{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-bb88db82654adde0", "name": "Possibly dead Python function: parseProject", "shortDescription": {"text": "Possibly dead Python function: parseProject"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3afc1511e6b67512", "name": "Debug `console.log` remains in browser-facing code \u2014 webgui-new/src/components/cookie-notice/cookie-notice.tsx:61", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 webgui-new/src/components/cookie-notice/cookie-notice.tsx:61"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-9b1131d99055bf0d", "name": "React Flow <Controls> without dark theming \u2014 webgui-new/src/components/codebites/codebites.tsx:52", "shortDescription": {"text": "React Flow <Controls> without dark theming \u2014 webgui-new/src/components/codebites/codebites.tsx:52"}, "fullDescription": {"text": "`<Controls>` ships with white buttons. Override `.react-flow__controls` and `.react-flow__controls-button` in your stylesheet or pass a styled wrapper.\n\nWhy: P1 in CHECKLIST.md \u2014 vendor defaults bleed light through.\nRule id: fq.controls.no-bg"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-365ce81d8f841a34", "name": "TODO/FIXME marker in shipping code \u2014 webgui/scripts/codecompass/view/diagram.js:91", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 webgui/scripts/codecompass/view/diagram.js:91"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-57a70f1f8271fa2d", "name": "TODO/FIXME marker in shipping code \u2014 webgui/scripts/codecompass/view/fileManager.js:123", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 webgui/scripts/codecompass/view/fileManager.js:123"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-eab91328fa772651", "name": "TODO/FIXME marker in shipping code \u2014 webgui/scripts/codecompass/view/component/IconTextBox.js:24", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 webgui/scripts/codecompass/view/component/IconTextBox.js:24"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-79b3576a77ca89e0", "name": "TODO/FIXME marker in shipping code \u2014 webgui/scripts/codecompass/view/component/Text.js:294", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 webgui/scripts/codecompass/view/component/Text.js:294"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-577a6965e40b359d", "name": "TODO/FIXME marker in shipping code \u2014 webgui/scripts/codecompass/view/component/Pager.js:160", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 webgui/scripts/codecompass/view/component/Pager.js:160"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-f2ba29f414f4c6fa", "name": "TODO/FIXME marker in shipping code \u2014 plugins/cpp_reparse/webgui/js/cppReparseFileAST.js:29", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 plugins/cpp_reparse/webgui/js/cppReparseFileAST.js:29"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-198072b3b0d1970d", "name": "TODO/FIXME marker in shipping code \u2014 plugins/git/webgui/js/gitNavigator.js:349", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 plugins/git/webgui/js/gitNavigator.js:349"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-ce9ddb8afcf21704", "name": "Debug `console.log` remains in browser-facing code \u2014 plugins/git/webgui/js/gitNavigator.js:175", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 plugins/git/webgui/js/gitNavigator.js:175"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-38ab8870595cba37", "name": "insecure use strcat fn \u2014 logger/src/ldlogger-logger.c:145", "shortDescription": {"text": "insecure use strcat fn \u2014 logger/src/ldlogger-logger.c:145"}, "fullDescription": {"text": "Finding triggers whenever there is a strcat or strncat used. This is an issue because strcat or strncat can lead to buffer overflow vulns. Fix this by using strcat_s instead.\n\nRule: c.lang.security.insecure-use-strcat-fn.insecure-use-strcat-fn\nSeverity: WARNING\nOWASP: \u2014\nCWE: CWE-676: Use of Potentially Dangerous Function\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-107cb58109ccd895", "name": "insecure use string copy fn \u2014 logger/src/ldlogger-tool-gcc.c:67", "shortDescription": {"text": "insecure use string copy fn \u2014 logger/src/ldlogger-tool-gcc.c:67"}, "fullDescription": {"text": "Finding triggers whenever there is a strcpy or strncpy used. This is an issue because strcpy does not affirm the size of the destination array and strncpy will not automatically NULL-terminate strings. This can lead to buffer overflows, which can cause program crashes and potentially let an attacker inject code in the program. Fix this by using strcpy_s instead (although note that strcpy_s is an optional part of the C11 standard, and so may not be available).\n\nRule: c.lang.security.insecure-use-string-copy-fn.insecure-use-string-copy-fn\nSeverity: WARNING\nOWASP: \u2014\nCWE: CWE-676: Use of Potentially Dangerous Function\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-a2910f4ac755f8df", "name": "insecure use strcat fn \u2014 logger/src/ldlogger-tool-gcc.c:90", "shortDescription": {"text": "insecure use strcat fn \u2014 logger/src/ldlogger-tool-gcc.c:90"}, "fullDescription": {"text": "Finding triggers whenever there is a strcat or strncat used. This is an issue because strcat or strncat can lead to buffer overflow vulns. Fix this by using strcat_s instead.\n\nRule: c.lang.security.insecure-use-strcat-fn.insecure-use-strcat-fn\nSeverity: WARNING\nOWASP: \u2014\nCWE: CWE-676: Use of Potentially Dangerous Function\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-3ea2c41706c12df1", "name": "insecure use string copy fn \u2014 logger/src/ldlogger-tool-javac.c:116", "shortDescription": {"text": "insecure use string copy fn \u2014 logger/src/ldlogger-tool-javac.c:116"}, "fullDescription": {"text": "Finding triggers whenever there is a strcpy or strncpy used. This is an issue because strcpy does not affirm the size of the destination array and strncpy will not automatically NULL-terminate strings. This can lead to buffer overflows, which can cause program crashes and potentially let an attacker inject code in the program. Fix this by using strcpy_s instead (although note that strcpy_s is an optional part of the C11 standard, and so may not be available).\n\nRule: c.lang.security.insecure-use-string-copy-fn.insecure-use-string-copy-fn\nSeverity: WARNING\nOWASP: \u2014\nCWE: CWE-676: Use of Potentially Dangerous Function\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-63098e16cf700257", "name": "insecure use strtok fn \u2014 logger/src/ldlogger-tool-javac.c:118", "shortDescription": {"text": "insecure use strtok fn \u2014 logger/src/ldlogger-tool-javac.c:118"}, "fullDescription": {"text": "Avoid using 'strtok()'. This function directly modifies the first argument buffer, permanently erasing the delimiter character. Use 'strtok_r()' instead.\n\nRule: c.lang.security.insecure-use-strtok-fn.insecure-use-strtok-fn\nSeverity: WARNING\nOWASP: \u2014\nCWE: CWE-676: Use of Potentially Dangerous Function\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-0f1d412c4640da2f", "name": "insecure use strcat fn \u2014 logger/src/ldlogger-tool-javac.c:160", "shortDescription": {"text": "insecure use strcat fn \u2014 logger/src/ldlogger-tool-javac.c:160"}, "fullDescription": {"text": "Finding triggers whenever there is a strcat or strncat used. This is an issue because strcat or strncat can lead to buffer overflow vulns. Fix this by using strcat_s instead.\n\nRule: c.lang.security.insecure-use-strcat-fn.insecure-use-strcat-fn\nSeverity: WARNING\nOWASP: \u2014\nCWE: CWE-676: Use of Potentially Dangerous Function\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-3d8bd07015edb892", "name": "insecure use strtok fn \u2014 logger/src/ldlogger-tool.c:39", "shortDescription": {"text": "insecure use strtok fn \u2014 logger/src/ldlogger-tool.c:39"}, "fullDescription": {"text": "Avoid using 'strtok()'. This function directly modifies the first argument buffer, permanently erasing the delimiter character. Use 'strtok_r()' instead.\n\nRule: c.lang.security.insecure-use-strtok-fn.insecure-use-strtok-fn\nSeverity: WARNING\nOWASP: \u2014\nCWE: CWE-676: Use of Potentially Dangerous Function\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-33b8a9f60de0e1ad", "name": "insecure use string copy fn \u2014 logger/src/ldlogger-tool.c:78", "shortDescription": {"text": "insecure use string copy fn \u2014 logger/src/ldlogger-tool.c:78"}, "fullDescription": {"text": "Finding triggers whenever there is a strcpy or strncpy used. This is an issue because strcpy does not affirm the size of the destination array and strncpy will not automatically NULL-terminate strings. This can lead to buffer overflows, which can cause program crashes and potentially let an attacker inject code in the program. Fix this by using strcpy_s instead (although note that strcpy_s is an optional part of the C11 standard, and so may not be available).\n\nRule: c.lang.security.insecure-use-string-copy-fn.insecure-use-string-copy-fn\nSeverity: WARNING\nOWASP: \u2014\nCWE: CWE-676: Use of Potentially Dangerous Function\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-72824774c85ea2b1", "name": "insecure use string copy fn \u2014 logger/src/ldlogger-util.c:20", "shortDescription": {"text": "insecure use string copy fn \u2014 logger/src/ldlogger-util.c:20"}, "fullDescription": {"text": "Finding triggers whenever there is a strcpy or strncpy used. This is an issue because strcpy does not affirm the size of the destination array and strncpy will not automatically NULL-terminate strings. This can lead to buffer overflows, which can cause program crashes and potentially let an attacker inject code in the program. Fix this by using strcpy_s instead (although note that strcpy_s is an optional part of the C11 standard, and so may not be available).\n\nRule: c.lang.security.insecure-use-string-copy-fn.insecure-use-string-copy-fn\nSeverity: WARNING\nOWASP: \u2014\nCWE: CWE-676: Use of Potentially Dangerous Function\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-fcd964c62927e2aa", "name": "insecure use strcat fn \u2014 logger/src/ldlogger-util.c:44", "shortDescription": {"text": "insecure use strcat fn \u2014 logger/src/ldlogger-util.c:44"}, "fullDescription": {"text": "Finding triggers whenever there is a strcat or strncat used. This is an issue because strcat or strncat can lead to buffer overflow vulns. Fix this by using strcat_s instead.\n\nRule: c.lang.security.insecure-use-strcat-fn.insecure-use-strcat-fn\nSeverity: WARNING\nOWASP: \u2014\nCWE: CWE-676: Use of Potentially Dangerous Function\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-79ce5b3e24ed11d7", "name": "insecure hash algorithm sha1 \u2014 plugins/python/parser/pyparser/parserutil.py:6", "shortDescription": {"text": "insecure hash algorithm sha1 \u2014 plugins/python/parser/pyparser/parserutil.py:6"}, "fullDescription": {"text": "Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead.\n\nRule: python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1\nSeverity: WARNING\nOWASP: A03:2017 - Sensitive Data Exposure, A02:2021 - Cryptographic Failures, A04:2025 - Cryptographic Failures\nCWE: CWE-327: Use of a Broken or Risky Cryptographic Algorithm\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.75}}, {"id": "scanner-3e5318cabb93de27", "name": "object deserialization \u2014 plugins/search/common/src/cc/search/analysis/tags/Tags.java:171", "shortDescription": {"text": "object deserialization \u2014 plugins/search/common/src/cc/search/analysis/tags/Tags.java:171"}, "fullDescription": {"text": "Found object deserialization using ObjectInputStream. Deserializing entire Java objects is dangerous because malicious actors can create Java object streams with unintended consequences. Ensure that the objects being deserialized are not user-controlled. If this must be done, consider using HMACs to sign the data stream to make sure it is not tampered with, or consider only transmitting object fields and populating a new object.\n\nRule: java.lang.security.audit.object-deserialization.object-deserialization\nSeverity: WARNING\nOWASP: A08:2017 - Insecure Deserialization, A08:2021 - Software and Data Integrity Failures, A08:2025 - Software or Data Integrity Failures\nCWE: CWE-502: Deserialization of Untrusted Data\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-b89489c3b1c531bc", "name": "Dockerfile runs as root: docker/web/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: docker/web/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bead1b9c2a330c18", "name": "Docker base image is tag-pinned but not digest-pinned: codecompass:runtime", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: codecompass:runtime"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-819070b5ea6acf4f", "name": "Docker base image is tag-pinned but not digest-pinned: ubuntu:22.04", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: ubuntu:22.04"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-88bb91f0c6fcbd94", "name": "Dockerfile runs as root: docker/runtime/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: docker/runtime/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-988d3b92d0e853b6", "name": "Docker base image is tag-pinned but not digest-pinned: codecompass:dev", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: codecompass:dev"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c64e34669fa5354c", "name": "Docker base image is tag-pinned but not digest-pinned: ubuntu:22.04", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: ubuntu:22.04"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8d53c8cd353752e7", "name": "Dockerfile runs as root: docker/dev/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: docker/dev/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f67a86995ad02e9c", "name": "Docker base image is tag-pinned but not digest-pinned: ubuntu:22.04", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: ubuntu:22.04"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa92ece5df982af9", "name": "Runtime dotenv file present in repo: webgui-new/.env", "shortDescription": {"text": "Runtime dotenv file present in repo: webgui-new/.env"}, "fullDescription": {"text": "`webgui-new/.env` looks like a runtime dotenv file. No high-confidence secret value was matched, but runtime dotenv files often drift into live credentials. Move real values to a secret manager and keep only `.env.example` style templates in source control."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-04afbf9d8cc5dc75", "name": "Insecure pattern 'domparser_html_parse' in webgui-new/src/components/editor-context-menu/editor-context-menu.tsx:79", "shortDescription": {"text": "Insecure pattern 'domparser_html_parse' in webgui-new/src/components/editor-context-menu/editor-context-menu.tsx:79"}, "fullDescription": {"text": "Found a known-risky pattern (domparser_html_parse). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-566dc23bc09fac81", "name": "Insecure pattern 'direct_innerhtml_assignment' in webgui-new/src/components/codebites/codebites-node.tsx:91", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in webgui-new/src/components/codebites/codebites-node.tsx:91"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-137c8c8d5afaf3a2", "name": "Insecure pattern 'eval_used' in webgui/scripts/thrift.js:1096", "shortDescription": {"text": "Insecure pattern 'eval_used' in webgui/scripts/thrift.js:1096"}, "fullDescription": {"text": "Found a known-risky pattern (eval_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a977808cf9b11de3", "name": "Insecure pattern 'direct_innerhtml_assignment' in webgui/scripts/codecompass/view/diagram.js:286", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in webgui/scripts/codecompass/view/diagram.js:286"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-ea4d1047914cc7df", "name": "Insecure pattern 'direct_innerhtml_assignment' in webgui/scripts/codecompass/view/fileManager.js:275", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in webgui/scripts/codecompass/view/fileManager.js:275"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-65aa740cba4a4a73", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7f0f9976570faa6d", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e04eab3aa1f521d4", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-65a716a27d2be993", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-27924aa79fa4a517", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/cache/restore@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f7df1b8b94937a8f", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "3 test file(s) for 124 source file(s) (ratio 0.02). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a84a1d05ba37f95f", "name": "Node manifest has dependencies but no lockfile: webgui/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: webgui/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 10 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 36 placeholder/mock markers across 15 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-28a4da2394a6b670", "name": "Vulnerable dependency http-proxy-middleware 3.0.5: GHSA-64mm-vxmg-q3vj", "shortDescription": {"text": "Vulnerable dependency http-proxy-middleware 3.0.5: GHSA-64mm-vxmg-q3vj"}, "fullDescription": {"text": "OSV.dev reports `http-proxy-middleware` at version `3.0.5` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-64mm-vxmg-q3vj (aka CVE-2026-55602).\n\nhttp-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass\n\nAliases: CVE-2026-55602\nAdvisory: https://osv.dev/vulnerability/GHSA-64mm-vxmg-q3vj\nFix: upgrade `http-proxy-middleware` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-ed8e4ff40519cc71", "name": "Vulnerable dependency http-proxy-middleware 3.0.5: GHSA-gcq2-9pq2-cxqm", "shortDescription": {"text": "Vulnerable dependency http-proxy-middleware 3.0.5: GHSA-gcq2-9pq2-cxqm"}, "fullDescription": {"text": "OSV.dev reports `http-proxy-middleware` at version `3.0.5` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-gcq2-9pq2-cxqm.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-gcq2-9pq2-cxqm\nFix: upgrade `http-proxy-middleware` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-b63ea4bf7e9ab37e", "name": "Vulnerable dependency next 14.2.35: GHSA-36qx-fr4f-26g5", "shortDescription": {"text": "Vulnerable dependency next 14.2.35: GHSA-36qx-fr4f-26g5"}, "fullDescription": {"text": "OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-36qx-fr4f-26g5 (aka CVE-2026-44573).\n\nNext.js has a Middleware / Proxy bypass in Pages Router applications using i18n\n\nAliases: CVE-2026-44573\nAdvisory: https://osv.dev/vulnerability/GHSA-36qx-fr4f-26g5\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b241936b566cdb7e", "name": "Vulnerable dependency next 14.2.35: GHSA-3g8h-86w9-wvmq", "shortDescription": {"text": "Vulnerable dependency next 14.2.35: GHSA-3g8h-86w9-wvmq"}, "fullDescription": {"text": "OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-3g8h-86w9-wvmq (aka CVE-2026-44572).\n\nNext.js's Middleware / Proxy redirects can be cache-poisoned\n\nAliases: CVE-2026-44572\nAdvisory: https://osv.dev/vulnerability/GHSA-3g8h-86w9-wvmq\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4eb9e045a62dd69a", "name": "Vulnerable dependency next 14.2.35: GHSA-3x4c-7xq6-9pq8", "shortDescription": {"text": "Vulnerable dependency next 14.2.35: GHSA-3x4c-7xq6-9pq8"}, "fullDescription": {"text": "OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-3x4c-7xq6-9pq8 (aka CVE-2026-27980).\n\nNext.js: Unbounded next/image disk cache growth can exhaust storage\n\nAliases: CVE-2026-27980\nAdvisory: https://osv.dev/vulnerability/GHSA-3x4c-7xq6-9pq8\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a8ac5c3b713855b4", "name": "Vulnerable dependency next 14.2.35: GHSA-4633-3j49-mh5q", "shortDescription": {"text": "Vulnerable dependency next 14.2.35: GHSA-4633-3j49-mh5q"}, "fullDescription": {"text": "OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-4633-3j49-mh5q (aka CVE-2026-64647).\n\nNext.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\nAliases: CVE-2026-64647\nAdvisory: https://osv.dev/vulnerability/GHSA-4633-3j49-mh5q\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f152102264526b73", "name": "Vulnerable dependency next 14.2.35: GHSA-4c39-4ccg-62r3", "shortDescription": {"text": "Vulnerable dependency next 14.2.35: GHSA-4c39-4ccg-62r3"}, "fullDescription": {"text": "OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-4c39-4ccg-62r3 (aka CVE-2026-64646).\n\nNext.js: Unbounded Server Action payload in Edge runtime\n\nAliases: CVE-2026-64646\nAdvisory: https://osv.dev/vulnerability/GHSA-4c39-4ccg-62r3\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5d988bd28bb331bb", "name": "Vulnerable dependency next 14.2.35: GHSA-68g3-v927-f742", "shortDescription": {"text": "Vulnerable dependency next 14.2.35: GHSA-68g3-v927-f742"}, "fullDescription": {"text": "OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-68g3-v927-f742 (aka CVE-2026-64648).\n\nNext.js: Cache confusion of response bodies for requests with bodies\n\nAliases: CVE-2026-64648\nAdvisory: https://osv.dev/vulnerability/GHSA-68g3-v927-f742\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-43d8aae5f3b1b72f", "name": "Vulnerable dependency next 14.2.35: GHSA-89xv-2m56-2m9x", "shortDescription": {"text": "Vulnerable dependency next 14.2.35: GHSA-89xv-2m56-2m9x"}, "fullDescription": {"text": "OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-89xv-2m56-2m9x (aka CVE-2026-64649).\n\nNext.js: Server-Side Request Forgery in Server Actions on custom servers\n\nAliases: CVE-2026-64649\nAdvisory: https://osv.dev/vulnerability/GHSA-89xv-2m56-2m9x\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fd01dbd6b2ebf57a", "name": "Vulnerable dependency next 14.2.35: GHSA-8h8q-6873-q5fj", "shortDescription": {"text": "Vulnerable dependency next 14.2.35: GHSA-8h8q-6873-q5fj"}, "fullDescription": {"text": "OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-8h8q-6873-q5fj.\n\nNext.js Vulnerable to Denial of Service with Server Components\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8h8q-6873-q5fj\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4a2acafa1ed3acaf", "name": "Vulnerable dependency next 14.2.35: GHSA-955p-x3mx-jcvp", "shortDescription": {"text": "Vulnerable dependency next 14.2.35: GHSA-955p-x3mx-jcvp"}, "fullDescription": {"text": "OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-955p-x3mx-jcvp (aka CVE-2026-64643).\n\nNext.js: Unauthenticated disclosure of internal Server Function endpoints\n\nAliases: CVE-2026-64643\nAdvisory: https://osv.dev/vulnerability/GHSA-955p-x3mx-jcvp\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3395b8c67f3bf84d", "name": "Vulnerable dependency next 14.2.35: GHSA-9g9p-9gw9-jx7f", "shortDescription": {"text": "Vulnerable dependency next 14.2.35: GHSA-9g9p-9gw9-jx7f"}, "fullDescription": {"text": "OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-9g9p-9gw9-jx7f.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9g9p-9gw9-jx7f\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f6795799c5e41b80", "name": "Vulnerable dependency next 14.2.35: GHSA-c4j6-fc7j-m34r", "shortDescription": {"text": "Vulnerable dependency next 14.2.35: GHSA-c4j6-fc7j-m34r"}, "fullDescription": {"text": "OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-c4j6-fc7j-m34r (aka CVE-2026-44578).\n\nNext.js vulnerable to server-side request forgery in applications using WebSocket upgrades\n\nAliases: CVE-2026-44578\nAdvisory: https://osv.dev/vulnerability/GHSA-c4j6-fc7j-m34r\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c0554992b62c8042", "name": "Vulnerable dependency next 14.2.35: GHSA-ffhc-5mcf-pf4q", "shortDescription": {"text": "Vulnerable dependency next 14.2.35: GHSA-ffhc-5mcf-pf4q"}, "fullDescription": {"text": "OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-ffhc-5mcf-pf4q (aka CVE-2026-44581).\n\nNext.js vulnerable to cross-site scripting in App Router applications using CSP nonces\n\nAliases: CVE-2026-44581\nAdvisory: https://osv.dev/vulnerability/GHSA-ffhc-5mcf-pf4q\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-88c2ccd1181784f2", "name": "Vulnerable dependency next 14.2.35: GHSA-ggv3-7p47-pfv8", "shortDescription": {"text": "Vulnerable dependency next 14.2.35: GHSA-ggv3-7p47-pfv8"}, "fullDescription": {"text": "OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-ggv3-7p47-pfv8 (aka CVE-2026-29057).\n\nNext.js: HTTP request smuggling in rewrites\n\nAliases: CVE-2026-29057\nAdvisory: https://osv.dev/vulnerability/GHSA-ggv3-7p47-pfv8\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-665af5fa4a61639a", "name": "Vulnerable dependency next 14.2.35: GHSA-gx5p-jg67-6x7h", "shortDescription": {"text": "Vulnerable dependency next 14.2.35: GHSA-gx5p-jg67-6x7h"}, "fullDescription": {"text": "OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-gx5p-jg67-6x7h (aka CVE-2026-44580).\n\nNext.js has cross-site scripting in beforeInteractive scripts with untrusted input\n\nAliases: CVE-2026-44580\nAdvisory: https://osv.dev/vulnerability/GHSA-gx5p-jg67-6x7h\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a38b2402cff17da9", "name": "Vulnerable dependency next 14.2.35: GHSA-h25m-26qc-wcjf", "shortDescription": {"text": "Vulnerable dependency next 14.2.35: GHSA-h25m-26qc-wcjf"}, "fullDescription": {"text": "OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-h25m-26qc-wcjf.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-h25m-26qc-wcjf\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fb4bcd9b80467636", "name": "Vulnerable dependency next 14.2.35: GHSA-h64f-5h5j-jqjh", "shortDescription": {"text": "Vulnerable dependency next 14.2.35: GHSA-h64f-5h5j-jqjh"}, "fullDescription": {"text": "OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-h64f-5h5j-jqjh (aka CVE-2026-44577).\n\nNext.js has a Denial of Service in the Image Optimization API\n\nAliases: CVE-2026-44577\nAdvisory: https://osv.dev/vulnerability/GHSA-h64f-5h5j-jqjh\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-913b94b8a285f9bf", "name": "Vulnerable dependency next 14.2.35: GHSA-m99w-x7hq-7vfj", "shortDescription": {"text": "Vulnerable dependency next 14.2.35: GHSA-m99w-x7hq-7vfj"}, "fullDescription": {"text": "OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-m99w-x7hq-7vfj (aka CVE-2026-64641).\n\nNext.js: Denial of Service in App Router using Server Actions\n\nAliases: CVE-2026-64641\nAdvisory: https://osv.dev/vulnerability/GHSA-m99w-x7hq-7vfj\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ffa69eff77cf76b5", "name": "Vulnerable dependency next 14.2.35: GHSA-p9j2-gv94-2wf4", "shortDescription": {"text": "Vulnerable dependency next 14.2.35: GHSA-p9j2-gv94-2wf4"}, "fullDescription": {"text": "OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-p9j2-gv94-2wf4 (aka CVE-2026-64645).\n\nNext.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname\n\nAliases: CVE-2026-64645\nAdvisory: https://osv.dev/vulnerability/GHSA-p9j2-gv94-2wf4\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4aa6b13458954ca4", "name": "Vulnerable dependency next 14.2.35: GHSA-q4gf-8mx6-v5v3", "shortDescription": {"text": "Vulnerable dependency next 14.2.35: GHSA-q4gf-8mx6-v5v3"}, "fullDescription": {"text": "OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-q4gf-8mx6-v5v3.\n\nNext.js has a Denial of Service with Server Components\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q4gf-8mx6-v5v3\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2f02be4b6c8ddbeb", "name": "Vulnerable dependency next 14.2.35: GHSA-vfv6-92ff-j949", "shortDescription": {"text": "Vulnerable dependency next 14.2.35: GHSA-vfv6-92ff-j949"}, "fullDescription": {"text": "OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-vfv6-92ff-j949 (aka CVE-2026-44582).\n\nNext.js vulnerable to cache poisoning via collisions in React Server Component cache-busting\n\nAliases: CVE-2026-44582\nAdvisory: https://osv.dev/vulnerability/GHSA-vfv6-92ff-j949\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d66153d36a645f11", "name": "Vulnerable dependency next 14.2.35: GHSA-wfc6-r584-vfw7", "shortDescription": {"text": "Vulnerable dependency next 14.2.35: GHSA-wfc6-r584-vfw7"}, "fullDescription": {"text": "OSV.dev reports `next` at version `14.2.35` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-wfc6-r584-vfw7 (aka CVE-2026-44576).\n\nNext.js vulnerable to cache poisoning in React Server Component responses\n\nAliases: CVE-2026-44576\nAdvisory: https://osv.dev/vulnerability/GHSA-wfc6-r584-vfw7\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-15bb7c211d3ec736", "name": "Vulnerable dependency sharp 0.32.6: GHSA-f88m-g3jw-g9cj", "shortDescription": {"text": "Vulnerable dependency sharp 0.32.6: GHSA-f88m-g3jw-g9cj"}, "fullDescription": {"text": "OSV.dev reports `sharp` at version `0.32.6` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-f88m-g3jw-g9cj.\n\nsharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591\n\nAdvisory: https://osv.dev/vulnerability/GHSA-f88m-g3jw-g9cj\nFix: upgrade `sharp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-daec965a1bd76cca", "name": "Vulnerable dependency thrift 0.16.0: GHSA-526f-jxpj-jmg2", "shortDescription": {"text": "Vulnerable dependency thrift 0.16.0: GHSA-526f-jxpj-jmg2"}, "fullDescription": {"text": "OSV.dev reports `thrift` at version `0.16.0` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-526f-jxpj-jmg2 (aka CVE-2026-43870).\n\nApache Thrift vulnerable to Path Traversal, HTTP Request/Response Splitting, Uncontrolled Resource Consumption\n\nAliases: BIT-thrift-2026-43870, CVE-2026-43870\nAdvisory: https://osv.dev/vulnerability/GHSA-526f-jxpj-jmg2\nFix: upgrade `thrift` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9ec427dab9937b51", "name": "Vulnerable dependency thrift 0.16.0: GHSA-r67j-r569-jrwp", "shortDescription": {"text": "Vulnerable dependency thrift 0.16.0: GHSA-r67j-r569-jrwp"}, "fullDescription": {"text": "OSV.dev reports `thrift` at version `0.16.0` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-r67j-r569-jrwp.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r67j-r569-jrwp\nFix: upgrade `thrift` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-16e1578151da83a6", "name": "Vulnerable dependency dojo 1.11.2: GHSA-536q-8gxx-m782", "shortDescription": {"text": "Vulnerable dependency dojo 1.11.2: GHSA-536q-8gxx-m782"}, "fullDescription": {"text": "OSV.dev reports `dojo` at version `1.11.2` (declared in `webgui/package.json`) is affected by GHSA-536q-8gxx-m782 (aka CVE-2010-2273).\nNote: `1.11.2` is the declared floor of a range \u2014 the installed version may be newer.\n\nCross-Site Scripting in dojo\n\nAliases: CVE-2010-2273\nAdvisory: https://osv.dev/vulnerability/GHSA-536q-8gxx-m782\nFix: upgrade `dojo` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-cb5010e5eef35986", "name": "Vulnerable dependency dojo 1.11.2: GHSA-jxfh-8wgv-vfr2", "shortDescription": {"text": "Vulnerable dependency dojo 1.11.2: GHSA-jxfh-8wgv-vfr2"}, "fullDescription": {"text": "OSV.dev reports `dojo` at version `1.11.2` (declared in `webgui/package.json`) is affected by GHSA-jxfh-8wgv-vfr2.\nNote: `1.11.2` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jxfh-8wgv-vfr2\nFix: upgrade `dojo` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-33dd0d5e97bbc602", "name": "Vulnerable dependency dojo 1.11.2: GHSA-m8gw-hjpr-rjv7", "shortDescription": {"text": "Vulnerable dependency dojo 1.11.2: GHSA-m8gw-hjpr-rjv7"}, "fullDescription": {"text": "OSV.dev reports `dojo` at version `1.11.2` (declared in `webgui/package.json`) is affected by GHSA-m8gw-hjpr-rjv7.\nNote: `1.11.2` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-m8gw-hjpr-rjv7\nFix: upgrade `dojo` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-4b622e0f3121e28f", "name": "Vulnerable dependency dijit 1.11.2: GHSA-cxjc-r2fp-7mq6", "shortDescription": {"text": "Vulnerable dependency dijit 1.11.2: GHSA-cxjc-r2fp-7mq6"}, "fullDescription": {"text": "OSV.dev reports `dijit` at version `1.11.2` (declared in `webgui/package.json`) is affected by GHSA-cxjc-r2fp-7mq6.\nNote: `1.11.2` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-cxjc-r2fp-7mq6\nFix: upgrade `dijit` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-ba83d16d8a5ef246", "name": "Vulnerable dependency dijit 1.11.2: GHSA-wp32-wq34-2rqh", "shortDescription": {"text": "Vulnerable dependency dijit 1.11.2: GHSA-wp32-wq34-2rqh"}, "fullDescription": {"text": "OSV.dev reports `dijit` at version `1.11.2` (declared in `webgui/package.json`) is affected by GHSA-wp32-wq34-2rqh.\nNote: `1.11.2` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wp32-wq34-2rqh\nFix: upgrade `dijit` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-71ed30f793244798", "name": "Vulnerable dependency dojox 1.11.2: GHSA-3hw5-q855-g6cw", "shortDescription": {"text": "Vulnerable dependency dojox 1.11.2: GHSA-3hw5-q855-g6cw"}, "fullDescription": {"text": "OSV.dev reports `dojox` at version `1.11.2` (declared in `webgui/package.json`) is affected by GHSA-3hw5-q855-g6cw (aka CVE-2020-5259).\nNote: `1.11.2` is the declared floor of a range \u2014 the installed version may be newer.\n\nPrototype Pollution in Dojox\n\nAliases: CVE-2020-5259\nAdvisory: https://osv.dev/vulnerability/GHSA-3hw5-q855-g6cw\nFix: upgrade `dojox` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.7}}, {"id": "scanner-f73573556ede5559", "name": "Vulnerable dependency dojox 1.11.2: GHSA-84cm-x2q5-8225", "shortDescription": {"text": "Vulnerable dependency dojox 1.11.2: GHSA-84cm-x2q5-8225"}, "fullDescription": {"text": "OSV.dev reports `dojox` at version `1.11.2` (declared in `webgui/package.json`) is affected by GHSA-84cm-x2q5-8225.\nNote: `1.11.2` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-84cm-x2q5-8225\nFix: upgrade `dojox` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-1e4e4f07a48bdb34", "name": "Vulnerable dependency dojox 1.11.2: GHSA-pg97-ww7h-5mjr", "shortDescription": {"text": "Vulnerable dependency dojox 1.11.2: GHSA-pg97-ww7h-5mjr"}, "fullDescription": {"text": "OSV.dev reports `dojox` at version `1.11.2` (declared in `webgui/package.json`) is affected by GHSA-pg97-ww7h-5mjr.\nNote: `1.11.2` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pg97-ww7h-5mjr\nFix: upgrade `dojox` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-a750ba2f5524cdde", "name": "Vulnerable dependency codemirror 5.19.0: GHSA-4gw3-8f77-f72c", "shortDescription": {"text": "Vulnerable dependency codemirror 5.19.0: GHSA-4gw3-8f77-f72c"}, "fullDescription": {"text": "OSV.dev reports `codemirror` at version `5.19.0` (declared in `webgui/package.json`) is affected by GHSA-4gw3-8f77-f72c (aka CVE-2020-7760).\nNote: `5.19.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nRegular expression denial of service in codemirror\n\nAliases: CVE-2020-7760\nAdvisory: https://osv.dev/vulnerability/GHSA-4gw3-8f77-f72c\nFix: upgrade `codemirror` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-6f990f9c3cefe9f1", "name": "Vulnerable dependency jquery 3.1.1: GHSA-6c3j-c64m-qhgq", "shortDescription": {"text": "Vulnerable dependency jquery 3.1.1: GHSA-6c3j-c64m-qhgq"}, "fullDescription": {"text": "OSV.dev reports `jquery` at version `3.1.1` (declared in `webgui/package.json`) is affected by GHSA-6c3j-c64m-qhgq.\nNote: `3.1.1` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6c3j-c64m-qhgq\nFix: upgrade `jquery` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-2fd0b5271a2161e7", "name": "Vulnerable dependency jquery 3.1.1: GHSA-gxr4-xjj5-5px2", "shortDescription": {"text": "Vulnerable dependency jquery 3.1.1: GHSA-gxr4-xjj5-5px2"}, "fullDescription": {"text": "OSV.dev reports `jquery` at version `3.1.1` (declared in `webgui/package.json`) is affected by GHSA-gxr4-xjj5-5px2.\nNote: `3.1.1` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-gxr4-xjj5-5px2\nFix: upgrade `jquery` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-3c30b52bd6042ad0", "name": "Vulnerable dependency jquery 3.1.1: GHSA-jpcq-cgw6-v4j6", "shortDescription": {"text": "Vulnerable dependency jquery 3.1.1: GHSA-jpcq-cgw6-v4j6"}, "fullDescription": {"text": "OSV.dev reports `jquery` at version `3.1.1` (declared in `webgui/package.json`) is affected by GHSA-jpcq-cgw6-v4j6.\nNote: `3.1.1` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jpcq-cgw6-v4j6\nFix: upgrade `jquery` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-448c444a42ac1308", "name": "Vulnerable dependency js-cookie 2.2.1: GHSA-qjx8-664m-686j", "shortDescription": {"text": "Vulnerable dependency js-cookie 2.2.1: GHSA-qjx8-664m-686j"}, "fullDescription": {"text": "OSV.dev reports `js-cookie` at version `2.2.1` (declared in `webgui/package.json`) is affected by GHSA-qjx8-664m-686j.\nNote: `2.2.1` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-qjx8-664m-686j\nFix: upgrade `js-cookie` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-a1864da73f42cea2", "name": "Vulnerable dependency ajv 6.12.6: GHSA-2g4f-4pwh-qvx6", "shortDescription": {"text": "Vulnerable dependency ajv 6.12.6: GHSA-2g4f-4pwh-qvx6"}, "fullDescription": {"text": "OSV.dev reports `ajv` at version `6.12.6` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-2g4f-4pwh-qvx6 (aka CVE-2025-69873).\nNote: `ajv` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\najv has ReDoS when using `$data` option\n\nAliases: CVE-2025-69873\nAdvisory: https://osv.dev/vulnerability/GHSA-2g4f-4pwh-qvx6\nFix: upgrade `ajv` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-eb96c84569c926ad", "name": "Vulnerable dependency body-parser 1.20.3: GHSA-v422-hmwv-36x6", "shortDescription": {"text": "Vulnerable dependency body-parser 1.20.3: GHSA-v422-hmwv-36x6"}, "fullDescription": {"text": "OSV.dev reports `body-parser` at version `1.20.3` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-v422-hmwv-36x6 (aka CVE-2026-12590).\nNote: `body-parser` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbody-parser vulnerable to denial of service when invalid limit value silently disables size enforcement\n\nAliases: CVE-2026-12590\nAdvisory: https://osv.dev/vulnerability/GHSA-v422-hmwv-36x6\nFix: upgrade `body-parser` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-ce25ea0359474940", "name": "Vulnerable dependency brace-expansion 1.1.12: GHSA-3jxr-9vmj-r5cp", "shortDescription": {"text": "Vulnerable dependency brace-expansion 1.1.12: GHSA-3jxr-9vmj-r5cp"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `1.1.12` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-3jxr-9vmj-r5cp (aka CVE-2026-13149).\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbrace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups\n\nAliases: CVE-2026-13149\nAdvisory: https://osv.dev/vulnerability/GHSA-3jxr-9vmj-r5cp\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-20cefe2b2f05f230", "name": "Vulnerable dependency brace-expansion 1.1.12: GHSA-f886-m6hf-6m8v", "shortDescription": {"text": "Vulnerable dependency brace-expansion 1.1.12: GHSA-f886-m6hf-6m8v"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `1.1.12` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-f886-m6hf-6m8v (aka CVE-2026-33750).\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbrace-expansion: Zero-step sequence causes process hang and memory exhaustion\n\nAliases: CVE-2026-33750\nAdvisory: https://osv.dev/vulnerability/GHSA-f886-m6hf-6m8v\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-c3c27ce3d333950a", "name": "Vulnerable dependency brace-expansion 1.1.12: GHSA-mh99-v99m-4gvg", "shortDescription": {"text": "Vulnerable dependency brace-expansion 1.1.12: GHSA-mh99-v99m-4gvg"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `1.1.12` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-mh99-v99m-4gvg (aka CVE-2026-14257).\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbrace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash\n\nAliases: CVE-2026-14257\nAdvisory: https://osv.dev/vulnerability/GHSA-mh99-v99m-4gvg\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-d52932e319415dfa", "name": "Vulnerable dependency brace-expansion 1.1.12: GHSA-rgw5-rvv9-x895", "shortDescription": {"text": "Vulnerable dependency brace-expansion 1.1.12: GHSA-rgw5-rvv9-x895"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `1.1.12` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-rgw5-rvv9-x895.\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-rgw5-rvv9-x895\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-f5979ec0975c056f", "name": "Vulnerable dependency qs 6.14.1: GHSA-q8mj-m7cp-5q26", "shortDescription": {"text": "Vulnerable dependency qs 6.14.1: GHSA-q8mj-m7cp-5q26"}, "fullDescription": {"text": "OSV.dev reports `qs` at version `6.14.1` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-q8mj-m7cp-5q26.\nNote: `qs` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q8mj-m7cp-5q26\nFix: upgrade `qs` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-ff0ecc00cfb079ff", "name": "Vulnerable dependency qs 6.14.1: GHSA-w7fw-mjwx-w883", "shortDescription": {"text": "Vulnerable dependency qs 6.14.1: GHSA-w7fw-mjwx-w883"}, "fullDescription": {"text": "OSV.dev reports `qs` at version `6.14.1` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-w7fw-mjwx-w883.\nNote: `qs` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w7fw-mjwx-w883\nFix: upgrade `qs` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-e1f05ea9f18fb0bc", "name": "Vulnerable dependency immutable 5.1.5: GHSA-v56q-mh7h-f735", "shortDescription": {"text": "Vulnerable dependency immutable 5.1.5: GHSA-v56q-mh7h-f735"}, "fullDescription": {"text": "OSV.dev reports `immutable` at version `5.1.5` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-v56q-mh7h-f735.\nNote: `immutable` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-v56q-mh7h-f735\nFix: upgrade `immutable` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-8955a8eb7390072d", "name": "Vulnerable dependency immutable 5.1.5: GHSA-xvcm-6775-5m9r", "shortDescription": {"text": "Vulnerable dependency immutable 5.1.5: GHSA-xvcm-6775-5m9r"}, "fullDescription": {"text": "OSV.dev reports `immutable` at version `5.1.5` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-xvcm-6775-5m9r.\nNote: `immutable` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xvcm-6775-5m9r\nFix: upgrade `immutable` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-0f6034232fb36527", "name": "Vulnerable dependency js-yaml 4.1.1: GHSA-52cp-r559-cp3m", "shortDescription": {"text": "Vulnerable dependency js-yaml 4.1.1: GHSA-52cp-r559-cp3m"}, "fullDescription": {"text": "OSV.dev reports `js-yaml` at version `4.1.1` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-52cp-r559-cp3m (aka CVE-2026-59869).\nNote: `js-yaml` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\njs-yaml: YAML merge-key chains can force quadratic CPU consumption\n\nAliases: CVE-2026-59869\nAdvisory: https://osv.dev/vulnerability/GHSA-52cp-r559-cp3m\nFix: upgrade `js-yaml` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-a4bcd16c73faf375", "name": "Vulnerable dependency js-yaml 4.1.1: GHSA-5p4m-2wfm-xmqj", "shortDescription": {"text": "Vulnerable dependency js-yaml 4.1.1: GHSA-5p4m-2wfm-xmqj"}, "fullDescription": {"text": "OSV.dev reports `js-yaml` at version `4.1.1` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-5p4m-2wfm-xmqj.\nNote: `js-yaml` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nJS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) \u2014 CVE-2026-59870 fix not backported\n\nAdvisory: https://osv.dev/vulnerability/GHSA-5p4m-2wfm-xmqj\nFix: upgrade `js-yaml` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-f7976c1931edafe3", "name": "Vulnerable dependency js-yaml 4.1.1: GHSA-h67p-54hq-rp68", "shortDescription": {"text": "Vulnerable dependency js-yaml 4.1.1: GHSA-h67p-54hq-rp68"}, "fullDescription": {"text": "OSV.dev reports `js-yaml` at version `4.1.1` (resolved in `webgui-new/package-lock.json`) is affected by GHSA-h67p-54hq-rp68 (aka CVE-2026-53550).\nNote: `js-yaml` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nJS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases\n\nAliases: CVE-2026-53550\nAdvisory: https://osv.dev/vulnerability/GHSA-h67p-54hq-rp68\nFix: upgrade `js-yaml` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-6917ce00235b7ac3", "name": "Dependency @mui/icons-material is two or more major versions behind", "shortDescription": {"text": "Dependency @mui/icons-material is two or more major versions behind"}, "fullDescription": {"text": "`@mui/icons-material` is pinned at `5.18.0` in `webgui-new/package.json` while the latest release on the npm registry is `9.3.1` \u2014 4 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@mui/icons-material` to `9.3.1`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-d84dbf3b35980e3a", "name": "Dependency @mui/material is two or more major versions behind", "shortDescription": {"text": "Dependency @mui/material is two or more major versions behind"}, "fullDescription": {"text": "`@mui/material` is pinned at `5.18.0` in `webgui-new/package.json` while the latest release on the npm registry is `9.3.1` \u2014 4 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@mui/material` to `9.3.1`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-115872a4c1a69c5f", "name": "Dependency @mui/x-tree-view is two or more major versions behind", "shortDescription": {"text": "Dependency @mui/x-tree-view is two or more major versions behind"}, "fullDescription": {"text": "`@mui/x-tree-view` is pinned at `6.17.0` in `webgui-new/package.json` while the latest release on the npm registry is `9.11.0` \u2014 3 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@mui/x-tree-view` to `9.11.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-d9f73af3cf2f8c3b", "name": "Dependency codemirror is a major version behind", "shortDescription": {"text": "Dependency codemirror is a major version behind"}, "fullDescription": {"text": "`codemirror` is pinned at `5.19.0` in `webgui/package.json` while the latest release on the npm registry is `6.0.2` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `codemirror` to `6.0.2`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-0af119d0214d43e3", "name": "Dependency d3 is two or more major versions behind", "shortDescription": {"text": "Dependency d3 is two or more major versions behind"}, "fullDescription": {"text": "`d3` is pinned at `3.5.6` in `webgui/package.json` while the latest release on the npm registry is `7.9.0` \u2014 4 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `d3` to `7.9.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-955fc71664e303f6", "name": "Dependency i18next is two or more major versions behind", "shortDescription": {"text": "Dependency i18next is two or more major versions behind"}, "fullDescription": {"text": "`i18next` is pinned at `23.16.8` in `webgui-new/package.json` while the latest release on the npm registry is `26.3.6` \u2014 3 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `i18next` to `26.3.6`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-211258d3bc61625a", "name": "Dependency jquery is a major version behind", "shortDescription": {"text": "Dependency jquery is a major version behind"}, "fullDescription": {"text": "`jquery` is pinned at `3.1.1` in `webgui/package.json` while the latest release on the npm registry is `4.0.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `jquery` to `4.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-7222b006d5f3157b", "name": "Dependency js-cookie is a major version behind", "shortDescription": {"text": "Dependency js-cookie is a major version behind"}, "fullDescription": {"text": "`js-cookie` is pinned at `2.2.1` in `webgui/package.json` while the latest release on the npm registry is `3.0.8` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `js-cookie` to `3.0.8`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-7a434064dbdddea5", "name": "Dependency marked is two or more major versions behind", "shortDescription": {"text": "Dependency marked is two or more major versions behind"}, "fullDescription": {"text": "`marked` is pinned at `4.0.10` in `webgui/package.json` while the latest release on the npm registry is `18.0.9` \u2014 14 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `marked` to `18.0.9`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-8dcbbd3671fd2355", "name": "Dependency next is two or more major versions behind", "shortDescription": {"text": "Dependency next is two or more major versions behind"}, "fullDescription": {"text": "`next` is pinned at `14.2.35` in `webgui-new/package.json` while the latest release on the npm registry is `16.3.0` \u2014 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `next` to `16.3.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-ae5816ddc8134efe", "name": "Dependency react-diff-viewer-continued is a major version behind", "shortDescription": {"text": "Dependency react-diff-viewer-continued is a major version behind"}, "fullDescription": {"text": "`react-diff-viewer-continued` is pinned at `3.4.0` in `webgui-new/package.json` while the latest release on the npm registry is `4.4.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `react-diff-viewer-continued` to `4.4.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-8c0d634ee4bf63de", "name": "Dependency react-dom is a major version behind", "shortDescription": {"text": "Dependency react-dom is a major version behind"}, "fullDescription": {"text": "`react-dom` is pinned at `18.3.1` in `webgui-new/package.json` while the latest release on the npm registry is `19.2.8` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `react-dom` to `19.2.8`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-d8beeec900eecdaa", "name": "Dependency react-ga4 is a major version behind", "shortDescription": {"text": "Dependency react-ga4 is a major version behind"}, "fullDescription": {"text": "`react-ga4` is pinned at `2.1.0` in `webgui-new/package.json` while the latest release on the npm registry is `3.0.1` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `react-ga4` to `3.0.1`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-c4b3a90cd4ee58b8", "name": "Dependency react-i18next is two or more major versions behind", "shortDescription": {"text": "Dependency react-i18next is two or more major versions behind"}, "fullDescription": {"text": "`react-i18next` is pinned at `13.5.0` in `webgui-new/package.json` while the latest release on the npm registry is `17.0.11` \u2014 4 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `react-i18next` to `17.0.11`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-3c44bc19f695e001", "name": "Dependency react-icons is a major version behind", "shortDescription": {"text": "Dependency react-icons is a major version behind"}, "fullDescription": {"text": "`react-icons` is pinned at `4.12.0` in `webgui-new/package.json` while the latest release on the npm registry is `5.7.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `react-icons` to `5.7.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-69046c46d9ea5d69", "name": "Dependency react-toastify is two or more major versions behind", "shortDescription": {"text": "Dependency react-toastify is two or more major versions behind"}, "fullDescription": {"text": "`react-toastify` is pinned at `9.1.3` in `webgui-new/package.json` while the latest release on the npm registry is `11.1.0` \u2014 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `react-toastify` to `11.1.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-191355cb039b823e", "name": "Dependency react-zoom-pan-pinch is a major version behind", "shortDescription": {"text": "Dependency react-zoom-pan-pinch is a major version behind"}, "fullDescription": {"text": "`react-zoom-pan-pinch` is pinned at `3.7.0` in `webgui-new/package.json` while the latest release on the npm registry is `4.0.4` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `react-zoom-pan-pinch` to `4.0.4`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-e675a30e79a4432b", "name": "Dependency react is a major version behind", "shortDescription": {"text": "Dependency react is a major version behind"}, "fullDescription": {"text": "`react` is pinned at `18.3.1` in `webgui-new/package.json` while the latest release on the npm registry is `19.2.8` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `react` to `19.2.8`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-99123909e554d909", "name": "Dependency recharts is a major version behind", "shortDescription": {"text": "Dependency recharts is a major version behind"}, "fullDescription": {"text": "`recharts` is pinned at `2.15.4` in `webgui-new/package.json` while the latest release on the npm registry is `3.10.1` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `recharts` to `3.10.1`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}]}}, "automationDetails": {"id": "repobility/30812"}, "properties": {"repository": "Ericsson/CodeCompass", "repoUrl": "https://github.com/Ericsson/CodeCompass", "branch": "main"}, "results": [{"ruleId": "scanner-bb88db82654adde0", "level": "note", "message": {"text": "Possibly dead Python function: parseProject"}, "properties": {"repobilityId": "a50ded41299803b9", "scanner": "scanner-primary", "fingerprint": "bb88db82654adde0", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/python/parser/pyparser/parser.py:16"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3afc1511e6b67512", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 webgui-new/src/components/cookie-notice/cookie-notice.tsx:61"}, "properties": {"repobilityId": "3a64cfe6b133e5a8", "scanner": "scanner-primary", "fingerprint": "3afc1511e6b67512", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/src/components/cookie-notice/cookie-notice.tsx"}, "region": {"startLine": 61}}}]}, {"ruleId": "scanner-9b1131d99055bf0d", "level": "note", "message": {"text": "React Flow <Controls> without dark theming \u2014 webgui-new/src/components/codebites/codebites.tsx:52"}, "properties": {"repobilityId": "caeb04d9d66516a4", "scanner": "scanner-primary", "fingerprint": "9b1131d99055bf0d", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.controls.no-bg"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/src/components/codebites/codebites.tsx"}, "region": {"startLine": 52}}}]}, {"ruleId": "scanner-365ce81d8f841a34", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 webgui/scripts/codecompass/view/diagram.js:91"}, "properties": {"repobilityId": "97daa0d0e8530dfa", "scanner": "scanner-primary", "fingerprint": "365ce81d8f841a34", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/scripts/codecompass/view/diagram.js"}, "region": {"startLine": 91}}}]}, {"ruleId": "scanner-57a70f1f8271fa2d", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 webgui/scripts/codecompass/view/fileManager.js:123"}, "properties": {"repobilityId": "4000835eda7082cf", "scanner": "scanner-primary", "fingerprint": "57a70f1f8271fa2d", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/scripts/codecompass/view/fileManager.js"}, "region": {"startLine": 123}}}]}, {"ruleId": "scanner-eab91328fa772651", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 webgui/scripts/codecompass/view/component/IconTextBox.js:24"}, "properties": {"repobilityId": "f94ec37cba845462", "scanner": "scanner-primary", "fingerprint": "eab91328fa772651", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/scripts/codecompass/view/component/IconTextBox.js"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-79b3576a77ca89e0", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 webgui/scripts/codecompass/view/component/Text.js:294"}, "properties": {"repobilityId": "2f2842c84047ce43", "scanner": "scanner-primary", "fingerprint": "79b3576a77ca89e0", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/scripts/codecompass/view/component/Text.js"}, "region": {"startLine": 294}}}]}, {"ruleId": "scanner-577a6965e40b359d", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 webgui/scripts/codecompass/view/component/Pager.js:160"}, "properties": {"repobilityId": "66f0437e068442d6", "scanner": "scanner-primary", "fingerprint": "577a6965e40b359d", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/scripts/codecompass/view/component/Pager.js"}, "region": {"startLine": 160}}}]}, {"ruleId": "scanner-f2ba29f414f4c6fa", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 plugins/cpp_reparse/webgui/js/cppReparseFileAST.js:29"}, "properties": {"repobilityId": "78ae8cfc31d21779", "scanner": "scanner-primary", "fingerprint": "f2ba29f414f4c6fa", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/cpp_reparse/webgui/js/cppReparseFileAST.js"}, "region": {"startLine": 29}}}]}, {"ruleId": "scanner-198072b3b0d1970d", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 plugins/git/webgui/js/gitNavigator.js:349"}, "properties": {"repobilityId": "976618adcaed1771", "scanner": "scanner-primary", "fingerprint": "198072b3b0d1970d", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/git/webgui/js/gitNavigator.js"}, "region": {"startLine": 349}}}]}, {"ruleId": "scanner-ce9ddb8afcf21704", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 plugins/git/webgui/js/gitNavigator.js:175"}, "properties": {"repobilityId": "c6993008cc370a96", "scanner": "scanner-primary", "fingerprint": "ce9ddb8afcf21704", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/git/webgui/js/gitNavigator.js"}, "region": {"startLine": 175}}}]}, {"ruleId": "scanner-38ab8870595cba37", "level": "warning", "message": {"text": "insecure use strcat fn \u2014 logger/src/ldlogger-logger.c:145"}, "properties": {"repobilityId": "c20073d287aaa6a7", "scanner": "scanner-primary", "fingerprint": "38ab8870595cba37", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "c"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "logger/src/ldlogger-logger.c"}, "region": {"startLine": 145}}}]}, {"ruleId": "scanner-107cb58109ccd895", "level": "warning", "message": {"text": "insecure use string copy fn \u2014 logger/src/ldlogger-tool-gcc.c:67"}, "properties": {"repobilityId": "2d32df3aa10b34b3", "scanner": "scanner-primary", "fingerprint": "107cb58109ccd895", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "c"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "logger/src/ldlogger-tool-gcc.c"}, "region": {"startLine": 67}}}]}, {"ruleId": "scanner-a2910f4ac755f8df", "level": "warning", "message": {"text": "insecure use strcat fn \u2014 logger/src/ldlogger-tool-gcc.c:90"}, "properties": {"repobilityId": "60be48e43423294c", "scanner": "scanner-primary", "fingerprint": "a2910f4ac755f8df", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "c"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "logger/src/ldlogger-tool-gcc.c"}, "region": {"startLine": 90}}}]}, {"ruleId": "scanner-3ea2c41706c12df1", "level": "warning", "message": {"text": "insecure use string copy fn \u2014 logger/src/ldlogger-tool-javac.c:116"}, "properties": {"repobilityId": "a6924416df5d8e6d", "scanner": "scanner-primary", "fingerprint": "3ea2c41706c12df1", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "c"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "logger/src/ldlogger-tool-javac.c"}, "region": {"startLine": 116}}}]}, {"ruleId": "scanner-63098e16cf700257", "level": "warning", "message": {"text": "insecure use strtok fn \u2014 logger/src/ldlogger-tool-javac.c:118"}, "properties": {"repobilityId": "35495a5257573005", "scanner": "scanner-primary", "fingerprint": "63098e16cf700257", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "c"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "logger/src/ldlogger-tool-javac.c"}, "region": {"startLine": 118}}}]}, {"ruleId": "scanner-0f1d412c4640da2f", "level": "warning", "message": {"text": "insecure use strcat fn \u2014 logger/src/ldlogger-tool-javac.c:160"}, "properties": {"repobilityId": "c3d789388908cdcd", "scanner": "scanner-primary", "fingerprint": "0f1d412c4640da2f", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "c"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "logger/src/ldlogger-tool-javac.c"}, "region": {"startLine": 160}}}]}, {"ruleId": "scanner-3d8bd07015edb892", "level": "warning", "message": {"text": "insecure use strtok fn \u2014 logger/src/ldlogger-tool.c:39"}, "properties": {"repobilityId": "5780a85d44de4ddb", "scanner": "scanner-primary", "fingerprint": "3d8bd07015edb892", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "c"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "logger/src/ldlogger-tool.c"}, "region": {"startLine": 39}}}]}, {"ruleId": "scanner-33b8a9f60de0e1ad", "level": "warning", "message": {"text": "insecure use string copy fn \u2014 logger/src/ldlogger-tool.c:78"}, "properties": {"repobilityId": "adb553140a16841c", "scanner": "scanner-primary", "fingerprint": "33b8a9f60de0e1ad", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "c"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "logger/src/ldlogger-tool.c"}, "region": {"startLine": 78}}}]}, {"ruleId": "scanner-72824774c85ea2b1", "level": "warning", "message": {"text": "insecure use string copy fn \u2014 logger/src/ldlogger-util.c:20"}, "properties": {"repobilityId": "8b6e11dac41d7553", "scanner": "scanner-primary", "fingerprint": "72824774c85ea2b1", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "c"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "logger/src/ldlogger-util.c"}, "region": {"startLine": 20}}}]}, {"ruleId": "scanner-fcd964c62927e2aa", "level": "warning", "message": {"text": "insecure use strcat fn \u2014 logger/src/ldlogger-util.c:44"}, "properties": {"repobilityId": "a4e04a222ec0f590", "scanner": "scanner-primary", "fingerprint": "fcd964c62927e2aa", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "c"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "logger/src/ldlogger-util.c"}, "region": {"startLine": 44}}}]}, {"ruleId": "scanner-79ce5b3e24ed11d7", "level": "warning", "message": {"text": "insecure hash algorithm sha1 \u2014 plugins/python/parser/pyparser/parserutil.py:6"}, "properties": {"repobilityId": "c0aaf2abd7b7ffc2", "scanner": "scanner-primary", "fingerprint": "79ce5b3e24ed11d7", "layer": "security", "severity": "medium", "confidence": 0.75, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/python/parser/pyparser/parserutil.py"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-3e5318cabb93de27", "level": "warning", "message": {"text": "object deserialization \u2014 plugins/search/common/src/cc/search/analysis/tags/Tags.java:171"}, "properties": {"repobilityId": "87f2c0dc5b58da2a", "scanner": "scanner-primary", "fingerprint": "3e5318cabb93de27", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "java"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/search/common/src/cc/search/analysis/tags/Tags.java"}, "region": {"startLine": 171}}}]}, {"ruleId": "scanner-b89489c3b1c531bc", "level": "warning", "message": {"text": "Dockerfile runs as root: docker/web/Dockerfile"}, "properties": {"repobilityId": "6601bb7dd19f00f8", "scanner": "scanner-primary", "fingerprint": "b89489c3b1c531bc", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-bead1b9c2a330c18", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: codecompass:runtime"}, "properties": {"repobilityId": "d2280d4ed57cb1ad", "scanner": "scanner-primary", "fingerprint": "bead1b9c2a330c18", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker/web/Dockerfile"}, "region": {"startLine": 4}}}]}, {"ruleId": "scanner-819070b5ea6acf4f", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: ubuntu:22.04"}, "properties": {"repobilityId": "c6def0dea85a5d80", "scanner": "scanner-primary", "fingerprint": "819070b5ea6acf4f", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker/web/Dockerfile"}, "region": {"startLine": 10}}}]}, {"ruleId": "scanner-88bb91f0c6fcbd94", "level": "warning", "message": {"text": "Dockerfile runs as root: docker/runtime/Dockerfile"}, "properties": {"repobilityId": "ef04a43337ec01ff", "scanner": "scanner-primary", "fingerprint": "88bb91f0c6fcbd94", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-988d3b92d0e853b6", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: codecompass:dev"}, "properties": {"repobilityId": "77077d9290675fec", "scanner": "scanner-primary", "fingerprint": "988d3b92d0e853b6", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker/runtime/Dockerfile"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-c64e34669fa5354c", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: ubuntu:22.04"}, "properties": {"repobilityId": "7c5fbf4694eda55f", "scanner": "scanner-primary", "fingerprint": "c64e34669fa5354c", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker/runtime/Dockerfile"}, "region": {"startLine": 43}}}]}, {"ruleId": "scanner-8d53c8cd353752e7", "level": "warning", "message": {"text": "Dockerfile runs as root: docker/dev/Dockerfile"}, "properties": {"repobilityId": "5b1c919fe2ac9880", "scanner": "scanner-primary", "fingerprint": "8d53c8cd353752e7", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-f67a86995ad02e9c", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: ubuntu:22.04"}, "properties": {"repobilityId": "bc50345be99d5753", "scanner": "scanner-primary", "fingerprint": "f67a86995ad02e9c", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker/dev/Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa92ece5df982af9", "level": "warning", "message": {"text": "Runtime dotenv file present in repo: webgui-new/.env"}, "properties": {"repobilityId": "2ff9a5b06ceb0768", "scanner": "scanner-primary", "fingerprint": "aa92ece5df982af9", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["secrets", "config", "env-file", "runtime-env"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/.env"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-04afbf9d8cc5dc75", "level": "warning", "message": {"text": "Insecure pattern 'domparser_html_parse' in webgui-new/src/components/editor-context-menu/editor-context-menu.tsx:79"}, "properties": {"repobilityId": "626aeb868f6cbaba", "scanner": "scanner-primary", "fingerprint": "04afbf9d8cc5dc75", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "domparser_html_parse"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/src/components/editor-context-menu/editor-context-menu.tsx"}, "region": {"startLine": 79}}}]}, {"ruleId": "scanner-566dc23bc09fac81", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in webgui-new/src/components/codebites/codebites-node.tsx:91"}, "properties": {"repobilityId": "bde216c060988187", "scanner": "scanner-primary", "fingerprint": "566dc23bc09fac81", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/src/components/codebites/codebites-node.tsx"}, "region": {"startLine": 91}}}]}, {"ruleId": "scanner-137c8c8d5afaf3a2", "level": "error", "message": {"text": "Insecure pattern 'eval_used' in webgui/scripts/thrift.js:1096"}, "properties": {"repobilityId": "fc26188457af3e81", "scanner": "scanner-primary", "fingerprint": "137c8c8d5afaf3a2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "eval_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/scripts/thrift.js"}, "region": {"startLine": 1096}}}]}, {"ruleId": "scanner-a977808cf9b11de3", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in webgui/scripts/codecompass/view/diagram.js:286"}, "properties": {"repobilityId": "904a29f88883fd1f", "scanner": "scanner-primary", "fingerprint": "a977808cf9b11de3", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/scripts/codecompass/view/diagram.js"}, "region": {"startLine": 286}}}]}, {"ruleId": "scanner-ea4d1047914cc7df", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in webgui/scripts/codecompass/view/fileManager.js:275"}, "properties": {"repobilityId": "1641f9c579829b4e", "scanner": "scanner-primary", "fingerprint": "ea4d1047914cc7df", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/scripts/codecompass/view/fileManager.js"}, "region": {"startLine": 275}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-65aa740cba4a4a73", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "f72e4b498f09201b", "scanner": "scanner-primary", "fingerprint": "65aa740cba4a4a73", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/codeql.yml"}, "region": {"startLine": 26}}}]}, {"ruleId": "scanner-7f0f9976570faa6d", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "8ae5e48e366ecdcb", "scanner": "scanner-primary", "fingerprint": "7f0f9976570faa6d", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/docker.yml"}, "region": {"startLine": 26}}}]}, {"ruleId": "scanner-e04eab3aa1f521d4", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "f9052e961cd3f867", "scanner": "scanner-primary", "fingerprint": "e04eab3aa1f521d4", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/scorecard.yml"}, "region": {"startLine": 36}}}]}, {"ruleId": "scanner-65a716a27d2be993", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "3133a88ce98acc76", "scanner": "scanner-primary", "fingerprint": "65a716a27d2be993", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/scorecard.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "b2e0ce9052399d41", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 72}}}]}, {"ruleId": "scanner-f7df1b8b94937a8f", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "60d73e06e82de370", "scanner": "scanner-primary", "fingerprint": "f7df1b8b94937a8f", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/linting.yml"}, "region": {"startLine": 16}}}]}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-a84a1d05ba37f95f", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: webgui/package.json"}, "properties": {"repobilityId": "7376327d9f910ff0", "scanner": "scanner-primary", "fingerprint": "a84a1d05ba37f95f", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "2f8898939d4dd697", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "998cc052af45b3d7", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "b5f27b0fe8a2d324", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-28a4da2394a6b670", "level": "warning", "message": {"text": "Vulnerable dependency http-proxy-middleware 3.0.5: GHSA-64mm-vxmg-q3vj"}, "properties": {"repobilityId": "e2aa9e05d2be43d1", "scanner": "scanner-primary", "fingerprint": "28a4da2394a6b670", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-64mm-vxmg-q3vj", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ed8e4ff40519cc71", "level": "warning", "message": {"text": "Vulnerable dependency http-proxy-middleware 3.0.5: GHSA-gcq2-9pq2-cxqm"}, "properties": {"repobilityId": "5ea16157e306b033", "scanner": "scanner-primary", "fingerprint": "ed8e4ff40519cc71", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-gcq2-9pq2-cxqm", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b63ea4bf7e9ab37e", "level": "error", "message": {"text": "Vulnerable dependency next 14.2.35: GHSA-36qx-fr4f-26g5"}, "properties": {"repobilityId": "daba51e4a16b23a4", "scanner": "scanner-primary", "fingerprint": "b63ea4bf7e9ab37e", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-36qx-fr4f-26g5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b241936b566cdb7e", "level": "note", "message": {"text": "Vulnerable dependency next 14.2.35: GHSA-3g8h-86w9-wvmq"}, "properties": {"repobilityId": "01ddfa4f7d28f1c6", "scanner": "scanner-primary", "fingerprint": "b241936b566cdb7e", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3g8h-86w9-wvmq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4eb9e045a62dd69a", "level": "warning", "message": {"text": "Vulnerable dependency next 14.2.35: GHSA-3x4c-7xq6-9pq8"}, "properties": {"repobilityId": "8310c72f9cd38b1b", "scanner": "scanner-primary", "fingerprint": "4eb9e045a62dd69a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3x4c-7xq6-9pq8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a8ac5c3b713855b4", "level": "warning", "message": {"text": "Vulnerable dependency next 14.2.35: GHSA-4633-3j49-mh5q"}, "properties": {"repobilityId": "b1ccda3dec1710fd", "scanner": "scanner-primary", "fingerprint": "a8ac5c3b713855b4", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4633-3j49-mh5q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f152102264526b73", "level": "warning", "message": {"text": "Vulnerable dependency next 14.2.35: GHSA-4c39-4ccg-62r3"}, "properties": {"repobilityId": "a3aa401c98f6d997", "scanner": "scanner-primary", "fingerprint": "f152102264526b73", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4c39-4ccg-62r3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5d988bd28bb331bb", "level": "warning", "message": {"text": "Vulnerable dependency next 14.2.35: GHSA-68g3-v927-f742"}, "properties": {"repobilityId": "af07cad35c67aa3c", "scanner": "scanner-primary", "fingerprint": "5d988bd28bb331bb", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-68g3-v927-f742"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-43d8aae5f3b1b72f", "level": "error", "message": {"text": "Vulnerable dependency next 14.2.35: GHSA-89xv-2m56-2m9x"}, "properties": {"repobilityId": "86be1ccee45aa799", "scanner": "scanner-primary", "fingerprint": "43d8aae5f3b1b72f", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-89xv-2m56-2m9x"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fd01dbd6b2ebf57a", "level": "error", "message": {"text": "Vulnerable dependency next 14.2.35: GHSA-8h8q-6873-q5fj"}, "properties": {"repobilityId": "bdcca184ade63d0b", "scanner": "scanner-primary", "fingerprint": "fd01dbd6b2ebf57a", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-8h8q-6873-q5fj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4a2acafa1ed3acaf", "level": "warning", "message": {"text": "Vulnerable dependency next 14.2.35: GHSA-955p-x3mx-jcvp"}, "properties": {"repobilityId": "f49141d2dc2e05fd", "scanner": "scanner-primary", "fingerprint": "4a2acafa1ed3acaf", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-955p-x3mx-jcvp"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3395b8c67f3bf84d", "level": "warning", "message": {"text": "Vulnerable dependency next 14.2.35: GHSA-9g9p-9gw9-jx7f"}, "properties": {"repobilityId": "eb49541888369225", "scanner": "scanner-primary", "fingerprint": "3395b8c67f3bf84d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9g9p-9gw9-jx7f"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f6795799c5e41b80", "level": "error", "message": {"text": "Vulnerable dependency next 14.2.35: GHSA-c4j6-fc7j-m34r"}, "properties": {"repobilityId": "5fa1a61088825b55", "scanner": "scanner-primary", "fingerprint": "f6795799c5e41b80", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-c4j6-fc7j-m34r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c0554992b62c8042", "level": "warning", "message": {"text": "Vulnerable dependency next 14.2.35: GHSA-ffhc-5mcf-pf4q"}, "properties": {"repobilityId": "5d2e9d06d87f1934", "scanner": "scanner-primary", "fingerprint": "c0554992b62c8042", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-ffhc-5mcf-pf4q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-88c2ccd1181784f2", "level": "warning", "message": {"text": "Vulnerable dependency next 14.2.35: GHSA-ggv3-7p47-pfv8"}, "properties": {"repobilityId": "143bb93e201d2036", "scanner": "scanner-primary", "fingerprint": "88c2ccd1181784f2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-ggv3-7p47-pfv8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-665af5fa4a61639a", "level": "warning", "message": {"text": "Vulnerable dependency next 14.2.35: GHSA-gx5p-jg67-6x7h"}, "properties": {"repobilityId": "00f705eac13b2b56", "scanner": "scanner-primary", "fingerprint": "665af5fa4a61639a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gx5p-jg67-6x7h"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a38b2402cff17da9", "level": "warning", "message": {"text": "Vulnerable dependency next 14.2.35: GHSA-h25m-26qc-wcjf"}, "properties": {"repobilityId": "4a7ea04dbf775e0b", "scanner": "scanner-primary", "fingerprint": "a38b2402cff17da9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-h25m-26qc-wcjf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fb4bcd9b80467636", "level": "warning", "message": {"text": "Vulnerable dependency next 14.2.35: GHSA-h64f-5h5j-jqjh"}, "properties": {"repobilityId": "a771fe1159016566", "scanner": "scanner-primary", "fingerprint": "fb4bcd9b80467636", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-h64f-5h5j-jqjh"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-913b94b8a285f9bf", "level": "error", "message": {"text": "Vulnerable dependency next 14.2.35: GHSA-m99w-x7hq-7vfj"}, "properties": {"repobilityId": "ae3774cb18e27e87", "scanner": "scanner-primary", "fingerprint": "913b94b8a285f9bf", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-m99w-x7hq-7vfj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ffa69eff77cf76b5", "level": "error", "message": {"text": "Vulnerable dependency next 14.2.35: GHSA-p9j2-gv94-2wf4"}, "properties": {"repobilityId": "620e320728575c87", "scanner": "scanner-primary", "fingerprint": "ffa69eff77cf76b5", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p9j2-gv94-2wf4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4aa6b13458954ca4", "level": "error", "message": {"text": "Vulnerable dependency next 14.2.35: GHSA-q4gf-8mx6-v5v3"}, "properties": {"repobilityId": "2d2fb0aa22c60c6b", "scanner": "scanner-primary", "fingerprint": "4aa6b13458954ca4", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-q4gf-8mx6-v5v3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2f02be4b6c8ddbeb", "level": "note", "message": {"text": "Vulnerable dependency next 14.2.35: GHSA-vfv6-92ff-j949"}, "properties": {"repobilityId": "27d45518cc9c81df", "scanner": "scanner-primary", "fingerprint": "2f02be4b6c8ddbeb", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vfv6-92ff-j949"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d66153d36a645f11", "level": "warning", "message": {"text": "Vulnerable dependency next 14.2.35: GHSA-wfc6-r584-vfw7"}, "properties": {"repobilityId": "3ecd436f8d87bf7b", "scanner": "scanner-primary", "fingerprint": "d66153d36a645f11", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wfc6-r584-vfw7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-15bb7c211d3ec736", "level": "error", "message": {"text": "Vulnerable dependency sharp 0.32.6: GHSA-f88m-g3jw-g9cj"}, "properties": {"repobilityId": "9018657dc1610910", "scanner": "scanner-primary", "fingerprint": "15bb7c211d3ec736", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-f88m-g3jw-g9cj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-daec965a1bd76cca", "level": "error", "message": {"text": "Vulnerable dependency thrift 0.16.0: GHSA-526f-jxpj-jmg2"}, "properties": {"repobilityId": "53ac255343e702d7", "scanner": "scanner-primary", "fingerprint": "daec965a1bd76cca", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-526f-jxpj-jmg2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9ec427dab9937b51", "level": "warning", "message": {"text": "Vulnerable dependency thrift 0.16.0: GHSA-r67j-r569-jrwp"}, "properties": {"repobilityId": "ee4e65681eee15dc", "scanner": "scanner-primary", "fingerprint": "9ec427dab9937b51", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-r67j-r569-jrwp"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-16e1578151da83a6", "level": "warning", "message": {"text": "Vulnerable dependency dojo 1.11.2: GHSA-536q-8gxx-m782"}, "properties": {"repobilityId": "a86ac2b914e08806", "scanner": "scanner-primary", "fingerprint": "16e1578151da83a6", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-536q-8gxx-m782"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cb5010e5eef35986", "level": "warning", "message": {"text": "Vulnerable dependency dojo 1.11.2: GHSA-jxfh-8wgv-vfr2"}, "properties": {"repobilityId": "ecc87b8883dd5905", "scanner": "scanner-primary", "fingerprint": "cb5010e5eef35986", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-jxfh-8wgv-vfr2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-33dd0d5e97bbc602", "level": "warning", "message": {"text": "Vulnerable dependency dojo 1.11.2: GHSA-m8gw-hjpr-rjv7"}, "properties": {"repobilityId": "c5fcbad342b04190", "scanner": "scanner-primary", "fingerprint": "33dd0d5e97bbc602", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-m8gw-hjpr-rjv7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4b622e0f3121e28f", "level": "warning", "message": {"text": "Vulnerable dependency dijit 1.11.2: GHSA-cxjc-r2fp-7mq6"}, "properties": {"repobilityId": "fa8cf5fb4fcacc5b", "scanner": "scanner-primary", "fingerprint": "4b622e0f3121e28f", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-cxjc-r2fp-7mq6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ba83d16d8a5ef246", "level": "warning", "message": {"text": "Vulnerable dependency dijit 1.11.2: GHSA-wp32-wq34-2rqh"}, "properties": {"repobilityId": "f1ef23a64033507e", "scanner": "scanner-primary", "fingerprint": "ba83d16d8a5ef246", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-wp32-wq34-2rqh"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-71ed30f793244798", "level": "error", "message": {"text": "Vulnerable dependency dojox 1.11.2: GHSA-3hw5-q855-g6cw"}, "properties": {"repobilityId": "29fdcc8e41f2ece8", "scanner": "scanner-primary", "fingerprint": "71ed30f793244798", "layer": "dependencies", "severity": "high", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-3hw5-q855-g6cw"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f73573556ede5559", "level": "warning", "message": {"text": "Vulnerable dependency dojox 1.11.2: GHSA-84cm-x2q5-8225"}, "properties": {"repobilityId": "afde5b7fa445b82a", "scanner": "scanner-primary", "fingerprint": "f73573556ede5559", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-84cm-x2q5-8225"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1e4e4f07a48bdb34", "level": "warning", "message": {"text": "Vulnerable dependency dojox 1.11.2: GHSA-pg97-ww7h-5mjr"}, "properties": {"repobilityId": "dc08d5350d681143", "scanner": "scanner-primary", "fingerprint": "1e4e4f07a48bdb34", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-pg97-ww7h-5mjr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a750ba2f5524cdde", "level": "warning", "message": {"text": "Vulnerable dependency codemirror 5.19.0: GHSA-4gw3-8f77-f72c"}, "properties": {"repobilityId": "fc870b655b9e74a2", "scanner": "scanner-primary", "fingerprint": "a750ba2f5524cdde", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-4gw3-8f77-f72c"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6f990f9c3cefe9f1", "level": "warning", "message": {"text": "Vulnerable dependency jquery 3.1.1: GHSA-6c3j-c64m-qhgq"}, "properties": {"repobilityId": "255f619914c92747", "scanner": "scanner-primary", "fingerprint": "6f990f9c3cefe9f1", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-6c3j-c64m-qhgq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2fd0b5271a2161e7", "level": "warning", "message": {"text": "Vulnerable dependency jquery 3.1.1: GHSA-gxr4-xjj5-5px2"}, "properties": {"repobilityId": "c7c4f0beafb942b8", "scanner": "scanner-primary", "fingerprint": "2fd0b5271a2161e7", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-gxr4-xjj5-5px2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3c30b52bd6042ad0", "level": "warning", "message": {"text": "Vulnerable dependency jquery 3.1.1: GHSA-jpcq-cgw6-v4j6"}, "properties": {"repobilityId": "345b4debcd70d6a8", "scanner": "scanner-primary", "fingerprint": "3c30b52bd6042ad0", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-jpcq-cgw6-v4j6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-448c444a42ac1308", "level": "warning", "message": {"text": "Vulnerable dependency js-cookie 2.2.1: GHSA-qjx8-664m-686j"}, "properties": {"repobilityId": "168767f2c88e86cd", "scanner": "scanner-primary", "fingerprint": "448c444a42ac1308", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-qjx8-664m-686j"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a1864da73f42cea2", "level": "warning", "message": {"text": "Vulnerable dependency ajv 6.12.6: GHSA-2g4f-4pwh-qvx6"}, "properties": {"repobilityId": "cf8ef5d83527dc1c", "scanner": "scanner-primary", "fingerprint": "a1864da73f42cea2", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-2g4f-4pwh-qvx6", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-eb96c84569c926ad", "level": "note", "message": {"text": "Vulnerable dependency body-parser 1.20.3: GHSA-v422-hmwv-36x6"}, "properties": {"repobilityId": "2ad267bc43500266", "scanner": "scanner-primary", "fingerprint": "eb96c84569c926ad", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-v422-hmwv-36x6", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ce25ea0359474940", "level": "error", "message": {"text": "Vulnerable dependency brace-expansion 1.1.12: GHSA-3jxr-9vmj-r5cp"}, "properties": {"repobilityId": "5d2ce580505ef5a7", "scanner": "scanner-primary", "fingerprint": "ce25ea0359474940", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3jxr-9vmj-r5cp", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-20cefe2b2f05f230", "level": "warning", "message": {"text": "Vulnerable dependency brace-expansion 1.1.12: GHSA-f886-m6hf-6m8v"}, "properties": {"repobilityId": "c4fa6cea7167ee7e", "scanner": "scanner-primary", "fingerprint": "20cefe2b2f05f230", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-f886-m6hf-6m8v", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c3c27ce3d333950a", "level": "error", "message": {"text": "Vulnerable dependency brace-expansion 1.1.12: GHSA-mh99-v99m-4gvg"}, "properties": {"repobilityId": "0fc24bfbdae70a7f", "scanner": "scanner-primary", "fingerprint": "c3c27ce3d333950a", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-mh99-v99m-4gvg", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d52932e319415dfa", "level": "warning", "message": {"text": "Vulnerable dependency brace-expansion 1.1.12: GHSA-rgw5-rvv9-x895"}, "properties": {"repobilityId": "3d617062bafcab77", "scanner": "scanner-primary", "fingerprint": "d52932e319415dfa", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-rgw5-rvv9-x895", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f5979ec0975c056f", "level": "warning", "message": {"text": "Vulnerable dependency qs 6.14.1: GHSA-q8mj-m7cp-5q26"}, "properties": {"repobilityId": "1f0b8b0f86313e91", "scanner": "scanner-primary", "fingerprint": "f5979ec0975c056f", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-q8mj-m7cp-5q26", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ff0ecc00cfb079ff", "level": "warning", "message": {"text": "Vulnerable dependency qs 6.14.1: GHSA-w7fw-mjwx-w883"}, "properties": {"repobilityId": "837b12f962a87956", "scanner": "scanner-primary", "fingerprint": "ff0ecc00cfb079ff", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-w7fw-mjwx-w883", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e1f05ea9f18fb0bc", "level": "warning", "message": {"text": "Vulnerable dependency immutable 5.1.5: GHSA-v56q-mh7h-f735"}, "properties": {"repobilityId": "f3c0824efc06e059", "scanner": "scanner-primary", "fingerprint": "e1f05ea9f18fb0bc", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-v56q-mh7h-f735", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8955a8eb7390072d", "level": "warning", "message": {"text": "Vulnerable dependency immutable 5.1.5: GHSA-xvcm-6775-5m9r"}, "properties": {"repobilityId": "4fbb7ced729a6b8f", "scanner": "scanner-primary", "fingerprint": "8955a8eb7390072d", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-xvcm-6775-5m9r", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0f6034232fb36527", "level": "error", "message": {"text": "Vulnerable dependency js-yaml 4.1.1: GHSA-52cp-r559-cp3m"}, "properties": {"repobilityId": "bb9354b1169e66e2", "scanner": "scanner-primary", "fingerprint": "0f6034232fb36527", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-52cp-r559-cp3m", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a4bcd16c73faf375", "level": "error", "message": {"text": "Vulnerable dependency js-yaml 4.1.1: GHSA-5p4m-2wfm-xmqj"}, "properties": {"repobilityId": "d199cdf9944050fc", "scanner": "scanner-primary", "fingerprint": "a4bcd16c73faf375", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-5p4m-2wfm-xmqj", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f7976c1931edafe3", "level": "warning", "message": {"text": "Vulnerable dependency js-yaml 4.1.1: GHSA-h67p-54hq-rp68"}, "properties": {"repobilityId": "2e7af66f705e9148", "scanner": "scanner-primary", "fingerprint": "f7976c1931edafe3", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-h67p-54hq-rp68", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6917ce00235b7ac3", "level": "warning", "message": {"text": "Dependency @mui/icons-material is two or more major versions behind"}, "properties": {"repobilityId": "6a92464d8f42d459", "scanner": "scanner-primary", "fingerprint": "6917ce00235b7ac3", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d84dbf3b35980e3a", "level": "warning", "message": {"text": "Dependency @mui/material is two or more major versions behind"}, "properties": {"repobilityId": "ee9832db73053bc3", "scanner": "scanner-primary", "fingerprint": "d84dbf3b35980e3a", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-115872a4c1a69c5f", "level": "warning", "message": {"text": "Dependency @mui/x-tree-view is two or more major versions behind"}, "properties": {"repobilityId": "3bc1bcafd8e9e25d", "scanner": "scanner-primary", "fingerprint": "115872a4c1a69c5f", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d9f73af3cf2f8c3b", "level": "note", "message": {"text": "Dependency codemirror is a major version behind"}, "properties": {"repobilityId": "f23fcefa244c926e", "scanner": "scanner-primary", "fingerprint": "d9f73af3cf2f8c3b", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0af119d0214d43e3", "level": "warning", "message": {"text": "Dependency d3 is two or more major versions behind"}, "properties": {"repobilityId": "454d368037b96832", "scanner": "scanner-primary", "fingerprint": "0af119d0214d43e3", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-955fc71664e303f6", "level": "warning", "message": {"text": "Dependency i18next is two or more major versions behind"}, "properties": {"repobilityId": "6cd4da26fb61ff7f", "scanner": "scanner-primary", "fingerprint": "955fc71664e303f6", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-211258d3bc61625a", "level": "note", "message": {"text": "Dependency jquery is a major version behind"}, "properties": {"repobilityId": "834b55a5ffc70d29", "scanner": "scanner-primary", "fingerprint": "211258d3bc61625a", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7222b006d5f3157b", "level": "note", "message": {"text": "Dependency js-cookie is a major version behind"}, "properties": {"repobilityId": "f65bec46f719543b", "scanner": "scanner-primary", "fingerprint": "7222b006d5f3157b", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7a434064dbdddea5", "level": "warning", "message": {"text": "Dependency marked is two or more major versions behind"}, "properties": {"repobilityId": "1fc989546cc29353", "scanner": "scanner-primary", "fingerprint": "7a434064dbdddea5", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8dcbbd3671fd2355", "level": "warning", "message": {"text": "Dependency next is two or more major versions behind"}, "properties": {"repobilityId": "79dfea6020af54f3", "scanner": "scanner-primary", "fingerprint": "8dcbbd3671fd2355", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ae5816ddc8134efe", "level": "note", "message": {"text": "Dependency react-diff-viewer-continued is a major version behind"}, "properties": {"repobilityId": "d247f4a32629bb8e", "scanner": "scanner-primary", "fingerprint": "ae5816ddc8134efe", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8c0d634ee4bf63de", "level": "note", "message": {"text": "Dependency react-dom is a major version behind"}, "properties": {"repobilityId": "40460699c823d617", "scanner": "scanner-primary", "fingerprint": "8c0d634ee4bf63de", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d8beeec900eecdaa", "level": "note", "message": {"text": "Dependency react-ga4 is a major version behind"}, "properties": {"repobilityId": "ad116423a2794f2a", "scanner": "scanner-primary", "fingerprint": "d8beeec900eecdaa", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c4b3a90cd4ee58b8", "level": "warning", "message": {"text": "Dependency react-i18next is two or more major versions behind"}, "properties": {"repobilityId": "a7d86a00f6fbce79", "scanner": "scanner-primary", "fingerprint": "c4b3a90cd4ee58b8", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3c44bc19f695e001", "level": "note", "message": {"text": "Dependency react-icons is a major version behind"}, "properties": {"repobilityId": "6473a1519bc9bd92", "scanner": "scanner-primary", "fingerprint": "3c44bc19f695e001", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-69046c46d9ea5d69", "level": "warning", "message": {"text": "Dependency react-toastify is two or more major versions behind"}, "properties": {"repobilityId": "645b1562d0357d96", "scanner": "scanner-primary", "fingerprint": "69046c46d9ea5d69", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-191355cb039b823e", "level": "note", "message": {"text": "Dependency react-zoom-pan-pinch is a major version behind"}, "properties": {"repobilityId": "fe1b8a398d4129b5", "scanner": "scanner-primary", "fingerprint": "191355cb039b823e", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e675a30e79a4432b", "level": "note", "message": {"text": "Dependency react is a major version behind"}, "properties": {"repobilityId": "9ade52fdb0217eaa", "scanner": "scanner-primary", "fingerprint": "e675a30e79a4432b", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-99123909e554d909", "level": "note", "message": {"text": "Dependency recharts is a major version behind"}, "properties": {"repobilityId": "d424c84623a89580", "scanner": "scanner-primary", "fingerprint": "99123909e554d909", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "webgui-new/package.json"}, "region": {"startLine": 1}}}]}]}]}