{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-c9124dec21c7cf60", "name": "Stray `console.log` in TS/JS \u2014 tests/setup.js:300", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/setup.js:300"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7176b3feed09812f", "name": "Stray `console.log` in TS/JS \u2014 backend/server.js:67", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/server.js:67"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-28583e0bb90bd8f6", "name": "Stray `console.log` in TS/JS \u2014 backend/utils/logger.js:17", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/utils/logger.js:17"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-80791757a92901c7", "name": "Stray `console.log` in TS/JS \u2014 backend/services/notifications.js:29", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/notifications.js:29"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4383cf288a7844e1", "name": "Stray `console.log` in TS/JS \u2014 backend/services/storage.js:61", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/storage.js:61"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-306f4127c5c3bb79", "name": "Stray `console.log` in TS/JS \u2014 backend/config/database-sqlite.js:33", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/config/database-sqlite.js:33"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e3217b68d6b425ad", "name": "Stray `console.log` in TS/JS \u2014 backend/config/database-pg.js:28", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/config/database-pg.js:28"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d5d7dcc74540a9e7", "name": "Stray `console.log` in TS/JS \u2014 backend/migrations/001_initial_schema.js:89", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/001_initial_schema.js:89"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-341d42a713aa7ea1", "name": "Stray `console.log` in TS/JS \u2014 backend/migrations/003_seed_data.js:33", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/003_seed_data.js:33"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-429d72b5971ab679", "name": "Stray `console.log` in TS/JS \u2014 backend/migrations/006_fix_product_images-pg.js:48", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/006_fix_product_images-pg.js:48"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9947e7df2f74e065", "name": "Stray `console.log` in TS/JS \u2014 backend/migrations/002_seed_categories-pg.js:12", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/002_seed_categories-pg.js:12"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-12a80f9ecca0e883", "name": "Stray `console.log` in TS/JS \u2014 backend/migrations/003_seed_data-pg.js:34", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/003_seed_data-pg.js:34"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ac0fab1773b537fe", "name": "Stray `console.log` in TS/JS \u2014 backend/migrations/migrator.js:41", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/migrator.js:41"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7113a03fb1d7cc6d", "name": "Stray `console.log` in TS/JS \u2014 backend/migrations/001_initial_schema-pg.js:89", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/001_initial_schema-pg.js:89"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-94ffd33e45f6ba51", "name": "Stray `console.log` in TS/JS \u2014 backend/migrations/006_fix_product_images.js:48", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/006_fix_product_images.js:48"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f46151cca99c430b", "name": "Stray `console.log` in TS/JS \u2014 backend/migrations/007_cleanup_seed_categories-pg.js:28", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/007_cleanup_seed_categories-pg.js:28"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e5d53f755ace2cf5", "name": "Stray `console.log` in TS/JS \u2014 backend/migrations/004_seed_products-pg.js:98", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/004_seed_products-pg.js:98"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dc9ca5439a7163ea", "name": "Stray `console.log` in TS/JS \u2014 backend/migrations/007_cleanup_seed_categories.js:21", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/007_cleanup_seed_categories.js:21"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6f4e2299af8052af", "name": "Stray `console.log` in TS/JS \u2014 backend/migrations/002_seed_categories.js:12", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/002_seed_categories.js:12"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dbfcb72ca1fd353d", "name": "Stray `console.log` in TS/JS \u2014 backend/migrations/migrator-pg.js:41", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/migrator-pg.js:41"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bb60f2f20f62d8fd", "name": "Stray `console.log` in TS/JS \u2014 scripts/generate-product-images.js:44", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/generate-product-images.js:44"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e9fd16e1ef53d547", "name": "Stray `console.log` in TS/JS \u2014 scripts/generate-sitemap.js:22", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/generate-sitemap.js:22"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-836598ac963a5ac0", "name": "Stray `console.log` in TS/JS \u2014 scripts/create-admin.js:50", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/create-admin.js:50"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3218ce9d90e9e73b", "name": "Stray `console.log` in TS/JS \u2014 scripts/backup.js:18", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/backup.js:18"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7d892806fef0313b", "name": "Stray `console.log` in TS/JS \u2014 public/sw.js:29", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 public/sw.js:29"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a456d299635a8619", "name": "Stray `console.log` in TS/JS \u2014 assets/js/main.js:10", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 assets/js/main.js:10"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d63da3583b14afc0", "name": "Dockerfile runs as root: Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8987d6d1c30c7202", "name": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4cba4999310eb2f6", "name": "Insecure pattern 'direct_innerhtml_assignment' in admin/js/settings.js:24", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in admin/js/settings.js:24"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b8decb52bc5aee9d", "name": "Insecure pattern 'local_storage_auth_token' in admin/js/auth.js:21", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in admin/js/auth.js:21"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a2f516049e181144", "name": "Insecure pattern 'direct_innerhtml_assignment' in assets/js/shop.js:144", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in assets/js/shop.js:144"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-24abe46cc6be0383", "name": "Insecure pattern 'direct_innerhtml_assignment' in assets/js/site-settings.js:97", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in assets/js/site-settings.js:97"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea3b5e389d8c9c0f", "name": "Low test-to-source ratio", "shortDescription": {"text": "Low test-to-source ratio"}, "fullDescription": {"text": "6 tests / 54 src (ratio 0.11)."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 75 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-11ceeb6469548eaf", "name": "Commented-code block (6 lines) in admin/js/auth.js:3", "shortDescription": {"text": "Commented-code block (6 lines) in admin/js/auth.js:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e4c7ab36f2969c05", "name": "`fetch()` without try/.catch or AbortSignal \u2014 public/sw.js:134", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/sw.js:134"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f9a328ba184b4342", "name": "Commented-code block (5 lines) in assets/js/main.js:87", "shortDescription": {"text": "Commented-code block (5 lines) in assets/js/main.js:87"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b334d875f2339fa1", "name": "5 env vars used in code but missing from .env.example", "shortDescription": {"text": "5 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `BACKUP_KEEP`, `BIOLAB_ADMIN_PASSWORD`, `BIOLAB_ADMIN_USERNAME`, `DATABASE_URL`, `HCAPTCHA_SECRET`. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c4d4c281b990abe4", "name": "Dangling fetch: GET /api/settings (admin/js/settings.js:101)", "shortDescription": {"text": "Dangling fetch: GET /api/settings (admin/js/settings.js:101)"}, "fullDescription": {"text": "`admin/js/settings.js:101` calls `GET /api/settings` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/settings`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-be24e78510cc330c", "name": "Dangling fetch: GET /api/settings (assets/js/site-settings.js:133)", "shortDescription": {"text": "Dangling fetch: GET /api/settings (assets/js/site-settings.js:133)"}, "fullDescription": {"text": "`assets/js/site-settings.js:133` calls `GET /api/settings` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/settings`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8bf2f7ca3faa1f1b", "name": "Unused endpoint: USE /api/auth/login", "shortDescription": {"text": "Unused endpoint: USE /api/auth/login"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/auth/login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-def16861a13564b0", "name": "Unused endpoint: USE /api/auth/register", "shortDescription": {"text": "Unused endpoint: USE /api/auth/register"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/auth/register` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-972b54078ec2581f", "name": "Unused endpoint: USE /api/health", "shortDescription": {"text": "Unused endpoint: USE /api/health"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/health` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f70dc6781d26c791", "name": "Unused endpoint: USE /api/orders", "shortDescription": {"text": "Unused endpoint: USE /api/orders"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/orders` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cefe3e16e4a7273d", "name": "Unused endpoint: USE /api/products", "shortDescription": {"text": "Unused endpoint: USE /api/products"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/products` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c10a85b9ad227a45", "name": "Unused endpoint: USE /api/categories", "shortDescription": {"text": "Unused endpoint: USE /api/categories"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/categories` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8ca4664c9cda1cd6", "name": "Unused endpoint: USE /api/settings", "shortDescription": {"text": "Unused endpoint: USE /api/settings"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a74449cc5d561bad", "name": "Unused endpoint: USE /api/search", "shortDescription": {"text": "Unused endpoint: USE /api/search"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/search` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1bc898b3b7565990", "name": "Unused endpoint: USE /uploads", "shortDescription": {"text": "Unused endpoint: USE /uploads"}, "fullDescription": {"text": "`backend/server.js` declares `USE /uploads` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3b59435b3211a9df", "name": "Unused endpoint: USE /assets", "shortDescription": {"text": "Unused endpoint: USE /assets"}, "fullDescription": {"text": "`backend/server.js` declares `USE /assets` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4006f18ec4db10cf", "name": "Unused endpoint: USE /images", "shortDescription": {"text": "Unused endpoint: USE /images"}, "fullDescription": {"text": "`backend/server.js` declares `USE /images` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b2d8849fb6b1ac47", "name": "Unused endpoint: USE /admin", "shortDescription": {"text": "Unused endpoint: USE /admin"}, "fullDescription": {"text": "`backend/server.js` declares `USE /admin` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ef59b2d14824b5ed", "name": "Unused endpoint: USE /favicon.svg", "shortDescription": {"text": "Unused endpoint: USE /favicon.svg"}, "fullDescription": {"text": "`backend/server.js` declares `USE /favicon.svg` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`backend/server.js` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6eb452fbfb454d20", "name": "Unused endpoint: USE /api/auth", "shortDescription": {"text": "Unused endpoint: USE /api/auth"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/auth` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4756b4c4da7d2088", "name": "Unused endpoint: GET /api/health", "shortDescription": {"text": "Unused endpoint: GET /api/health"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/health` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dde3adb27bf7eebe", "name": "Unused endpoint: USE /api", "shortDescription": {"text": "Unused endpoint: USE /api"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a009b1a56794f45", "name": "Unused endpoint: POST /", "shortDescription": {"text": "Unused endpoint: POST /"}, "fullDescription": {"text": "`backend/routes/orders.js` declares `POST /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-707a218ca98cef20", "name": "Unused endpoint: GET /code/:orderCode", "shortDescription": {"text": "Unused endpoint: GET /code/:orderCode"}, "fullDescription": {"text": "`backend/routes/orders.js` declares `GET /code/:orderCode` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a61765f777cc8edd", "name": "Unused endpoint: GET /phone/:phone", "shortDescription": {"text": "Unused endpoint: GET /phone/:phone"}, "fullDescription": {"text": "`backend/routes/orders.js` declares `GET /phone/:phone` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-530f191d1463298e", "name": "Unused endpoint: GET /admin/code/:orderCode", "shortDescription": {"text": "Unused endpoint: GET /admin/code/:orderCode"}, "fullDescription": {"text": "`backend/routes/orders.js` declares `GET /admin/code/:orderCode` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d1885a6852627c97", "name": "Unused endpoint: POST /:orderCode/complete", "shortDescription": {"text": "Unused endpoint: POST /:orderCode/complete"}, "fullDescription": {"text": "`backend/routes/orders.js` declares `POST /:orderCode/complete` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-77bacc2d0b23b7c0", "name": "Unused endpoint: POST /:orderCode/cancel", "shortDescription": {"text": "Unused endpoint: POST /:orderCode/cancel"}, "fullDescription": {"text": "`backend/routes/orders.js` declares `POST /:orderCode/cancel` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ca5756175765b49d", "name": "Unused endpoint: GET /:id", "shortDescription": {"text": "Unused endpoint: GET /:id"}, "fullDescription": {"text": "`backend/routes/products.js` declares `GET /:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8d5b2b188d08ca82", "name": "Unused endpoint: PUT /:id", "shortDescription": {"text": "Unused endpoint: PUT /:id"}, "fullDescription": {"text": "`backend/routes/products.js` declares `PUT /:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a61c112b611f4bb", "name": "Unused endpoint: DELETE /:id", "shortDescription": {"text": "Unused endpoint: DELETE /:id"}, "fullDescription": {"text": "`backend/routes/products.js` declares `DELETE /:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-67d28fa8cd6bb12f", "name": "Unused endpoint: PUT /", "shortDescription": {"text": "Unused endpoint: PUT /"}, "fullDescription": {"text": "`backend/routes/settings.js` declares `PUT /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-875446534ec5da6f", "name": "Unused endpoint: GET /translate", "shortDescription": {"text": "Unused endpoint: GET /translate"}, "fullDescription": {"text": "`backend/routes/search.js` declares `GET /translate` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f5c922b9512394db", "name": "Unused endpoint: GET /csrf-token", "shortDescription": {"text": "Unused endpoint: GET /csrf-token"}, "fullDescription": {"text": "`backend/routes/auth.js` declares `GET /csrf-token` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-618721b912bad1c2", "name": "Unused endpoint: POST /login", "shortDescription": {"text": "Unused endpoint: POST /login"}, "fullDescription": {"text": "`backend/routes/auth.js` declares `POST /login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-304b6f2b403d93f7", "name": "Unused endpoint: POST /register", "shortDescription": {"text": "Unused endpoint: POST /register"}, "fullDescription": {"text": "`backend/routes/auth.js` declares `POST /register` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-822f5812dc9de7a7", "name": "Unused endpoint: GET /verify", "shortDescription": {"text": "Unused endpoint: GET /verify"}, "fullDescription": {"text": "`backend/routes/auth.js` declares `GET /verify` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-99fc36db98c134ce", "name": "Unused endpoint: POST /logout", "shortDescription": {"text": "Unused endpoint: POST /logout"}, "fullDescription": {"text": "`backend/routes/auth.js` declares `POST /logout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/24013"}, "properties": {"repository": "ajvar010-beep/shablon", "repoUrl": "https://github.com/ajvar010-beep/shablon", "branch": "main"}, "results": [{"ruleId": "scanner-c9124dec21c7cf60", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/setup.js:300"}, "properties": {"repobilityId": "301e4c0184bf291d", "scanner": "scanner-primary", "fingerprint": "c9124dec21c7cf60", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7176b3feed09812f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/server.js:67"}, "properties": {"repobilityId": "ec6c625862fd9ddc", "scanner": "scanner-primary", "fingerprint": "7176b3feed09812f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-28583e0bb90bd8f6", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/utils/logger.js:17"}, "properties": {"repobilityId": "774f0deddb47da8b", "scanner": "scanner-primary", "fingerprint": "28583e0bb90bd8f6", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-80791757a92901c7", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/notifications.js:29"}, "properties": {"repobilityId": "1a0a3f2d5a1abc5b", "scanner": "scanner-primary", "fingerprint": "80791757a92901c7", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4383cf288a7844e1", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/storage.js:61"}, "properties": {"repobilityId": "b6bcf0b35540b964", "scanner": "scanner-primary", "fingerprint": "4383cf288a7844e1", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-306f4127c5c3bb79", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/config/database-sqlite.js:33"}, "properties": {"repobilityId": "8adf26e2d3b39290", "scanner": "scanner-primary", "fingerprint": "306f4127c5c3bb79", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e3217b68d6b425ad", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/config/database-pg.js:28"}, "properties": {"repobilityId": "4e49b977f729e8b8", "scanner": "scanner-primary", "fingerprint": "e3217b68d6b425ad", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d5d7dcc74540a9e7", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/001_initial_schema.js:89"}, "properties": {"repobilityId": "7fdaa6f9e7650b13", "scanner": "scanner-primary", "fingerprint": "d5d7dcc74540a9e7", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-341d42a713aa7ea1", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/003_seed_data.js:33"}, "properties": {"repobilityId": "a3f50c0f92f47eec", "scanner": "scanner-primary", "fingerprint": "341d42a713aa7ea1", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-429d72b5971ab679", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/006_fix_product_images-pg.js:48"}, "properties": {"repobilityId": "9970b30dfad8341c", "scanner": "scanner-primary", "fingerprint": "429d72b5971ab679", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9947e7df2f74e065", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/002_seed_categories-pg.js:12"}, "properties": {"repobilityId": "6e48dc490c30a43c", "scanner": "scanner-primary", "fingerprint": "9947e7df2f74e065", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-12a80f9ecca0e883", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/003_seed_data-pg.js:34"}, "properties": {"repobilityId": "adc2a05036b9ee7d", "scanner": "scanner-primary", "fingerprint": "12a80f9ecca0e883", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ac0fab1773b537fe", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/migrator.js:41"}, "properties": {"repobilityId": "4f95bb20e0550df3", "scanner": "scanner-primary", "fingerprint": "ac0fab1773b537fe", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7113a03fb1d7cc6d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/001_initial_schema-pg.js:89"}, "properties": {"repobilityId": "5c4b8a21e6c66648", "scanner": "scanner-primary", "fingerprint": "7113a03fb1d7cc6d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-94ffd33e45f6ba51", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/006_fix_product_images.js:48"}, "properties": {"repobilityId": "84db42dd05c5714d", "scanner": "scanner-primary", "fingerprint": "94ffd33e45f6ba51", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f46151cca99c430b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/007_cleanup_seed_categories-pg.js:28"}, "properties": {"repobilityId": "d4a409e93f537bc3", "scanner": "scanner-primary", "fingerprint": "f46151cca99c430b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e5d53f755ace2cf5", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/004_seed_products-pg.js:98"}, "properties": {"repobilityId": "e71c0582f9f0c71a", "scanner": "scanner-primary", "fingerprint": "e5d53f755ace2cf5", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-dc9ca5439a7163ea", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/007_cleanup_seed_categories.js:21"}, "properties": {"repobilityId": "a6084c28146909b8", "scanner": "scanner-primary", "fingerprint": "dc9ca5439a7163ea", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-6f4e2299af8052af", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/002_seed_categories.js:12"}, "properties": {"repobilityId": "2301de3c69b85a57", "scanner": "scanner-primary", "fingerprint": "6f4e2299af8052af", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-dbfcb72ca1fd353d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrations/migrator-pg.js:41"}, "properties": {"repobilityId": "4d405bf560a3d072", "scanner": "scanner-primary", "fingerprint": "dbfcb72ca1fd353d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-bb60f2f20f62d8fd", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/generate-product-images.js:44"}, "properties": {"repobilityId": "cb4ebc17595dca0e", "scanner": "scanner-primary", "fingerprint": "bb60f2f20f62d8fd", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e9fd16e1ef53d547", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/generate-sitemap.js:22"}, "properties": {"repobilityId": "97c662424750e259", "scanner": "scanner-primary", "fingerprint": "e9fd16e1ef53d547", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-836598ac963a5ac0", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/create-admin.js:50"}, "properties": {"repobilityId": "855f1b10a3a3072b", "scanner": "scanner-primary", "fingerprint": "836598ac963a5ac0", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3218ce9d90e9e73b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/backup.js:18"}, "properties": {"repobilityId": "5ee81335d821e828", "scanner": "scanner-primary", "fingerprint": "3218ce9d90e9e73b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7d892806fef0313b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 public/sw.js:29"}, "properties": {"repobilityId": "19ecb22d48da856c", "scanner": "scanner-primary", "fingerprint": "7d892806fef0313b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a456d299635a8619", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 assets/js/main.js:10"}, "properties": {"repobilityId": "4a1dba8142a09584", "scanner": "scanner-primary", "fingerprint": "a456d299635a8619", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d63da3583b14afc0", "level": "warning", "message": {"text": "Dockerfile runs as root: Dockerfile"}, "properties": {"repobilityId": "a2ed1bd120e507db", "scanner": "scanner-primary", "fingerprint": "d63da3583b14afc0", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-8987d6d1c30c7202", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine"}, "properties": {"repobilityId": "068fbf45727eac17", "scanner": "scanner-primary", "fingerprint": "8987d6d1c30c7202", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4cba4999310eb2f6", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in admin/js/settings.js:24"}, "properties": {"repobilityId": "52772c82475e1f22", "scanner": "scanner-primary", "fingerprint": "4cba4999310eb2f6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "admin/js/settings.js"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-b8decb52bc5aee9d", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in admin/js/auth.js:21"}, "properties": {"repobilityId": "ac4ca277c0a81530", "scanner": "scanner-primary", "fingerprint": "b8decb52bc5aee9d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "admin/js/auth.js"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-a2f516049e181144", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in assets/js/shop.js:144"}, "properties": {"repobilityId": "1415406046ead531", "scanner": "scanner-primary", "fingerprint": "a2f516049e181144", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "assets/js/shop.js"}, "region": {"startLine": 144}}}]}, {"ruleId": "scanner-24abe46cc6be0383", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in assets/js/site-settings.js:97"}, "properties": {"repobilityId": "eeb006b37991244f", "scanner": "scanner-primary", "fingerprint": "24abe46cc6be0383", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "assets/js/site-settings.js"}, "region": {"startLine": 97}}}]}, {"ruleId": "scanner-ea3b5e389d8c9c0f", "level": "note", "message": {"text": "Low test-to-source ratio"}, "properties": {"repobilityId": "ef7b2552cc00a375", "scanner": "scanner-primary", "fingerprint": "ea3b5e389d8c9c0f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["tests"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "9af24f456378c87b", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "b8f3cae7dcdafb30", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "89ac5caeb1613424", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "741bc31314795e51", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-11ceeb6469548eaf", "level": "none", "message": {"text": "Commented-code block (6 lines) in admin/js/auth.js:3"}, "properties": {"repobilityId": "ca5198dc93613821", "scanner": "scanner-primary", "fingerprint": "11ceeb6469548eaf", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e4c7ab36f2969c05", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/sw.js:134"}, "properties": {"repobilityId": "d880e313fe466233", "scanner": "scanner-primary", "fingerprint": "e4c7ab36f2969c05", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-f9a328ba184b4342", "level": "none", "message": {"text": "Commented-code block (5 lines) in assets/js/main.js:87"}, "properties": {"repobilityId": "dd7bdebcb429c3b6", "scanner": "scanner-primary", "fingerprint": "f9a328ba184b4342", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b334d875f2339fa1", "level": "note", "message": {"text": "5 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "faa38682016f5d53", "scanner": "scanner-primary", "fingerprint": "b334d875f2339fa1", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-c4d4c281b990abe4", "level": "error", "message": {"text": "Dangling fetch: GET /api/settings (admin/js/settings.js:101)"}, "properties": {"repobilityId": "121470f0e19e56b9", "scanner": "scanner-primary", "fingerprint": "c4d4c281b990abe4", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-be24e78510cc330c", "level": "error", "message": {"text": "Dangling fetch: GET /api/settings (assets/js/site-settings.js:133)"}, "properties": {"repobilityId": "ba2e02ecd7404263", "scanner": "scanner-primary", "fingerprint": "be24e78510cc330c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-8bf2f7ca3faa1f1b", "level": "note", "message": {"text": "Unused endpoint: USE /api/auth/login"}, "properties": {"repobilityId": "c172beb7cb603d72", "scanner": "scanner-primary", "fingerprint": "8bf2f7ca3faa1f1b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-def16861a13564b0", "level": "note", "message": {"text": "Unused endpoint: USE /api/auth/register"}, "properties": {"repobilityId": "d1d9984dee170083", "scanner": "scanner-primary", "fingerprint": "def16861a13564b0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-972b54078ec2581f", "level": "note", "message": {"text": "Unused endpoint: USE /api/health"}, "properties": {"repobilityId": "376cfcfbc7d04d4b", "scanner": "scanner-primary", "fingerprint": "972b54078ec2581f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f70dc6781d26c791", "level": "note", "message": {"text": "Unused endpoint: USE /api/orders"}, "properties": {"repobilityId": "90fada8852ed3200", "scanner": "scanner-primary", "fingerprint": "f70dc6781d26c791", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cefe3e16e4a7273d", "level": "note", "message": {"text": "Unused endpoint: USE /api/products"}, "properties": {"repobilityId": "fe9cf4a30a8dd1d7", "scanner": "scanner-primary", "fingerprint": "cefe3e16e4a7273d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c10a85b9ad227a45", "level": "note", "message": {"text": "Unused endpoint: USE /api/categories"}, "properties": {"repobilityId": "1d57d075ed6f0318", "scanner": "scanner-primary", "fingerprint": "c10a85b9ad227a45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8ca4664c9cda1cd6", "level": "note", "message": {"text": "Unused endpoint: USE /api/settings"}, "properties": {"repobilityId": "d31f193a57f1e3ce", "scanner": "scanner-primary", "fingerprint": "8ca4664c9cda1cd6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a74449cc5d561bad", "level": "note", "message": {"text": "Unused endpoint: USE /api/search"}, "properties": {"repobilityId": "863bfe1cbf2d8543", "scanner": "scanner-primary", "fingerprint": "a74449cc5d561bad", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1bc898b3b7565990", "level": "note", "message": {"text": "Unused endpoint: USE /uploads"}, "properties": {"repobilityId": "d2c9d1907a1121fd", "scanner": "scanner-primary", "fingerprint": "1bc898b3b7565990", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3b59435b3211a9df", "level": "note", "message": {"text": "Unused endpoint: USE /assets"}, "properties": {"repobilityId": "6f3b8db08c78fe71", "scanner": "scanner-primary", "fingerprint": "3b59435b3211a9df", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4006f18ec4db10cf", "level": "note", "message": {"text": "Unused endpoint: USE /images"}, "properties": {"repobilityId": "acfd05e664c0d819", "scanner": "scanner-primary", "fingerprint": "4006f18ec4db10cf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b2d8849fb6b1ac47", "level": "note", "message": {"text": "Unused endpoint: USE /admin"}, "properties": {"repobilityId": "e5bd3f9c2b81d11e", "scanner": "scanner-primary", "fingerprint": "b2d8849fb6b1ac47", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ef59b2d14824b5ed", "level": "note", "message": {"text": "Unused endpoint: USE /favicon.svg"}, "properties": {"repobilityId": "831a62ebb42083fb", "scanner": "scanner-primary", "fingerprint": "ef59b2d14824b5ed", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "7d4772f7c52bce64", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6eb452fbfb454d20", "level": "note", "message": {"text": "Unused endpoint: USE /api/auth"}, "properties": {"repobilityId": "0a5793afc5ea0a13", "scanner": "scanner-primary", "fingerprint": "6eb452fbfb454d20", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4756b4c4da7d2088", "level": "note", "message": {"text": "Unused endpoint: GET /api/health"}, "properties": {"repobilityId": "1e5295e69c6e06d8", "scanner": "scanner-primary", "fingerprint": "4756b4c4da7d2088", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dde3adb27bf7eebe", "level": "note", "message": {"text": "Unused endpoint: USE /api"}, "properties": {"repobilityId": "e7ff5964127d9924", "scanner": "scanner-primary", "fingerprint": "dde3adb27bf7eebe", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a009b1a56794f45", "level": "note", "message": {"text": "Unused endpoint: POST /"}, "properties": {"repobilityId": "0d2b496ec7db21cc", "scanner": "scanner-primary", "fingerprint": "7a009b1a56794f45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-707a218ca98cef20", "level": "note", "message": {"text": "Unused endpoint: GET /code/:orderCode"}, "properties": {"repobilityId": "c2a36da3e47ae19f", "scanner": "scanner-primary", "fingerprint": "707a218ca98cef20", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a61765f777cc8edd", "level": "note", "message": {"text": "Unused endpoint: GET /phone/:phone"}, "properties": {"repobilityId": "a76dac5116899c3d", "scanner": "scanner-primary", "fingerprint": "a61765f777cc8edd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-530f191d1463298e", "level": "note", "message": {"text": "Unused endpoint: GET /admin/code/:orderCode"}, "properties": {"repobilityId": "9caedf083b1a4a3f", "scanner": "scanner-primary", "fingerprint": "530f191d1463298e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d1885a6852627c97", "level": "note", "message": {"text": "Unused endpoint: POST /:orderCode/complete"}, "properties": {"repobilityId": "682753a4faa917a0", "scanner": "scanner-primary", "fingerprint": "d1885a6852627c97", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-77bacc2d0b23b7c0", "level": "note", "message": {"text": "Unused endpoint: POST /:orderCode/cancel"}, "properties": {"repobilityId": "ce89d7eb80c399fa", "scanner": "scanner-primary", "fingerprint": "77bacc2d0b23b7c0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ca5756175765b49d", "level": "note", "message": {"text": "Unused endpoint: GET /:id"}, "properties": {"repobilityId": "7940b1172ff884cf", "scanner": "scanner-primary", "fingerprint": "ca5756175765b49d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8d5b2b188d08ca82", "level": "note", "message": {"text": "Unused endpoint: PUT /:id"}, "properties": {"repobilityId": "abca03307a62f09b", "scanner": "scanner-primary", "fingerprint": "8d5b2b188d08ca82", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a61c112b611f4bb", "level": "note", "message": {"text": "Unused endpoint: DELETE /:id"}, "properties": {"repobilityId": "090056bf7d57fdb3", "scanner": "scanner-primary", "fingerprint": "7a61c112b611f4bb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-67d28fa8cd6bb12f", "level": "note", "message": {"text": "Unused endpoint: PUT /"}, "properties": {"repobilityId": "3a60ff7c2ec6432e", "scanner": "scanner-primary", "fingerprint": "67d28fa8cd6bb12f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-875446534ec5da6f", "level": "note", "message": {"text": "Unused endpoint: GET /translate"}, "properties": {"repobilityId": "ae42a6545fdb87e0", "scanner": "scanner-primary", "fingerprint": "875446534ec5da6f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f5c922b9512394db", "level": "note", "message": {"text": "Unused endpoint: GET /csrf-token"}, "properties": {"repobilityId": "fd6b7d3f4d7aa9e7", "scanner": "scanner-primary", "fingerprint": "f5c922b9512394db", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-618721b912bad1c2", "level": "note", "message": {"text": "Unused endpoint: POST /login"}, "properties": {"repobilityId": "0739200902492336", "scanner": "scanner-primary", "fingerprint": "618721b912bad1c2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-304b6f2b403d93f7", "level": "note", "message": {"text": "Unused endpoint: POST /register"}, "properties": {"repobilityId": "75111c8cb20116c6", "scanner": "scanner-primary", "fingerprint": "304b6f2b403d93f7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-822f5812dc9de7a7", "level": "note", "message": {"text": "Unused endpoint: GET /verify"}, "properties": {"repobilityId": "afd107e2b549630c", "scanner": "scanner-primary", "fingerprint": "822f5812dc9de7a7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-99fc36db98c134ce", "level": "note", "message": {"text": "Unused endpoint: POST /logout"}, "properties": {"repobilityId": "f995610a39083f49", "scanner": "scanner-primary", "fingerprint": "99fc36db98c134ce", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}