{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-4a812742fd7fa6c5", "name": "Possibly dead Python function: check_url", "shortDescription": {"text": "Possibly dead Python function: check_url"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-de021663e5cd9a35", "name": "Possibly dead Python function: tokenize_jsonl_path", "shortDescription": {"text": "Possibly dead Python function: tokenize_jsonl_path"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be50a9b7fa2d9148", "name": "Possibly dead Python function: unsafe", "shortDescription": {"text": "Possibly dead Python function: unsafe"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d8a76ca146ebdb64", "name": "Possibly dead Python function: safe", "shortDescription": {"text": "Possibly dead Python function: safe"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7d1c499b5f334e72", "name": "Possibly dead Python function: tool_run_shell", "shortDescription": {"text": "Possibly dead Python function: tool_run_shell"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-98d4db7dfc6bc0f5", "name": "Possibly dead Python function: destructive_guard", "shortDescription": {"text": "Possibly dead Python function: destructive_guard"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-173c6078fa951fb7", "name": "Possibly dead Python function: synthetic_loader", "shortDescription": {"text": "Possibly dead Python function: synthetic_loader"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cd23e412e8161988", "name": "Possibly dead Python function: rank_main", "shortDescription": {"text": "Possibly dead Python function: rank_main"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e5b150cc4bc96803", "name": "Possibly dead Python function: write_response", "shortDescription": {"text": "Possibly dead Python function: write_response"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ce52a9913333dfc3", "name": "Possibly dead Python function: apply_known_fixes", "shortDescription": {"text": "Possibly dead Python function: apply_known_fixes"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5b4a787aaaa91e92", "name": "Possibly dead Python function: noop_candidate", "shortDescription": {"text": "Possibly dead Python function: noop_candidate"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-68c154aef3525fd1", "name": "Possibly dead Python function: reverse_list", "shortDescription": {"text": "Possibly dead Python function: reverse_list"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3e65786ffb3f40dd", "name": "Possibly dead Python function: reverse_list", "shortDescription": {"text": "Possibly dead Python function: reverse_list"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2600512e42a18b57", "name": "Possibly dead Python function: fizzbuzz", "shortDescription": {"text": "Possibly dead Python function: fizzbuzz"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ce229413542e8500", "name": "Possibly dead Python function: fizzbuzz", "shortDescription": {"text": "Possibly dead Python function: fizzbuzz"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ce935002d5258301", "name": "Possibly dead Python function: linked_list_length", "shortDescription": {"text": "Possibly dead Python function: linked_list_length"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa75e63ce1991472", "name": "Possibly dead Python function: linked_list_length", "shortDescription": {"text": "Possibly dead Python function: linked_list_length"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-697550bc1acaf330", "name": "Possibly dead Python function: baseline_pipeline", "shortDescription": {"text": "Possibly dead Python function: baseline_pipeline"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9b79afc69e633d93", "name": "Possibly dead Python function: hybrid_plus_rerank_pipeline", "shortDescription": {"text": "Possibly dead Python function: hybrid_plus_rerank_pipeline"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5f37af56efc4f07d", "name": "Possibly dead Python function: inject_inf_into_first_grad", "shortDescription": {"text": "Possibly dead Python function: inject_inf_into_first_grad"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-06702fdeeb246417", "name": "Possibly dead Python function: deterministic_expander", "shortDescription": {"text": "Possibly dead Python function: deterministic_expander"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-90db289ef1bed21a", "name": "Possibly dead Python function: to_envelope", "shortDescription": {"text": "Possibly dead Python function: to_envelope"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a87fb8b39ed0c8c0", "name": "Stray `console.log` in TS/JS \u2014 site/build.js:416", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 site/build.js:416"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a237b75f9f872a1d", "name": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/08-production-rag-chatbot/code/ts/src/index.ts:52", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/08-production-rag-chatbot/code/ts/src/index.ts:52"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ec077f27a21aea96", "name": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/10-multi-agent-software-team/code/ts/tests/runtime.test.ts:46", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/10-multi-agent-software-team/code/ts/tests/runtime.test.ts:46"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-826d20092d689444", "name": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/10-multi-agent-software-team/code/ts/src/index.ts:17", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/10-multi-agent-software-team/code/ts/src/index.ts:17"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0adff22e10741564", "name": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/06-devops-troubleshooting-agent/code/ts/src/index.ts:59", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/06-devops-troubleshooting-agent/code/ts/src/index.ts:59"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cb1678f2c0a213de", "name": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/01-terminal-native-coding-agent/code/ts/src/index.ts:32", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/01-terminal-native-coding-agent/code/ts/src/index.ts:32"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6ae8c68dc7dff908", "name": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/01-terminal-native-coding-agent/code/ts/src/repl.ts:39", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/01-terminal-native-coding-agent/code/ts/src/repl.ts:39"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3cd87cd024c11ef3", "name": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/04-multimodal-document-qa/code/ts/src/index.ts:47", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/04-multimodal-document-qa/code/ts/src/index.ts:47"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-49e7681b82418f8a", "name": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/09-code-migration-agent/code/ts/src/index.ts:19", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/09-code-migration-agent/code/ts/src/index.ts:19"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1412d3263bb2624b", "name": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/11-llm-observability-dashboard/code/ts/src/index.ts:67", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/11-llm-observability-dashboard/code/ts/src/index.ts:67"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0cd3758c93741fee", "name": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/02-rag-over-codebase/code/ts/src/index.ts:81", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/02-rag-over-codebase/code/ts/src/index.ts:81"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3302593f16cf871c", "name": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/03-realtime-voice-assistant/code/ts/src/index.ts:107", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/03-realtime-voice-assistant/code/ts/src/index.ts:107"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d5575f25cfc8b71", "name": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/03-realtime-voice-assistant/code/ts/src/orchestrator.ts:154", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/03-realtime-voice-assistant/code/ts/src/orchestrator.ts:154"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9ee0978b7ad7373a", "name": "Stray `console.log` in TS/JS \u2014 phases/13-tools-and-protocols/01-the-tool-interface/code/main.ts:206", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/13-tools-and-protocols/01-the-tool-interface/code/main.ts:206"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ecbbc92204469b3", "name": "Stray `console.log` in TS/JS \u2014 phases/13-tools-and-protocols/19-a2a-protocol/code/main.ts:107", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/13-tools-and-protocols/19-a2a-protocol/code/main.ts:107"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cf16cd3a14861551", "name": "Stray `console.log` in TS/JS \u2014 phases/13-tools-and-protocols/07-building-an-mcp-server/code/main.ts:298", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/13-tools-and-protocols/07-building-an-mcp-server/code/main.ts:298"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-072b3c2c2add441a", "name": "Stray `console.log` in TS/JS \u2014 phases/05-nlp-foundations-to-advanced/19-subword-tokenization/code/main.ts:174", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/05-nlp-foundations-to-advanced/19-subword-tokenization/code/main.ts:174"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d19289461ab40a2c", "name": "Stray `console.log` in TS/JS \u2014 phases/05-nlp-foundations-to-advanced/23-chunking-strategies-rag/code/main.ts:169", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/05-nlp-foundations-to-advanced/23-chunking-strategies-rag/code/main.ts:169"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1bbe4b4eb824f20b", "name": "Stray `console.log` in TS/JS \u2014 phases/14-agent-engineering/01-the-agent-loop/code/main.ts:143", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/14-agent-engineering/01-the-agent-loop/code/main.ts:143"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5960f3f6733ecf4b", "name": "Stray `console.log` in TS/JS \u2014 phases/14-agent-engineering/06-tool-use-and-function-calling/code/main.ts:204", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/14-agent-engineering/06-tool-use-and-function-calling/code/main.ts:204"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8d97ad7142627c89", "name": "Stray `console.log` in TS/JS \u2014 phases/14-agent-engineering/13-langgraph-stateful-graphs/code/main.ts:187", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/14-agent-engineering/13-langgraph-stateful-graphs/code/main.ts:187"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bd83bd835d86cdd3", "name": "Stray `console.log` in TS/JS \u2014 phases/16-multi-agent-and-swarms/01-why-multi-agent/code/single_vs_multi.ts:228", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/16-multi-agent-and-swarms/01-why-multi-agent/code/single_vs_multi.ts:228"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-03b696f2b0a5297c", "name": "Stray `console.log` in TS/JS \u2014 phases/16-multi-agent-and-swarms/03-communication-protocols/code/main.ts:681", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/16-multi-agent-and-swarms/03-communication-protocols/code/main.ts:681"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d61d02743bbce821", "name": "Stray `console.log` in TS/JS \u2014 phases/11-llm-engineering/12-guardrails/code/main.ts:351", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/11-llm-engineering/12-guardrails/code/main.ts:351"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1df528d7d48c045a", "name": "Stray `console.log` in TS/JS \u2014 phases/11-llm-engineering/04-embeddings/code/main.ts:249", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/11-llm-engineering/04-embeddings/code/main.ts:249"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bc8d180f0e85a1dd", "name": "Stray `console.log` in TS/JS \u2014 phases/11-llm-engineering/01-prompt-engineering/code/main.ts:360", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/11-llm-engineering/01-prompt-engineering/code/main.ts:360"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c632866472abb1ee", "name": "Stray `console.log` in TS/JS \u2014 phases/11-llm-engineering/09-function-calling/code/main.ts:324", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/11-llm-engineering/09-function-calling/code/main.ts:324"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-135f08e81661ae28", "name": "Stray `console.log` in TS/JS \u2014 phases/17-infrastructure-and-production/20-shadow-canary-progressive/code/main.ts:224", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/17-infrastructure-and-production/20-shadow-canary-progressive/code/main.ts:224"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-396efdad02b8c0f0", "name": "Stray `console.log` in TS/JS \u2014 phases/17-infrastructure-and-production/16-model-routing/code/main.ts:326", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/17-infrastructure-and-production/16-model-routing/code/main.ts:326"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2f8f335d6b50ea5c", "name": "Stray `console.log` in TS/JS \u2014 phases/17-infrastructure-and-production/19-ai-gateways/code/main.ts:362", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/17-infrastructure-and-production/19-ai-gateways/code/main.ts:362"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4b0896a9b50e4625", "name": "Stray `console.log` in TS/JS \u2014 phases/17-infrastructure-and-production/14-prompt-semantic-caching/code/main.ts:308", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/17-infrastructure-and-production/14-prompt-semantic-caching/code/main.ts:308"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c0c84c17a18efa92", "name": "Stray `console.log` in TS/JS \u2014 phases/17-infrastructure-and-production/15-batch-apis/code/main.ts:154", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/17-infrastructure-and-production/15-batch-apis/code/main.ts:154"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d2bdd29d21ef1e48", "name": "Stray `console.log` in TS/JS \u2014 phases/17-infrastructure-and-production/13-llm-observability/code/main.ts:119", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 phases/17-infrastructure-and-production/13-llm-observability/code/main.ts:119"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-35808192a3c0f8a9", "name": "dynamic urllib use detected \u2014 phases/00-setup-and-tooling/04-apis-and-keys/code/first_api_call.py:42", "shortDescription": {"text": "dynamic urllib use detected \u2014 phases/00-setup-and-tooling/04-apis-and-keys/code/first_api_call.py:42"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A, 0, 1, :, 2, 0, 1, 7,  , -,  , I, n, j, e, c, t, i, o, n\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3a32ff1e2ce455cd", "name": "dynamic urllib use detected \u2014 phases/03-deep-learning-core/11-intro-to-pytorch/code/pytorch_intro.py:25", "shortDescription": {"text": "dynamic urllib use detected \u2014 phases/03-deep-learning-core/11-intro-to-pytorch/code/pytorch_intro.py:25"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A, 0, 1, :, 2, 0, 1, 7,  , -,  , I, n, j, e, c, t, i, o, n\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-687c40c77068bfae", "name": "dynamic urllib use detected \u2014 phases/04-computer-vision/01-image-fundamentals/code/main.py:25", "shortDescription": {"text": "dynamic urllib use detected \u2014 phases/04-computer-vision/01-image-fundamentals/code/main.py:25"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A, 0, 1, :, 2, 0, 1, 7,  , -,  , I, n, j, e, c, t, i, o, n\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e39ecc73f6ad4808", "name": "eval detected \u2014 phases/10-llms-from-scratch/09-constitutional-ai-self-improvement/code/main.py:79", "shortDescription": {"text": "eval detected \u2014 phases/10-llms-from-scratch/09-constitutional-ai-self-improvement/code/main.py:79"}, "fullDescription": {"text": "Detected the use of eval(). eval() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources.\n\nRule: python.lang.security.audit.eval-detected.eval-detected\nSeverity: WARNING\nOWASP: A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-99766a0248e39a64", "name": "eval detected \u2014 phases/10-llms-from-scratch/09-constitutional-ai-self-improvement/code/main.py:136", "shortDescription": {"text": "eval detected \u2014 phases/10-llms-from-scratch/09-constitutional-ai-self-improvement/code/main.py:136"}, "fullDescription": {"text": "Detected the use of eval(). eval() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources.\n\nRule: python.lang.security.audit.eval-detected.eval-detected\nSeverity: WARNING\nOWASP: A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-45d7430a3443b3dc", "name": "eval detected \u2014 phases/11-llm-engineering/02-few-shot-cot/code/advanced_prompting.py:324", "shortDescription": {"text": "eval detected \u2014 phases/11-llm-engineering/02-few-shot-cot/code/advanced_prompting.py:324"}, "fullDescription": {"text": "Detected the use of eval(). eval() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources.\n\nRule: python.lang.security.audit.eval-detected.eval-detected\nSeverity: WARNING\nOWASP: A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-367150fee35bd37d", "name": "eval detected \u2014 phases/11-llm-engineering/09-function-calling/code/function_calling.py:28", "shortDescription": {"text": "eval detected \u2014 phases/11-llm-engineering/09-function-calling/code/function_calling.py:28"}, "fullDescription": {"text": "Detected the use of eval(). eval() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources.\n\nRule: python.lang.security.audit.eval-detected.eval-detected\nSeverity: WARNING\nOWASP: A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6696660210f2f54f", "name": "exec detected \u2014 phases/11-llm-engineering/09-function-calling/code/function_calling.py:109", "shortDescription": {"text": "exec detected \u2014 phases/11-llm-engineering/09-function-calling/code/function_calling.py:109"}, "fullDescription": {"text": "Detected the use of exec(). exec() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources.\n\nRule: python.lang.security.audit.exec-detected.exec-detected\nSeverity: WARNING\nOWASP: A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0e0dd4c6868225ed", "name": "eval detected \u2014 phases/11-llm-engineering/16-langgraph-state-machines/code/main.py:55", "shortDescription": {"text": "eval detected \u2014 phases/11-llm-engineering/16-langgraph-state-machines/code/main.py:55"}, "fullDescription": {"text": "Detected the use of eval(). eval() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources.\n\nRule: python.lang.security.audit.eval-detected.eval-detected\nSeverity: WARNING\nOWASP: A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4d1fd8bfd89fd829", "name": "dynamic urllib use detected \u2014 phases/13-tools-and-protocols/09-mcp-transports/code/main.py:191", "shortDescription": {"text": "dynamic urllib use detected \u2014 phases/13-tools-and-protocols/09-mcp-transports/code/main.py:191"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A, 0, 1, :, 2, 0, 1, 7,  , -,  , I, n, j, e, c, t, i, o, n\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9d771a8b7a6ee0da", "name": "dynamic urllib use detected \u2014 phases/13-tools-and-protocols/09-mcp-transports/code/main.py:200", "shortDescription": {"text": "dynamic urllib use detected \u2014 phases/13-tools-and-protocols/09-mcp-transports/code/main.py:200"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A, 0, 1, :, 2, 0, 1, 7,  , -,  , I, n, j, e, c, t, i, o, n\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1f565e0648101805", "name": "dynamic urllib use detected \u2014 phases/13-tools-and-protocols/09-mcp-transports/code/main.py:210", "shortDescription": {"text": "dynamic urllib use detected \u2014 phases/13-tools-and-protocols/09-mcp-transports/code/main.py:210"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A, 0, 1, :, 2, 0, 1, 7,  , -,  , I, n, j, e, c, t, i, o, n\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c5cd715d6738cc7b", "name": "dynamic urllib use detected \u2014 phases/13-tools-and-protocols/09-mcp-transports/code/main.py:219", "shortDescription": {"text": "dynamic urllib use detected \u2014 phases/13-tools-and-protocols/09-mcp-transports/code/main.py:219"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A, 0, 1, :, 2, 0, 1, 7,  , -,  , I, n, j, e, c, t, i, o, n\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d97585af057a4cc3", "name": "dynamic urllib use detected \u2014 phases/13-tools-and-protocols/09-mcp-transports/code/main.py:229", "shortDescription": {"text": "dynamic urllib use detected \u2014 phases/13-tools-and-protocols/09-mcp-transports/code/main.py:229"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A, 0, 1, :, 2, 0, 1, 7,  , -,  , I, n, j, e, c, t, i, o, n\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1dc30b06e7be92c3", "name": "eval detected \u2014 phases/14-agent-engineering/01-the-agent-loop/code/main.py:61", "shortDescription": {"text": "eval detected \u2014 phases/14-agent-engineering/01-the-agent-loop/code/main.py:61"}, "fullDescription": {"text": "Detected the use of eval(). eval() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources.\n\nRule: python.lang.security.audit.eval-detected.eval-detected\nSeverity: WARNING\nOWASP: A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-202c93a2d6874756", "name": "exec detected \u2014 phases/16-multi-agent-and-swarms/08-role-specialization/code/main.py:74", "shortDescription": {"text": "exec detected \u2014 phases/16-multi-agent-and-swarms/08-role-specialization/code/main.py:74"}, "fullDescription": {"text": "Detected the use of exec(). exec() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources.\n\nRule: python.lang.security.audit.exec-detected.exec-detected\nSeverity: WARNING\nOWASP: A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-421307507d3b56f7", "name": "dynamic urllib use detected \u2014 phases/16-multi-agent-and-swarms/12-a2a-protocol/code/main.py:129", "shortDescription": {"text": "dynamic urllib use detected \u2014 phases/16-multi-agent-and-swarms/12-a2a-protocol/code/main.py:129"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A, 0, 1, :, 2, 0, 1, 7,  , -,  , I, n, j, e, c, t, i, o, n\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7f2b1cb4d444677e", "name": "subprocess shell true \u2014 phases/19-capstone-projects/01-terminal-native-coding-agent/code/main.py:116", "shortDescription": {"text": "subprocess shell true \u2014 phases/19-capstone-projects/01-terminal-native-coding-agent/code/main.py:116"}, "fullDescription": {"text": "Found 'subprocess' function 'run' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead.\n\nRule: python.lang.security.audit.subprocess-shell-true.subprocess-shell-true\nSeverity: ERROR\nOWASP: A01:2017 - Injection, A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-6b51eda891019f65", "name": "exec detected \u2014 phases/19-capstone-projects/49-lm-eval-harness/code/main.py:224", "shortDescription": {"text": "exec detected \u2014 phases/19-capstone-projects/49-lm-eval-harness/code/main.py:224"}, "fullDescription": {"text": "Detected the use of exec(). exec() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources.\n\nRule: python.lang.security.audit.exec-detected.exec-detected\nSeverity: WARNING\nOWASP: A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c9e03732cbf468b7", "name": "insecure hash algorithm sha1 \u2014 phases/19-capstone-projects/50-hypothesis-generator/code/main.py:134", "shortDescription": {"text": "insecure hash algorithm sha1 \u2014 phases/19-capstone-projects/50-hypothesis-generator/code/main.py:134"}, "fullDescription": {"text": "Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead.\n\nRule: python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1\nSeverity: WARNING\nOWASP: A03:2017 - Sensitive Data Exposure, A02:2021 - Cryptographic Failures, A04:2025 - Cryptographic Failures\nCWE: CWE-327: Use of a Broken or Risky Cryptographic Algorithm\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-916c8e2e7b74c1d6", "name": "dynamic urllib use detected \u2014 scripts/link_check.py:245", "shortDescription": {"text": "dynamic urllib use detected \u2014 scripts/link_check.py:245"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A, 0, 1, :, 2, 0, 1, 7,  , -,  , I, n, j, e, c, t, i, o, n\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fdfb82c94eea36ef", "name": "DS-0002: Image user should not be 'root' \u2014 phases/00-setup-and-tooling/07-docker-for-ai/code/Dockerfile", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 phases/00-setup-and-tooling/07-docker-for-ai/code/Dockerfile"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: phases/00-setup-and-tooling/07-docker-for-ai/code/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c07e418427423aaf", "name": "DS-0026: No HEALTHCHECK defined \u2014 phases/00-setup-and-tooling/07-docker-for-ai/code/Dockerfile", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 phases/00-setup-and-tooling/07-docker-for-ai/code/Dockerfile"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: phases/00-setup-and-tooling/07-docker-for-ai/code/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e637c415447867e4", "name": "Run SkillSpector's LLM-backed analysis in your own pipeline", "shortDescription": {"text": "Run SkillSpector's LLM-backed analysis in your own pipeline"}, "fullDescription": {"text": "Repobility ran SkillSpector's static rules server-side. The deeper LLM-backed analyzers \u2014 tool-poisoning (TP*), semantic security discovery (SSD*), developer-intent mismatch (SDI*) \u2014 are meant to run on YOUR machine with YOUR model; repobility never sends your code to an LLM. Recipe:\n\n# 1. Install SkillSpector in your own isolated env\npipx install \"skillspector @ git+https://github.com/NVIDIA/SkillSpector.git\"\n\n# 2. Point it at YOUR LLM pipeline (pick one) - your code stays on your machine\nexport SKILLSPECTOR_PROVIDER=anthropic && export ANTHROPIC_API_KEY=sk-ant-...\n# export SKILLSPECTOR_PROVIDER=openai   && export OPENAI_API_KEY=sk-...\n# export SKILLSPECTOR_PROVIDER=openai OPENAI_API_KEY=ollama OPENAI_BASE_URL=http://localhost:11434/v1 SKILLSPECTOR_MODEL=llama3.1:8b\n# export SKILLSPECTOR_PROVIDER=nv_build && export NVIDIA_INFERENCE_KEY=nvapi-...\n\n# 3. Run the LLM-backed scan per skill (omit --no-llm to enable the LLM analyzers)\nskillspector scan .claude/skills/check-understanding --fo"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8c25f9a51a830a1e", "name": "Dockerfile runs as root: phases/00-setup-and-tooling/07-docker-for-ai/code/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: phases/00-setup-and-tooling/07-docker-for-ai/code/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8f7ded22e2cf2baa", "name": "Docker base image is tag-pinned but not digest-pinned: nvidia/cuda:12.4.1-devel-ubuntu22.04", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: nvidia/cuda:12.4.1-devel-ubuntu22.04"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-30635e0ff67dac8e", "name": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-dl.js:51", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-dl.js:51"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-caf76574a6a854b1", "name": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-vision-speech.js:160", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-vision-speech.js:160"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-81f27af24990d897", "name": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-agents-alignment.js:283", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-agents-alignment.js:283"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-467ac758f7b2aa70", "name": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-nlp2.js:232", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-nlp2.js:232"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-a12d2aa0cd949b94", "name": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-math.js:36", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-math.js:36"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-25731e6f602fdd60", "name": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-genai-rl.js:168", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-genai-rl.js:168"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-bda1d7077e0e6436", "name": "Insecure pattern 'direct_innerhtml_assignment' in site/app.js:134", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/app.js:134"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-5cadbd740c000574", "name": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-math2.js:59", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-math2.js:59"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-e3fc6c87ac4709cf", "name": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-transformers.js:169", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-transformers.js:169"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-0daae44df92de527", "name": "Insecure pattern 'direct_innerhtml_assignment' in site/lesson.html:1822", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/lesson.html:1822"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-53988ae5c0bbfbb6", "name": "Insecure pattern 'insert_adjacent_html' in site/lesson.html:2819", "shortDescription": {"text": "Insecure pattern 'insert_adjacent_html' in site/lesson.html:2819"}, "fullDescription": {"text": "Found a known-risky pattern (insert_adjacent_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-8dcd84c24899c58b", "name": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-llms2.js:43", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-llms2.js:43"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-b5d30605e14a45a5", "name": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-llms-systems.js:104", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-llms-systems.js:104"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-25b9d3c202fb003f", "name": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-infra.js:53", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-infra.js:53"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-9699b0390a7e98f9", "name": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-frontier.js:105", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-frontier.js:105"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-230a0352589904ea", "name": "Insecure pattern 'direct_innerhtml_assignment' in site/lesson-figures.js:49", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/lesson-figures.js:49"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-5c07e7194c4cd48d", "name": "Insecure pattern 'eval_used' in phases/19-capstone-projects/72-code-exec-metric/code/main.py:116", "shortDescription": {"text": "Insecure pattern 'eval_used' in phases/19-capstone-projects/72-code-exec-metric/code/main.py:116"}, "fullDescription": {"text": "Found a known-risky pattern (eval_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-07f10b81d68ead2d", "name": "Insecure pattern 'exec_used' in phases/19-capstone-projects/72-code-exec-metric/code/main.py:106", "shortDescription": {"text": "Insecure pattern 'exec_used' in phases/19-capstone-projects/72-code-exec-metric/code/main.py:106"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ab09ae565e85d31b", "name": "Insecure pattern 'subprocess_shell_true' in phases/19-capstone-projects/01-terminal-native-coding-agent/code/main.py:116", "shortDescription": {"text": "Insecure pattern 'subprocess_shell_true' in phases/19-capstone-projects/01-terminal-native-coding-agent/code/main.py:116"}, "fullDescription": {"text": "Found a known-risky pattern (subprocess_shell_true). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c4745110fb82fce8", "name": "Insecure pattern 'exec_used' in phases/19-capstone-projects/49-lm-eval-harness/code/main.py:224", "shortDescription": {"text": "Insecure pattern 'exec_used' in phases/19-capstone-projects/49-lm-eval-harness/code/main.py:224"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-aa00b236173b7b21", "name": "Insecure pattern 'exec_used' in phases/15-autonomous-systems/08-bounded-self-improvement/code/main.py:60", "shortDescription": {"text": "Insecure pattern 'exec_used' in phases/15-autonomous-systems/08-bounded-self-improvement/code/main.py:60"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-968a360abfaeea28", "name": "Possible secret in phases/15-autonomous-systems/18-llama-guard/code/main.py", "shortDescription": {"text": "Possible secret in phases/15-autonomous-systems/18-llama-guard/code/main.py"}, "fullDescription": {"text": "Detected 1 occurrence(s) matching openai_or_anthropic_key. Rotate real credentials and move them to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 0.95}}, {"id": "scanner-dec5d3892be78a4c", "name": "Insecure pattern 'exec_used' in phases/15-autonomous-systems/10-claude-code-permission-modes/code/main.py:46", "shortDescription": {"text": "Insecure pattern 'exec_used' in phases/15-autonomous-systems/10-claude-code-permission-modes/code/main.py:46"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3a9e93b68b5690b5", "name": "Insecure pattern 'exec_used' in phases/13-tools-and-protocols/07-building-an-mcp-server/code/main.ts:185", "shortDescription": {"text": "Insecure pattern 'exec_used' in phases/13-tools-and-protocols/07-building-an-mcp-server/code/main.ts:185"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-94991bb8bd8ad1b0", "name": "Insecure pattern 'exec_used' in phases/18-ethics-safety-alignment/16-red-team-tooling-garak-llamaguard-pyrit/code/main.p", "shortDescription": {"text": "Insecure pattern 'exec_used' in phases/18-ethics-safety-alignment/16-red-team-tooling-garak-llamaguard-pyrit/code/main.py:35"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fa450f54daa35f58", "name": "Insecure pattern 'eval_used' in phases/18-ethics-safety-alignment/08-in-context-scheming-frontier-models/code/main.py:12", "shortDescription": {"text": "Insecure pattern 'eval_used' in phases/18-ethics-safety-alignment/08-in-context-scheming-frontier-models/code/main.py:124"}, "fullDescription": {"text": "Found a known-risky pattern (eval_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7b850224f5b9772a", "name": "Insecure pattern 'new_function_used' in phases/14-agent-engineering/01-the-agent-loop/code/main.ts:58", "shortDescription": {"text": "Insecure pattern 'new_function_used' in phases/14-agent-engineering/01-the-agent-loop/code/main.ts:58"}, "fullDescription": {"text": "Found a known-risky pattern (new_function_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1e367ff5e8488d30", "name": "Insecure pattern 'eval_used' in phases/14-agent-engineering/01-the-agent-loop/code/main.py:61", "shortDescription": {"text": "Insecure pattern 'eval_used' in phases/14-agent-engineering/01-the-agent-loop/code/main.py:61"}, "fullDescription": {"text": "Found a known-risky pattern (eval_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4972a3377d88f498", "name": "Insecure pattern 'eval_used' in phases/14-agent-engineering/14-autogen-actor-model/code/main.py:85", "shortDescription": {"text": "Insecure pattern 'eval_used' in phases/14-agent-engineering/14-autogen-actor-model/code/main.py:85"}, "fullDescription": {"text": "Found a known-risky pattern (eval_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-516e9de0fd461c49", "name": "Insecure pattern 'exec_used' in phases/16-multi-agent-and-swarms/08-role-specialization/code/main.py:74", "shortDescription": {"text": "Insecure pattern 'exec_used' in phases/16-multi-agent-and-swarms/08-role-specialization/code/main.py:74"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-93215a01a51049d7", "name": "Insecure pattern 'eval_used' in phases/10-llms-from-scratch/09-constitutional-ai-self-improvement/code/main.py:79", "shortDescription": {"text": "Insecure pattern 'eval_used' in phases/10-llms-from-scratch/09-constitutional-ai-self-improvement/code/main.py:79"}, "fullDescription": {"text": "Found a known-risky pattern (eval_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3b6dc379488ca9bd", "name": "Insecure pattern 'eval_used' in phases/11-llm-engineering/02-few-shot-cot/code/advanced_prompting.py:324", "shortDescription": {"text": "Insecure pattern 'eval_used' in phases/11-llm-engineering/02-few-shot-cot/code/advanced_prompting.py:324"}, "fullDescription": {"text": "Found a known-risky pattern (eval_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-51ca21268b7c7170", "name": "Insecure pattern 'eval_used' in phases/11-llm-engineering/16-langgraph-state-machines/code/main.py:55", "shortDescription": {"text": "Insecure pattern 'eval_used' in phases/11-llm-engineering/16-langgraph-state-machines/code/main.py:55"}, "fullDescription": {"text": "Found a known-risky pattern (eval_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-26223f85659796e1", "name": "Insecure pattern 'eval_used' in phases/11-llm-engineering/09-function-calling/code/function_calling.py:28", "shortDescription": {"text": "Insecure pattern 'eval_used' in phases/11-llm-engineering/09-function-calling/code/function_calling.py:28"}, "fullDescription": {"text": "Found a known-risky pattern (eval_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e2beb9b5c772a3f7", "name": "Insecure pattern 'python_os_system' in phases/11-llm-engineering/09-function-calling/code/function_calling.py:376", "shortDescription": {"text": "Insecure pattern 'python_os_system' in phases/11-llm-engineering/09-function-calling/code/function_calling.py:376"}, "fullDescription": {"text": "Found a known-risky pattern (python_os_system). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-76c1e5ccd427ca70", "name": "Insecure pattern 'exec_used' in phases/11-llm-engineering/09-function-calling/code/function_calling.py:103", "shortDescription": {"text": "Insecure pattern 'exec_used' in phases/11-llm-engineering/09-function-calling/code/function_calling.py:103"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-daca0589a5b769c2", "name": "Insecure pattern 'eval_used' in phases/11-llm-engineering/09-function-calling/code/main.ts:144", "shortDescription": {"text": "Insecure pattern 'eval_used' in phases/11-llm-engineering/09-function-calling/code/main.ts:144"}, "fullDescription": {"text": "Found a known-risky pattern (eval_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1cf979005ff4d9e9", "name": "Insecure pattern 'new_function_used' in phases/11-llm-engineering/09-function-calling/code/main.ts:62", "shortDescription": {"text": "Insecure pattern 'new_function_used' in phases/11-llm-engineering/09-function-calling/code/main.ts:62"}, "fullDescription": {"text": "Found a known-risky pattern (new_function_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e36351d2b9f0f64d", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8f8014030fdfbaf6", "name": "Very large file: site/data.js (12478 lines)", "shortDescription": {"text": "Very large file: site/data.js (12478 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea3b5e389d8c9c0f", "name": "Low test-to-source ratio", "shortDescription": {"text": "Low test-to-source ratio"}, "fullDescription": {"text": "102 tests / 661 src (ratio 0.15)."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c4a802d21503560d", "name": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/08-production-rag-chatbot/code/ts/package.js", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/08-production-rag-chatbot/code/ts/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a90a55577dd2fe92", "name": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/17-personal-ai-tutor/code/ts/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/17-personal-ai-tutor/code/ts/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-486dabef9f6a6d95", "name": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/10-multi-agent-software-team/code/ts/package", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/10-multi-agent-software-team/code/ts/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-50059cc1f3a38071", "name": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/06-devops-troubleshooting-agent/code/ts/pack", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/06-devops-troubleshooting-agent/code/ts/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7c90d35c3bc3fe77", "name": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/01-terminal-native-coding-agent/code/ts/pack", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/01-terminal-native-coding-agent/code/ts/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cf7ed5e03f223b66", "name": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/12-video-understanding-pipeline/code/ts/pack", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/12-video-understanding-pipeline/code/ts/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cf2a60db3b06da67", "name": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/04-multimodal-document-qa/code/ts/package.js", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/04-multimodal-document-qa/code/ts/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0fe67f4195500c35", "name": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b02d81e0eefa66f9", "name": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/11-llm-observability-dashboard/code/ts/packa", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/11-llm-observability-dashboard/code/ts/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-75ffe26c05c92a03", "name": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2efdeda8de7bdcd7", "name": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/13-mcp-server-with-registry/code/ts/package.", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/13-mcp-server-with-registry/code/ts/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7b558402dccbab53", "name": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/03-realtime-voice-assistant/code/ts/package.", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/03-realtime-voice-assistant/code/ts/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-facd20757db92ab6", "name": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/16-github-issue-to-pr-agent/code/ts/package.", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/16-github-issue-to-pr-agent/code/ts/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 11595 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 106 placeholder/mock markers across 63 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing lockfile. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-da3899da2ebbd641", "name": "Commented-code block (5 lines) in site/app.js:139", "shortDescription": {"text": "Commented-code block (5 lines) in site/app.js:139"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d42c390228467862", "name": "Legacy-named symbol `\u03c0_old` in site/data.js:1682", "shortDescription": {"text": "Legacy-named symbol `\u03c0_old` in site/data.js:1682"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3724a1c0a5590903", "name": "Commented-code block (5 lines) in site/build.js:79", "shortDescription": {"text": "Commented-code block (5 lines) in site/build.js:79"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c88a7281497a02ec", "name": "Commented-code block (6 lines) in phases/19-capstone-projects/08-production-rag-chatbot/code/ts/src/index.ts:1", "shortDescription": {"text": "Commented-code block (6 lines) in phases/19-capstone-projects/08-production-rag-chatbot/code/ts/src/index.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-47f2f1d8f7516e7b", "name": "Commented-code block (6 lines) in phases/19-capstone-projects/17-personal-ai-tutor/code/ts/src/index.ts:1", "shortDescription": {"text": "Commented-code block (6 lines) in phases/19-capstone-projects/17-personal-ai-tutor/code/ts/src/index.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-51577f024aecfd55", "name": "Network/subprocess call without timeout or try/except \u2014 phases/19-capstone-projects/72-code-exec-metric/code/main.py:313", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 phases/19-capstone-projects/72-code-exec-metric/code/main.py:313"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1d97cd0e41894294", "name": "Commented-code block (6 lines) in phases/19-capstone-projects/06-devops-troubleshooting-agent/code/ts/src/index.ts:1", "shortDescription": {"text": "Commented-code block (6 lines) in phases/19-capstone-projects/06-devops-troubleshooting-agent/code/ts/src/index.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-02fe635ea6b4869a", "name": "Commented-code block (5 lines) in phases/19-capstone-projects/01-terminal-native-coding-agent/code/ts/src/index.ts:3", "shortDescription": {"text": "Commented-code block (5 lines) in phases/19-capstone-projects/01-terminal-native-coding-agent/code/ts/src/index.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a8568ea43264b8c9", "name": "Commented-code block (6 lines) in phases/19-capstone-projects/12-video-understanding-pipeline/code/ts/src/index.ts:1", "shortDescription": {"text": "Commented-code block (6 lines) in phases/19-capstone-projects/12-video-understanding-pipeline/code/ts/src/index.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-766be6012d53fcdb", "name": "`fetch()` without try/.catch or AbortSignal \u2014 phases/19-capstone-projects/12-video-understanding-pipeline/code/ts/src/in", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 phases/19-capstone-projects/12-video-understanding-pipeline/code/ts/src/index.ts:51"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e0b5feb549130319", "name": "Commented-code block (6 lines) in phases/19-capstone-projects/04-multimodal-document-qa/code/ts/src/index.ts:1", "shortDescription": {"text": "Commented-code block (6 lines) in phases/19-capstone-projects/04-multimodal-document-qa/code/ts/src/index.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6277722fc37d9534", "name": "Legacy-named symbol `transform_v1` in phases/19-capstone-projects/24-plan-execute-control-flow/code/tests/test_agent.py:", "shortDescription": {"text": "Legacy-named symbol `transform_v1` in phases/19-capstone-projects/24-plan-execute-control-flow/code/tests/test_agent.py:50"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dd55768cbd11529e", "name": "Stub function `reverse_list` (body is just `pass`/`return`) \u2014 phases/19-capstone-projects/27-eval-harness-fixture-tasks/", "shortDescription": {"text": "Stub function `reverse_list` (body is just `pass`/`return`) \u2014 phases/19-capstone-projects/27-eval-harness-fixture-tasks/code/tasks/task_004_empty_reverse/buggy/reverse.py:1"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8f558a9d563c9ada", "name": "Commented-code block (5 lines) in phases/19-capstone-projects/02-rag-over-codebase/code/ts/src/index.ts:3", "shortDescription": {"text": "Commented-code block (5 lines) in phases/19-capstone-projects/02-rag-over-codebase/code/ts/src/index.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-277566c2b3f81874", "name": "Legacy-named symbol `idxs_copy` in phases/19-capstone-projects/39-instruction-tuning-sft/code/main.py:357", "shortDescription": {"text": "Legacy-named symbol `idxs_copy` in phases/19-capstone-projects/39-instruction-tuning-sft/code/main.py:357"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-526f8bc6eceba973", "name": "Stub function `close` (body is just `pass`/`return`) \u2014 phases/19-capstone-projects/28-observability-otel-traces/code/mai", "shortDescription": {"text": "Stub function `close` (body is just `pass`/`return`) \u2014 phases/19-capstone-projects/28-observability-otel-traces/code/main.py:174"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b0aa08ad0540e102", "name": "Commented-code block (7 lines) in phases/19-capstone-projects/13-mcp-server-with-registry/code/ts/src/index.ts:1", "shortDescription": {"text": "Commented-code block (7 lines) in phases/19-capstone-projects/13-mcp-server-with-registry/code/ts/src/index.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7c7349fe5eb43454", "name": "Commented-code block (5 lines) in phases/19-capstone-projects/03-realtime-voice-assistant/code/ts/src/index.ts:3", "shortDescription": {"text": "Commented-code block (5 lines) in phases/19-capstone-projects/03-realtime-voice-assistant/code/ts/src/index.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6f562bc437cd5924", "name": "Commented-code block (6 lines) in phases/19-capstone-projects/16-github-issue-to-pr-agent/code/ts/src/index.ts:1", "shortDescription": {"text": "Commented-code block (6 lines) in phases/19-capstone-projects/16-github-issue-to-pr-agent/code/ts/src/index.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-25961559ea4266e1", "name": "`fetch()` without try/.catch or AbortSignal \u2014 phases/19-capstone-projects/16-github-issue-to-pr-agent/code/ts/src/index.", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 phases/19-capstone-projects/16-github-issue-to-pr-agent/code/ts/src/index.ts:119"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c4fc5c9ec85182fd", "name": "Legacy-named symbol `idxs_copy` in phases/19-capstone-projects/38-classifier-finetuning/code/main.py:272", "shortDescription": {"text": "Legacy-named symbol `idxs_copy` in phases/19-capstone-projects/38-classifier-finetuning/code/main.py:272"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-156bbb8ee46290a7", "name": "Commented-code block (5 lines) in phases/15-autonomous-systems/18-llama-guard/code/main.py:59", "shortDescription": {"text": "Commented-code block (5 lines) in phases/15-autonomous-systems/18-llama-guard/code/main.py:59"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-697acd1bb3d3f226", "name": "Commented-code block (9 lines) in phases/15-autonomous-systems/16-checkpoints-rollback/code/main.py:107", "shortDescription": {"text": "Commented-code block (9 lines) in phases/15-autonomous-systems/16-checkpoints-rollback/code/main.py:107"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7b8c8de315d236ab", "name": "Commented-code block (5 lines) in phases/15-autonomous-systems/06-automated-alignment-research/code/main.py:108", "shortDescription": {"text": "Commented-code block (5 lines) in phases/15-autonomous-systems/06-automated-alignment-research/code/main.py:108"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-342b6b1eabdd2d82", "name": "Commented-code block (5 lines) in phases/15-autonomous-systems/05-ai-scientist-v2/code/main.py:65", "shortDescription": {"text": "Commented-code block (5 lines) in phases/15-autonomous-systems/05-ai-scientist-v2/code/main.py:65"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cf4a9d0907f25db8", "name": "Network/subprocess call without timeout or try/except \u2014 phases/00-setup-and-tooling/04-apis-and-keys/code/first_api_call", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 phases/00-setup-and-tooling/04-apis-and-keys/code/first_api_call.py:42"}, "fullDescription": {"text": "`urllib.request.urlopen(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a6b438d44d6d8665", "name": "Commented-code block (6 lines) in phases/00-setup-and-tooling/04-apis-and-keys/code/first_api_call.ts:1", "shortDescription": {"text": "Commented-code block (6 lines) in phases/00-setup-and-tooling/04-apis-and-keys/code/first_api_call.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6e5620428d34ac22", "name": "`fetch()` without try/.catch or AbortSignal \u2014 phases/00-setup-and-tooling/04-apis-and-keys/code/first_api_call.ts:6", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 phases/00-setup-and-tooling/04-apis-and-keys/code/first_api_call.ts:6"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5bd804014444b23a", "name": "Legacy-named symbol `exp_old` in phases/07-transformers-deep-dive/12-kv-cache-flash-attention/code/main.py:48", "shortDescription": {"text": "Legacy-named symbol `exp_old` in phases/07-transformers-deep-dive/12-kv-cache-flash-attention/code/main.py:48"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-faeb1d376db2ce4a", "name": "Network/subprocess call without timeout or try/except \u2014 phases/13-tools-and-protocols/09-mcp-transports/code/main.py:200", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 phases/13-tools-and-protocols/09-mcp-transports/code/main.py:200"}, "fullDescription": {"text": "`urllib.request.urlopen(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c24d06ab6127ddc3", "name": "Legacy-named symbol `maskrcnn_resnet50_fpn_v2` in phases/04-computer-vision/08-instance-segmentation-mask-rcnn/code/main", "shortDescription": {"text": "Legacy-named symbol `maskrcnn_resnet50_fpn_v2` in phases/04-computer-vision/08-instance-segmentation-mask-rcnn/code/main.py:47"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d7844a8c80f5cfa", "name": "Commented-code block (7 lines) in phases/05-nlp-foundations-to-advanced/19-subword-tokenization/code/main.ts:1", "shortDescription": {"text": "Commented-code block (7 lines) in phases/05-nlp-foundations-to-advanced/19-subword-tokenization/code/main.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8436002f496a61c2", "name": "Commented-code block (7 lines) in phases/05-nlp-foundations-to-advanced/23-chunking-strategies-rag/code/main.ts:1", "shortDescription": {"text": "Commented-code block (7 lines) in phases/05-nlp-foundations-to-advanced/23-chunking-strategies-rag/code/main.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3eebadc9dd48a70c", "name": "Stub function `on_edited` (body is just `pass`/`return`) \u2014 phases/14-agent-engineering/15-crewai-role-based-crews/code/m", "shortDescription": {"text": "Stub function `on_edited` (body is just `pass`/`return`) \u2014 phases/14-agent-engineering/15-crewai-role-based-crews/code/main.py:316"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-81c456788dc5f026", "name": "Commented-code block (8 lines) in phases/14-agent-engineering/18-agno-and-mastra-runtimes/code/main.ts:1", "shortDescription": {"text": "Commented-code block (8 lines) in phases/14-agent-engineering/18-agno-and-mastra-runtimes/code/main.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d9aafff71d58ab9c", "name": "Legacy-named symbol `_craft_iron_pick_v1` in phases/14-agent-engineering/10-skill-libraries-voyager/code/main.py:125", "shortDescription": {"text": "Legacy-named symbol `_craft_iron_pick_v1` in phases/14-agent-engineering/10-skill-libraries-voyager/code/main.py:125"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6e9e0a7f7cf51a42", "name": "Network/subprocess call without timeout or try/except \u2014 phases/16-multi-agent-and-swarms/12-a2a-protocol/code/main.py:12", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 phases/16-multi-agent-and-swarms/12-a2a-protocol/code/main.py:129"}, "fullDescription": {"text": "`urllib.request.urlopen(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f41fcb08e756115e", "name": "Stub function `log_message` (body is just `pass`/`return`) \u2014 phases/16-multi-agent-and-swarms/12-a2a-protocol/code/main.", "shortDescription": {"text": "Stub function `log_message` (body is just `pass`/`return`) \u2014 phases/16-multi-agent-and-swarms/12-a2a-protocol/code/main.py:84"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8e20e9297e830f65", "name": "Legacy-named symbol `diff_v1` in phases/10-llms-from-scratch/16-differential-attention-v2/code/main.py:125", "shortDescription": {"text": "Legacy-named symbol `diff_v1` in phases/10-llms-from-scratch/16-differential-attention-v2/code/main.py:125"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-505637f172e07304", "name": "Network/subprocess call without timeout or try/except \u2014 phases/03-deep-learning-core/11-intro-to-pytorch/code/pytorch_in", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 phases/03-deep-learning-core/11-intro-to-pytorch/code/pytorch_intro.py:25"}, "fullDescription": {"text": "`urllib.request.urlretrieve(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a48890876efd0588", "name": "Legacy-named symbol `rs_old` in phases/01-math-foundations/17-linear-systems/code/linear_systems.py:122", "shortDescription": {"text": "Legacy-named symbol `rs_old` in phases/01-math-foundations/17-linear-systems/code/linear_systems.py:122"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6a24067a5bde0749", "name": "Legacy-named symbol `log_pi_old` in phases/09-reinforcement-learning/09-reward-modeling-rlhf/code/main.py:106", "shortDescription": {"text": "Legacy-named symbol `log_pi_old` in phases/09-reinforcement-learning/09-reward-modeling-rlhf/code/main.py:106"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-34edd1cadbb35a87", "name": "Legacy-named symbol `v_old` in phases/09-reinforcement-learning/08-ppo/code/main.py:81", "shortDescription": {"text": "Legacy-named symbol `v_old` in phases/09-reinforcement-learning/08-ppo/code/main.py:81"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa76c908d52778db", "name": "Commented-code block (7 lines) in phases/11-llm-engineering/12-guardrails/code/main.ts:1", "shortDescription": {"text": "Commented-code block (7 lines) in phases/11-llm-engineering/12-guardrails/code/main.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-069f9af51ed02a6e", "name": "Commented-code block (7 lines) in phases/11-llm-engineering/03-structured-outputs/code/main.ts:1", "shortDescription": {"text": "Commented-code block (7 lines) in phases/11-llm-engineering/03-structured-outputs/code/main.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b4c3f75c94ba2084", "name": "Commented-code block (9 lines) in phases/11-llm-engineering/06-rag/code/main.ts:1", "shortDescription": {"text": "Commented-code block (9 lines) in phases/11-llm-engineering/06-rag/code/main.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d973b86fff66f0f4", "name": "Network/subprocess call without timeout or try/except \u2014 phases/11-llm-engineering/09-function-calling/code/function_call", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 phases/11-llm-engineering/09-function-calling/code/function_calling.py:417"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-db88eda2dc7eb9d6", "name": "Commented-code block (7 lines) in phases/11-llm-engineering/05-context-engineering/code/main.ts:1", "shortDescription": {"text": "Commented-code block (7 lines) in phases/11-llm-engineering/05-context-engineering/code/main.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nscripts/lesson_run.py:iter_lesson_dirs, scripts/audit_lessons.py:iter_lesson_dirs\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be46ea126aa5d8dc", "name": "Near-duplicate function bodies in 3 places", "shortDescription": {"text": "Near-duplicate function bodies in 3 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nphases/19-capstone-projects/69-end-to-end-rag-system/code/main.py:add, phases/19-capstone-projects/69-end-to-end-rag-system/code/main.py:add, phases/19-capstone-projects/69-end-to-end-rag-system/code/main.py:add\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ecd86354d3c142ad", "name": "Near-duplicate function bodies in 20 places", "shortDescription": {"text": "Near-duplicate function bodies in 20 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nphases/19-capstone-projects/34-transformer-block/code/main.py:forward, phases/19-capstone-projects/34-transformer-block/code/main.py:forward, phases/19-capstone-projects/34-transformer-block/code/main.py:forward, phases/19-capstone-projects/34-transformer-block/code/main.py:forward\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-49c98f7cedd9c977", "name": "Near-duplicate function bodies in 4 places", "shortDescription": {"text": "Near-duplicate function bodies in 4 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nphases/19-capstone-projects/32-token-positional-embeddings/code/main.py:forward, phases/19-capstone-projects/32-token-positional-embeddings/code/main.py:forward, phases/19-capstone-projects/32-token-positional-embeddings/code/main.py:forward, phases/19-capstone-projects/32-token-positional-embeddings/code/main.py:forward\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-46969939caf8120b", "name": "Near-duplicate function bodies in 9 places", "shortDescription": {"text": "Near-duplicate function bodies in 9 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nphases/19-capstone-projects/40-dpo-from-scratch/code/main.py:forward, phases/19-capstone-projects/40-dpo-from-scratch/code/main.py:forward, phases/19-capstone-projects/40-dpo-from-scratch/code/main.py:forward, phases/19-capstone-projects/41-eval-pipeline/code/main.py:forward\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-37197262900b2e0f", "name": "Vulnerable dependency hono 4.6.14: GHSA-26pp-8wgv-hjvm", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-26pp-8wgv-hjvm"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-26pp-8wgv-hjvm (aka CVE-2026-56762).\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono missing validation of cookie name on write path in setCookie()\n\nAliases: CVE-2026-56762\nAdvisory: https://osv.dev/vulnerability/GHSA-26pp-8wgv-hjvm\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-c2040c9d7b57ff26", "name": "Vulnerable dependency hono 4.6.14: GHSA-2gcr-mfcq-wcc3", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-2gcr-mfcq-wcc3"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-2gcr-mfcq-wcc3 (aka CVE-2026-47676).\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths\n\nAliases: CVE-2026-47676\nAdvisory: https://osv.dev/vulnerability/GHSA-2gcr-mfcq-wcc3\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-80f0702b6ae0507b", "name": "Vulnerable dependency hono 4.6.14: GHSA-3hrh-pfw6-9m5x", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-3hrh-pfw6-9m5x"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-3hrh-pfw6-9m5x (aka CVE-2026-47675).\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection\n\nAliases: CVE-2026-47675\nAdvisory: https://osv.dev/vulnerability/GHSA-3hrh-pfw6-9m5x\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-d27c83995820d6bf", "name": "Vulnerable dependency hono 4.6.14: GHSA-3vhc-576x-3qv4", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-3vhc-576x-3qv4"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-3vhc-576x-3qv4 (aka CVE-2026-22818).\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono JWK Auth Middleware has JWT algorithm confusion when JWK lacks \"alg\" (untrusted header.alg fallback)\n\nAliases: CVE-2026-22818\nAdvisory: https://osv.dev/vulnerability/GHSA-3vhc-576x-3qv4\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.7}}, {"id": "scanner-30ea89d96332344c", "name": "Vulnerable dependency hono 4.6.14: GHSA-458j-xx4x-4375", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-458j-xx4x-4375"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-458j-xx4x-4375 (aka CVE-2026-56761).\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nhono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR\n\nAliases: CVE-2026-56761\nAdvisory: https://osv.dev/vulnerability/GHSA-458j-xx4x-4375\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-7f0ca5c85cd25542", "name": "Vulnerable dependency hono 4.6.14: GHSA-5pq2-9x2x-5p6w", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-5pq2-9x2x-5p6w"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-5pq2-9x2x-5p6w (aka CVE-2026-29086).\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie()\n\nAliases: CVE-2026-29086\nAdvisory: https://osv.dev/vulnerability/GHSA-5pq2-9x2x-5p6w\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-46ddd385d67c1cfe", "name": "Vulnerable dependency hono 4.6.14: GHSA-69xw-7hcm-h432", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-69xw-7hcm-h432"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-69xw-7hcm-h432 (aka CVE-2026-44455).\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nhono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection\n\nAliases: CVE-2026-44455\nAdvisory: https://osv.dev/vulnerability/GHSA-69xw-7hcm-h432\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-081df53e5a8ba026", "name": "Vulnerable dependency hono 4.6.14: GHSA-6wqw-2p9w-4vw4", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-6wqw-2p9w-4vw4"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-6wqw-2p9w-4vw4 (aka CVE-2026-24472).\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono cache middleware ignores \"Cache-Control: private\" leading to Web Cache Deception\n\nAliases: CVE-2026-24472\nAdvisory: https://osv.dev/vulnerability/GHSA-6wqw-2p9w-4vw4\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-a4942a053c514b6e", "name": "Vulnerable dependency hono 4.6.14: GHSA-88fw-hqm2-52qc", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-88fw-hqm2-52qc"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-88fw-hqm2-52qc (aka CVE-2026-54290).\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nhono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard\n\nAliases: CVE-2026-54290\nAdvisory: https://osv.dev/vulnerability/GHSA-88fw-hqm2-52qc\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.7}}, {"id": "scanner-fb6eae4a77fa7597", "name": "Vulnerable dependency hono 4.6.14: GHSA-92vj-g62v-jqhh", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-92vj-g62v-jqhh"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-92vj-g62v-jqhh (aka CVE-2025-59139).\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono has Body Limit Middleware Bypass\n\nAliases: CVE-2025-59139\nAdvisory: https://osv.dev/vulnerability/GHSA-92vj-g62v-jqhh\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-9f7560909c78c3c7", "name": "Vulnerable dependency hono 4.6.14: GHSA-9r54-q6cx-xmh5", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-9r54-q6cx-xmh5"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-9r54-q6cx-xmh5 (aka CVE-2026-24771).\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono vulnerable to XSS through ErrorBoundary component\n\nAliases: CVE-2026-24771\nAdvisory: https://osv.dev/vulnerability/GHSA-9r54-q6cx-xmh5\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-d3bdc4ea6b67eedd", "name": "Vulnerable dependency hono 4.6.14: GHSA-9vqf-7f2p-gf9v", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-9vqf-7f2p-gf9v"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-9vqf-7f2p-gf9v (aka CVE-2026-44456).\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono: bodyLimit() can be bypassed for chunked / unknown-length requests\n\nAliases: CVE-2026-44456\nAdvisory: https://osv.dev/vulnerability/GHSA-9vqf-7f2p-gf9v\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-dac77c50b362128f", "name": "Vulnerable dependency hono 4.6.14: GHSA-f577-qrjj-4474", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-f577-qrjj-4474"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-f577-qrjj-4474 (aka CVE-2026-47673).\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono: JWT middleware accepts any Authorization scheme, not only Bearer\n\nAliases: CVE-2026-47673\nAdvisory: https://osv.dev/vulnerability/GHSA-f577-qrjj-4474\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-3296d7ed6319c288", "name": "Vulnerable dependency hono 4.6.14: GHSA-f67f-6cw9-8mq4", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-f67f-6cw9-8mq4"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-f67f-6cw9-8mq4 (aka CVE-2026-22817).\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono JWT Middleware's JWT Algorithm Confusion via Unsafe Default (HS256) Allows Token Forgery and Auth Bypass\n\nAliases: CVE-2026-22817\nAdvisory: https://osv.dev/vulnerability/GHSA-f67f-6cw9-8mq4\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.7}}, {"id": "scanner-ffa1e9f6c686fe79", "name": "Vulnerable dependency hono 4.6.14: GHSA-gq3j-xvxp-8hrf", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-gq3j-xvxp-8hrf"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-gq3j-xvxp-8hrf (aka CVE-2026-56764).\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono added timing comparison hardening in basicAuth and bearerAuth\n\nAliases: CVE-2026-56764\nAdvisory: https://osv.dev/vulnerability/GHSA-gq3j-xvxp-8hrf\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.7}}, {"id": "scanner-f71b119a491d8b32", "name": "Vulnerable dependency hono 4.6.14: GHSA-hm8q-7f3q-5f36", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-hm8q-7f3q-5f36"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-hm8q-7f3q-5f36 (aka CVE-2026-44459).\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()\n\nAliases: CVE-2026-44459\nAdvisory: https://osv.dev/vulnerability/GHSA-hm8q-7f3q-5f36\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.7}}, {"id": "scanner-c30bd24555220c88", "name": "Vulnerable dependency hono 4.6.14: GHSA-j6c9-x7qj-28xf", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-j6c9-x7qj-28xf"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-j6c9-x7qj-28xf (aka CVE-2026-54287).\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nhono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice\n\nAliases: CVE-2026-54287\nAdvisory: https://osv.dev/vulnerability/GHSA-j6c9-x7qj-28xf\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-babfb05ed9a2614a", "name": "Vulnerable dependency hono 4.6.14: GHSA-m732-5p4w-x69g", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-m732-5p4w-x69g"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-m732-5p4w-x69g (aka CVE-2025-62610).\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono Improper Authorization vulnerability\n\nAliases: CVE-2025-62610\nAdvisory: https://osv.dev/vulnerability/GHSA-m732-5p4w-x69g\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.7}}, {"id": "scanner-8fa677dbe9f2d7ff", "name": "Vulnerable dependency hono 4.6.14: GHSA-p6xx-57qc-3wxr", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-p6xx-57qc-3wxr"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-p6xx-57qc-3wxr (aka CVE-2026-29085).\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE()\n\nAliases: CVE-2026-29085\nAdvisory: https://osv.dev/vulnerability/GHSA-p6xx-57qc-3wxr\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-23641608e04ac2d4", "name": "Vulnerable dependency hono 4.6.14: GHSA-p77w-8qqv-26rm", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-p77w-8qqv-26rm"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-p77w-8qqv-26rm (aka CVE-2026-44457).\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage\n\nAliases: CVE-2026-44457\nAdvisory: https://osv.dev/vulnerability/GHSA-p77w-8qqv-26rm\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-3aa30f0ce07c7eca", "name": "Vulnerable dependency hono 4.6.14: GHSA-q5qw-h33p-qvwr", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-q5qw-h33p-qvwr"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-q5qw-h33p-qvwr.\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q5qw-h33p-qvwr\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-165b421d3f66acbb", "name": "Vulnerable dependency hono 4.6.14: GHSA-q7jf-gf43-6x6p", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-q7jf-gf43-6x6p"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-q7jf-gf43-6x6p.\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q7jf-gf43-6x6p\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-a98f04cd004533b8", "name": "Vulnerable dependency hono 4.6.14: GHSA-qp7p-654g-cw7p", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-qp7p-654g-cw7p"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-qp7p-654g-cw7p.\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-qp7p-654g-cw7p\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-eef78d5561baa71e", "name": "Vulnerable dependency hono 4.6.14: GHSA-r354-f388-2fhh", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-r354-f388-2fhh"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-r354-f388-2fhh.\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r354-f388-2fhh\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-2f6cec31bff337f0", "name": "Vulnerable dependency hono 4.6.14: GHSA-r5rp-j6wh-rvv4", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-r5rp-j6wh-rvv4"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-r5rp-j6wh-rvv4.\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r5rp-j6wh-rvv4\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-c3bf2667d28100a6", "name": "Vulnerable dependency hono 4.6.14: GHSA-rv63-4mwf-qqc2", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-rv63-4mwf-qqc2"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-rv63-4mwf-qqc2.\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-rv63-4mwf-qqc2\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-07c33b9f0f20a85d", "name": "Vulnerable dependency hono 4.6.14: GHSA-v8w9-8mx6-g223", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-v8w9-8mx6-g223"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-v8w9-8mx6-g223.\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-v8w9-8mx6-g223\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-a710a3f8f9e6c4c6", "name": "Vulnerable dependency hono 4.6.14: GHSA-w332-q679-j88p", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-w332-q679-j88p"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-w332-q679-j88p.\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w332-q679-j88p\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-5c13141f9fe41f4c", "name": "Vulnerable dependency hono 4.6.14: GHSA-w62v-xxxg-mg59", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-w62v-xxxg-mg59"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-w62v-xxxg-mg59.\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w62v-xxxg-mg59\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-233775e736da0444", "name": "Vulnerable dependency hono 4.6.14: GHSA-wgpf-jwqj-8h8p", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-wgpf-jwqj-8h8p"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-wgpf-jwqj-8h8p.\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wgpf-jwqj-8h8p\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-ff8e253156f28e84", "name": "Vulnerable dependency hono 4.6.14: GHSA-wmmm-f939-6g9c", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-wmmm-f939-6g9c"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-wmmm-f939-6g9c.\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wmmm-f939-6g9c\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-1c57304cc50210e3", "name": "Vulnerable dependency hono 4.6.14: GHSA-wwfh-h76j-fc44", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-wwfh-h76j-fc44"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-wwfh-h76j-fc44.\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wwfh-h76j-fc44\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-c01913209a47d2ee", "name": "Vulnerable dependency hono 4.6.14: GHSA-xf4j-xp2r-rqqx", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-xf4j-xp2r-rqqx"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-xf4j-xp2r-rqqx.\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xf4j-xp2r-rqqx\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-e6c2f45ec12c4abd", "name": "Vulnerable dependency hono 4.6.14: GHSA-xgm2-5f3f-mvvc", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-xgm2-5f3f-mvvc"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-xgm2-5f3f-mvvc.\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xgm2-5f3f-mvvc\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-543ff6922130bcb2", "name": "Vulnerable dependency hono 4.6.14: GHSA-xpcf-pg52-r92g", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-xpcf-pg52-r92g"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-xpcf-pg52-r92g.\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xpcf-pg52-r92g\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-fa1847e765f5f553", "name": "Vulnerable dependency hono 4.6.14: GHSA-xrhx-7g5j-rcj5", "shortDescription": {"text": "Vulnerable dependency hono 4.6.14: GHSA-xrhx-7g5j-rcj5"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.14` (declared in `phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json`) is affected by GHSA-xrhx-7g5j-rcj5.\nNote: `4.6.14` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xrhx-7g5j-rcj5\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-e037a7c5be2d003f", "name": "Vulnerable dependency ws 8.18.0: GHSA-58qx-3vcg-4xpx", "shortDescription": {"text": "Vulnerable dependency ws 8.18.0: GHSA-58qx-3vcg-4xpx"}, "fullDescription": {"text": "OSV.dev reports `ws` at version `8.18.0` (declared in `phases/19-capstone-projects/03-realtime-voice-assistant/code/ts/package.json`) is affected by GHSA-58qx-3vcg-4xpx.\nNote: `8.18.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-58qx-3vcg-4xpx\nFix: upgrade `ws` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-ea2730a7122c9278", "name": "Vulnerable dependency ws 8.18.0: GHSA-96hv-2xvq-fx4p", "shortDescription": {"text": "Vulnerable dependency ws 8.18.0: GHSA-96hv-2xvq-fx4p"}, "fullDescription": {"text": "OSV.dev reports `ws` at version `8.18.0` (declared in `phases/19-capstone-projects/03-realtime-voice-assistant/code/ts/package.json`) is affected by GHSA-96hv-2xvq-fx4p.\nNote: `8.18.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-96hv-2xvq-fx4p\nFix: upgrade `ws` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-256ca97f8d8ea017", "name": "Vulnerable dependency hono 4.6.0: GHSA-2234-fmw7-43wr", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-2234-fmw7-43wr"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-2234-fmw7-43wr.\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-2234-fmw7-43wr\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-67a0a5b919ff587d", "name": "Vulnerable dependency hono 4.6.0: GHSA-26pp-8wgv-hjvm", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-26pp-8wgv-hjvm"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-26pp-8wgv-hjvm (aka CVE-2026-56762).\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono missing validation of cookie name on write path in setCookie()\n\nAliases: CVE-2026-56762\nAdvisory: https://osv.dev/vulnerability/GHSA-26pp-8wgv-hjvm\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-f115a7daab4a6dea", "name": "Vulnerable dependency hono 4.6.0: GHSA-2gcr-mfcq-wcc3", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-2gcr-mfcq-wcc3"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-2gcr-mfcq-wcc3 (aka CVE-2026-47676).\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths\n\nAliases: CVE-2026-47676\nAdvisory: https://osv.dev/vulnerability/GHSA-2gcr-mfcq-wcc3\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-e487de1be0874edd", "name": "Vulnerable dependency hono 4.6.0: GHSA-3hrh-pfw6-9m5x", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-3hrh-pfw6-9m5x"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-3hrh-pfw6-9m5x (aka CVE-2026-47675).\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection\n\nAliases: CVE-2026-47675\nAdvisory: https://osv.dev/vulnerability/GHSA-3hrh-pfw6-9m5x\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-25997eb20947260f", "name": "Vulnerable dependency hono 4.6.0: GHSA-3vhc-576x-3qv4", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-3vhc-576x-3qv4"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-3vhc-576x-3qv4 (aka CVE-2026-22818).\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono JWK Auth Middleware has JWT algorithm confusion when JWK lacks \"alg\" (untrusted header.alg fallback)\n\nAliases: CVE-2026-22818\nAdvisory: https://osv.dev/vulnerability/GHSA-3vhc-576x-3qv4\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.7}}, {"id": "scanner-c6154f5c8668fb57", "name": "Vulnerable dependency hono 4.6.0: GHSA-458j-xx4x-4375", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-458j-xx4x-4375"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-458j-xx4x-4375 (aka CVE-2026-56761).\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nhono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR\n\nAliases: CVE-2026-56761\nAdvisory: https://osv.dev/vulnerability/GHSA-458j-xx4x-4375\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-893e28bcbd765660", "name": "Vulnerable dependency hono 4.6.0: GHSA-5pq2-9x2x-5p6w", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-5pq2-9x2x-5p6w"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-5pq2-9x2x-5p6w (aka CVE-2026-29086).\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie()\n\nAliases: CVE-2026-29086\nAdvisory: https://osv.dev/vulnerability/GHSA-5pq2-9x2x-5p6w\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-e7fa01297971674c", "name": "Vulnerable dependency hono 4.6.0: GHSA-69xw-7hcm-h432", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-69xw-7hcm-h432"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-69xw-7hcm-h432 (aka CVE-2026-44455).\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nhono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection\n\nAliases: CVE-2026-44455\nAdvisory: https://osv.dev/vulnerability/GHSA-69xw-7hcm-h432\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-65a0a649b18e0fa0", "name": "Vulnerable dependency hono 4.6.0: GHSA-6wqw-2p9w-4vw4", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-6wqw-2p9w-4vw4"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-6wqw-2p9w-4vw4 (aka CVE-2026-24472).\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono cache middleware ignores \"Cache-Control: private\" leading to Web Cache Deception\n\nAliases: CVE-2026-24472\nAdvisory: https://osv.dev/vulnerability/GHSA-6wqw-2p9w-4vw4\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-90e1fdd6188b9902", "name": "Vulnerable dependency hono 4.6.0: GHSA-88fw-hqm2-52qc", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-88fw-hqm2-52qc"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-88fw-hqm2-52qc (aka CVE-2026-54290).\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nhono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard\n\nAliases: CVE-2026-54290\nAdvisory: https://osv.dev/vulnerability/GHSA-88fw-hqm2-52qc\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.7}}, {"id": "scanner-3b2c7586af575734", "name": "Vulnerable dependency hono 4.6.0: GHSA-92vj-g62v-jqhh", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-92vj-g62v-jqhh"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-92vj-g62v-jqhh (aka CVE-2025-59139).\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono has Body Limit Middleware Bypass\n\nAliases: CVE-2025-59139\nAdvisory: https://osv.dev/vulnerability/GHSA-92vj-g62v-jqhh\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-83c89ce4037c21b5", "name": "Vulnerable dependency hono 4.6.0: GHSA-9r54-q6cx-xmh5", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-9r54-q6cx-xmh5"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-9r54-q6cx-xmh5 (aka CVE-2026-24771).\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono vulnerable to XSS through ErrorBoundary component\n\nAliases: CVE-2026-24771\nAdvisory: https://osv.dev/vulnerability/GHSA-9r54-q6cx-xmh5\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-f94d9be9d3831e77", "name": "Vulnerable dependency hono 4.6.0: GHSA-9vqf-7f2p-gf9v", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-9vqf-7f2p-gf9v"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-9vqf-7f2p-gf9v (aka CVE-2026-44456).\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono: bodyLimit() can be bypassed for chunked / unknown-length requests\n\nAliases: CVE-2026-44456\nAdvisory: https://osv.dev/vulnerability/GHSA-9vqf-7f2p-gf9v\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-22a2d09dcddfaedd", "name": "Vulnerable dependency hono 4.6.0: GHSA-f577-qrjj-4474", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-f577-qrjj-4474"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-f577-qrjj-4474 (aka CVE-2026-47673).\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono: JWT middleware accepts any Authorization scheme, not only Bearer\n\nAliases: CVE-2026-47673\nAdvisory: https://osv.dev/vulnerability/GHSA-f577-qrjj-4474\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-21b0a747213001a7", "name": "Vulnerable dependency hono 4.6.0: GHSA-f67f-6cw9-8mq4", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-f67f-6cw9-8mq4"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-f67f-6cw9-8mq4 (aka CVE-2026-22817).\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono JWT Middleware's JWT Algorithm Confusion via Unsafe Default (HS256) Allows Token Forgery and Auth Bypass\n\nAliases: CVE-2026-22817\nAdvisory: https://osv.dev/vulnerability/GHSA-f67f-6cw9-8mq4\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.7}}, {"id": "scanner-51cb31cc33377190", "name": "Vulnerable dependency hono 4.6.0: GHSA-gq3j-xvxp-8hrf", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-gq3j-xvxp-8hrf"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-gq3j-xvxp-8hrf (aka CVE-2026-56764).\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono added timing comparison hardening in basicAuth and bearerAuth\n\nAliases: CVE-2026-56764\nAdvisory: https://osv.dev/vulnerability/GHSA-gq3j-xvxp-8hrf\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.7}}, {"id": "scanner-27fb064aea23e48f", "name": "Vulnerable dependency hono 4.6.0: GHSA-hm8q-7f3q-5f36", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-hm8q-7f3q-5f36"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-hm8q-7f3q-5f36 (aka CVE-2026-44459).\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()\n\nAliases: CVE-2026-44459\nAdvisory: https://osv.dev/vulnerability/GHSA-hm8q-7f3q-5f36\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.7}}, {"id": "scanner-6b07ab0e966e6814", "name": "Vulnerable dependency hono 4.6.0: GHSA-j6c9-x7qj-28xf", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-j6c9-x7qj-28xf"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-j6c9-x7qj-28xf (aka CVE-2026-54287).\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nhono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice\n\nAliases: CVE-2026-54287\nAdvisory: https://osv.dev/vulnerability/GHSA-j6c9-x7qj-28xf\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-5bf21d05cb8d994b", "name": "Vulnerable dependency hono 4.6.0: GHSA-m732-5p4w-x69g", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-m732-5p4w-x69g"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-m732-5p4w-x69g (aka CVE-2025-62610).\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono Improper Authorization vulnerability\n\nAliases: CVE-2025-62610\nAdvisory: https://osv.dev/vulnerability/GHSA-m732-5p4w-x69g\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.7}}, {"id": "scanner-9a944e3337278ff1", "name": "Vulnerable dependency hono 4.6.0: GHSA-p6xx-57qc-3wxr", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-p6xx-57qc-3wxr"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-p6xx-57qc-3wxr (aka CVE-2026-29085).\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE()\n\nAliases: CVE-2026-29085\nAdvisory: https://osv.dev/vulnerability/GHSA-p6xx-57qc-3wxr\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-17405deffaf61d3b", "name": "Vulnerable dependency hono 4.6.0: GHSA-p77w-8qqv-26rm", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-p77w-8qqv-26rm"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-p77w-8qqv-26rm (aka CVE-2026-44457).\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nHono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage\n\nAliases: CVE-2026-44457\nAdvisory: https://osv.dev/vulnerability/GHSA-p77w-8qqv-26rm\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-a0e039ef042a5815", "name": "Vulnerable dependency hono 4.6.0: GHSA-q5qw-h33p-qvwr", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-q5qw-h33p-qvwr"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-q5qw-h33p-qvwr.\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q5qw-h33p-qvwr\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-f6a615da69b61cfa", "name": "Vulnerable dependency hono 4.6.0: GHSA-q7jf-gf43-6x6p", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-q7jf-gf43-6x6p"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-q7jf-gf43-6x6p.\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q7jf-gf43-6x6p\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-d62cde5dd529fdbc", "name": "Vulnerable dependency hono 4.6.0: GHSA-qp7p-654g-cw7p", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-qp7p-654g-cw7p"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-qp7p-654g-cw7p.\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-qp7p-654g-cw7p\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-d364751725edc1f0", "name": "Vulnerable dependency hono 4.6.0: GHSA-r354-f388-2fhh", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-r354-f388-2fhh"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-r354-f388-2fhh.\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r354-f388-2fhh\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-85a52b2a406ad554", "name": "Vulnerable dependency hono 4.6.0: GHSA-r5rp-j6wh-rvv4", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-r5rp-j6wh-rvv4"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-r5rp-j6wh-rvv4.\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r5rp-j6wh-rvv4\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-111beb96e429d284", "name": "Vulnerable dependency hono 4.6.0: GHSA-rv63-4mwf-qqc2", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-rv63-4mwf-qqc2"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-rv63-4mwf-qqc2.\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-rv63-4mwf-qqc2\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-51ba23a30ec8142f", "name": "Vulnerable dependency hono 4.6.0: GHSA-v8w9-8mx6-g223", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-v8w9-8mx6-g223"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-v8w9-8mx6-g223.\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-v8w9-8mx6-g223\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-c7f142b6ed2e342b", "name": "Vulnerable dependency hono 4.6.0: GHSA-w332-q679-j88p", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-w332-q679-j88p"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-w332-q679-j88p.\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w332-q679-j88p\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-70a7dc1d94167d55", "name": "Vulnerable dependency hono 4.6.0: GHSA-w62v-xxxg-mg59", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-w62v-xxxg-mg59"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-w62v-xxxg-mg59.\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w62v-xxxg-mg59\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-ca63e52d53651dde", "name": "Vulnerable dependency hono 4.6.0: GHSA-wgpf-jwqj-8h8p", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-wgpf-jwqj-8h8p"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-wgpf-jwqj-8h8p.\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wgpf-jwqj-8h8p\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-0ee9745e3210faf1", "name": "Vulnerable dependency hono 4.6.0: GHSA-wmmm-f939-6g9c", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-wmmm-f939-6g9c"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-wmmm-f939-6g9c.\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wmmm-f939-6g9c\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-db31a745930dd2b3", "name": "Vulnerable dependency hono 4.6.0: GHSA-wwfh-h76j-fc44", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-wwfh-h76j-fc44"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-wwfh-h76j-fc44.\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wwfh-h76j-fc44\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-7178e7f917cc399b", "name": "Vulnerable dependency hono 4.6.0: GHSA-xf4j-xp2r-rqqx", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-xf4j-xp2r-rqqx"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-xf4j-xp2r-rqqx.\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xf4j-xp2r-rqqx\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-9299c7549768c4f9", "name": "Vulnerable dependency hono 4.6.0: GHSA-xgm2-5f3f-mvvc", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-xgm2-5f3f-mvvc"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-xgm2-5f3f-mvvc.\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xgm2-5f3f-mvvc\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-1748f491c1af20f0", "name": "Vulnerable dependency hono 4.6.0: GHSA-xpcf-pg52-r92g", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-xpcf-pg52-r92g"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-xpcf-pg52-r92g.\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xpcf-pg52-r92g\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-ad5e37e928edaca7", "name": "Vulnerable dependency hono 4.6.0: GHSA-xrhx-7g5j-rcj5", "shortDescription": {"text": "Vulnerable dependency hono 4.6.0: GHSA-xrhx-7g5j-rcj5"}, "fullDescription": {"text": "OSV.dev reports `hono` at version `4.6.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-xrhx-7g5j-rcj5.\nNote: `4.6.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xrhx-7g5j-rcj5\nFix: upgrade `hono` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-022edcd4f6cf7098", "name": "Vulnerable dependency @hono/node-server 1.13.0: GHSA-92pp-h63x-v22m", "shortDescription": {"text": "Vulnerable dependency @hono/node-server 1.13.0: GHSA-92pp-h63x-v22m"}, "fullDescription": {"text": "OSV.dev reports `@hono/node-server` at version `1.13.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-92pp-h63x-v22m.\nNote: `1.13.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-92pp-h63x-v22m\nFix: upgrade `@hono/node-server` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-2f1a078078132d4e", "name": "Vulnerable dependency @hono/node-server 1.13.0: GHSA-frvp-7c67-39w9", "shortDescription": {"text": "Vulnerable dependency @hono/node-server 1.13.0: GHSA-frvp-7c67-39w9"}, "fullDescription": {"text": "OSV.dev reports `@hono/node-server` at version `1.13.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-frvp-7c67-39w9.\nNote: `1.13.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-frvp-7c67-39w9\nFix: upgrade `@hono/node-server` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-482595b72bc11014", "name": "Vulnerable dependency @hono/node-server 1.13.0: GHSA-wc8c-qw6v-h7f6", "shortDescription": {"text": "Vulnerable dependency @hono/node-server 1.13.0: GHSA-wc8c-qw6v-h7f6"}, "fullDescription": {"text": "OSV.dev reports `@hono/node-server` at version `1.13.0` (declared in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json`) is affected by GHSA-wc8c-qw6v-h7f6.\nNote: `1.13.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wc8c-qw6v-h7f6\nFix: upgrade `@hono/node-server` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-450ecf7a0d2f58dc", "name": "Dependency @hono/node-server is a major version behind", "shortDescription": {"text": "Dependency @hono/node-server is a major version behind"}, "fullDescription": {"text": "`@hono/node-server` is pinned at `1.13.0` in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json` while the latest release on the npm registry is `2.0.11` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@hono/node-server` to `2.0.11`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-0933b3b15005bc1e", "name": "Dependency zod is a major version behind", "shortDescription": {"text": "Dependency zod is a major version behind"}, "fullDescription": {"text": "`zod` is pinned at `3.23.0` in `phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json` while the latest release on the npm registry is `4.4.3` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `zod` to `4.4.3`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-f92d78fc52693c3b", "name": "Dependency zod is a major version behind", "shortDescription": {"text": "Dependency zod is a major version behind"}, "fullDescription": {"text": "`zod` is pinned at `3.23.8` in `phases/19-capstone-projects/01-terminal-native-coding-agent/code/ts/package.json` while the latest release on the npm registry is `4.4.3` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `zod` to `4.4.3`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-71c62f13729b3c54", "name": "Dangling fetch: GET /document/10k-acme-2025 (phases/19-capstone-projects/04-multimodal-document-qa/code/ts/tests/server.", "shortDescription": {"text": "Dangling fetch: GET /document/10k-acme-2025 (phases/19-capstone-projects/04-multimodal-document-qa/code/ts/tests/server.test.ts:22)"}, "fullDescription": {"text": "`phases/19-capstone-projects/04-multimodal-document-qa/code/ts/tests/server.test.ts:22` calls `GET /document/10k-acme-2025` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/document/10k-acme-2025`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-62ccc7f0dd1c0c27", "name": "Dangling fetch: GET /document/10k-acme-2025 (phases/19-capstone-projects/04-multimodal-document-qa/code/ts/tests/server.", "shortDescription": {"text": "Dangling fetch: GET /document/10k-acme-2025 (phases/19-capstone-projects/04-multimodal-document-qa/code/ts/tests/server.test.ts:32)"}, "fullDescription": {"text": "`phases/19-capstone-projects/04-multimodal-document-qa/code/ts/tests/server.test.ts:32` calls `GET /document/10k-acme-2025` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/document/10k-acme-2025`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-93e5dc70e250c01a", "name": "Dangling fetch: GET /document/missing (phases/19-capstone-projects/04-multimodal-document-qa/code/ts/tests/server.test.t", "shortDescription": {"text": "Dangling fetch: GET /document/missing (phases/19-capstone-projects/04-multimodal-document-qa/code/ts/tests/server.test.ts:38)"}, "fullDescription": {"text": "`phases/19-capstone-projects/04-multimodal-document-qa/code/ts/tests/server.test.ts:38` calls `GET /document/missing` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/document/missing`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a483e3f1df563d6c", "name": "Dangling fetch: GET /document/has.dot (phases/19-capstone-projects/04-multimodal-document-qa/code/ts/tests/server.test.t", "shortDescription": {"text": "Dangling fetch: GET /document/has.dot (phases/19-capstone-projects/04-multimodal-document-qa/code/ts/tests/server.test.ts:45)"}, "fullDescription": {"text": "`phases/19-capstone-projects/04-multimodal-document-qa/code/ts/tests/server.test.ts:45` calls `GET /document/has.dot` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/document/has.dot`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ee170cea5be40f0a", "name": "Dangling fetch: POST https://api.anthropic.com/v1/messages (phases/00-setup-and-tooling/04-apis-and-keys/code/first_api_", "shortDescription": {"text": "Dangling fetch: POST https://api.anthropic.com/v1/messages (phases/00-setup-and-tooling/04-apis-and-keys/code/first_api_call.ts:74)"}, "fullDescription": {"text": "`phases/00-setup-and-tooling/04-apis-and-keys/code/first_api_call.ts:74` calls `POST https://api.anthropic.com/v1/messages` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.anthropic.com/v1/messages`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4a8f762925460ea1", "name": "Unused endpoint: GET /lesson/next", "shortDescription": {"text": "Unused endpoint: GET /lesson/next"}, "fullDescription": {"text": "`phases/19-capstone-projects/17-personal-ai-tutor/code/ts/src/server.ts` declares `GET /lesson/next` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b33b638af57cd3a9", "name": "Unused endpoint: POST /lesson/:id/submit", "shortDescription": {"text": "Unused endpoint: POST /lesson/:id/submit"}, "fullDescription": {"text": "`phases/19-capstone-projects/17-personal-ai-tutor/code/ts/src/server.ts` declares `POST /lesson/:id/submit` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1008c575819b3d37", "name": "Unused endpoint: GET /jobs", "shortDescription": {"text": "Unused endpoint: GET /jobs"}, "fullDescription": {"text": "`phases/19-capstone-projects/12-video-understanding-pipeline/code/ts/src/server.ts` declares `GET /jobs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-80182839f64600f5", "name": "Unused endpoint: GET /job/:id", "shortDescription": {"text": "Unused endpoint: GET /job/:id"}, "fullDescription": {"text": "`phases/19-capstone-projects/12-video-understanding-pipeline/code/ts/src/server.ts` declares `GET /job/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4c197182957464b0", "name": "Unused endpoint: GET /document/:id", "shortDescription": {"text": "Unused endpoint: GET /document/:id"}, "fullDescription": {"text": "`phases/19-capstone-projects/04-multimodal-document-qa/code/ts/src/server.ts` declares `GET /document/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d504b80adc9409ec", "name": "Unused endpoint: GET /dashboard", "shortDescription": {"text": "Unused endpoint: GET /dashboard"}, "fullDescription": {"text": "`phases/19-capstone-projects/09-code-migration-agent/code/ts/src/server.ts` declares `GET /dashboard` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-50719d00ac3cf209", "name": "Unused endpoint: GET /migrations", "shortDescription": {"text": "Unused endpoint: GET /migrations"}, "fullDescription": {"text": "`phases/19-capstone-projects/09-code-migration-agent/code/ts/src/server.ts` declares `GET /migrations` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8e8bb263642cdbf9", "name": "Unused endpoint: GET /migrations/:id", "shortDescription": {"text": "Unused endpoint: GET /migrations/:id"}, "fullDescription": {"text": "`phases/19-capstone-projects/09-code-migration-agent/code/ts/src/server.ts` declares `GET /migrations/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-07f772e4ca8f34fa", "name": "Unused endpoint: POST /trace", "shortDescription": {"text": "Unused endpoint: POST /trace"}, "fullDescription": {"text": "`phases/19-capstone-projects/11-llm-observability-dashboard/code/ts/src/server.ts` declares `POST /trace` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6eab0e0e4e3fc0c9", "name": "Unused endpoint: GET /dashboard.json", "shortDescription": {"text": "Unused endpoint: GET /dashboard.json"}, "fullDescription": {"text": "`phases/19-capstone-projects/11-llm-observability-dashboard/code/ts/src/server.ts` declares `GET /dashboard.json` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-59f45351017a2161", "name": "Unused endpoint: GET /query", "shortDescription": {"text": "Unused endpoint: GET /query"}, "fullDescription": {"text": "`phases/19-capstone-projects/02-rag-over-codebase/code/ts/src/server.ts` declares `GET /query` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1bb3714794b14146", "name": "Unused endpoint: POST /query", "shortDescription": {"text": "Unused endpoint: POST /query"}, "fullDescription": {"text": "`phases/19-capstone-projects/02-rag-over-codebase/code/ts/src/server.ts` declares `POST /query` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0ae38010c60493f1", "name": "Unused endpoint: POST /webhook", "shortDescription": {"text": "Unused endpoint: POST /webhook"}, "fullDescription": {"text": "`phases/19-capstone-projects/16-github-issue-to-pr-agent/code/ts/src/server.ts` declares `POST /webhook` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/30750"}, "properties": {"repository": "rohitg00/ai-engineering-from-scratch", "repoUrl": "https://github.com/rohitg00/ai-engineering-from-scratch", "branch": "main"}, "results": [{"ruleId": "scanner-4a812742fd7fa6c5", "level": "note", "message": {"text": "Possibly dead Python function: check_url"}, "properties": {"repobilityId": "58f52ed55b566159", "scanner": "scanner-primary", "fingerprint": "4a812742fd7fa6c5", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/link_check.py:262"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-de021663e5cd9a35", "level": "note", "message": {"text": "Possibly dead Python function: tokenize_jsonl_path"}, "properties": {"repobilityId": "d071bb45da3373cf", "scanner": "scanner-primary", "fingerprint": "de021663e5cd9a35", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/43-hdf5-tokenized-corpus/code/main.py:437"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-be50a9b7fa2d9148", "level": "note", "message": {"text": "Possibly dead Python function: unsafe"}, "properties": {"repobilityId": "fbd6556b16d9a28c", "scanner": "scanner-primary", "fingerprint": "be50a9b7fa2d9148", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/84-refusal-evaluation/code/prompts.py:99"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d8a76ca146ebdb64", "level": "note", "message": {"text": "Possibly dead Python function: safe"}, "properties": {"repobilityId": "6116b830eccf3b0d", "scanner": "scanner-primary", "fingerprint": "d8a76ca146ebdb64", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/84-refusal-evaluation/code/prompts.py:103"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7d1c499b5f334e72", "level": "note", "message": {"text": "Possibly dead Python function: tool_run_shell"}, "properties": {"repobilityId": "015ac642a8f8661c", "scanner": "scanner-primary", "fingerprint": "7d1c499b5f334e72", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/01-terminal-native-coding-agent/code/main.py:115"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-98d4db7dfc6bc0f5", "level": "note", "message": {"text": "Possibly dead Python function: destructive_guard"}, "properties": {"repobilityId": "e4460943560565e4", "scanner": "scanner-primary", "fingerprint": "98d4db7dfc6bc0f5", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/01-terminal-native-coding-agent/code/main.py:164"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-173c6078fa951fb7", "level": "note", "message": {"text": "Possibly dead Python function: synthetic_loader"}, "properties": {"repobilityId": "0f1ab0328cab5e85", "scanner": "scanner-primary", "fingerprint": "173c6078fa951fb7", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/47-checkpoint-save-resume/code/main.py:70"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cd23e412e8161988", "level": "note", "message": {"text": "Possibly dead Python function: rank_main"}, "properties": {"repobilityId": "3af70bf88460bc29", "scanner": "scanner-primary", "fingerprint": "cd23e412e8161988", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/48-distributed-fsdp-ddp/code/main.py:223"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e5b150cc4bc96803", "level": "note", "message": {"text": "Possibly dead Python function: write_response"}, "properties": {"repobilityId": "2bdf19af562afa7e", "scanner": "scanner-primary", "fingerprint": "e5b150cc4bc96803", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/22-jsonrpc-stdio-transport/code/main.py:122"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ce52a9913333dfc3", "level": "note", "message": {"text": "Possibly dead Python function: apply_known_fixes"}, "properties": {"repobilityId": "fa7a1b98b0156094", "scanner": "scanner-primary", "fingerprint": "ce52a9913333dfc3", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/27-eval-harness-fixture-tasks/code/main.py:290"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5b4a787aaaa91e92", "level": "note", "message": {"text": "Possibly dead Python function: noop_candidate"}, "properties": {"repobilityId": "65976f400e28127a", "scanner": "scanner-primary", "fingerprint": "5b4a787aaaa91e92", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/27-eval-harness-fixture-tasks/code/main.py:317"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-68c154aef3525fd1", "level": "note", "message": {"text": "Possibly dead Python function: reverse_list"}, "properties": {"repobilityId": "9eca8ee357ca3e1a", "scanner": "scanner-primary", "fingerprint": "68c154aef3525fd1", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/27-eval-harness-fixture-tasks/code/tasks/task_004_empty_reverse/expected/reverse.py:1"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3e65786ffb3f40dd", "level": "note", "message": {"text": "Possibly dead Python function: reverse_list"}, "properties": {"repobilityId": "9eca8ee357ca3e1a", "scanner": "scanner-primary", "fingerprint": "3e65786ffb3f40dd", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/27-eval-harness-fixture-tasks/code/tasks/task_004_empty_reverse/buggy/reverse.py:1"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2600512e42a18b57", "level": "note", "message": {"text": "Possibly dead Python function: fizzbuzz"}, "properties": {"repobilityId": "4a763d673363f4af", "scanner": "scanner-primary", "fingerprint": "2600512e42a18b57", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/27-eval-harness-fixture-tasks/code/tasks/task_001_fizzbuzz_offbyone/expected/fizzbuzz.py:1"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ce229413542e8500", "level": "note", "message": {"text": "Possibly dead Python function: fizzbuzz"}, "properties": {"repobilityId": "4a763d673363f4af", "scanner": "scanner-primary", "fingerprint": "ce229413542e8500", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/27-eval-harness-fixture-tasks/code/tasks/task_001_fizzbuzz_offbyone/buggy/fizzbuzz.py:1"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ce935002d5258301", "level": "note", "message": {"text": "Possibly dead Python function: linked_list_length"}, "properties": {"repobilityId": "6c67c22b3d6c1797", "scanner": "scanner-primary", "fingerprint": "ce935002d5258301", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/27-eval-harness-fixture-tasks/code/tasks/task_005_linked_list_traversal/expected/linked_list.py:7"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa75e63ce1991472", "level": "note", "message": {"text": "Possibly dead Python function: linked_list_length"}, "properties": {"repobilityId": "6c67c22b3d6c1797", "scanner": "scanner-primary", "fingerprint": "aa75e63ce1991472", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/27-eval-harness-fixture-tasks/code/tasks/task_005_linked_list_traversal/buggy/linked_list.py:7"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-697550bc1acaf330", "level": "note", "message": {"text": "Possibly dead Python function: baseline_pipeline"}, "properties": {"repobilityId": "d4662ebc8284fbe2", "scanner": "scanner-primary", "fingerprint": "697550bc1acaf330", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/68-rag-eval-precision-recall/code/main.py:272"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9b79afc69e633d93", "level": "note", "message": {"text": "Possibly dead Python function: hybrid_plus_rerank_pipeline"}, "properties": {"repobilityId": "44b5d1f1d1db4cca", "scanner": "scanner-primary", "fingerprint": "9b79afc69e633d93", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/68-rag-eval-precision-recall/code/main.py:324"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5f37af56efc4f07d", "level": "note", "message": {"text": "Possibly dead Python function: inject_inf_into_first_grad"}, "properties": {"repobilityId": "50c363f572ae8429", "scanner": "scanner-primary", "fingerprint": "5f37af56efc4f07d", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/45-gradient-clipping-amp/code/main.py:361"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-06702fdeeb246417", "level": "note", "message": {"text": "Possibly dead Python function: deterministic_expander"}, "properties": {"repobilityId": "47e2e826f7ae804f", "scanner": "scanner-primary", "fingerprint": "06702fdeeb246417", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/56-iteration-scheduler/code/main.py:319"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-90db289ef1bed21a", "level": "note", "message": {"text": "Possibly dead Python function: to_envelope"}, "properties": {"repobilityId": "99d4a3a7fa6bb386", "scanner": "scanner-primary", "fingerprint": "90db289ef1bed21a", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/23-function-call-dispatcher/code/main.py:50"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a87fb8b39ed0c8c0", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 site/build.js:416"}, "properties": {"repobilityId": "9ea7157acfc42c3b", "scanner": "scanner-primary", "fingerprint": "a87fb8b39ed0c8c0", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a237b75f9f872a1d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/08-production-rag-chatbot/code/ts/src/index.ts:52"}, "properties": {"repobilityId": "1a5e19f16949c3f3", "scanner": "scanner-primary", "fingerprint": "a237b75f9f872a1d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ec077f27a21aea96", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/10-multi-agent-software-team/code/ts/tests/runtime.test.ts:46"}, "properties": {"repobilityId": "3040f8424772f17e", "scanner": "scanner-primary", "fingerprint": "ec077f27a21aea96", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-826d20092d689444", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/10-multi-agent-software-team/code/ts/src/index.ts:17"}, "properties": {"repobilityId": "599954cab5334c33", "scanner": "scanner-primary", "fingerprint": "826d20092d689444", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0adff22e10741564", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/06-devops-troubleshooting-agent/code/ts/src/index.ts:59"}, "properties": {"repobilityId": "a9f701d3e58063a0", "scanner": "scanner-primary", "fingerprint": "0adff22e10741564", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-cb1678f2c0a213de", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/01-terminal-native-coding-agent/code/ts/src/index.ts:32"}, "properties": {"repobilityId": "fe48f0e825b18934", "scanner": "scanner-primary", "fingerprint": "cb1678f2c0a213de", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-6ae8c68dc7dff908", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/01-terminal-native-coding-agent/code/ts/src/repl.ts:39"}, "properties": {"repobilityId": "72a4cbf3b2bc820a", "scanner": "scanner-primary", "fingerprint": "6ae8c68dc7dff908", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3cd87cd024c11ef3", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/04-multimodal-document-qa/code/ts/src/index.ts:47"}, "properties": {"repobilityId": "e376fe13611756f6", "scanner": "scanner-primary", "fingerprint": "3cd87cd024c11ef3", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-49e7681b82418f8a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/09-code-migration-agent/code/ts/src/index.ts:19"}, "properties": {"repobilityId": "87ab1d88d9a9be63", "scanner": "scanner-primary", "fingerprint": "49e7681b82418f8a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-1412d3263bb2624b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/11-llm-observability-dashboard/code/ts/src/index.ts:67"}, "properties": {"repobilityId": "448679aed6fbfa6a", "scanner": "scanner-primary", "fingerprint": "1412d3263bb2624b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0cd3758c93741fee", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/02-rag-over-codebase/code/ts/src/index.ts:81"}, "properties": {"repobilityId": "b1bef55944fd0474", "scanner": "scanner-primary", "fingerprint": "0cd3758c93741fee", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3302593f16cf871c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/03-realtime-voice-assistant/code/ts/src/index.ts:107"}, "properties": {"repobilityId": "f678972feb107fd7", "scanner": "scanner-primary", "fingerprint": "3302593f16cf871c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2d5575f25cfc8b71", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/19-capstone-projects/03-realtime-voice-assistant/code/ts/src/orchestrator.ts:154"}, "properties": {"repobilityId": "2b468d465e26569e", "scanner": "scanner-primary", "fingerprint": "2d5575f25cfc8b71", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9ee0978b7ad7373a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/13-tools-and-protocols/01-the-tool-interface/code/main.ts:206"}, "properties": {"repobilityId": "2d3aff175bfea3a1", "scanner": "scanner-primary", "fingerprint": "9ee0978b7ad7373a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3ecbbc92204469b3", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/13-tools-and-protocols/19-a2a-protocol/code/main.ts:107"}, "properties": {"repobilityId": "c20cc37255db9e51", "scanner": "scanner-primary", "fingerprint": "3ecbbc92204469b3", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-cf16cd3a14861551", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/13-tools-and-protocols/07-building-an-mcp-server/code/main.ts:298"}, "properties": {"repobilityId": "398bd6b1aa825fa1", "scanner": "scanner-primary", "fingerprint": "cf16cd3a14861551", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-072b3c2c2add441a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/05-nlp-foundations-to-advanced/19-subword-tokenization/code/main.ts:174"}, "properties": {"repobilityId": "7fb1666c4b3c59d9", "scanner": "scanner-primary", "fingerprint": "072b3c2c2add441a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d19289461ab40a2c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/05-nlp-foundations-to-advanced/23-chunking-strategies-rag/code/main.ts:169"}, "properties": {"repobilityId": "e2d5c86ef4230a5b", "scanner": "scanner-primary", "fingerprint": "d19289461ab40a2c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-1bbe4b4eb824f20b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/14-agent-engineering/01-the-agent-loop/code/main.ts:143"}, "properties": {"repobilityId": "bda13114dd11fc35", "scanner": "scanner-primary", "fingerprint": "1bbe4b4eb824f20b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5960f3f6733ecf4b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/14-agent-engineering/06-tool-use-and-function-calling/code/main.ts:204"}, "properties": {"repobilityId": "b450fc5e6cd85421", "scanner": "scanner-primary", "fingerprint": "5960f3f6733ecf4b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8d97ad7142627c89", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/14-agent-engineering/13-langgraph-stateful-graphs/code/main.ts:187"}, "properties": {"repobilityId": "c8438fb200de6a4c", "scanner": "scanner-primary", "fingerprint": "8d97ad7142627c89", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-bd83bd835d86cdd3", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/16-multi-agent-and-swarms/01-why-multi-agent/code/single_vs_multi.ts:228"}, "properties": {"repobilityId": "05399f202dfa67af", "scanner": "scanner-primary", "fingerprint": "bd83bd835d86cdd3", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-03b696f2b0a5297c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/16-multi-agent-and-swarms/03-communication-protocols/code/main.ts:681"}, "properties": {"repobilityId": "126b1bd087edde7f", "scanner": "scanner-primary", "fingerprint": "03b696f2b0a5297c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d61d02743bbce821", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/11-llm-engineering/12-guardrails/code/main.ts:351"}, "properties": {"repobilityId": "1ca6be1b7bb14dc8", "scanner": "scanner-primary", "fingerprint": "d61d02743bbce821", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-1df528d7d48c045a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/11-llm-engineering/04-embeddings/code/main.ts:249"}, "properties": {"repobilityId": "dded257585b9acac", "scanner": "scanner-primary", "fingerprint": "1df528d7d48c045a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-bc8d180f0e85a1dd", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/11-llm-engineering/01-prompt-engineering/code/main.ts:360"}, "properties": {"repobilityId": "96f628c766b15842", "scanner": "scanner-primary", "fingerprint": "bc8d180f0e85a1dd", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c632866472abb1ee", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/11-llm-engineering/09-function-calling/code/main.ts:324"}, "properties": {"repobilityId": "97731037a6b4ea15", "scanner": "scanner-primary", "fingerprint": "c632866472abb1ee", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-135f08e81661ae28", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/17-infrastructure-and-production/20-shadow-canary-progressive/code/main.ts:224"}, "properties": {"repobilityId": "e20c0a250c0f0ee8", "scanner": "scanner-primary", "fingerprint": "135f08e81661ae28", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-396efdad02b8c0f0", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/17-infrastructure-and-production/16-model-routing/code/main.ts:326"}, "properties": {"repobilityId": "4a3a7e3aabbdbdd7", "scanner": "scanner-primary", "fingerprint": "396efdad02b8c0f0", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2f8f335d6b50ea5c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/17-infrastructure-and-production/19-ai-gateways/code/main.ts:362"}, "properties": {"repobilityId": "7ab5495523b895bd", "scanner": "scanner-primary", "fingerprint": "2f8f335d6b50ea5c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4b0896a9b50e4625", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/17-infrastructure-and-production/14-prompt-semantic-caching/code/main.ts:308"}, "properties": {"repobilityId": "4d3cfa676def035a", "scanner": "scanner-primary", "fingerprint": "4b0896a9b50e4625", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c0c84c17a18efa92", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/17-infrastructure-and-production/15-batch-apis/code/main.ts:154"}, "properties": {"repobilityId": "04e1200568178821", "scanner": "scanner-primary", "fingerprint": "c0c84c17a18efa92", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d2bdd29d21ef1e48", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 phases/17-infrastructure-and-production/13-llm-observability/code/main.ts:119"}, "properties": {"repobilityId": "9077f8aacdba442d", "scanner": "scanner-primary", "fingerprint": "d2bdd29d21ef1e48", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-35808192a3c0f8a9", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 phases/00-setup-and-tooling/04-apis-and-keys/code/first_api_call.py:42"}, "properties": {"repobilityId": "f19e62d46f3c8761", "scanner": "scanner-primary", "fingerprint": "35808192a3c0f8a9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-3a32ff1e2ce455cd", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 phases/03-deep-learning-core/11-intro-to-pytorch/code/pytorch_intro.py:25"}, "properties": {"repobilityId": "66f4bc23dccb5bd3", "scanner": "scanner-primary", "fingerprint": "3a32ff1e2ce455cd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-687c40c77068bfae", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 phases/04-computer-vision/01-image-fundamentals/code/main.py:25"}, "properties": {"repobilityId": "85a303bbd80681f5", "scanner": "scanner-primary", "fingerprint": "687c40c77068bfae", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-e39ecc73f6ad4808", "level": "warning", "message": {"text": "eval detected \u2014 phases/10-llms-from-scratch/09-constitutional-ai-self-improvement/code/main.py:79"}, "properties": {"repobilityId": "5cc0905a01ae39c2", "scanner": "scanner-primary", "fingerprint": "e39ecc73f6ad4808", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-99766a0248e39a64", "level": "warning", "message": {"text": "eval detected \u2014 phases/10-llms-from-scratch/09-constitutional-ai-self-improvement/code/main.py:136"}, "properties": {"repobilityId": "977afabd7826363f", "scanner": "scanner-primary", "fingerprint": "99766a0248e39a64", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-45d7430a3443b3dc", "level": "warning", "message": {"text": "eval detected \u2014 phases/11-llm-engineering/02-few-shot-cot/code/advanced_prompting.py:324"}, "properties": {"repobilityId": "5225d15a6cfd22ba", "scanner": "scanner-primary", "fingerprint": "45d7430a3443b3dc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-367150fee35bd37d", "level": "warning", "message": {"text": "eval detected \u2014 phases/11-llm-engineering/09-function-calling/code/function_calling.py:28"}, "properties": {"repobilityId": "bb0895fc5abd9929", "scanner": "scanner-primary", "fingerprint": "367150fee35bd37d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-6696660210f2f54f", "level": "warning", "message": {"text": "exec detected \u2014 phases/11-llm-engineering/09-function-calling/code/function_calling.py:109"}, "properties": {"repobilityId": "aebd07d71633cd3e", "scanner": "scanner-primary", "fingerprint": "6696660210f2f54f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-0e0dd4c6868225ed", "level": "warning", "message": {"text": "eval detected \u2014 phases/11-llm-engineering/16-langgraph-state-machines/code/main.py:55"}, "properties": {"repobilityId": "94b6cd85573b4556", "scanner": "scanner-primary", "fingerprint": "0e0dd4c6868225ed", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-4d1fd8bfd89fd829", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 phases/13-tools-and-protocols/09-mcp-transports/code/main.py:191"}, "properties": {"repobilityId": "acd29a33d261b1f9", "scanner": "scanner-primary", "fingerprint": "4d1fd8bfd89fd829", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-9d771a8b7a6ee0da", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 phases/13-tools-and-protocols/09-mcp-transports/code/main.py:200"}, "properties": {"repobilityId": "a5edcd4bc7e142aa", "scanner": "scanner-primary", "fingerprint": "9d771a8b7a6ee0da", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-1f565e0648101805", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 phases/13-tools-and-protocols/09-mcp-transports/code/main.py:210"}, "properties": {"repobilityId": "1f18ff9747af728b", "scanner": "scanner-primary", "fingerprint": "1f565e0648101805", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-c5cd715d6738cc7b", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 phases/13-tools-and-protocols/09-mcp-transports/code/main.py:219"}, "properties": {"repobilityId": "be6504fe68064f6c", "scanner": "scanner-primary", "fingerprint": "c5cd715d6738cc7b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-d97585af057a4cc3", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 phases/13-tools-and-protocols/09-mcp-transports/code/main.py:229"}, "properties": {"repobilityId": "ca6e5df6a0afd81b", "scanner": "scanner-primary", "fingerprint": "d97585af057a4cc3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-1dc30b06e7be92c3", "level": "warning", "message": {"text": "eval detected \u2014 phases/14-agent-engineering/01-the-agent-loop/code/main.py:61"}, "properties": {"repobilityId": "f0ec6556aa9f3d97", "scanner": "scanner-primary", "fingerprint": "1dc30b06e7be92c3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-202c93a2d6874756", "level": "warning", "message": {"text": "exec detected \u2014 phases/16-multi-agent-and-swarms/08-role-specialization/code/main.py:74"}, "properties": {"repobilityId": "575f84942e570e2e", "scanner": "scanner-primary", "fingerprint": "202c93a2d6874756", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-421307507d3b56f7", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 phases/16-multi-agent-and-swarms/12-a2a-protocol/code/main.py:129"}, "properties": {"repobilityId": "eaf410df05ea24b8", "scanner": "scanner-primary", "fingerprint": "421307507d3b56f7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-7f2b1cb4d444677e", "level": "error", "message": {"text": "subprocess shell true \u2014 phases/19-capstone-projects/01-terminal-native-coding-agent/code/main.py:116"}, "properties": {"repobilityId": "c0be297889264655", "scanner": "scanner-primary", "fingerprint": "7f2b1cb4d444677e", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-6b51eda891019f65", "level": "warning", "message": {"text": "exec detected \u2014 phases/19-capstone-projects/49-lm-eval-harness/code/main.py:224"}, "properties": {"repobilityId": "4d7f1384164b7440", "scanner": "scanner-primary", "fingerprint": "6b51eda891019f65", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-c9e03732cbf468b7", "level": "warning", "message": {"text": "insecure hash algorithm sha1 \u2014 phases/19-capstone-projects/50-hypothesis-generator/code/main.py:134"}, "properties": {"repobilityId": "0af1a620292c9524", "scanner": "scanner-primary", "fingerprint": "c9e03732cbf468b7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-916c8e2e7b74c1d6", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 scripts/link_check.py:245"}, "properties": {"repobilityId": "62a198e18d2dcec6", "scanner": "scanner-primary", "fingerprint": "916c8e2e7b74c1d6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["semgrep", "security", "python"]}}, {"ruleId": "scanner-fdfb82c94eea36ef", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 phases/00-setup-and-tooling/07-docker-for-ai/code/Dockerfile"}, "properties": {"repobilityId": "226d1592c8abcfb1", "scanner": "scanner-primary", "fingerprint": "fdfb82c94eea36ef", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-c07e418427423aaf", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 phases/00-setup-and-tooling/07-docker-for-ai/code/Dockerfile"}, "properties": {"repobilityId": "0ad1e71b9d47d529", "scanner": "scanner-primary", "fingerprint": "c07e418427423aaf", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-e637c415447867e4", "level": "none", "message": {"text": "Run SkillSpector's LLM-backed analysis in your own pipeline"}, "properties": {"repobilityId": "1936f198ff5212bf", "scanner": "scanner-primary", "fingerprint": "e637c415447867e4", "layer": "security", "severity": "info", "confidence": 1.0, "tags": ["skillspector", "mcp-skill", "llm-advisory", "ai-coder"]}}, {"ruleId": "scanner-8c25f9a51a830a1e", "level": "warning", "message": {"text": "Dockerfile runs as root: phases/00-setup-and-tooling/07-docker-for-ai/code/Dockerfile"}, "properties": {"repobilityId": "f5a1fc78cd134b26", "scanner": "scanner-primary", "fingerprint": "8c25f9a51a830a1e", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-8f7ded22e2cf2baa", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: nvidia/cuda:12.4.1-devel-ubuntu22.04"}, "properties": {"repobilityId": "30270a8e5a96bfd0", "scanner": "scanner-primary", "fingerprint": "8f7ded22e2cf2baa", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/00-setup-and-tooling/07-docker-for-ai/code/Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-30635e0ff67dac8e", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-dl.js:51"}, "properties": {"repobilityId": "1300be7c860b15d5", "scanner": "scanner-primary", "fingerprint": "30635e0ff67dac8e", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "site/figures-dl.js"}, "region": {"startLine": 51}}}]}, {"ruleId": "scanner-caf76574a6a854b1", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-vision-speech.js:160"}, "properties": {"repobilityId": "d904631989d0485a", "scanner": "scanner-primary", "fingerprint": "caf76574a6a854b1", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "site/figures-vision-speech.js"}, "region": {"startLine": 160}}}]}, {"ruleId": "scanner-81f27af24990d897", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-agents-alignment.js:283"}, "properties": {"repobilityId": "19e96d97a7c94426", "scanner": "scanner-primary", "fingerprint": "81f27af24990d897", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "site/figures-agents-alignment.js"}, "region": {"startLine": 283}}}]}, {"ruleId": "scanner-467ac758f7b2aa70", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-nlp2.js:232"}, "properties": {"repobilityId": "24cbbe1a86fed91d", "scanner": "scanner-primary", "fingerprint": "467ac758f7b2aa70", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "site/figures-nlp2.js"}, "region": {"startLine": 232}}}]}, {"ruleId": "scanner-a12d2aa0cd949b94", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-math.js:36"}, "properties": {"repobilityId": "6b88b93763d1dd3b", "scanner": "scanner-primary", "fingerprint": "a12d2aa0cd949b94", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "site/figures-math.js"}, "region": {"startLine": 36}}}]}, {"ruleId": "scanner-25731e6f602fdd60", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-genai-rl.js:168"}, "properties": {"repobilityId": "3c6e5b212842a267", "scanner": "scanner-primary", "fingerprint": "25731e6f602fdd60", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "site/figures-genai-rl.js"}, "region": {"startLine": 168}}}]}, {"ruleId": "scanner-bda1d7077e0e6436", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/app.js:134"}, "properties": {"repobilityId": "2dbada2e02ea99b7", "scanner": "scanner-primary", "fingerprint": "bda1d7077e0e6436", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "site/app.js"}, "region": {"startLine": 134}}}]}, {"ruleId": "scanner-5cadbd740c000574", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-math2.js:59"}, "properties": {"repobilityId": "8875e83166164fc8", "scanner": "scanner-primary", "fingerprint": "5cadbd740c000574", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "site/figures-math2.js"}, "region": {"startLine": 59}}}]}, {"ruleId": "scanner-e3fc6c87ac4709cf", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-transformers.js:169"}, "properties": {"repobilityId": "208daf723bc23ddb", "scanner": "scanner-primary", "fingerprint": "e3fc6c87ac4709cf", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "site/figures-transformers.js"}, "region": {"startLine": 169}}}]}, {"ruleId": "scanner-0daae44df92de527", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/lesson.html:1822"}, "properties": {"repobilityId": "1df70a90d753b954", "scanner": "scanner-primary", "fingerprint": "0daae44df92de527", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "site/lesson.html"}, "region": {"startLine": 1822}}}]}, {"ruleId": "scanner-53988ae5c0bbfbb6", "level": "warning", "message": {"text": "Insecure pattern 'insert_adjacent_html' in site/lesson.html:2819"}, "properties": {"repobilityId": "147f8932d940b3f4", "scanner": "scanner-primary", "fingerprint": "53988ae5c0bbfbb6", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "insert_adjacent_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "site/lesson.html"}, "region": {"startLine": 2819}}}]}, {"ruleId": "scanner-8dcd84c24899c58b", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-llms2.js:43"}, "properties": {"repobilityId": "3a63c0237d2d0214", "scanner": "scanner-primary", "fingerprint": "8dcd84c24899c58b", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "site/figures-llms2.js"}, "region": {"startLine": 43}}}]}, {"ruleId": "scanner-b5d30605e14a45a5", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-llms-systems.js:104"}, "properties": {"repobilityId": "78503c17c154c23c", "scanner": "scanner-primary", "fingerprint": "b5d30605e14a45a5", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "site/figures-llms-systems.js"}, "region": {"startLine": 104}}}]}, {"ruleId": "scanner-25b9d3c202fb003f", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-infra.js:53"}, "properties": {"repobilityId": "9fcde579a4f50bfe", "scanner": "scanner-primary", "fingerprint": "25b9d3c202fb003f", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "site/figures-infra.js"}, "region": {"startLine": 53}}}]}, {"ruleId": "scanner-9699b0390a7e98f9", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/figures-frontier.js:105"}, "properties": {"repobilityId": "b95df36659d2241f", "scanner": "scanner-primary", "fingerprint": "9699b0390a7e98f9", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "site/figures-frontier.js"}, "region": {"startLine": 105}}}]}, {"ruleId": "scanner-230a0352589904ea", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in site/lesson-figures.js:49"}, "properties": {"repobilityId": "ac944369db8f5581", "scanner": "scanner-primary", "fingerprint": "230a0352589904ea", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "site/lesson-figures.js"}, "region": {"startLine": 49}}}]}, {"ruleId": "scanner-5c07e7194c4cd48d", "level": "error", "message": {"text": "Insecure pattern 'eval_used' in phases/19-capstone-projects/72-code-exec-metric/code/main.py:116"}, "properties": {"repobilityId": "3b52a131b3977364", "scanner": "scanner-primary", "fingerprint": "5c07e7194c4cd48d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "eval_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/72-code-exec-metric/code/main.py"}, "region": {"startLine": 116}}}]}, {"ruleId": "scanner-07f10b81d68ead2d", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in phases/19-capstone-projects/72-code-exec-metric/code/main.py:106"}, "properties": {"repobilityId": "9aa7d6104901b0ba", "scanner": "scanner-primary", "fingerprint": "07f10b81d68ead2d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/72-code-exec-metric/code/main.py"}, "region": {"startLine": 106}}}]}, {"ruleId": "scanner-ab09ae565e85d31b", "level": "error", "message": {"text": "Insecure pattern 'subprocess_shell_true' in phases/19-capstone-projects/01-terminal-native-coding-agent/code/main.py:116"}, "properties": {"repobilityId": "744646d2705ae65e", "scanner": "scanner-primary", "fingerprint": "ab09ae565e85d31b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "subprocess_shell_true"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/01-terminal-native-coding-agent/code/main.py"}, "region": {"startLine": 116}}}]}, {"ruleId": "scanner-c4745110fb82fce8", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in phases/19-capstone-projects/49-lm-eval-harness/code/main.py:224"}, "properties": {"repobilityId": "0a814e89612c6105", "scanner": "scanner-primary", "fingerprint": "c4745110fb82fce8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/49-lm-eval-harness/code/main.py"}, "region": {"startLine": 224}}}]}, {"ruleId": "scanner-aa00b236173b7b21", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in phases/15-autonomous-systems/08-bounded-self-improvement/code/main.py:60"}, "properties": {"repobilityId": "d23b5b0a46d39e90", "scanner": "scanner-primary", "fingerprint": "aa00b236173b7b21", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/15-autonomous-systems/08-bounded-self-improvement/code/main.py"}, "region": {"startLine": 60}}}]}, {"ruleId": "scanner-968a360abfaeea28", "level": "error", "message": {"text": "Possible secret in phases/15-autonomous-systems/18-llama-guard/code/main.py"}, "properties": {"repobilityId": "707f91068cded309", "scanner": "scanner-primary", "fingerprint": "968a360abfaeea28", "layer": "security", "severity": "critical", "confidence": 0.95, "tags": ["secrets", "openai_or_anthropic_key", "high-confidence-secret"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/15-autonomous-systems/18-llama-guard/code/main.py"}, "region": {"startLine": 154}}}]}, {"ruleId": "scanner-dec5d3892be78a4c", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in phases/15-autonomous-systems/10-claude-code-permission-modes/code/main.py:46"}, "properties": {"repobilityId": "26684f71790413cd", "scanner": "scanner-primary", "fingerprint": "dec5d3892be78a4c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/15-autonomous-systems/10-claude-code-permission-modes/code/main.py"}, "region": {"startLine": 46}}}]}, {"ruleId": "scanner-3a9e93b68b5690b5", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in phases/13-tools-and-protocols/07-building-an-mcp-server/code/main.ts:185"}, "properties": {"repobilityId": "de641cae43802c11", "scanner": "scanner-primary", "fingerprint": "3a9e93b68b5690b5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/13-tools-and-protocols/07-building-an-mcp-server/code/main.ts"}, "region": {"startLine": 185}}}]}, {"ruleId": "scanner-94991bb8bd8ad1b0", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in phases/18-ethics-safety-alignment/16-red-team-tooling-garak-llamaguard-pyrit/code/main.py:35"}, "properties": {"repobilityId": "a40bf6017de35bf3", "scanner": "scanner-primary", "fingerprint": "94991bb8bd8ad1b0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/18-ethics-safety-alignment/16-red-team-tooling-garak-llamaguard-pyrit/code/main.py"}, "region": {"startLine": 35}}}]}, {"ruleId": "scanner-fa450f54daa35f58", "level": "error", "message": {"text": "Insecure pattern 'eval_used' in phases/18-ethics-safety-alignment/08-in-context-scheming-frontier-models/code/main.py:124"}, "properties": {"repobilityId": "c7bbaf7eb778ca85", "scanner": "scanner-primary", "fingerprint": "fa450f54daa35f58", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "eval_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/18-ethics-safety-alignment/08-in-context-scheming-frontier-models/code/main.py"}, "region": {"startLine": 124}}}]}, {"ruleId": "scanner-7b850224f5b9772a", "level": "error", "message": {"text": "Insecure pattern 'new_function_used' in phases/14-agent-engineering/01-the-agent-loop/code/main.ts:58"}, "properties": {"repobilityId": "c4fc600f9e77e113", "scanner": "scanner-primary", "fingerprint": "7b850224f5b9772a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "new_function_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/14-agent-engineering/01-the-agent-loop/code/main.ts"}, "region": {"startLine": 58}}}]}, {"ruleId": "scanner-1e367ff5e8488d30", "level": "error", "message": {"text": "Insecure pattern 'eval_used' in phases/14-agent-engineering/01-the-agent-loop/code/main.py:61"}, "properties": {"repobilityId": "d56b61f5837be968", "scanner": "scanner-primary", "fingerprint": "1e367ff5e8488d30", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "eval_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/14-agent-engineering/01-the-agent-loop/code/main.py"}, "region": {"startLine": 61}}}]}, {"ruleId": "scanner-4972a3377d88f498", "level": "error", "message": {"text": "Insecure pattern 'eval_used' in phases/14-agent-engineering/14-autogen-actor-model/code/main.py:85"}, "properties": {"repobilityId": "91b18b8f93b5a5d6", "scanner": "scanner-primary", "fingerprint": "4972a3377d88f498", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "eval_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/14-agent-engineering/14-autogen-actor-model/code/main.py"}, "region": {"startLine": 85}}}]}, {"ruleId": "scanner-516e9de0fd461c49", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in phases/16-multi-agent-and-swarms/08-role-specialization/code/main.py:74"}, "properties": {"repobilityId": "69d0736f6c45cc14", "scanner": "scanner-primary", "fingerprint": "516e9de0fd461c49", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/16-multi-agent-and-swarms/08-role-specialization/code/main.py"}, "region": {"startLine": 74}}}]}, {"ruleId": "scanner-93215a01a51049d7", "level": "error", "message": {"text": "Insecure pattern 'eval_used' in phases/10-llms-from-scratch/09-constitutional-ai-self-improvement/code/main.py:79"}, "properties": {"repobilityId": "a9ec43af5d721f0c", "scanner": "scanner-primary", "fingerprint": "93215a01a51049d7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "eval_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/10-llms-from-scratch/09-constitutional-ai-self-improvement/code/main.py"}, "region": {"startLine": 79}}}]}, {"ruleId": "scanner-3b6dc379488ca9bd", "level": "error", "message": {"text": "Insecure pattern 'eval_used' in phases/11-llm-engineering/02-few-shot-cot/code/advanced_prompting.py:324"}, "properties": {"repobilityId": "4b14a5d69c68cab1", "scanner": "scanner-primary", "fingerprint": "3b6dc379488ca9bd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "eval_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/11-llm-engineering/02-few-shot-cot/code/advanced_prompting.py"}, "region": {"startLine": 324}}}]}, {"ruleId": "scanner-51ca21268b7c7170", "level": "error", "message": {"text": "Insecure pattern 'eval_used' in phases/11-llm-engineering/16-langgraph-state-machines/code/main.py:55"}, "properties": {"repobilityId": "ce58024ed790008d", "scanner": "scanner-primary", "fingerprint": "51ca21268b7c7170", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "eval_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/11-llm-engineering/16-langgraph-state-machines/code/main.py"}, "region": {"startLine": 55}}}]}, {"ruleId": "scanner-26223f85659796e1", "level": "error", "message": {"text": "Insecure pattern 'eval_used' in phases/11-llm-engineering/09-function-calling/code/function_calling.py:28"}, "properties": {"repobilityId": "278074c93b1f1706", "scanner": "scanner-primary", "fingerprint": "26223f85659796e1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "eval_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/11-llm-engineering/09-function-calling/code/function_calling.py"}, "region": {"startLine": 28}}}]}, {"ruleId": "scanner-e2beb9b5c772a3f7", "level": "error", "message": {"text": "Insecure pattern 'python_os_system' in phases/11-llm-engineering/09-function-calling/code/function_calling.py:376"}, "properties": {"repobilityId": "dfc47ff0aed9d0d0", "scanner": "scanner-primary", "fingerprint": "e2beb9b5c772a3f7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "python_os_system"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/11-llm-engineering/09-function-calling/code/function_calling.py"}, "region": {"startLine": 376}}}]}, {"ruleId": "scanner-76c1e5ccd427ca70", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in phases/11-llm-engineering/09-function-calling/code/function_calling.py:103"}, "properties": {"repobilityId": "4da1a976f953a71d", "scanner": "scanner-primary", "fingerprint": "76c1e5ccd427ca70", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/11-llm-engineering/09-function-calling/code/function_calling.py"}, "region": {"startLine": 103}}}]}, {"ruleId": "scanner-daca0589a5b769c2", "level": "error", "message": {"text": "Insecure pattern 'eval_used' in phases/11-llm-engineering/09-function-calling/code/main.ts:144"}, "properties": {"repobilityId": "0732716f004e71fb", "scanner": "scanner-primary", "fingerprint": "daca0589a5b769c2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "eval_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/11-llm-engineering/09-function-calling/code/main.ts"}, "region": {"startLine": 144}}}]}, {"ruleId": "scanner-1cf979005ff4d9e9", "level": "error", "message": {"text": "Insecure pattern 'new_function_used' in phases/11-llm-engineering/09-function-calling/code/main.ts:62"}, "properties": {"repobilityId": "783309c2580d5a65", "scanner": "scanner-primary", "fingerprint": "1cf979005ff4d9e9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "new_function_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/11-llm-engineering/09-function-calling/code/main.ts"}, "region": {"startLine": 62}}}]}, {"ruleId": "scanner-e36351d2b9f0f64d", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "b777f42577b364b0", "scanner": "scanner-primary", "fingerprint": "e36351d2b9f0f64d", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/curriculum.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8f8014030fdfbaf6", "level": "note", "message": {"text": "Very large file: site/data.js (12478 lines)"}, "properties": {"repobilityId": "7b9face60a40d718", "scanner": "scanner-primary", "fingerprint": "8f8014030fdfbaf6", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ea3b5e389d8c9c0f", "level": "note", "message": {"text": "Low test-to-source ratio"}, "properties": {"repobilityId": "ef7b2552cc00a375", "scanner": "scanner-primary", "fingerprint": "ea3b5e389d8c9c0f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["tests"]}}, {"ruleId": "scanner-c4a802d21503560d", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/08-production-rag-chatbot/code/ts/package.json"}, "properties": {"repobilityId": "203d066bbea13166", "scanner": "scanner-primary", "fingerprint": "c4a802d21503560d", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/08-production-rag-chatbot/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a90a55577dd2fe92", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/17-personal-ai-tutor/code/ts/package.json"}, "properties": {"repobilityId": "817c1b5f4cf6b093", "scanner": "scanner-primary", "fingerprint": "a90a55577dd2fe92", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/17-personal-ai-tutor/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-486dabef9f6a6d95", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/10-multi-agent-software-team/code/ts/package.json"}, "properties": {"repobilityId": "a70f68e800f0ddf0", "scanner": "scanner-primary", "fingerprint": "486dabef9f6a6d95", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/10-multi-agent-software-team/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-50059cc1f3a38071", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/06-devops-troubleshooting-agent/code/ts/package.json"}, "properties": {"repobilityId": "04351bf5c7286c70", "scanner": "scanner-primary", "fingerprint": "50059cc1f3a38071", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/06-devops-troubleshooting-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7c90d35c3bc3fe77", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/01-terminal-native-coding-agent/code/ts/package.json"}, "properties": {"repobilityId": "aaf9b6b5b1c7d87b", "scanner": "scanner-primary", "fingerprint": "7c90d35c3bc3fe77", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/01-terminal-native-coding-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cf7ed5e03f223b66", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/12-video-understanding-pipeline/code/ts/package.json"}, "properties": {"repobilityId": "6b8ccfd34f860680", "scanner": "scanner-primary", "fingerprint": "cf7ed5e03f223b66", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/12-video-understanding-pipeline/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cf2a60db3b06da67", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/04-multimodal-document-qa/code/ts/package.json"}, "properties": {"repobilityId": "cc0f3e9feb89fd63", "scanner": "scanner-primary", "fingerprint": "cf2a60db3b06da67", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/04-multimodal-document-qa/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0fe67f4195500c35", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "properties": {"repobilityId": "8cba0bc8d4158312", "scanner": "scanner-primary", "fingerprint": "0fe67f4195500c35", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b02d81e0eefa66f9", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/11-llm-observability-dashboard/code/ts/package.json"}, "properties": {"repobilityId": "b9f9cae832c32700", "scanner": "scanner-primary", "fingerprint": "b02d81e0eefa66f9", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/11-llm-observability-dashboard/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-75ffe26c05c92a03", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "properties": {"repobilityId": "b40949f676501943", "scanner": "scanner-primary", "fingerprint": "75ffe26c05c92a03", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2efdeda8de7bdcd7", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/13-mcp-server-with-registry/code/ts/package.json"}, "properties": {"repobilityId": "bde2e57ef3c4eb24", "scanner": "scanner-primary", "fingerprint": "2efdeda8de7bdcd7", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/13-mcp-server-with-registry/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7b558402dccbab53", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/03-realtime-voice-assistant/code/ts/package.json"}, "properties": {"repobilityId": "d65e7ce7c7ff7448", "scanner": "scanner-primary", "fingerprint": "7b558402dccbab53", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/03-realtime-voice-assistant/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-facd20757db92ab6", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: phases/19-capstone-projects/16-github-issue-to-pr-agent/code/ts/package.json"}, "properties": {"repobilityId": "30bf3d56b24eab09", "scanner": "scanner-primary", "fingerprint": "facd20757db92ab6", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/16-github-issue-to-pr-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "7e4f0dbd80c117d9", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "befd3e8ea5663a47", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "6f3b0f5009bb2a25", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "572ef4105ff36324", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-da3899da2ebbd641", "level": "none", "message": {"text": "Commented-code block (5 lines) in site/app.js:139"}, "properties": {"repobilityId": "27ccffff87a45d2f", "scanner": "scanner-primary", "fingerprint": "da3899da2ebbd641", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d42c390228467862", "level": "note", "message": {"text": "Legacy-named symbol `\u03c0_old` in site/data.js:1682"}, "properties": {"repobilityId": "bfd5bf4029e9baf2", "scanner": "scanner-primary", "fingerprint": "d42c390228467862", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-3724a1c0a5590903", "level": "none", "message": {"text": "Commented-code block (5 lines) in site/build.js:79"}, "properties": {"repobilityId": "feadcdb9867c5cb4", "scanner": "scanner-primary", "fingerprint": "3724a1c0a5590903", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c88a7281497a02ec", "level": "none", "message": {"text": "Commented-code block (6 lines) in phases/19-capstone-projects/08-production-rag-chatbot/code/ts/src/index.ts:1"}, "properties": {"repobilityId": "37dfdc06df9f9e68", "scanner": "scanner-primary", "fingerprint": "c88a7281497a02ec", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-47f2f1d8f7516e7b", "level": "none", "message": {"text": "Commented-code block (6 lines) in phases/19-capstone-projects/17-personal-ai-tutor/code/ts/src/index.ts:1"}, "properties": {"repobilityId": "7d7c31cb99a57963", "scanner": "scanner-primary", "fingerprint": "47f2f1d8f7516e7b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-51577f024aecfd55", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 phases/19-capstone-projects/72-code-exec-metric/code/main.py:313"}, "properties": {"repobilityId": "7475e23b4baaafc1", "scanner": "scanner-primary", "fingerprint": "51577f024aecfd55", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-1d97cd0e41894294", "level": "none", "message": {"text": "Commented-code block (6 lines) in phases/19-capstone-projects/06-devops-troubleshooting-agent/code/ts/src/index.ts:1"}, "properties": {"repobilityId": "9b2f13899f352f27", "scanner": "scanner-primary", "fingerprint": "1d97cd0e41894294", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-02fe635ea6b4869a", "level": "none", "message": {"text": "Commented-code block (5 lines) in phases/19-capstone-projects/01-terminal-native-coding-agent/code/ts/src/index.ts:3"}, "properties": {"repobilityId": "6531637af036d40b", "scanner": "scanner-primary", "fingerprint": "02fe635ea6b4869a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a8568ea43264b8c9", "level": "none", "message": {"text": "Commented-code block (6 lines) in phases/19-capstone-projects/12-video-understanding-pipeline/code/ts/src/index.ts:1"}, "properties": {"repobilityId": "34cec22d69ad1975", "scanner": "scanner-primary", "fingerprint": "a8568ea43264b8c9", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-766be6012d53fcdb", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 phases/19-capstone-projects/12-video-understanding-pipeline/code/ts/src/index.ts:51"}, "properties": {"repobilityId": "898c4a209771eea8", "scanner": "scanner-primary", "fingerprint": "766be6012d53fcdb", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-e0b5feb549130319", "level": "none", "message": {"text": "Commented-code block (6 lines) in phases/19-capstone-projects/04-multimodal-document-qa/code/ts/src/index.ts:1"}, "properties": {"repobilityId": "05d6324d5b740cb3", "scanner": "scanner-primary", "fingerprint": "e0b5feb549130319", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6277722fc37d9534", "level": "note", "message": {"text": "Legacy-named symbol `transform_v1` in phases/19-capstone-projects/24-plan-execute-control-flow/code/tests/test_agent.py:50"}, "properties": {"repobilityId": "08399333634dbb97", "scanner": "scanner-primary", "fingerprint": "6277722fc37d9534", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-dd55768cbd11529e", "level": "note", "message": {"text": "Stub function `reverse_list` (body is just `pass`/`return`) \u2014 phases/19-capstone-projects/27-eval-harness-fixture-tasks/code/tasks/task_004_empty_reverse/buggy/reverse.py:1"}, "properties": {"repobilityId": "e616735e3b620208", "scanner": "scanner-primary", "fingerprint": "dd55768cbd11529e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-8f558a9d563c9ada", "level": "none", "message": {"text": "Commented-code block (5 lines) in phases/19-capstone-projects/02-rag-over-codebase/code/ts/src/index.ts:3"}, "properties": {"repobilityId": "558629ee2d246e2d", "scanner": "scanner-primary", "fingerprint": "8f558a9d563c9ada", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-277566c2b3f81874", "level": "note", "message": {"text": "Legacy-named symbol `idxs_copy` in phases/19-capstone-projects/39-instruction-tuning-sft/code/main.py:357"}, "properties": {"repobilityId": "0ff3b6b45fc3f68c", "scanner": "scanner-primary", "fingerprint": "277566c2b3f81874", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-526f8bc6eceba973", "level": "note", "message": {"text": "Stub function `close` (body is just `pass`/`return`) \u2014 phases/19-capstone-projects/28-observability-otel-traces/code/main.py:174"}, "properties": {"repobilityId": "ca2053ddbc4623af", "scanner": "scanner-primary", "fingerprint": "526f8bc6eceba973", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-b0aa08ad0540e102", "level": "none", "message": {"text": "Commented-code block (7 lines) in phases/19-capstone-projects/13-mcp-server-with-registry/code/ts/src/index.ts:1"}, "properties": {"repobilityId": "8e15b13532eed671", "scanner": "scanner-primary", "fingerprint": "b0aa08ad0540e102", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7c7349fe5eb43454", "level": "none", "message": {"text": "Commented-code block (5 lines) in phases/19-capstone-projects/03-realtime-voice-assistant/code/ts/src/index.ts:3"}, "properties": {"repobilityId": "968829d5722da3c9", "scanner": "scanner-primary", "fingerprint": "7c7349fe5eb43454", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6f562bc437cd5924", "level": "none", "message": {"text": "Commented-code block (6 lines) in phases/19-capstone-projects/16-github-issue-to-pr-agent/code/ts/src/index.ts:1"}, "properties": {"repobilityId": "2bddcddb10a74b77", "scanner": "scanner-primary", "fingerprint": "6f562bc437cd5924", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-25961559ea4266e1", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 phases/19-capstone-projects/16-github-issue-to-pr-agent/code/ts/src/index.ts:119"}, "properties": {"repobilityId": "78a0df63c5207b30", "scanner": "scanner-primary", "fingerprint": "25961559ea4266e1", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-c4fc5c9ec85182fd", "level": "note", "message": {"text": "Legacy-named symbol `idxs_copy` in phases/19-capstone-projects/38-classifier-finetuning/code/main.py:272"}, "properties": {"repobilityId": "7c52bafab114629f", "scanner": "scanner-primary", "fingerprint": "c4fc5c9ec85182fd", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-156bbb8ee46290a7", "level": "none", "message": {"text": "Commented-code block (5 lines) in phases/15-autonomous-systems/18-llama-guard/code/main.py:59"}, "properties": {"repobilityId": "ac7e23c9b4abc1f4", "scanner": "scanner-primary", "fingerprint": "156bbb8ee46290a7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-697acd1bb3d3f226", "level": "none", "message": {"text": "Commented-code block (9 lines) in phases/15-autonomous-systems/16-checkpoints-rollback/code/main.py:107"}, "properties": {"repobilityId": "9299561a4d303d04", "scanner": "scanner-primary", "fingerprint": "697acd1bb3d3f226", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7b8c8de315d236ab", "level": "none", "message": {"text": "Commented-code block (5 lines) in phases/15-autonomous-systems/06-automated-alignment-research/code/main.py:108"}, "properties": {"repobilityId": "bcad13042df9eeb9", "scanner": "scanner-primary", "fingerprint": "7b8c8de315d236ab", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-342b6b1eabdd2d82", "level": "none", "message": {"text": "Commented-code block (5 lines) in phases/15-autonomous-systems/05-ai-scientist-v2/code/main.py:65"}, "properties": {"repobilityId": "651fa7512f21e828", "scanner": "scanner-primary", "fingerprint": "342b6b1eabdd2d82", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-cf4a9d0907f25db8", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 phases/00-setup-and-tooling/04-apis-and-keys/code/first_api_call.py:42"}, "properties": {"repobilityId": "45ce8760a9ce3db9", "scanner": "scanner-primary", "fingerprint": "cf4a9d0907f25db8", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-a6b438d44d6d8665", "level": "none", "message": {"text": "Commented-code block (6 lines) in phases/00-setup-and-tooling/04-apis-and-keys/code/first_api_call.ts:1"}, "properties": {"repobilityId": "ff2022ab5c463a32", "scanner": "scanner-primary", "fingerprint": "a6b438d44d6d8665", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6e5620428d34ac22", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 phases/00-setup-and-tooling/04-apis-and-keys/code/first_api_call.ts:6"}, "properties": {"repobilityId": "cc0830dd358ad251", "scanner": "scanner-primary", "fingerprint": "6e5620428d34ac22", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-5bd804014444b23a", "level": "note", "message": {"text": "Legacy-named symbol `exp_old` in phases/07-transformers-deep-dive/12-kv-cache-flash-attention/code/main.py:48"}, "properties": {"repobilityId": "68501d1eba968699", "scanner": "scanner-primary", "fingerprint": "5bd804014444b23a", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-faeb1d376db2ce4a", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 phases/13-tools-and-protocols/09-mcp-transports/code/main.py:200"}, "properties": {"repobilityId": "1bdf6cde606e7000", "scanner": "scanner-primary", "fingerprint": "faeb1d376db2ce4a", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-c24d06ab6127ddc3", "level": "note", "message": {"text": "Legacy-named symbol `maskrcnn_resnet50_fpn_v2` in phases/04-computer-vision/08-instance-segmentation-mask-rcnn/code/main.py:47"}, "properties": {"repobilityId": "728ab71d6b5d6cbb", "scanner": "scanner-primary", "fingerprint": "c24d06ab6127ddc3", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-2d7844a8c80f5cfa", "level": "none", "message": {"text": "Commented-code block (7 lines) in phases/05-nlp-foundations-to-advanced/19-subword-tokenization/code/main.ts:1"}, "properties": {"repobilityId": "0595a04e0901cd73", "scanner": "scanner-primary", "fingerprint": "2d7844a8c80f5cfa", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8436002f496a61c2", "level": "none", "message": {"text": "Commented-code block (7 lines) in phases/05-nlp-foundations-to-advanced/23-chunking-strategies-rag/code/main.ts:1"}, "properties": {"repobilityId": "54c3cae65e8c0416", "scanner": "scanner-primary", "fingerprint": "8436002f496a61c2", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3eebadc9dd48a70c", "level": "note", "message": {"text": "Stub function `on_edited` (body is just `pass`/`return`) \u2014 phases/14-agent-engineering/15-crewai-role-based-crews/code/main.py:316"}, "properties": {"repobilityId": "9f80f77173f0d95a", "scanner": "scanner-primary", "fingerprint": "3eebadc9dd48a70c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-81c456788dc5f026", "level": "none", "message": {"text": "Commented-code block (8 lines) in phases/14-agent-engineering/18-agno-and-mastra-runtimes/code/main.ts:1"}, "properties": {"repobilityId": "7a10199eb1083114", "scanner": "scanner-primary", "fingerprint": "81c456788dc5f026", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d9aafff71d58ab9c", "level": "note", "message": {"text": "Legacy-named symbol `_craft_iron_pick_v1` in phases/14-agent-engineering/10-skill-libraries-voyager/code/main.py:125"}, "properties": {"repobilityId": "ddb13358147f39af", "scanner": "scanner-primary", "fingerprint": "d9aafff71d58ab9c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-6e9e0a7f7cf51a42", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 phases/16-multi-agent-and-swarms/12-a2a-protocol/code/main.py:129"}, "properties": {"repobilityId": "af19f64528c68fb1", "scanner": "scanner-primary", "fingerprint": "6e9e0a7f7cf51a42", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-f41fcb08e756115e", "level": "note", "message": {"text": "Stub function `log_message` (body is just `pass`/`return`) \u2014 phases/16-multi-agent-and-swarms/12-a2a-protocol/code/main.py:84"}, "properties": {"repobilityId": "e4290f2045154384", "scanner": "scanner-primary", "fingerprint": "f41fcb08e756115e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-8e20e9297e830f65", "level": "note", "message": {"text": "Legacy-named symbol `diff_v1` in phases/10-llms-from-scratch/16-differential-attention-v2/code/main.py:125"}, "properties": {"repobilityId": "44d4d7fdc049bfd7", "scanner": "scanner-primary", "fingerprint": "8e20e9297e830f65", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-505637f172e07304", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 phases/03-deep-learning-core/11-intro-to-pytorch/code/pytorch_intro.py:25"}, "properties": {"repobilityId": "2ca6a1b2139b000d", "scanner": "scanner-primary", "fingerprint": "505637f172e07304", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-a48890876efd0588", "level": "note", "message": {"text": "Legacy-named symbol `rs_old` in phases/01-math-foundations/17-linear-systems/code/linear_systems.py:122"}, "properties": {"repobilityId": "5cf22c99954997f7", "scanner": "scanner-primary", "fingerprint": "a48890876efd0588", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-6a24067a5bde0749", "level": "note", "message": {"text": "Legacy-named symbol `log_pi_old` in phases/09-reinforcement-learning/09-reward-modeling-rlhf/code/main.py:106"}, "properties": {"repobilityId": "22dd8b0ec63684b3", "scanner": "scanner-primary", "fingerprint": "6a24067a5bde0749", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-34edd1cadbb35a87", "level": "note", "message": {"text": "Legacy-named symbol `v_old` in phases/09-reinforcement-learning/08-ppo/code/main.py:81"}, "properties": {"repobilityId": "5bd8672a194c16dd", "scanner": "scanner-primary", "fingerprint": "34edd1cadbb35a87", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-aa76c908d52778db", "level": "none", "message": {"text": "Commented-code block (7 lines) in phases/11-llm-engineering/12-guardrails/code/main.ts:1"}, "properties": {"repobilityId": "ad6f9397ece9ac9b", "scanner": "scanner-primary", "fingerprint": "aa76c908d52778db", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-069f9af51ed02a6e", "level": "none", "message": {"text": "Commented-code block (7 lines) in phases/11-llm-engineering/03-structured-outputs/code/main.ts:1"}, "properties": {"repobilityId": "f74489c3ffd9bc5f", "scanner": "scanner-primary", "fingerprint": "069f9af51ed02a6e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b4c3f75c94ba2084", "level": "none", "message": {"text": "Commented-code block (9 lines) in phases/11-llm-engineering/06-rag/code/main.ts:1"}, "properties": {"repobilityId": "d5bcb8c1dc1454fd", "scanner": "scanner-primary", "fingerprint": "b4c3f75c94ba2084", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d973b86fff66f0f4", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 phases/11-llm-engineering/09-function-calling/code/function_calling.py:417"}, "properties": {"repobilityId": "d4cea23c061fb357", "scanner": "scanner-primary", "fingerprint": "d973b86fff66f0f4", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-db88eda2dc7eb9d6", "level": "none", "message": {"text": "Commented-code block (7 lines) in phases/11-llm-engineering/05-context-engineering/code/main.ts:1"}, "properties": {"repobilityId": "74846ea3ec748762", "scanner": "scanner-primary", "fingerprint": "db88eda2dc7eb9d6", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "89d488b6bff5407a", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "bdc03be582d9a97e", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-ecd86354d3c142ad", "level": "note", "message": {"text": "Near-duplicate function bodies in 20 places"}, "properties": {"repobilityId": "66210fca76bdd02b", "scanner": "scanner-primary", "fingerprint": "ecd86354d3c142ad", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "c0711603e93a19b7", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-46969939caf8120b", "level": "note", "message": {"text": "Near-duplicate function bodies in 9 places"}, "properties": {"repobilityId": "3da0d3bb1f87e270", "scanner": "scanner-primary", "fingerprint": "46969939caf8120b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-37197262900b2e0f", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-26pp-8wgv-hjvm"}, "properties": {"repobilityId": "0215e7c6151f21c1", "scanner": "scanner-primary", "fingerprint": "37197262900b2e0f", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-26pp-8wgv-hjvm"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c2040c9d7b57ff26", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-2gcr-mfcq-wcc3"}, "properties": {"repobilityId": "6daf2fb249b8e095", "scanner": "scanner-primary", "fingerprint": "c2040c9d7b57ff26", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-2gcr-mfcq-wcc3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-80f0702b6ae0507b", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-3hrh-pfw6-9m5x"}, "properties": {"repobilityId": "f0e6f04571c5492e", "scanner": "scanner-primary", "fingerprint": "80f0702b6ae0507b", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-3hrh-pfw6-9m5x"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d27c83995820d6bf", "level": "error", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-3vhc-576x-3qv4"}, "properties": {"repobilityId": "d853b6c2c0edb9a0", "scanner": "scanner-primary", "fingerprint": "d27c83995820d6bf", "layer": "dependencies", "severity": "high", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-3vhc-576x-3qv4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-30ea89d96332344c", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-458j-xx4x-4375"}, "properties": {"repobilityId": "dcf6004bab44d8f7", "scanner": "scanner-primary", "fingerprint": "30ea89d96332344c", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-458j-xx4x-4375"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7f0ca5c85cd25542", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-5pq2-9x2x-5p6w"}, "properties": {"repobilityId": "f1050510ca7dadfb", "scanner": "scanner-primary", "fingerprint": "7f0ca5c85cd25542", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-5pq2-9x2x-5p6w"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-46ddd385d67c1cfe", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-69xw-7hcm-h432"}, "properties": {"repobilityId": "2e266e77d15c2232", "scanner": "scanner-primary", "fingerprint": "46ddd385d67c1cfe", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-69xw-7hcm-h432"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-081df53e5a8ba026", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-6wqw-2p9w-4vw4"}, "properties": {"repobilityId": "c15e7b01cbade20c", "scanner": "scanner-primary", "fingerprint": "081df53e5a8ba026", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-6wqw-2p9w-4vw4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a4942a053c514b6e", "level": "error", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-88fw-hqm2-52qc"}, "properties": {"repobilityId": "40d1335983294a9f", "scanner": "scanner-primary", "fingerprint": "a4942a053c514b6e", "layer": "dependencies", "severity": "high", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-88fw-hqm2-52qc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fb6eae4a77fa7597", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-92vj-g62v-jqhh"}, "properties": {"repobilityId": "1864e69be882f03d", "scanner": "scanner-primary", "fingerprint": "fb6eae4a77fa7597", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-92vj-g62v-jqhh"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9f7560909c78c3c7", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-9r54-q6cx-xmh5"}, "properties": {"repobilityId": "b16ec39894db07d7", "scanner": "scanner-primary", "fingerprint": "9f7560909c78c3c7", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-9r54-q6cx-xmh5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d3bdc4ea6b67eedd", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-9vqf-7f2p-gf9v"}, "properties": {"repobilityId": "996901f87fd7bee1", "scanner": "scanner-primary", "fingerprint": "d3bdc4ea6b67eedd", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-9vqf-7f2p-gf9v"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dac77c50b362128f", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-f577-qrjj-4474"}, "properties": {"repobilityId": "ed0ea092eb5f0a3e", "scanner": "scanner-primary", "fingerprint": "dac77c50b362128f", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-f577-qrjj-4474"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3296d7ed6319c288", "level": "error", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-f67f-6cw9-8mq4"}, "properties": {"repobilityId": "c03626d5dae53e5b", "scanner": "scanner-primary", "fingerprint": "3296d7ed6319c288", "layer": "dependencies", "severity": "high", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-f67f-6cw9-8mq4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ffa1e9f6c686fe79", "level": "note", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-gq3j-xvxp-8hrf"}, "properties": {"repobilityId": "0c34f6e807e65c8b", "scanner": "scanner-primary", "fingerprint": "ffa1e9f6c686fe79", "layer": "dependencies", "severity": "low", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-gq3j-xvxp-8hrf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f71b119a491d8b32", "level": "note", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-hm8q-7f3q-5f36"}, "properties": {"repobilityId": "e3fad395d7b05220", "scanner": "scanner-primary", "fingerprint": "f71b119a491d8b32", "layer": "dependencies", "severity": "low", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-hm8q-7f3q-5f36"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c30bd24555220c88", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-j6c9-x7qj-28xf"}, "properties": {"repobilityId": "bb442cb4a8236911", "scanner": "scanner-primary", "fingerprint": "c30bd24555220c88", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-j6c9-x7qj-28xf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-babfb05ed9a2614a", "level": "error", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-m732-5p4w-x69g"}, "properties": {"repobilityId": "975001235cf49bf2", "scanner": "scanner-primary", "fingerprint": "babfb05ed9a2614a", "layer": "dependencies", "severity": "high", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-m732-5p4w-x69g"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8fa677dbe9f2d7ff", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-p6xx-57qc-3wxr"}, "properties": {"repobilityId": "bf6e1eafa569bc48", "scanner": "scanner-primary", "fingerprint": "8fa677dbe9f2d7ff", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-p6xx-57qc-3wxr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-23641608e04ac2d4", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-p77w-8qqv-26rm"}, "properties": {"repobilityId": "34bacd95e250f778", "scanner": "scanner-primary", "fingerprint": "23641608e04ac2d4", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-p77w-8qqv-26rm"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3aa30f0ce07c7eca", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-q5qw-h33p-qvwr"}, "properties": {"repobilityId": "8da2e5e260bc90f1", "scanner": "scanner-primary", "fingerprint": "3aa30f0ce07c7eca", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-q5qw-h33p-qvwr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-165b421d3f66acbb", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-q7jf-gf43-6x6p"}, "properties": {"repobilityId": "ae0c4be3995f0c2f", "scanner": "scanner-primary", "fingerprint": "165b421d3f66acbb", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-q7jf-gf43-6x6p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a98f04cd004533b8", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-qp7p-654g-cw7p"}, "properties": {"repobilityId": "bd08342117c9d8ef", "scanner": "scanner-primary", "fingerprint": "a98f04cd004533b8", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-qp7p-654g-cw7p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-eef78d5561baa71e", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-r354-f388-2fhh"}, "properties": {"repobilityId": "c7b1ad0c053920d5", "scanner": "scanner-primary", "fingerprint": "eef78d5561baa71e", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-r354-f388-2fhh"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2f6cec31bff337f0", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-r5rp-j6wh-rvv4"}, "properties": {"repobilityId": "d5b0f129056cd27f", "scanner": "scanner-primary", "fingerprint": "2f6cec31bff337f0", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-r5rp-j6wh-rvv4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c3bf2667d28100a6", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-rv63-4mwf-qqc2"}, "properties": {"repobilityId": "5c8378d69d77b4cb", "scanner": "scanner-primary", "fingerprint": "c3bf2667d28100a6", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-rv63-4mwf-qqc2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-07c33b9f0f20a85d", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-v8w9-8mx6-g223"}, "properties": {"repobilityId": "cc8c8690aa1eed97", "scanner": "scanner-primary", "fingerprint": "07c33b9f0f20a85d", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-v8w9-8mx6-g223"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a710a3f8f9e6c4c6", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-w332-q679-j88p"}, "properties": {"repobilityId": "b7f81708b1b54c6a", "scanner": "scanner-primary", "fingerprint": "a710a3f8f9e6c4c6", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-w332-q679-j88p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5c13141f9fe41f4c", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-w62v-xxxg-mg59"}, "properties": {"repobilityId": "c1be62dda4303fe6", "scanner": "scanner-primary", "fingerprint": "5c13141f9fe41f4c", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-w62v-xxxg-mg59"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-233775e736da0444", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-wgpf-jwqj-8h8p"}, "properties": {"repobilityId": "158679f6942815fa", "scanner": "scanner-primary", "fingerprint": "233775e736da0444", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-wgpf-jwqj-8h8p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ff8e253156f28e84", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-wmmm-f939-6g9c"}, "properties": {"repobilityId": "f79d2c76f16be6d6", "scanner": "scanner-primary", "fingerprint": "ff8e253156f28e84", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-wmmm-f939-6g9c"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1c57304cc50210e3", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-wwfh-h76j-fc44"}, "properties": {"repobilityId": "5a3ac2ad72ea2598", "scanner": "scanner-primary", "fingerprint": "1c57304cc50210e3", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-wwfh-h76j-fc44"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c01913209a47d2ee", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-xf4j-xp2r-rqqx"}, "properties": {"repobilityId": "db9592fef2f07fd1", "scanner": "scanner-primary", "fingerprint": "c01913209a47d2ee", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-xf4j-xp2r-rqqx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e6c2f45ec12c4abd", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-xgm2-5f3f-mvvc"}, "properties": {"repobilityId": "ca1a17750975fe05", "scanner": "scanner-primary", "fingerprint": "e6c2f45ec12c4abd", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-xgm2-5f3f-mvvc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-543ff6922130bcb2", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-xpcf-pg52-r92g"}, "properties": {"repobilityId": "2718b3ef4258c751", "scanner": "scanner-primary", "fingerprint": "543ff6922130bcb2", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-xpcf-pg52-r92g"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fa1847e765f5f553", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.14: GHSA-xrhx-7g5j-rcj5"}, "properties": {"repobilityId": "c62c3a540e9fe1b8", "scanner": "scanner-primary", "fingerprint": "fa1847e765f5f553", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-xrhx-7g5j-rcj5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/02-rag-over-codebase/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e037a7c5be2d003f", "level": "warning", "message": {"text": "Vulnerable dependency ws 8.18.0: GHSA-58qx-3vcg-4xpx"}, "properties": {"repobilityId": "4b711e251c99749c", "scanner": "scanner-primary", "fingerprint": "e037a7c5be2d003f", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-58qx-3vcg-4xpx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/03-realtime-voice-assistant/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ea2730a7122c9278", "level": "warning", "message": {"text": "Vulnerable dependency ws 8.18.0: GHSA-96hv-2xvq-fx4p"}, "properties": {"repobilityId": "ac83265fafaa07b6", "scanner": "scanner-primary", "fingerprint": "ea2730a7122c9278", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-96hv-2xvq-fx4p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/03-realtime-voice-assistant/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-256ca97f8d8ea017", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-2234-fmw7-43wr"}, "properties": {"repobilityId": "edc3616dc123314c", "scanner": "scanner-primary", "fingerprint": "256ca97f8d8ea017", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-2234-fmw7-43wr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-67a0a5b919ff587d", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-26pp-8wgv-hjvm"}, "properties": {"repobilityId": "fe9927fb436f4ab9", "scanner": "scanner-primary", "fingerprint": "67a0a5b919ff587d", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-26pp-8wgv-hjvm"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f115a7daab4a6dea", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-2gcr-mfcq-wcc3"}, "properties": {"repobilityId": "c86a5453aa1b0b29", "scanner": "scanner-primary", "fingerprint": "f115a7daab4a6dea", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-2gcr-mfcq-wcc3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e487de1be0874edd", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-3hrh-pfw6-9m5x"}, "properties": {"repobilityId": "47f4f00e5cd6252c", "scanner": "scanner-primary", "fingerprint": "e487de1be0874edd", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-3hrh-pfw6-9m5x"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-25997eb20947260f", "level": "error", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-3vhc-576x-3qv4"}, "properties": {"repobilityId": "1a7c17c601982363", "scanner": "scanner-primary", "fingerprint": "25997eb20947260f", "layer": "dependencies", "severity": "high", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-3vhc-576x-3qv4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c6154f5c8668fb57", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-458j-xx4x-4375"}, "properties": {"repobilityId": "058e40cbab96be16", "scanner": "scanner-primary", "fingerprint": "c6154f5c8668fb57", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-458j-xx4x-4375"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-893e28bcbd765660", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-5pq2-9x2x-5p6w"}, "properties": {"repobilityId": "4dcc9beae4b1e495", "scanner": "scanner-primary", "fingerprint": "893e28bcbd765660", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-5pq2-9x2x-5p6w"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e7fa01297971674c", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-69xw-7hcm-h432"}, "properties": {"repobilityId": "74947ba76fd598db", "scanner": "scanner-primary", "fingerprint": "e7fa01297971674c", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-69xw-7hcm-h432"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-65a0a649b18e0fa0", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-6wqw-2p9w-4vw4"}, "properties": {"repobilityId": "b5d8fe4a3a79c073", "scanner": "scanner-primary", "fingerprint": "65a0a649b18e0fa0", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-6wqw-2p9w-4vw4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-90e1fdd6188b9902", "level": "error", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-88fw-hqm2-52qc"}, "properties": {"repobilityId": "624dddb96b505390", "scanner": "scanner-primary", "fingerprint": "90e1fdd6188b9902", "layer": "dependencies", "severity": "high", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-88fw-hqm2-52qc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3b2c7586af575734", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-92vj-g62v-jqhh"}, "properties": {"repobilityId": "621f237756dbb7da", "scanner": "scanner-primary", "fingerprint": "3b2c7586af575734", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-92vj-g62v-jqhh"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-83c89ce4037c21b5", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-9r54-q6cx-xmh5"}, "properties": {"repobilityId": "8ebd3a30493d3fa0", "scanner": "scanner-primary", "fingerprint": "83c89ce4037c21b5", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-9r54-q6cx-xmh5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f94d9be9d3831e77", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-9vqf-7f2p-gf9v"}, "properties": {"repobilityId": "b010d1f3ce87b098", "scanner": "scanner-primary", "fingerprint": "f94d9be9d3831e77", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-9vqf-7f2p-gf9v"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-22a2d09dcddfaedd", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-f577-qrjj-4474"}, "properties": {"repobilityId": "09b6ed7c788c7b98", "scanner": "scanner-primary", "fingerprint": "22a2d09dcddfaedd", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-f577-qrjj-4474"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-21b0a747213001a7", "level": "error", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-f67f-6cw9-8mq4"}, "properties": {"repobilityId": "0aef9f9c491aa837", "scanner": "scanner-primary", "fingerprint": "21b0a747213001a7", "layer": "dependencies", "severity": "high", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-f67f-6cw9-8mq4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-51cb31cc33377190", "level": "note", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-gq3j-xvxp-8hrf"}, "properties": {"repobilityId": "690bf6bb374e9341", "scanner": "scanner-primary", "fingerprint": "51cb31cc33377190", "layer": "dependencies", "severity": "low", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-gq3j-xvxp-8hrf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-27fb064aea23e48f", "level": "note", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-hm8q-7f3q-5f36"}, "properties": {"repobilityId": "e399c3b0f073fe25", "scanner": "scanner-primary", "fingerprint": "27fb064aea23e48f", "layer": "dependencies", "severity": "low", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-hm8q-7f3q-5f36"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6b07ab0e966e6814", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-j6c9-x7qj-28xf"}, "properties": {"repobilityId": "63e9bc6c3517cd79", "scanner": "scanner-primary", "fingerprint": "6b07ab0e966e6814", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-j6c9-x7qj-28xf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5bf21d05cb8d994b", "level": "error", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-m732-5p4w-x69g"}, "properties": {"repobilityId": "959bc2d35c039370", "scanner": "scanner-primary", "fingerprint": "5bf21d05cb8d994b", "layer": "dependencies", "severity": "high", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-m732-5p4w-x69g"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9a944e3337278ff1", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-p6xx-57qc-3wxr"}, "properties": {"repobilityId": "ad56e40577ffda5d", "scanner": "scanner-primary", "fingerprint": "9a944e3337278ff1", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-p6xx-57qc-3wxr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-17405deffaf61d3b", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-p77w-8qqv-26rm"}, "properties": {"repobilityId": "f7c27170eca9e072", "scanner": "scanner-primary", "fingerprint": "17405deffaf61d3b", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-p77w-8qqv-26rm"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a0e039ef042a5815", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-q5qw-h33p-qvwr"}, "properties": {"repobilityId": "ed4d4cb58cb85c08", "scanner": "scanner-primary", "fingerprint": "a0e039ef042a5815", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-q5qw-h33p-qvwr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f6a615da69b61cfa", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-q7jf-gf43-6x6p"}, "properties": {"repobilityId": "b4f8beaec25e581d", "scanner": "scanner-primary", "fingerprint": "f6a615da69b61cfa", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-q7jf-gf43-6x6p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d62cde5dd529fdbc", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-qp7p-654g-cw7p"}, "properties": {"repobilityId": "5cdd8da6d5df203b", "scanner": "scanner-primary", "fingerprint": "d62cde5dd529fdbc", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-qp7p-654g-cw7p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d364751725edc1f0", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-r354-f388-2fhh"}, "properties": {"repobilityId": "824c46fa439c1cd0", "scanner": "scanner-primary", "fingerprint": "d364751725edc1f0", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-r354-f388-2fhh"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-85a52b2a406ad554", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-r5rp-j6wh-rvv4"}, "properties": {"repobilityId": "facaf88c8436a2ba", "scanner": "scanner-primary", "fingerprint": "85a52b2a406ad554", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-r5rp-j6wh-rvv4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-111beb96e429d284", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-rv63-4mwf-qqc2"}, "properties": {"repobilityId": "2106e5a0d4dbf2d2", "scanner": "scanner-primary", "fingerprint": "111beb96e429d284", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-rv63-4mwf-qqc2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-51ba23a30ec8142f", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-v8w9-8mx6-g223"}, "properties": {"repobilityId": "727615304926918e", "scanner": "scanner-primary", "fingerprint": "51ba23a30ec8142f", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-v8w9-8mx6-g223"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c7f142b6ed2e342b", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-w332-q679-j88p"}, "properties": {"repobilityId": "7f8900bd37f5ceb4", "scanner": "scanner-primary", "fingerprint": "c7f142b6ed2e342b", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-w332-q679-j88p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-70a7dc1d94167d55", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-w62v-xxxg-mg59"}, "properties": {"repobilityId": "0edbe67302a7a7d0", "scanner": "scanner-primary", "fingerprint": "70a7dc1d94167d55", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-w62v-xxxg-mg59"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ca63e52d53651dde", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-wgpf-jwqj-8h8p"}, "properties": {"repobilityId": "262a0ec1145269a4", "scanner": "scanner-primary", "fingerprint": "ca63e52d53651dde", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-wgpf-jwqj-8h8p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0ee9745e3210faf1", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-wmmm-f939-6g9c"}, "properties": {"repobilityId": "0624b71dfd766a20", "scanner": "scanner-primary", "fingerprint": "0ee9745e3210faf1", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-wmmm-f939-6g9c"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-db31a745930dd2b3", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-wwfh-h76j-fc44"}, "properties": {"repobilityId": "e2100656d5e30e13", "scanner": "scanner-primary", "fingerprint": "db31a745930dd2b3", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-wwfh-h76j-fc44"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7178e7f917cc399b", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-xf4j-xp2r-rqqx"}, "properties": {"repobilityId": "2c69fc28bb1d8d5f", "scanner": "scanner-primary", "fingerprint": "7178e7f917cc399b", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-xf4j-xp2r-rqqx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9299c7549768c4f9", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-xgm2-5f3f-mvvc"}, "properties": {"repobilityId": "fcfab4a22a59b30e", "scanner": "scanner-primary", "fingerprint": "9299c7549768c4f9", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-xgm2-5f3f-mvvc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1748f491c1af20f0", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-xpcf-pg52-r92g"}, "properties": {"repobilityId": "d9daff48273f4904", "scanner": "scanner-primary", "fingerprint": "1748f491c1af20f0", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-xpcf-pg52-r92g"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ad5e37e928edaca7", "level": "warning", "message": {"text": "Vulnerable dependency hono 4.6.0: GHSA-xrhx-7g5j-rcj5"}, "properties": {"repobilityId": "13fddb26761b86d1", "scanner": "scanner-primary", "fingerprint": "ad5e37e928edaca7", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-xrhx-7g5j-rcj5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-022edcd4f6cf7098", "level": "warning", "message": {"text": "Vulnerable dependency @hono/node-server 1.13.0: GHSA-92pp-h63x-v22m"}, "properties": {"repobilityId": "8451e65e63288f0c", "scanner": "scanner-primary", "fingerprint": "022edcd4f6cf7098", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-92pp-h63x-v22m"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2f1a078078132d4e", "level": "warning", "message": {"text": "Vulnerable dependency @hono/node-server 1.13.0: GHSA-frvp-7c67-39w9"}, "properties": {"repobilityId": "782ba6448acf7f4b", "scanner": "scanner-primary", "fingerprint": "2f1a078078132d4e", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-frvp-7c67-39w9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-482595b72bc11014", "level": "warning", "message": {"text": "Vulnerable dependency @hono/node-server 1.13.0: GHSA-wc8c-qw6v-h7f6"}, "properties": {"repobilityId": "da7d41510d5fcc8a", "scanner": "scanner-primary", "fingerprint": "482595b72bc11014", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-wc8c-qw6v-h7f6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-450ecf7a0d2f58dc", "level": "note", "message": {"text": "Dependency @hono/node-server is a major version behind"}, "properties": {"repobilityId": "fd9528e0007b9230", "scanner": "scanner-primary", "fingerprint": "450ecf7a0d2f58dc", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0933b3b15005bc1e", "level": "note", "message": {"text": "Dependency zod is a major version behind"}, "properties": {"repobilityId": "05a28c7326324901", "scanner": "scanner-primary", "fingerprint": "0933b3b15005bc1e", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/09-code-migration-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f92d78fc52693c3b", "level": "note", "message": {"text": "Dependency zod is a major version behind"}, "properties": {"repobilityId": "09005f1f689b1bbc", "scanner": "scanner-primary", "fingerprint": "f92d78fc52693c3b", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "phases/19-capstone-projects/01-terminal-native-coding-agent/code/ts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-71c62f13729b3c54", "level": "error", "message": {"text": "Dangling fetch: GET /document/10k-acme-2025 (phases/19-capstone-projects/04-multimodal-document-qa/code/ts/tests/server.test.ts:22)"}, "properties": {"repobilityId": "67f6c1d560ce11d5", "scanner": "scanner-primary", "fingerprint": "71c62f13729b3c54", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-62ccc7f0dd1c0c27", "level": "error", "message": {"text": "Dangling fetch: GET /document/10k-acme-2025 (phases/19-capstone-projects/04-multimodal-document-qa/code/ts/tests/server.test.ts:32)"}, "properties": {"repobilityId": "20a66653a9705c27", "scanner": "scanner-primary", "fingerprint": "62ccc7f0dd1c0c27", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-93e5dc70e250c01a", "level": "error", "message": {"text": "Dangling fetch: GET /document/missing (phases/19-capstone-projects/04-multimodal-document-qa/code/ts/tests/server.test.ts:38)"}, "properties": {"repobilityId": "b6b49b3ddc04c6b1", "scanner": "scanner-primary", "fingerprint": "93e5dc70e250c01a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-a483e3f1df563d6c", "level": "error", "message": {"text": "Dangling fetch: GET /document/has.dot (phases/19-capstone-projects/04-multimodal-document-qa/code/ts/tests/server.test.ts:45)"}, "properties": {"repobilityId": "79319a162b8e7ff2", "scanner": "scanner-primary", "fingerprint": "a483e3f1df563d6c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-ee170cea5be40f0a", "level": "error", "message": {"text": "Dangling fetch: POST https://api.anthropic.com/v1/messages (phases/00-setup-and-tooling/04-apis-and-keys/code/first_api_call.ts:74)"}, "properties": {"repobilityId": "cad93d8765f24b4c", "scanner": "scanner-primary", "fingerprint": "ee170cea5be40f0a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-4a8f762925460ea1", "level": "note", "message": {"text": "Unused endpoint: GET /lesson/next"}, "properties": {"repobilityId": "32f63f9b2be92ee9", "scanner": "scanner-primary", "fingerprint": "4a8f762925460ea1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b33b638af57cd3a9", "level": "note", "message": {"text": "Unused endpoint: POST /lesson/:id/submit"}, "properties": {"repobilityId": "8cb69f4bd935eab1", "scanner": "scanner-primary", "fingerprint": "b33b638af57cd3a9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1008c575819b3d37", "level": "note", "message": {"text": "Unused endpoint: GET /jobs"}, "properties": {"repobilityId": "561b9258eff0c578", "scanner": "scanner-primary", "fingerprint": "1008c575819b3d37", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-80182839f64600f5", "level": "note", "message": {"text": "Unused endpoint: GET /job/:id"}, "properties": {"repobilityId": "7694fbdc9b1d0e2d", "scanner": "scanner-primary", "fingerprint": "80182839f64600f5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4c197182957464b0", "level": "note", "message": {"text": "Unused endpoint: GET /document/:id"}, "properties": {"repobilityId": "5a1e1b85225d20b4", "scanner": "scanner-primary", "fingerprint": "4c197182957464b0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d504b80adc9409ec", "level": "note", "message": {"text": "Unused endpoint: GET /dashboard"}, "properties": {"repobilityId": "caf4a13b819199cb", "scanner": "scanner-primary", "fingerprint": "d504b80adc9409ec", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-50719d00ac3cf209", "level": "note", "message": {"text": "Unused endpoint: GET /migrations"}, "properties": {"repobilityId": "23e921e1717dcb94", "scanner": "scanner-primary", "fingerprint": "50719d00ac3cf209", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8e8bb263642cdbf9", "level": "note", "message": {"text": "Unused endpoint: GET /migrations/:id"}, "properties": {"repobilityId": "19197b5f5e4eab47", "scanner": "scanner-primary", "fingerprint": "8e8bb263642cdbf9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-07f772e4ca8f34fa", "level": "note", "message": {"text": "Unused endpoint: POST /trace"}, "properties": {"repobilityId": "26e0c9b0741a6ba7", "scanner": "scanner-primary", "fingerprint": "07f772e4ca8f34fa", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6eab0e0e4e3fc0c9", "level": "note", "message": {"text": "Unused endpoint: GET /dashboard.json"}, "properties": {"repobilityId": "f5a41e80e60d61c8", "scanner": "scanner-primary", "fingerprint": "6eab0e0e4e3fc0c9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-59f45351017a2161", "level": "note", "message": {"text": "Unused endpoint: GET /query"}, "properties": {"repobilityId": "0e57e21d599ab34d", "scanner": "scanner-primary", "fingerprint": "59f45351017a2161", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1bb3714794b14146", "level": "note", "message": {"text": "Unused endpoint: POST /query"}, "properties": {"repobilityId": "d3284bbb8496ce8a", "scanner": "scanner-primary", "fingerprint": "1bb3714794b14146", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0ae38010c60493f1", "level": "note", "message": {"text": "Unused endpoint: POST /webhook"}, "properties": {"repobilityId": "339443bdeb65fb37", "scanner": "scanner-primary", "fingerprint": "0ae38010c60493f1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}