5b53c9bee608754", "scanner": "scanner-primary", "fingerprint": "2760c1623f229234", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64648"]}}, {"ruleId": "scanner-b2b7c5551ca6f9c9", "level": "warning", "message": {"text": "CVE-2026-8723: qs 6.15.1 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "c382b234af6926dc", "scanner": "scanner-primary", "fingerprint": "b2b7c5551ca6f9c9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8723"]}}, {"ruleId": "scanner-f6a2bbde51594faa", "level": "error", "message": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 docs/package-lock.json"}, "properties": {"repobilityId": "dab0ba26bd195392", "scanner": "scanner-primary", "fingerprint": "f6a2bbde51594faa", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-f88m-g3jw-g9cj"]}}, {"ruleId": "scanner-8121075e5e96682b", "level": "error", "message": {"text": "CVE-2026-12151: undici 6.26.0 \u2014 viewer/package-lock.json"}, "properties": {"repobilityId": "e45816d8e9d9bd05", "scanner": "scanner-primary", "fingerprint": "8121075e5e96682b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12151"]}}, {"ruleId": "scanner-42d78536b39df07a", "level": "warning", "message": {"text": "CVE-2026-9679: undici 6.26.0 \u2014 viewer/package-lock.json"}, "properties": {"repobilityId": "6e0193ed2c5d1840", "scanner": "scanner-primary", "fingerprint": "42d78536b39df07a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-9679"]}}, {"ruleId": "scanner-cb26403d68aab7f7", "level": "note", "message": {"text": "CVE-2026-11525: undici 6.26.0 \u2014 viewer/package-lock.json"}, "properties": {"repobilityId": "7fe80d85350cb9f5", "scanner": "scanner-primary", "fingerprint": "cb26403d68aab7f7", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-11525"]}}, {"ruleId": "scanner-2ae28684ad9c413b", "level": "note", "message": {"text": "CVE-2026-6733: undici 6.26.0 \u2014 viewer/package-lock.json"}, "properties": {"repobilityId": "1e44d8bad7e15f69", "scanner": "scanner-primary", "fingerprint": "2ae28684ad9c413b", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6733"]}}, {"ruleId": "scanner-1ddec8c719cdd4e9", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: skills/gcode/SKILL.md"}, "properties": {"repobilityId": "b6c339922c2c0192", "scanner": "scanner-primary", "fingerprint": "1ddec8c719cdd4e9", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "skill_file"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/gcode/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6e09d06bd056fd8d", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: skills/cad-viewer/SKILL.md"}, "properties": {"repobilityId": "23db6fb4c4aeb130", "scanner": "scanner-primary", "fingerprint": "6e09d06bd056fd8d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "skill_file"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/cad-viewer/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8997f5d83ba2bba0", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: skills/sdf/SKILL.md"}, "properties": {"repobilityId": "d45c31145b61959c", "scanner": "scanner-primary", "fingerprint": "8997f5d83ba2bba0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "skill_file"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/sdf/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b9679f5699b22a59", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: skills/srdf/SKILL.md"}, "properties": {"repobilityId": "d77d07e8656ee90f", "scanner": "scanner-primary", "fingerprint": "b9679f5699b22a59", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "skill_file"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/srdf/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4476f2e17cd090e3", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: plugins/cad/skills/gcode/SKILL.md"}, "properties": {"repobilityId": "df3aa33c816270e4", "scanner": "scanner-primary", "fingerprint": "4476f2e17cd090e3", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "skill_file"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/gcode/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7683eadb7104dd40", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: plugins/cad/skills/cad-viewer/SKILL.md"}, "properties": {"repobilityId": "13e1b53e9cebc24d", "scanner": "scanner-primary", "fingerprint": "7683eadb7104dd40", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "skill_file"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/cad-viewer/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6851dc8667a26fd7", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: plugins/cad/skills/sdf/SKILL.md"}, "properties": {"repobilityId": "48fa37dd585fa67f", "scanner": "scanner-primary", "fingerprint": "6851dc8667a26fd7", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "skill_file"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/sdf/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-454aa15226806f31", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: plugins/cad/skills/srdf/SKILL.md"}, "properties": {"repobilityId": "46194d37079934a8", "scanner": "scanner-primary", "fingerprint": "454aa15226806f31", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "skill_file"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/srdf/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e725d2ab884fbd49", "level": "note", "message": {"text": "Multiple root agent instruction files without precedence"}, "properties": {"repobilityId": "1953db6c89508d22", "scanner": "scanner-primary", "fingerprint": "e725d2ab884fbd49", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["agent-instructions", "governance"]}}, {"ruleId": "scanner-82a5961ce9bab681", "level": "warning", "message": {"text": "SkillSpector AST4 (behavioral-ast) in skills/bambu-labs/scripts/bambu_lan_print.py"}, "properties": {"repobilityId": "b7580e69643fd11f", "scanner": "scanner-primary", "fingerprint": "82a5961ce9bab681", "layer": "security", "severity": "medium", "confidence": 0.6, "tags": ["skillspector", "mcp-skill", "behavioral-ast", "AST4", "code-exec"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/bambu-labs/scripts/bambu_lan_print.py"}, "region": {"startLine": 580}}}]}, {"ruleId": "scanner-446dfef84e6e4c28", "level": "note", "message": {"text": "SkillSpector AST7 (behavioral-ast) in skills/bambu-labs/scripts/bambu_lan_print.py"}, "properties": {"repobilityId": "9ffeec1dc3234e7f", "scanner": "scanner-primary", "fingerprint": "446dfef84e6e4c28", "layer": "security", "severity": "low", "confidence": 0.5, "tags": ["skillspector", "mcp-skill", "behavioral-ast", "AST7", "code-exec"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/bambu-labs/scripts/bambu_lan_print.py"}, "region": {"startLine": 207}}}]}, {"ruleId": "scanner-56ea5beb3aa6ef2c", "level": "warning", "message": {"text": "SkillSpector LP3 (mcp-least-priv) in skills/bambu-labs/SKILL.md"}, "properties": {"repobilityId": "abbbf4c6eb25f4bb", "scanner": "scanner-primary", "fingerprint": "56ea5beb3aa6ef2c", "layer": "security", "severity": "medium", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "mcp-least-priv", "LP3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/bambu-labs/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f1367926d0b0fbb0", "level": "note", "message": {"text": "SkillSpector EA3 (excessive-agency) in skills/bambu-labs/LICENSE"}, "properties": {"repobilityId": "b00c00b32a91b7f7", "scanner": "scanner-primary", "fingerprint": "f1367926d0b0fbb0", "layer": "security", "severity": "low", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "excessive-agency", "EA3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/bambu-labs/LICENSE"}, "region": {"startLine": 16}}}]}, {"ruleId": "scanner-0d21a494ae06e5c2", "level": "error", "message": {"text": "SkillSpector OH1 (output-handling) in skills/bambu-labs/scripts/bambu_lan_print.py"}, "properties": {"repobilityId": "2743c57cbd21e276", "scanner": "scanner-primary", "fingerprint": "0d21a494ae06e5c2", "layer": "security", "severity": "high", "confidence": 0.95, "tags": ["skillspector", "mcp-skill", "output-handling", "OH1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/bambu-labs/scripts/bambu_lan_print.py"}, "region": {"startLine": 580}}}]}, {"ruleId": "scanner-0430798f1d4ae1f1", "level": "error", "message": {"text": "SkillSpector P1 (prompt-injection) in skills/bambu-labs/SKILL.md"}, "properties": {"repobilityId": "a4c729f51078bb8e", "scanner": "scanner-primary", "fingerprint": "0430798f1d4ae1f1", "layer": "security", "severity": "high", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "prompt-injection", "P1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/bambu-labs/SKILL.md"}, "region": {"startLine": 43}}}]}, {"ruleId": "scanner-b976fbebcf8b0043", "level": "error", "message": {"text": "SkillSpector P1 (prompt-injection) in skills/bambu-labs/references/new-printer-onboarding.md"}, "properties": {"repobilityId": "5983c633b8448a84", "scanner": "scanner-primary", "fingerprint": "b976fbebcf8b0043", "layer": "security", "severity": "high", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "prompt-injection", "P1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/bambu-labs/references/new-printer-onboarding.md"}, "region": {"startLine": 20}}}]}, {"ruleId": "scanner-f2d6c610bf9f12df", "level": "note", "message": {"text": "SkillSpector AST7 (behavioral-ast) in skills/cad/scripts/packages/cadpy/src/cadpy/assembly.py"}, "properties": {"repobilityId": "29ba6d69f070145f", "scanner": "scanner-primary", "fingerprint": "f2d6c610bf9f12df", "layer": "security", "severity": "low", "confidence": 0.5, "tags": ["skillspector", "mcp-skill", "behavioral-ast", "AST7", "code-exec"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/cad/scripts/packages/cadpy/src/cadpy/assembly.py"}, "region": {"startLine": 282}}}]}, {"ruleId": "scanner-1e518561bdc488bb", "level": "note", "message": {"text": "SkillSpector AST7 (behavioral-ast) in skills/cad/scripts/packages/cadpy/src/cadpy/generation.py"}, "properties": {"repobilityId": "534a33b520bed683", "scanner": "scanner-primary", "fingerprint": "1e518561bdc488bb", "layer": "security", "severity": "low", "confidence": 0.5, "tags": ["skillspector", "mcp-skill", "behavioral-ast", "AST7", "code-exec"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/cad/scripts/packages/cadpy/src/cadpy/generation.py"}, "region": {"startLine": 1088}}}]}, {"ruleId": "scanner-76f20f656e1511f7", "level": "note", "message": {"text": "SkillSpector AST7 (behavioral-ast) in skills/cad/scripts/packages/cadpy/src/cadpy/step_scene.py"}, "properties": {"repobilityId": "1f524a124c1a1fa7", "scanner": "scanner-primary", "fingerprint": "76f20f656e1511f7", "layer": "security", "severity": "low", "confidence": 0.5, "tags": ["skillspector", "mcp-skill", "behavioral-ast", "AST7", "code-exec"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/cad/scripts/packages/cadpy/src/cadpy/step_scene.py"}, "region": {"startLine": 968}}}]}, {"ruleId": "scanner-5b002377515a2528", "level": "warning", "message": {"text": "SkillSpector LP3 (mcp-least-priv) in skills/cad/SKILL.md"}, "properties": {"repobilityId": "cdce97751ee0df89", "scanner": "scanner-primary", "fingerprint": "5b002377515a2528", "layer": "security", "severity": "medium", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "mcp-least-priv", "LP3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/cad/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ac2176b96122d24e", "level": "note", "message": {"text": "SkillSpector EA3 (excessive-agency) in skills/cad/LICENSE"}, "properties": {"repobilityId": "4e027d7f63f3d4ff", "scanner": "scanner-primary", "fingerprint": "ac2176b96122d24e", "layer": "security", "severity": "low", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "excessive-agency", "EA3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/cad/LICENSE"}, "region": {"startLine": 16}}}]}, {"ruleId": "scanner-3368b0beff5c900d", "level": "warning", "message": {"text": "SkillSpector EA2 (excessive-agency) in skills/cad/references/cad-brief.md"}, "properties": {"repobilityId": "07bcf886f1a0b5eb", "scanner": "scanner-primary", "fingerprint": "3368b0beff5c900d", "layer": "security", "severity": "medium", "confidence": 0.8, "tags": ["skillspector", "mcp-skill", "excessive-agency", "EA2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/cad/references/cad-brief.md"}, "region": {"startLine": 3}}}]}, {"ruleId": "scanner-6471fc7fa114d165", "level": "warning", "message": {"text": "SkillSpector EA4 (excessive-agency) in skills/cad/scripts/packages/cadpy/src/cadpy/generation_status.py"}, "properties": {"repobilityId": "b43fd801b7780c86", "scanner": "scanner-primary", "fingerprint": "6471fc7fa114d165", "layer": "security", "severity": "medium", "confidence": 0.75, "tags": ["skillspector", "mcp-skill", "excessive-agency", "EA4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/cad/scripts/packages/cadpy/src/cadpy/generation_status.py"}, "region": {"startLine": 101}}}]}, {"ruleId": "scanner-3496198c4972df9b", "level": "error", "message": {"text": "SkillSpector PE3 (priv-esc) in skills/cad/scripts/packages/cadpy/src/cadpy/catalog.py"}, "properties": {"repobilityId": "bab9d61127cd3f52", "scanner": "scanner-primary", "fingerprint": "3496198c4972df9b", "layer": "security", "severity": "high", "confidence": 0.6, "tags": ["skillspector", "mcp-skill", "priv-esc", "PE3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/cad/scripts/packages/cadpy/src/cadpy/catalog.py"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-8f8a929f4c09cc87", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in skills/cad/requirements.txt"}, "properties": {"repobilityId": "e651e04a38492ebb", "scanner": "scanner-primary", "fingerprint": "8f8a929f4c09cc87", "layer": "security", "severity": "low", "confidence": 0.6, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/cad/requirements.txt"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-2fafb6ded4a7031e", "level": "error", "message": {"text": "SkillSpector SC4 (supply-chain) in skills/cad/scripts/packages/cadpy/pyproject.toml"}, "properties": {"repobilityId": "6b9cfb97646b10f2", "scanner": "scanner-primary", "fingerprint": "2fafb6ded4a7031e", "layer": "security", "severity": "high", "confidence": 0.8, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/cad/scripts/packages/cadpy/pyproject.toml"}, "region": {"startLine": 9}}}]}, {"ruleId": "scanner-e637c415447867e4", "level": "none", "message": {"text": "Run SkillSpector's LLM-backed analysis in your own pipeline"}, "properties": {"repobilityId": "1936f198ff5212bf", "scanner": "scanner-primary", "fingerprint": "e637c415447867e4", "layer": "security", "severity": "info", "confidence": 1.0, "tags": ["skillspector", "mcp-skill", "llm-advisory", "ai-coder"]}}, {"ruleId": "scanner-cf89f0aa75d843d8", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in docs/src/app/layout.tsx:112"}, "properties": {"repobilityId": "9d95ede695f9de8b", "scanner": "scanner-primary", "fingerprint": "cf89f0aa75d843d8", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/src/app/layout.tsx"}, "region": {"startLine": 112}}}]}, {"ruleId": "scanner-3ea6f1676018915f", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in viewer/scripts/start-agent-viewer.mjs:2"}, "properties": {"repobilityId": "0b1ca28e572b83a4", "scanner": "scanner-primary", "fingerprint": "3ea6f1676018915f", "layer": "security", "severity": "medium", "confidence": 0.8, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/scripts/start-agent-viewer.mjs"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-152826cd4c1d9b79", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in skills/implicit-cad/scripts/export.mjs:2"}, "properties": {"repobilityId": "8427c21bf270554d", "scanner": "scanner-primary", "fingerprint": "152826cd4c1d9b79", "layer": "security", "severity": "medium", "confidence": 0.8, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/implicit-cad/scripts/export.mjs"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-c4f3debab76441f8", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in plugins/cad/skills/implicit-cad/scripts/export.mjs:2"}, "properties": {"repobilityId": "3006bc3f76c29eee", "scanner": "scanner-primary", "fingerprint": "c4f3debab76441f8", "layer": "security", "severity": "medium", "confidence": 0.8, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/implicit-cad/scripts/export.mjs"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-7efbda965f283c17", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "56929525eac9a554", "scanner": "scanner-primary", "fingerprint": "7efbda965f283c17", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/test.yml"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-902782b3d73e83c7", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "44b51cf4fe1be2dc", "scanner": "scanner-primary", "fingerprint": "902782b3d73e83c7", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/upload-models.yml"}, "region": {"startLine": 32}}}]}, {"ruleId": "scanner-46c644c6227e4d4a", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "2644034c718fb80d", "scanner": "scanner-primary", "fingerprint": "46c644c6227e4d4a", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yml"}, "region": {"startLine": 71}}}]}, {"ruleId": "scanner-1838a141491ce38c", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "b8fd4f5048f96576", "scanner": "scanner-primary", "fingerprint": "1838a141491ce38c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-de39ac9e5cbf2f3d", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "4efcc5a9a318b5fa", "scanner": "scanner-primary", "fingerprint": "de39ac9e5cbf2f3d", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy-docs.yml"}, "region": {"startLine": 32}}}]}, {"ruleId": "scanner-25e2699bb316c8bb", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "f013affde30a6f35", "scanner": "scanner-primary", "fingerprint": "25e2699bb316c8bb", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy-viewer.yml"}, "region": {"startLine": 32}}}]}, {"ruleId": "scanner-a6508654f974a260", "level": "note", "message": {"text": "Very large file: tests/python/skills/cad/cadpy/test_generation.py (2691 lines)"}, "properties": {"repobilityId": "67aef881d0a3e062", "scanner": "scanner-primary", "fingerprint": "a6508654f974a260", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-4c64e55796dc96cd", "level": "note", "message": {"text": "Very large file: viewer/packages/implicitjs/src/common/themeSettings.js (1717 lines)"}, "properties": {"repobilityId": "dbe9de93070dd083", "scanner": "scanner-primary", "fingerprint": "4c64e55796dc96cd", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-170a2ecf138ea84c", "level": "note", "message": {"text": "Very large file: viewer/packages/implicitjs/src/lib/implicitCad/render.js (1966 lines)"}, "properties": {"repobilityId": "64ef198200cb9fc2", "scanner": "scanner-primary", "fingerprint": "170a2ecf138ea84c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-aa1481e55e3fad0b", "level": "note", "message": {"text": "Very large file: viewer/packages/cadpy/src/cadpy/generation.py (2351 lines)"}, "properties": {"repobilityId": "0c8a50973aa3bd32", "scanner": "scanner-primary", "fingerprint": "aa1481e55e3fad0b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-124ba8bf3c8dd41d", "level": "note", "message": {"text": "Very large file: viewer/packages/cadpy/src/cadpy/assembly_composition.py (1269 lines)"}, "properties": {"repobilityId": "e529a1583b510bf2", "scanner": "scanner-primary", "fingerprint": "124ba8bf3c8dd41d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-e2aca858fc2ac90d", "level": "note", "message": {"text": "Very large file: viewer/packages/cadpy/src/cadpy/step_scene.py (2626 lines)"}, "properties": {"repobilityId": "fe1c7f773f9a8bc7", "scanner": "scanner-primary", "fingerprint": "e2aca858fc2ac90d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-8768c4820189b7cc", "level": "note", "message": {"text": "Very large file: viewer/packages/cadjs/src/common/cadScene.js (2203 lines)"}, "properties": {"repobilityId": "56c6d4007b829b89", "scanner": "scanner-primary", "fingerprint": "8768c4820189b7cc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-15b90e80e537fda3", "level": "note", "message": {"text": "Very large file: viewer/packages/cadjs/src/common/themeSettings.js (1688 lines)"}, "properties": {"repobilityId": "becbe525c9e3c19e", "scanner": "scanner-primary", "fingerprint": "15b90e80e537fda3", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-435be0071336741c", "level": "note", "message": {"text": "Very large file: viewer/src/client/components/CadViewer.js (4793 lines)"}, "properties": {"repobilityId": "16b630915bca5199", "scanner": "scanner-primary", "fingerprint": "435be0071336741c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-fb1885d70fe51d47", "level": "note", "message": {"text": "Very large file: viewer/src/client/components/CadWorkspace.js (9109 lines)"}, "properties": {"repobilityId": "d66c7744e905ecb6", "scanner": "scanner-primary", "fingerprint": "fb1885d70fe51d47", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6e75f95f099f9591", "level": "note", "message": {"text": "Very large file: viewer/src/client/components/viewer/hooks/useViewerPicking.js (1422 lines)"}, "properties": {"repobilityId": "ac58de02bf4a34d3", "scanner": "scanner-primary", "fingerprint": "6e75f95f099f9591", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ab7a16bbaed7d1d4", "level": "note", "message": {"text": "Very large file: viewer/src/client/components/workbench/StepFileSheet.js (1702 lines)"}, "properties": {"repobilityId": "13f5f4c33847cf0f", "scanner": "scanner-primary", "fingerprint": "ab7a16bbaed7d1d4", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-f6343683cdeac37e", "level": "note", "message": {"text": "Very large file: viewer/src/client/components/workbench/ThemeSettingsPopover.js (2438 lines)"}, "properties": {"repobilityId": "11d3945b6416a3e4", "scanner": "scanner-primary", "fingerprint": "f6343683cdeac37e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-d6a2abbf4e908024", "level": "note", "message": {"text": "Very large file: viewer/src/client/workbench/sidebar.test.js (2339 lines)"}, "properties": {"repobilityId": "96e72f3f60144449", "scanner": "scanner-primary", "fingerprint": "d6a2abbf4e908024", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-12d4bb3111539653", "level": "note", "message": {"text": "Very large file: packages/implicitjs/src/common/themeSettings.js (1717 lines)"}, "properties": {"repobilityId": "c59a7735753c3f4e", "scanner": "scanner-primary", "fingerprint": "12d4bb3111539653", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-8df87a654993863a", "level": "note", "message": {"text": "Very large file: packages/implicitjs/src/lib/implicitCad/render.js (1966 lines)"}, "properties": {"repobilityId": "f6cc662a05c383d1", "scanner": "scanner-primary", "fingerprint": "8df87a654993863a", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-8e5708095bd6e43b", "level": "note", "message": {"text": "Very large file: packages/cadpy/src/cadpy/generation.py (2351 lines)"}, "properties": {"repobilityId": "9570cae0f49ab1c1", "scanner": "scanner-primary", "fingerprint": "8e5708095bd6e43b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-de12f40332065f3c", "level": "note", "message": {"text": "Very large file: packages/cadpy/src/cadpy/assembly_composition.py (1269 lines)"}, "properties": {"repobilityId": "b84ce085c4fa538a", "scanner": "scanner-primary", "fingerprint": "de12f40332065f3c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ceb7842db8055be4", "level": "note", "message": {"text": "Very large file: packages/cadpy/src/cadpy/step_scene.py (2626 lines)"}, "properties": {"repobilityId": "8c515a63bbd775db", "scanner": "scanner-primary", "fingerprint": "ceb7842db8055be4", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-5271ba38c42aea2c", "level": "note", "message": {"text": "Very large file: packages/cadjs/src/common/cadScene.js (2203 lines)"}, "properties": {"repobilityId": "f606c597218e4d83", "scanner": "scanner-primary", "fingerprint": "5271ba38c42aea2c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-4a3a06b0da47872e", "level": "note", "message": {"text": "Very large file: packages/cadjs/src/common/themeSettings.js (1688 lines)"}, "properties": {"repobilityId": "16bcc48bbb709312", "scanner": "scanner-primary", "fingerprint": "4a3a06b0da47872e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-3586ee1c277f02f7", "level": "note", "message": {"text": "Very large file: skills/bambu-labs/scripts/bambu_lan_print.py (1771 lines)"}, "properties": {"repobilityId": "b2e7570eb3bc8c85", "scanner": "scanner-primary", "fingerprint": "3586ee1c277f02f7", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-289cf415e665db42", "level": "note", "message": {"text": "Very large file: skills/cad-viewer/scripts/viewer/packages/implicitjs/src/common/themeSettings.js (1717 lines)"}, "properties": {"repobilityId": "21780fdd130cc192", "scanner": "scanner-primary", "fingerprint": "289cf415e665db42", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-917f44a7e0020d51", "level": "note", "message": {"text": "Very large file: skills/cad-viewer/scripts/viewer/packages/implicitjs/src/lib/implicitCad/render.js (1966 lines)"}, "properties": {"repobilityId": "cd02054f642a3e14", "scanner": "scanner-primary", "fingerprint": "917f44a7e0020d51", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-b7ae46ea17dadcfa", "level": "note", "message": {"text": "Very large file: skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/generation.py (2351 lines)"}, "properties": {"repobilityId": "4efc6f75e048cb10", "scanner": "scanner-primary", "fingerprint": "b7ae46ea17dadcfa", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-4c0236823a1fa6aa", "level": "note", "message": {"text": "Very large file: skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/assembly_composition.py (1269 lines)"}, "properties": {"repobilityId": "12ab987cc22b216a", "scanner": "scanner-primary", "fingerprint": "4c0236823a1fa6aa", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-0e74cafcc8ff6cde", "level": "note", "message": {"text": "Very large file: skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/step_scene.py (2626 lines)"}, "properties": {"repobilityId": "7b293f5bb1eade1a", "scanner": "scanner-primary", "fingerprint": "0e74cafcc8ff6cde", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-7d602eaebfd371eb", "level": "note", "message": {"text": "Very large file: skills/cad-viewer/scripts/viewer/packages/cadjs/src/common/cadScene.js (2203 lines)"}, "properties": {"repobilityId": "eae9f521d62cfc80", "scanner": "scanner-primary", "fingerprint": "7d602eaebfd371eb", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-e2667b787a2a6e44", "level": "note", "message": {"text": "Very large file: skills/cad-viewer/scripts/viewer/packages/cadjs/src/common/themeSettings.js (1688 lines)"}, "properties": {"repobilityId": "bbe9e7e8b40788e2", "scanner": "scanner-primary", "fingerprint": "e2667b787a2a6e44", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-55ce51fbf1f60847", "level": "note", "message": {"text": "Very large file: skills/dxf/scripts/packages/cadpy/src/cadpy/generation.py (2351 lines)"}, "properties": {"repobilityId": "e3e78d07c1689072", "scanner": "scanner-primary", "fingerprint": "55ce51fbf1f60847", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-466aff75171e01d6", "level": "note", "message": {"text": "Very large file: skills/dxf/scripts/packages/cadpy/src/cadpy/assembly_composition.py (1269 lines)"}, "properties": {"repobilityId": "5191b7509044db9a", "scanner": "scanner-primary", "fingerprint": "466aff75171e01d6", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-8f01973a96acab13", "level": "note", "message": {"text": "Very large file: skills/dxf/scripts/packages/cadpy/src/cadpy/step_scene.py (2626 lines)"}, "properties": {"repobilityId": "a9e01a965f924c36", "scanner": "scanner-primary", "fingerprint": "8f01973a96acab13", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-d3c2b00b6e41866b", "level": "note", "message": {"text": "Very large file: skills/cad/scripts/packages/cadpy/src/cadpy/generation.py (2351 lines)"}, "properties": {"repobilityId": "94d67fee5472bb65", "scanner": "scanner-primary", "fingerprint": "d3c2b00b6e41866b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-fb46b65256203ab8", "level": "note", "message": {"text": "Very large file: skills/cad/scripts/packages/cadpy/src/cadpy/assembly_composition.py (1269 lines)"}, "properties": {"repobilityId": "9c9aac9f90e8c3d6", "scanner": "scanner-primary", "fingerprint": "fb46b65256203ab8", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ee5700d2aec5094d", "level": "note", "message": {"text": "Very large file: skills/cad/scripts/packages/cadpy/src/cadpy/step_scene.py (2626 lines)"}, "properties": {"repobilityId": "93d3658286fc1a92", "scanner": "scanner-primary", "fingerprint": "ee5700d2aec5094d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-a70c095fecf45001", "level": "note", "message": {"text": "Very large file: skills/cad/scripts/snapshot/runtime/snapshot-render.js (4168 lines)"}, "properties": {"repobilityId": "755f5f87f2b4555e", "scanner": "scanner-primary", "fingerprint": "a70c095fecf45001", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-a0f2e847920a2567", "level": "note", "message": {"text": "Very large file: skills/implicit-cad/scripts/packages/implicitjs/src/common/themeSettings.js (1717 lines)"}, "properties": {"repobilityId": "159256d425148f9a", "scanner": "scanner-primary", "fingerprint": "a0f2e847920a2567", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-4aa39507b6f379e5", "level": "note", "message": {"text": "Very large file: skills/implicit-cad/scripts/packages/implicitjs/src/lib/implicitCad/render.js (1966 lines)"}, "properties": {"repobilityId": "70338bb671a506ba", "scanner": "scanner-primary", "fingerprint": "4aa39507b6f379e5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-d8a6c7663679573f", "level": "note", "message": {"text": "Very large file: plugins/cad/skills/bambu-labs/scripts/bambu_lan_print.py (1771 lines)"}, "properties": {"repobilityId": "7b833a313b8bb730", "scanner": "scanner-primary", "fingerprint": "d8a6c7663679573f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-95f0070981bf3195", "level": "note", "message": {"text": "Very large file: plugins/cad/skills/cad-viewer/scripts/viewer/packages/implicitjs/src/common/themeSettings.js (1717 lines)"}, "properties": {"repobilityId": "86f547f11a3aa8b7", "scanner": "scanner-primary", "fingerprint": "95f0070981bf3195", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-3e389137eaa4783d", "level": "note", "message": {"text": "Very large file: plugins/cad/skills/cad-viewer/scripts/viewer/packages/implicitjs/src/lib/implicitCad/render.js (1966 lines)"}, "properties": {"repobilityId": "b14edd4aa5d7c89b", "scanner": "scanner-primary", "fingerprint": "3e389137eaa4783d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-780f3f6f2bb8a3cb", "level": "note", "message": {"text": "Very large file: plugins/cad/skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/generation.py (2351 lines)"}, "properties": {"repobilityId": "505410d46c61c46f", "scanner": "scanner-primary", "fingerprint": "780f3f6f2bb8a3cb", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-bdd6c2402ad60472", "level": "note", "message": {"text": "Very large file: plugins/cad/skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/assembly_composition.py (1269 lines)"}, "properties": {"repobilityId": "9d57386e2392b0eb", "scanner": "scanner-primary", "fingerprint": "bdd6c2402ad60472", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-7972c48ce431fef2", "level": "note", "message": {"text": "Very large file: plugins/cad/skills/cad-viewer/scripts/viewer/packages/cadpy/src/cadpy/step_scene.py (2626 lines)"}, "properties": {"repobilityId": "b9370a664053970d", "scanner": "scanner-primary", "fingerprint": "7972c48ce431fef2", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-685a1f827540aae8", "level": "note", "message": {"text": "Very large file: plugins/cad/skills/cad-viewer/scripts/viewer/packages/cadjs/src/common/cadScene.js (2203 lines)"}, "properties": {"repobilityId": "2390a8cb2412c5e6", "scanner": "scanner-primary", "fingerprint": "685a1f827540aae8", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-21235ac67d58e7a5", "level": "note", "message": {"text": "Very large file: plugins/cad/skills/cad-viewer/scripts/viewer/packages/cadjs/src/common/themeSettings.js (1688 lines)"}, "properties": {"repobilityId": "dfc3586f94ffa474", "scanner": "scanner-primary", "fingerprint": "21235ac67d58e7a5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-02d4a7e0ee2b6372", "level": "note", "message": {"text": "Very large file: plugins/cad/skills/dxf/scripts/packages/cadpy/src/cadpy/generation.py (2351 lines)"}, "properties": {"repobilityId": "8c00a0e2399d071d", "scanner": "scanner-primary", "fingerprint": "02d4a7e0ee2b6372", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-5768b4eb4039b050", "level": "note", "message": {"text": "Very large file: plugins/cad/skills/dxf/scripts/packages/cadpy/src/cadpy/assembly_composition.py (1269 lines)"}, "properties": {"repobilityId": "3a4dfef17de6011a", "scanner": "scanner-primary", "fingerprint": "5768b4eb4039b050", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-60a4917bbefdc336", "level": "note", "message": {"text": "Very large file: plugins/cad/skills/dxf/scripts/packages/cadpy/src/cadpy/step_scene.py (2626 lines)"}, "properties": {"repobilityId": "d7290c4c8497b575", "scanner": "scanner-primary", "fingerprint": "60a4917bbefdc336", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-da96ce28c8b3ef1e", "level": "note", "message": {"text": "Very large file: plugins/cad/skills/cad/scripts/packages/cadpy/src/cadpy/generation.py (2351 lines)"}, "properties": {"repobilityId": "8f474cfed9cd42e4", "scanner": "scanner-primary", "fingerprint": "da96ce28c8b3ef1e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-c6fb838c41c4aa6e", "level": "note", "message": {"text": "Very large file: plugins/cad/skills/cad/scripts/packages/cadpy/src/cadpy/assembly_composition.py (1269 lines)"}, "properties": {"repobilityId": "713bead4bdb41863", "scanner": "scanner-primary", "fingerprint": "c6fb838c41c4aa6e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-1db9bf5946c60148", "level": "note", "message": {"text": "Very large file: plugins/cad/skills/cad/scripts/packages/cadpy/src/cadpy/step_scene.py (2626 lines)"}, "properties": {"repobilityId": "2380ea4ace8e9d5a", "scanner": "scanner-primary", "fingerprint": "1db9bf5946c60148", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-18d59ee0655479fc", "level": "note", "message": {"text": "Very large file: plugins/cad/skills/cad/scripts/snapshot/runtime/snapshot-render.js (4168 lines)"}, "properties": {"repobilityId": "69428f557758e807", "scanner": "scanner-primary", "fingerprint": "18d59ee0655479fc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-5652350ece16f478", "level": "note", "message": {"text": "Very large file: plugins/cad/skills/implicit-cad/scripts/packages/implicitjs/src/common/themeSettings.js (1717 lines)"}, "properties": {"repobilityId": "270c231c08caa920", "scanner": "scanner-primary", "fingerprint": "5652350ece16f478", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-19624b341bb374ae", "level": "note", "message": {"text": "Very large file: plugins/cad/skills/implicit-cad/scripts/packages/implicitjs/src/lib/implicitCad/render.js (1966 lines)"}, "properties": {"repobilityId": "037204d5170c6bb5", "scanner": "scanner-primary", "fingerprint": "19624b341bb374ae", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ea3b5e389d8c9c0f", "level": "note", "message": {"text": "Low test-to-source ratio"}, "properties": {"repobilityId": "ef7b2552cc00a375", "scanner": "scanner-primary", "fingerprint": "ea3b5e389d8c9c0f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["tests"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "306c00768a228674", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "2feb27923603dc4b", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-06a39bd4b787b4e0", "level": "note", "message": {"text": "Legacy-named symbol `final_joint_values_legacy` in viewer/moveit2_server/moveit2_server/moveit_py.py:571"}, "properties": {"repobilityId": "5ec10861671c79ba", "scanner": "scanner-primary", "fingerprint": "06a39bd4b787b4e0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-ce89f17357f8ebc2", "level": "warning", "message": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 viewer/src/client/components/CadWorkspace.js:1746"}, "properties": {"repobilityId": "274c09c3c676a657", "scanner": "scanner-primary", "fingerprint": "ce89f17357f8ebc2", "layer": "quality", "severity": "medium", "confidence": 0.9, "tags": ["integrity", "fragile-runtime", "robustness", "unhandled-promise"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/src/client/components/CadWorkspace.js"}, "region": {"startLine": 1746}}}]}, {"ruleId": "scanner-c9221aa13cee5e9f", "level": "warning", "message": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 viewer/src/client/components/workbench/CadWorkspaceTopBar.js:834"}, "properties": {"repobilityId": "778a37ada0918f94", "scanner": "scanner-primary", "fingerprint": "c9221aa13cee5e9f", "layer": "quality", "severity": "medium", "confidence": 0.9, "tags": ["integrity", "fragile-runtime", "robustness", "unhandled-promise"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/src/client/components/workbench/CadWorkspaceTopBar.js"}, "region": {"startLine": 834}}}]}, {"ruleId": "scanner-08313ad176f50327", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 skills/bambu-labs/scripts/bambu_lan_print.py:580"}, "properties": {"repobilityId": "497d92c98dc9f369", "scanner": "scanner-primary", "fingerprint": "08313ad176f50327", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/bambu-labs/scripts/bambu_lan_print.py"}, "region": {"startLine": 580}}}]}, {"ruleId": "scanner-7904709fc9ad867d", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 skills/gcode/scripts/gcode_tool.py:528"}, "properties": {"repobilityId": "d3642fbb7cb83e25", "scanner": "scanner-primary", "fingerprint": "7904709fc9ad867d", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/gcode/scripts/gcode_tool.py"}, "region": {"startLine": 528}}}]}, {"ruleId": "scanner-12b9fe356b6f0553", "level": "note", "message": {"text": "Legacy-named symbol `final_joint_values_legacy` in skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/moveit_py.py:571"}, "properties": {"repobilityId": "4089877d5b0cef1e", "scanner": "scanner-primary", "fingerprint": "12b9fe356b6f0553", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-2d20f4c07e3088c4", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 plugins/cad/skills/bambu-labs/scripts/bambu_lan_print.py:580"}, "properties": {"repobilityId": "577babc97e3f9c23", "scanner": "scanner-primary", "fingerprint": "2d20f4c07e3088c4", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/bambu-labs/scripts/bambu_lan_print.py"}, "region": {"startLine": 580}}}]}, {"ruleId": "scanner-1c0c4372b6aaecfe", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 plugins/cad/skills/gcode/scripts/gcode_tool.py:528"}, "properties": {"repobilityId": "4c5a8221a48ee6d2", "scanner": "scanner-primary", "fingerprint": "1c0c4372b6aaecfe", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cad/skills/gcode/scripts/gcode_tool.py"}, "region": {"startLine": 528}}}]}, {"ruleId": "scanner-d49b34c6024a9039", "level": "note", "message": {"text": "Legacy-named symbol `final_joint_values_legacy` in plugins/cad/skills/cad-viewer/scripts/viewer/moveit2_server/moveit2_server/moveit_py.py:571"}, "properties": {"repobilityId": "73251f0719ccd915", "scanner": "scanner-primary", "fingerprint": "d49b34c6024a9039", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-51dbf90b6ad9e4e9", "level": "note", "message": {"text": "28 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "b01aa43f6ad2a3c8", "scanner": "scanner-primary", "fingerprint": "51dbf90b6ad9e4e9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "d802fab3cc472030", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-02525d39071dd2c7", "level": "note", "message": {"text": "Near-duplicate function bodies in 5 places"}, "properties": {"repobilityId": "57bec0930b38b1f3", "scanner": "scanner-primary", "fingerprint": "02525d39071dd2c7", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-76a2f6818267a9a8", "level": "note", "message": {"text": "Near-duplicate function bodies in 8 places"}, "properties": {"repobilityId": "163c980184d103bc", "scanner": "scanner-primary", "fingerprint": "76a2f6818267a9a8", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-fcd88a91331f7152", "level": "warning", "message": {"text": "Vulnerable dependency next 16.2.6: GHSA-4633-3j49-mh5q"}, "properties": {"repobilityId": "f2131d725e7f98ff", "scanner": "scanner-primary", "fingerprint": "fcd88a91331f7152", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4633-3j49-mh5q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-80eab56388ed30be", "level": "warning", "message": {"text": "Vulnerable dependency next 16.2.6: GHSA-4c39-4ccg-62r3"}, "properties": {"repobilityId": "ab5234e8fb7d29fe", "scanner": "scanner-primary", "fingerprint": "80eab56388ed30be", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4c39-4ccg-62r3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e1e683399882b8ec", "level": "warning", "message": {"text": "Vulnerable dependency next 16.2.6: GHSA-68g3-v927-f742"}, "properties": {"repobilityId": "26eec69746a11982", "scanner": "scanner-primary", "fingerprint": "e1e683399882b8ec", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-68g3-v927-f742"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6ab6bca6566112d2", "level": "error", "message": {"text": "Vulnerable dependency next 16.2.6: GHSA-6gpp-xcg3-4w24"}, "properties": {"repobilityId": "75a670d12eed4370", "scanner": "scanner-primary", "fingerprint": "6ab6bca6566112d2", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6gpp-xcg3-4w24"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-94f3890042c63abc", "level": "error", "message": {"text": "Vulnerable dependency next 16.2.6: GHSA-89xv-2m56-2m9x"}, "properties": {"repobilityId": "e2c042176e3131e7", "scanner": "scanner-primary", "fingerprint": "94f3890042c63abc", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-89xv-2m56-2m9x"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6b662c7a3d2e19cb", "level": "warning", "message": {"text": "Vulnerable dependency next 16.2.6: GHSA-955p-x3mx-jcvp"}, "properties": {"repobilityId": "beb917771eb8a8f2", "scanner": "scanner-primary", "fingerprint": "6b662c7a3d2e19cb", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-955p-x3mx-jcvp"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e62d23b157c9a09d", "level": "warning", "message": {"text": "Vulnerable dependency next 16.2.6: GHSA-m99w-x7hq-7vfj"}, "properties": {"repobilityId": "669e2f284ca41a1f", "scanner": "scanner-primary", "fingerprint": "e62d23b157c9a09d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-m99w-x7hq-7vfj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9d1d446ac129f3ea", "level": "warning", "message": {"text": "Vulnerable dependency next 16.2.6: GHSA-p9j2-gv94-2wf4"}, "properties": {"repobilityId": "025c578dcfb34c82", "scanner": "scanner-primary", "fingerprint": "9d1d446ac129f3ea", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p9j2-gv94-2wf4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a1284fe66dbb33d2", "level": "warning", "message": {"text": "Vulnerable dependency next 16.2.6: GHSA-q8wf-6r8g-63ch"}, "properties": {"repobilityId": "93e83bd7b4e57ddd", "scanner": "scanner-primary", "fingerprint": "a1284fe66dbb33d2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-q8wf-6r8g-63ch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ea7d421f6b7b4f8e", "level": "error", "message": {"text": "Vulnerable dependency vite 7.3.2: GHSA-fx2h-pf6j-xcff"}, "properties": {"repobilityId": "f0ee3826af2798f2", "scanner": "scanner-primary", "fingerprint": "ea7d421f6b7b4f8e", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-fx2h-pf6j-xcff", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e5eafff954911c18", "level": "warning", "message": {"text": "Vulnerable dependency vite 7.3.2: GHSA-v6wh-96g9-6wx3"}, "properties": {"repobilityId": "1c8709f8303b6b6d", "scanner": "scanner-primary", "fingerprint": "e5eafff954911c18", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-v6wh-96g9-6wx3", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a6c08e5a91b069c1", "level": "note", "message": {"text": "Vulnerable dependency @babel/core 7.29.0: GHSA-4x5r-pxfx-6jf8"}, "properties": {"repobilityId": "048ec5a9afac1732", "scanner": "scanner-primary", "fingerprint": "a6c08e5a91b069c1", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-4x5r-pxfx-6jf8", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6d8a804adf77ba47", "level": "warning", "message": {"text": "Vulnerable dependency @hono/node-server 1.19.14: GHSA-frvp-7c67-39w9"}, "properties": {"repobilityId": "e20a828d2748b708", "scanner": "scanner-primary", "fingerprint": "6d8a804adf77ba47", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-frvp-7c67-39w9", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b4c6a6664d1c8fd9", "level": "error", "message": {"text": "Vulnerable dependency brace-expansion 5.0.6: GHSA-3jxr-9vmj-r5cp"}, "properties": {"repobilityId": "d33b0db2b7d6b674", "scanner": "scanner-primary", "fingerprint": "b4c6a6664d1c8fd9", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3jxr-9vmj-r5cp", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9c11d20bbac49914", "level": "warning", "message": {"text": "Vulnerable dependency body-parser 2.2.2: GHSA-v422-hmwv-36x6"}, "properties": {"repobilityId": "33169ae6017d1ec9", "scanner": "scanner-primary", "fingerprint": "9c11d20bbac49914", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-v422-hmwv-36x6", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4db38ba4a1720c6f", "level": "error", "message": {"text": "Vulnerable dependency brace-expansion 1.1.14: GHSA-3jxr-9vmj-r5cp"}, "properties": {"repobilityId": "579bbb43dc72a04b", "scanner": "scanner-primary", "fingerprint": "4db38ba4a1720c6f", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3jxr-9vmj-r5cp", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d715a24db302912b", "level": "error", "message": {"text": "Vulnerable dependency fast-uri 3.1.2: GHSA-4c8g-83qw-93j6"}, "properties": {"repobilityId": "b415b1056beb5b08", "scanner": "scanner-primary", "fingerprint": "d715a24db302912b", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-4c8g-83qw-93j6", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2de1735eb417ad38", "level": "warning", "message": {"text": "Vulnerable dependency fast-uri 3.1.2: GHSA-v2hh-gcrm-f6hx"}, "properties": {"repobilityId": "963ee1409fedeb90", "scanner": "scanner-primary", "fingerprint": "2de1735eb417ad38", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-v2hh-gcrm-f6hx", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4a897fa1c54a1f18", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.18: GHSA-2gcr-mfcq-wcc3"}, "properties": {"repobilityId": "18a2570839adf7c5", "scanner": "scanner-primary", "fingerprint": "4a897fa1c54a1f18", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-2gcr-mfcq-wcc3", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5ecca733bf9aa8ea", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.18: GHSA-3hrh-pfw6-9m5x"}, "properties": {"repobilityId": "ed383a01c7512411", "scanner": "scanner-primary", "fingerprint": "5ecca733bf9aa8ea", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3hrh-pfw6-9m5x", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e453f92995f3b230", "level": "error", "message": {"text": "Vulnerable dependency hono 4.12.18: GHSA-88fw-hqm2-52qc"}, "properties": {"repobilityId": "3b0bec6651c6c5ba", "scanner": "scanner-primary", "fingerprint": "e453f92995f3b230", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-88fw-hqm2-52qc", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-49a1c53717ada9dc", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.18: GHSA-f577-qrjj-4474"}, "properties": {"repobilityId": "cfbf39f631d0e178", "scanner": "scanner-primary", "fingerprint": "49a1c53717ada9dc", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-f577-qrjj-4474", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-40c3422ea68dfc3c", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.18: GHSA-hvrm-45r6-mjfj"}, "properties": {"repobilityId": "6875077d9ccc0b49", "scanner": "scanner-primary", "fingerprint": "40c3422ea68dfc3c", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-hvrm-45r6-mjfj", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-27ab2b4ac9df19be", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.18: GHSA-j6c9-x7qj-28xf"}, "properties": {"repobilityId": "7b740462fb78e373", "scanner": "scanner-primary", "fingerprint": "27ab2b4ac9df19be", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-j6c9-x7qj-28xf", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-da48c9f20491ca11", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.18: GHSA-rv63-4mwf-qqc2"}, "properties": {"repobilityId": "c1a97129d33cda95", "scanner": "scanner-primary", "fingerprint": "da48c9f20491ca11", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-rv63-4mwf-qqc2", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e30e4930c54d98ae", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.18: GHSA-w62v-xxxg-mg59"}, "properties": {"repobilityId": "810b00e45a5e0844", "scanner": "scanner-primary", "fingerprint": "e30e4930c54d98ae", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-w62v-xxxg-mg59", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a7a76ffb56ac0eec", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.18: GHSA-wgpf-jwqj-8h8p"}, "properties": {"repobilityId": "d36875caeac724c7", "scanner": "scanner-primary", "fingerprint": "a7a76ffb56ac0eec", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-wgpf-jwqj-8h8p", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b8b9a587bf2c1ef5", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.18: GHSA-wwfh-h76j-fc44"}, "properties": {"repobilityId": "00aa3dfdf47e7e7d", "scanner": "scanner-primary", "fingerprint": "b8b9a587bf2c1ef5", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-wwfh-h76j-fc44", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bc66d4a10f6c12ce", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.18: GHSA-xgm2-5f3f-mvvc"}, "properties": {"repobilityId": "b0e5364d4bdacd89", "scanner": "scanner-primary", "fingerprint": "bc66d4a10f6c12ce", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-xgm2-5f3f-mvvc", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-de487e03ef8324a9", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.12.18: GHSA-xrhx-7g5j-rcj5"}, "properties": {"repobilityId": "68110c8701279da4", "scanner": "scanner-primary", "fingerprint": "de487e03ef8324a9", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-xrhx-7g5j-rcj5", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0fd75dc417cf8964", "level": "note", "message": {"text": "Dependency react-dom is a major version behind"}, "properties": {"repobilityId": "6c99217f4871dd0d", "scanner": "scanner-primary", "fingerprint": "0fd75dc417cf8964", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cdacbe3b9cec2a0f", "level": "note", "message": {"text": "Dependency react is a major version behind"}, "properties": {"repobilityId": "b211861090c57ddb", "scanner": "scanner-primary", "fingerprint": "cdacbe3b9cec2a0f", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-979034ad6535a75c", "level": "warning", "message": {"text": "Dangling fetch: POST /__cad/implicit-export?file=${encodeURIComponent(fileRef)}&format=${encodeURIComponent(exportFormat)} (viewer/src/client/workbench/implicitExport.js:34)"}, "properties": {"repobilityId": "31e2baba1198af2c", "scanner": "scanner-primary", "fingerprint": "979034ad6535a75c", "layer": "api", "severity": "medium", "confidence": 0.55, "tags": ["wiring", "dangling-fetch", "fetch", "non-production-context", "development-endpoint"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "viewer/src/client/workbench/implicitExport.js"}, "region": {"startLine": 34}}}]}, {"ruleId": "scanner-7f2f781df81936ce", "level": "note", "message": {"text": "6 backend endpoints not called by scanned frontend"}, "properties": {"repobilityId": "3c8e96670c5e1f9f", "scanner": "scanner-primary", "fingerprint": "7f2f781df81936ce", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}