{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "foundry_unresolved_feedback", "name": "Foundry mined unresolved feedback: unread-llc/meform", "shortDescription": {"text": "Foundry mined unresolved feedback: unread-llc/meform"}, "fullDescription": {"text": "Graph query export: Human feedback without linked fix evidence\nQuery id: unresolved_feedback\nQuery type: motif_query\nIntent: Negative/unresolved examples that should not be hallucinated into fixes.\nMotif: unlinked_feedback_needs_evidence\nTraining usage: negative_or_unresolved\nGraph gold label: needs_more_evidence\nRepo: unread-llc/meform\nThread: unread-llc/meform#1\nEvidence:\nGraph motif: Human feedback exists without a linked fix\nMotif id: unlinked_feedback_needs_evidence\nPolarity: bad\nTraining usage: negative_or_unresolved\nSeverity: medium\nRepo: unread-llc/meform\nThread: unread-llc/meform#1\nGraph gold label: needs_more_evidence\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: unread-llc/meform#1\nRepo: unread-llc/meform\nIssue/PR number: 1\nGraph consistency label: needs_more_evidence\nNodes: 11\nEdges: 17\nNode types: {'link_quality': 3, 'pr_file': 2, 'thread': 1, 'repo': 1, 'comment': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'chain_has_link_qu"}, "properties": {"scanner": "foundry_dataset", "category": "practices", "severity": "medium", "confidence": 0.7, "cwe": "", "owasp": ""}}, {"id": "foundry_bad_chain", "name": "Foundry mined bad chains: unread-llc/meform", "shortDescription": {"text": "Foundry mined bad chains: unread-llc/meform"}, "fullDescription": {"text": "Comment chain pattern product: bad_chains\nRepo: unread-llc/meform\nThread: unread-llc/meform#1\nOutcome: not_resolved_or_not_observed\nThread label: thread_has_human_issue_without_fix_context\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, repo_has_isolated_helicopter_views, link_quality_unresolved, high_risk_human_feedback_label\nChain evidence:\nIssue/PR evidence chain: unread-llc/meform#1\nRepo: unread-llc/meform\nThread label: thread_has_human_issue_without_fix_context\nOutcome: not_resolved_or_not_observed\nComment count: 1\nLinked commit count: 0\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 2\nLabels: {'security_auth_secret': 1}\nPolarities: {'bad': 1}\nChanged file labels: {'ui_or_frontend': 2}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-ba0c30fd0de674e4\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"security_auth_secret\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.co"}, "properties": {"scanner": "foundry_dataset", "category": "practices", "severity": "high", "confidence": 0.84, "cwe": "", "owasp": ""}}, {"id": "foundry_auth_guardrail_gap", "name": "Foundry mined security auth guardrail gaps: unread-llc/meform", "shortDescription": {"text": "Foundry mined security auth guardrail gaps: unread-llc/meform"}, "fullDescription": {"text": "Graph query export: Security/auth changes without enough guardrails\nQuery id: security_auth_guardrail_gaps\nQuery type: motif_query\nIntent: Assumption-check security/auth examples requiring stronger tests or CI.\nMotif: security_auth_without_guardrails\nTraining usage: assumption_check\nGraph gold label: needs_more_evidence\nRepo: unread-llc/meform\nThread: unread-llc/meform#1\nEvidence:\nGraph motif: Security/auth change without enough guardrails\nMotif id: security_auth_without_guardrails\nPolarity: bad\nTraining usage: assumption_check\nSeverity: critical\nRepo: unread-llc/meform\nThread: unread-llc/meform#1\nGraph gold label: needs_more_evidence\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: unread-llc/meform#1\nRepo: unread-llc/meform\nIssue/PR number: 1\nGraph consistency label: needs_more_evidence\nNodes: 11\nEdges: 17\nNode types: {'link_quality': 3, 'pr_file': 2, 'thread': 1, 'repo': 1, 'comment': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'chain_has_"}, "properties": {"scanner": "foundry_dataset", "category": "auth", "severity": "critical", "confidence": 0.78, "cwe": "", "owasp": ""}}, {"id": "scanner-bead75b0f9233e05", "name": "No API endpoints detected", "shortDescription": {"text": "No API endpoints detected"}, "fullDescription": {"text": "The scanner did not find FastAPI/Flask/Express/NestJS/GraphQL/gRPC routes. If this repo exposes APIs, the framework may be unsupported."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e1f58b794290ed8e", "name": "`truncate` class without `title=` for hover reveal \u2014 components/mongolia-section.tsx:360", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 components/mongolia-section.tsx:360"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ca4c06a9a037ee23", "name": "`truncate` class without `title=` for hover reveal \u2014 components/stats-section.tsx:162", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 components/stats-section.tsx:162"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-95ae0c8512e95479", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 components/ui/chart.tsx:83", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 components/ui/chart.tsx:83"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-685596ac13327136", "name": "`truncate` class without `title=` for hover reveal \u2014 components/registration/phone-input.tsx:69", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 components/registration/phone-input.tsx:69"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8ac5598c69cd4e46", "name": "Stray `console.log` in TS/JS \u2014 app/api/register/verify/route.ts:22", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 app/api/register/verify/route.ts:22"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-32650f989574df5b", "name": "Stray `console.log` in TS/JS \u2014 app/api/webhooks/byl/route.ts:21", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 app/api/webhooks/byl/route.ts:21"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8d2f546ffc9129cc", "name": "Stray `console.log` in TS/JS \u2014 app/api/webhooks/golomt/route.ts:17", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 app/api/webhooks/golomt/route.ts:17"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a823124e73ff38e4", "name": "Stray `console.log` in TS/JS \u2014 lib/byl.ts:75", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/byl.ts:75"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c33064638983daba", "name": "Stray `console.log` in TS/JS \u2014 lib/aws/ses.ts:78", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/aws/ses.ts:78"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-038f95f510f35674", "name": "Insecure pattern 'dangerous_innerhtml' in components/ui/chart.tsx:83", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in components/ui/chart.tsx:83"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "0 test file(s) for 135 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-01f96f71d9907a8c", "name": "README lacks setup or run instructions", "shortDescription": {"text": "README lacks setup or run instructions"}, "fullDescription": {"text": "A README exists, but it does not contain common install/setup/run markers. This matches a frequent generated-code pattern: UI is present, operational handoff is thin."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 18 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 19 placeholder/mock markers across 9 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci, tests, operator-readme. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-81bb2d58c3f9002d", "name": "Commented-code block (5 lines) in components/stats-section.tsx:17", "shortDescription": {"text": "Commented-code block (5 lines) in components/stats-section.tsx:17"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-764883111ec84fbf", "name": "`fetch()` without try/.catch or AbortSignal \u2014 app/[locale]/admin/page.tsx:84", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 app/[locale]/admin/page.tsx:84"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f1f25285e5009692", "name": "`fetch()` without try/.catch or AbortSignal \u2014 lib/meforum-videos.ts:92", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 lib/meforum-videos.ts:92"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a0f9779389def562", "name": "`fetch()` without try/.catch or AbortSignal \u2014 lib/byl.ts:50", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 lib/byl.ts:50"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-250f57e8a1dbd3c5", "name": "4 env vars used in code but missing from .env.example", "shortDescription": {"text": "4 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `INVITE_CODES`, `MEF_AWS_REGION`, `MEF_DYNAMODB_TABLE`, `MEF_S3_BUCKET`. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/21950"}, "properties": {"repository": "unread-llc/meform", "repoUrl": "https://github.com/unread-llc/meform", "branch": "main"}, "results": [{"ruleId": "foundry_unresolved_feedback", "level": "warning", "message": {"text": "Foundry mined unresolved feedback: unread-llc/meform"}, "properties": {"repobilityId": 371092, "scanner": "foundry_dataset", "fingerprint": "12e56709cac0a971e79aef75689d6bf39cb7105de2003d7bd70eacbff2611cd1", "category": "practices", "severity": "medium", "confidence": 0.7, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Human feedback without linked fix evidence", "intent": "Negative/unresolved examples that should not be hallucinated into fixes.", "labels": {"ui_or_frontend": 2, "security_auth_secret": 1, "issue_or_pull_request_thread": 1, "not_resolved_or_not_observed": 3, "human_reported_issue_no_linked_fix": 1, "thread_has_human_issue_without_fix_context": 2}, "source": "graph_query_export", "motif_id": "unlinked_feedback_needs_evidence", "outcomes": {"not_resolved_or_not_observed": 6}, "polarity": "bad", "query_id": "unresolved_feedback", "severity": "medium", "ci_labels": {}, "synthetic": false, "edge_count": 17, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "thread_touches_file": 2, "chain_has_link_quality": 3, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 2, "thread_has_comment_chain": 1, "comment_chain_touches_file": 2, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 11, "node_types": {"repo": 1, "thread": 1, "comment": 1, "pr_file": 2, "fix_outcome": 1, "issue_chain": 1, "link_quality": 3, "comment_chain": 1}, "query_type": "motif_query", "thread_key": "unread-llc/meform#1", "issue_number": "1", "quality_tiers": {"unresolved": 3}, "repo_full_name": "unread-llc/meform", "training_usage": "negative_or_unresolved", "source_motif_id": "graph-pattern-motif-thread-6a6abdf12fc94a83", "graph_gold_label": "needs_more_evidence", "changed_file_labels": {"ui_or_frontend": 8}}, "text": "Graph query export: Human feedback without linked fix evidence\nQuery id: unresolved_feedback\nQuery type: motif_query\nIntent: Negative/unresolved examples that should not be hallucinated into fixes.\nMotif: unlinked_feedback_needs_evidence\nTraining usage: negative_or_unresolved\nGraph gold label: needs_more_evidence\nRepo: unread-llc/meform\nThread: unread-llc/meform#1\nEvidence:\nGraph motif: Human feedback exists without a linked fix\nMotif id: unlinked_feedback_needs_evidence\nPolarity: bad\nTraining usage: negative_or_unresolved\nSeverity: medium\nRepo: unread-llc/meform\nThread: unread-llc/meform#1\nGraph gold label: needs_more_evidence\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: unread-llc/meform#1\nRepo: unread-llc/meform\nIssue/PR number: 1\nGraph consistency label: needs_more_evidence\nNodes: 11\nEdges: 17\nNode types: {'link_quality': 3, 'pr_file': 2, 'thread': 1, 'repo': 1, 'comment': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'chain_has_link_quality': 3, 'thread_touches_file': 2, 'comment_chain_touches_file': 2, 'issue_chain_touches_file': 2, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'not_resolved_or_not_observed': 3, 'ui_or_frontend': 2, 'thread_has_human_issue_without_fix_context': 2, 'issue_or_pull_request_thread': 1, 'security_auth_secret': 1, 'human_reported_issue_no_linked_fix': 1}\nOutcomes: {'not_resolved_or_not_observed': 6}\nQuality tiers: {'unresolved': 3}\nCI labels: {}\nCurriculum targets:\n- Teach models to preserve unresolved human feedback instead of hallucinating fixes.\n- Build issue-to-regression examples where no accepted fix exists yet.\nAssumption checks:\n- Can a commit be linked by issue number, SHA, changed path, or time window?\n- If no link exists, is this explicitly labelled unresolved?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/unread-llc/meform", "source_id": "graph-query-motif_query-be827cebeaf4ef4d", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/unresolved_feedback/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "unread-llc/meform", "source_dataset": "graph_queries/unresolved_feedback", "training_usage": "negative_or_unresolved"}}}, {"ruleId": "foundry_bad_chain", "level": "error", "message": {"text": "Foundry mined bad chains: unread-llc/meform"}, "properties": {"repobilityId": 323647, "scanner": "foundry_dataset", "fingerprint": "d609b2ac2d893151deab0eb36d92bbd75777d628b40308e2c4eb2cb3dd23fa28", "category": "practices", "severity": "high", "confidence": 0.84, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "comment_chain_pattern_product", "source": "comment_chain_pattern_miner", "product": "bad_chains", "synthetic": false, "thread_key": "unread-llc/meform#1", "human_labels": ["security_auth_secret", "ui_or_frontend"], "issue_number": "1", "thread_label": "thread_has_human_issue_without_fix_context", "outcome_label": "not_resolved_or_not_observed", "source_backed": true, "max_confidence": 0.0, "repo_full_name": "unread-llc/meform", "training_usage": "negative_or_unresolved", "confidence_tier": "unresolved", "source_chain_id": "evidence-chain-issue_chain-3a75c3abe4288a4d", "helicopter_views": {"graphs": 2}, "artifact_families": {"ci": 1, "docs": 2, "designs": 1, "schemas": 1, "routes_api": 3}, "source_chain_kind": "issue_chain", "changed_file_count": 2, "source_graph_label": "source_backed_multi_signal_graph", "changed_file_labels": {"ui_or_frontend": 2}, "linked_commit_count": 0, "helicopter_view_count": 2, "source_artifact_count": 8, "classification_reasons": ["source_graph_has_real_artifacts", "source_graph_has_verification_artifacts", "repo_has_isolated_helicopter_views", "link_quality_unresolved", "high_risk_human_feedback_label"], "linked_ci_commit_count": 0, "verification_artifact_count": 2, "design_schema_api_artifact_count": 5}, "text": "Comment chain pattern product: bad_chains\nRepo: unread-llc/meform\nThread: unread-llc/meform#1\nOutcome: not_resolved_or_not_observed\nThread label: thread_has_human_issue_without_fix_context\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, repo_has_isolated_helicopter_views, link_quality_unresolved, high_risk_human_feedback_label\nChain evidence:\nIssue/PR evidence chain: unread-llc/meform#1\nRepo: unread-llc/meform\nThread label: thread_has_human_issue_without_fix_context\nOutcome: not_resolved_or_not_observed\nComment count: 1\nLinked commit count: 0\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 2\nLabels: {'security_auth_secret': 1}\nPolarities: {'bad': 1}\nChanged file labels: {'ui_or_frontend': 2}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-ba0c30fd0de674e4\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"security_auth_secret\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.com/unread-llc/meform/pull/1\",\n    \"text\": \"GitHub feedback: security_auth_secret\\nPolarity: bad\\nKind: pull_request_body\\nRepo: unread-llc/meform\\nAuthor: Copilot (Bot)\\nURL: https://github.com/unread-llc/meform/pull/1\\nTitle: [WIP] Update date handling in application\\nBody:\\n## Plan: Add Missing Date Picker Component\\n\\n- [x] Understand the issue - \\\"where is date part\\\" refers to a missing date picker component\\n- [x] Identify that the project has Calendar and Popover components but no DatePicker component\\n- [x] Create a DatePicker component by combining Calendar and Popover\\n- [x] Create DateRangePicker component for date range selection\\n- [x] Add documentation with usage examples\\n- [x] Verify component structure and imports\\n- [ ] Run security checks\\n- [ ] Request code review\\n- [ ] Finalize changes\\n\\n<!-- START COPILOT CODING AGENT SUFFIX -->\\n\\n\\n\\n<!-- START COPILOT ORIGINAL PROMPT -->\\n\\n\\n\\n<details>\\n\\n<summary>Original prompt</summary>\\n\\n> where is date part\\n\\n\\n</details>\\n\\n\\n\\n<!-- START COPILOT CODING AGENT TIPS -->\\n---\\n\\n\ud83d\udca1 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more [Copilot coding agent tips](https://gh.io/copilot-codi\"\n  }\n]\nChanged files:\n[\n  {\n    \"id\": \"github-pr-file-file-4d763666d91c0d4c\",\n    \"filename\": \"components/ui/date-picker.md\",\n    \"label\": \"ui_or_frontend\",\n    \"status\": \"added\",\n    \"additions\": 184,\n    \"deletions\": 0,\n    \"changes\": 184,\n    \"blob_url\": \"https://github.com/unread-llc/meform/blob/ce154216f89d9d6017d06b2d381bd456cfbd06bf/components%2Fui%2Fdate-picker.md\"\n  },\n  {\n    \"id\": \"github-pr-file-file-c7a0b9a69d8d23d1\",\n    \"filename\": \"components/ui/date-picker.tsx\",\n    \"label\": \"ui_or_frontend\",\n    \"status\": \"added\",\n    \"additions\": 135,\n    \"deletions\": 0,\n    \"changes\": 135,\n    \"blob_url\": \"https://github.com/unread-llc/meform/blob/ce154216f89d9d6017d06b\n[truncated by importer]", "source": "foundry_mined_dataset", "repo_url": "https://github.com/unread-llc/meform", "source_id": "comment-chain-pattern-bad_chains-54ad9e71775b7e18", "synthetic": false, "gold_label": "", "graph_label": "source_backed_multi_signal_graph", "source_path": "/data/distillate/foundry_data/comment_chain_patterns/bad_chains/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "unread-llc/meform", "source_dataset": "comment_chain_patterns/bad_chains", "training_usage": "negative_or_unresolved"}}}, {"ruleId": "foundry_auth_guardrail_gap", "level": "error", "message": {"text": "Foundry mined security auth guardrail gaps: unread-llc/meform"}, "properties": {"repobilityId": 335182, "scanner": "foundry_dataset", "fingerprint": "a856e520968c4de3de3f0ca76235059c04fe675621972e9b4765e1cc5850cbf5", "category": "auth", "severity": "critical", "confidence": 0.78, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Security/auth changes without enough guardrails", "intent": "Assumption-check security/auth examples requiring stronger tests or CI.", "labels": {"ui_or_frontend": 2, "security_auth_secret": 1, "issue_or_pull_request_thread": 1, "not_resolved_or_not_observed": 3, "human_reported_issue_no_linked_fix": 1, "thread_has_human_issue_without_fix_context": 2}, "source": "graph_query_export", "motif_id": "security_auth_without_guardrails", "outcomes": {"not_resolved_or_not_observed": 6}, "polarity": "bad", "query_id": "security_auth_guardrail_gaps", "severity": "critical", "ci_labels": {}, "synthetic": false, "edge_count": 17, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "thread_touches_file": 2, "chain_has_link_quality": 3, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 2, "thread_has_comment_chain": 1, "comment_chain_touches_file": 2, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 11, "node_types": {"repo": 1, "thread": 1, "comment": 1, "pr_file": 2, "fix_outcome": 1, "issue_chain": 1, "link_quality": 3, "comment_chain": 1}, "query_type": "motif_query", "thread_key": "unread-llc/meform#1", "issue_number": "1", "quality_tiers": {"unresolved": 3}, "repo_full_name": "unread-llc/meform", "training_usage": "assumption_check", "source_motif_id": "graph-pattern-motif-thread-6b42118f8e05144a", "graph_gold_label": "needs_more_evidence", "changed_file_labels": {"ui_or_frontend": 8}}, "text": "Graph query export: Security/auth changes without enough guardrails\nQuery id: security_auth_guardrail_gaps\nQuery type: motif_query\nIntent: Assumption-check security/auth examples requiring stronger tests or CI.\nMotif: security_auth_without_guardrails\nTraining usage: assumption_check\nGraph gold label: needs_more_evidence\nRepo: unread-llc/meform\nThread: unread-llc/meform#1\nEvidence:\nGraph motif: Security/auth change without enough guardrails\nMotif id: security_auth_without_guardrails\nPolarity: bad\nTraining usage: assumption_check\nSeverity: critical\nRepo: unread-llc/meform\nThread: unread-llc/meform#1\nGraph gold label: needs_more_evidence\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: unread-llc/meform#1\nRepo: unread-llc/meform\nIssue/PR number: 1\nGraph consistency label: needs_more_evidence\nNodes: 11\nEdges: 17\nNode types: {'link_quality': 3, 'pr_file': 2, 'thread': 1, 'repo': 1, 'comment': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'chain_has_link_quality': 3, 'thread_touches_file': 2, 'comment_chain_touches_file': 2, 'issue_chain_touches_file': 2, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'not_resolved_or_not_observed': 3, 'ui_or_frontend': 2, 'thread_has_human_issue_without_fix_context': 2, 'issue_or_pull_request_thread': 1, 'security_auth_secret': 1, 'human_reported_issue_no_linked_fix': 1}\nOutcomes: {'not_resolved_or_not_observed': 6}\nQuality tiers: {'unresolved': 3}\nCI labels: {}\nCurriculum targets:\n- Train auth boundary repair with tests, permission matrices, and secret-handling checks.\n- Keep risky auth changes separate from ordinary bug-fix examples.\nAssumption checks:\n- Are auth/permission paths covered by tests?\n- Are secrets, CORS, or access rules verified rather than summarized?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/unread-llc/meform", "source_id": "graph-query-motif_query-94fbaaeb9dbd9d6e", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/security_auth_guardrail_gaps/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "unread-llc/meform", "source_dataset": "graph_queries/security_auth_guardrail_gaps", "training_usage": "assumption_check"}}}, {"ruleId": "scanner-bead75b0f9233e05", "level": "none", "message": {"text": "No API endpoints detected"}, "properties": {"repobilityId": "0f8bb852027c38f8", "scanner": "scanner-primary", "fingerprint": "bead75b0f9233e05", "layer": "api", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-e1f58b794290ed8e", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 components/mongolia-section.tsx:360"}, "properties": {"repobilityId": "1c7e9a5606978e68", "scanner": "scanner-primary", "fingerprint": "e1f58b794290ed8e", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-ca4c06a9a037ee23", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 components/stats-section.tsx:162"}, "properties": {"repobilityId": "20d1cab8c2979969", "scanner": "scanner-primary", "fingerprint": "ca4c06a9a037ee23", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-95ae0c8512e95479", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 components/ui/chart.tsx:83"}, "properties": {"repobilityId": "dd1e3f2d87b6f488", "scanner": "scanner-primary", "fingerprint": "95ae0c8512e95479", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-685596ac13327136", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 components/registration/phone-input.tsx:69"}, "properties": {"repobilityId": "538a264d92024f43", "scanner": "scanner-primary", "fingerprint": "685596ac13327136", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-8ac5598c69cd4e46", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 app/api/register/verify/route.ts:22"}, "properties": {"repobilityId": "de89d10a8d9e0b1d", "scanner": "scanner-primary", "fingerprint": "8ac5598c69cd4e46", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-32650f989574df5b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 app/api/webhooks/byl/route.ts:21"}, "properties": {"repobilityId": "3be975faba5052e0", "scanner": "scanner-primary", "fingerprint": "32650f989574df5b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8d2f546ffc9129cc", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 app/api/webhooks/golomt/route.ts:17"}, "properties": {"repobilityId": "2487497d62c020c2", "scanner": "scanner-primary", "fingerprint": "8d2f546ffc9129cc", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a823124e73ff38e4", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/byl.ts:75"}, "properties": {"repobilityId": "929494531cbef6cb", "scanner": "scanner-primary", "fingerprint": "a823124e73ff38e4", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c33064638983daba", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/aws/ses.ts:78"}, "properties": {"repobilityId": "59ba186d4b9c634f", "scanner": "scanner-primary", "fingerprint": "c33064638983daba", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-038f95f510f35674", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in components/ui/chart.tsx:83"}, "properties": {"repobilityId": "c41c7626c87bbabe", "scanner": "scanner-primary", "fingerprint": "038f95f510f35674", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "components/ui/chart.tsx"}, "region": {"startLine": 83}}}]}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "20c2ed3a407a3d24", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-01f96f71d9907a8c", "level": "note", "message": {"text": "README lacks setup or run instructions"}, "properties": {"repobilityId": "d4132c0da4363c7f", "scanner": "scanner-primary", "fingerprint": "01f96f71d9907a8c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["docs", "readme", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "b8928a19dca7f79f", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "3d832cd1aa175c10", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "84939aff89f1e4d9", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "warning", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "be60745cbf419d0a", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "46af9e3c85ae0f74", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "f7f1c0bf5d784b36", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-81bb2d58c3f9002d", "level": "none", "message": {"text": "Commented-code block (5 lines) in components/stats-section.tsx:17"}, "properties": {"repobilityId": "50595f10e79bf242", "scanner": "scanner-primary", "fingerprint": "81bb2d58c3f9002d", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-764883111ec84fbf", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 app/[locale]/admin/page.tsx:84"}, "properties": {"repobilityId": "e2b6964640e5127a", "scanner": "scanner-primary", "fingerprint": "764883111ec84fbf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-f1f25285e5009692", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 lib/meforum-videos.ts:92"}, "properties": {"repobilityId": "4b687feb7e5994a0", "scanner": "scanner-primary", "fingerprint": "f1f25285e5009692", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-a0f9779389def562", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 lib/byl.ts:50"}, "properties": {"repobilityId": "9cd719364d1cc856", "scanner": "scanner-primary", "fingerprint": "a0f9779389def562", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-250f57e8a1dbd3c5", "level": "none", "message": {"text": "4 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "57584f22b735b5ee", "scanner": "scanner-primary", "fingerprint": "250f57e8a1dbd3c5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}]}]}