{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "foundry_unresolved_feedback", "name": "Foundry mined unresolved feedback: vibedeckx/vibedeckx", "shortDescription": {"text": "Foundry mined unresolved feedback: vibedeckx/vibedeckx"}, "fullDescription": {"text": "Graph query export: Human feedback without linked fix evidence\nQuery id: unresolved_feedback\nQuery type: motif_query\nIntent: Negative/unresolved examples that should not be hallucinated into fixes.\nMotif: unlinked_feedback_needs_evidence\nTraining usage: negative_or_unresolved\nGraph gold label: assumption_check\nRepo: vibedeckx/vibedeckx\nThread: vibedeckx/vibedeckx#2\nEvidence:\nGraph motif: Human feedback exists without a linked fix\nMotif id: unlinked_feedback_needs_evidence\nPolarity: bad\nTraining usage: negative_or_unresolved\nSeverity: medium\nRepo: vibedeckx/vibedeckx\nThread: vibedeckx/vibedeckx#2\nGraph gold label: assumption_check\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: vibedeckx/vibedeckx#2\nRepo: vibedeckx/vibedeckx\nIssue/PR number: 2\nGraph consistency label: assumption_check\nNodes: 35\nEdges: 76\nNode types: {'pr_file': 20, 'link_quality': 5, 'comment': 2, 'comment_chain': 2, 'thread': 1, 'repo': 1, 'issue_chain': 1, 'fix_outcome': 1, 'alignment': 1, 'blueprint_"}, "properties": {"scanner": "foundry_dataset", "category": "practices", "severity": "medium", "confidence": 0.7, "cwe": "", "owasp": ""}}, {"id": "foundry_blueprint_gap", "name": "Foundry mined blueprint gap alignment: vibedeckx/vibedeckx", "shortDescription": {"text": "Foundry mined blueprint gap alignment: vibedeckx/vibedeckx"}, "fullDescription": {"text": "Graph query export: Human feedback aligned with blueprint or architecture gaps\nQuery id: blueprint_gap_alignment\nQuery type: motif_query\nIntent: Curriculum-gap examples connecting issue threads to helicopter-view gaps.\nMotif: blueprint_gap_alignment\nTraining usage: curriculum_gap\nGraph gold label: assumption_check\nRepo: vibedeckx/vibedeckx\nThread: vibedeckx/vibedeckx#2\nEvidence:\nGraph motif: Human feedback aligns with blueprint or architecture gaps\nMotif id: blueprint_gap_alignment\nPolarity: mixed\nTraining usage: curriculum_gap\nSeverity: medium\nRepo: vibedeckx/vibedeckx\nThread: vibedeckx/vibedeckx#2\nGraph gold label: assumption_check\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: vibedeckx/vibedeckx#2\nRepo: vibedeckx/vibedeckx\nIssue/PR number: 2\nGraph consistency label: assumption_check\nNodes: 35\nEdges: 76\nNode types: {'pr_file': 20, 'link_quality': 5, 'comment': 2, 'comment_chain': 2, 'thread': 1, 'repo': 1, 'issue_chain': 1, 'fix_outcome': 1, 'alignment': 1, 'bluepr"}, "properties": {"scanner": "foundry_dataset", "category": "tech_debt", "severity": "medium", "confidence": 0.7, "cwe": "", "owasp": ""}}, {"id": "foundry_assumption_check", "name": "Foundry mined assumption checks: vibedeckx/vibedeckx", "shortDescription": {"text": "Foundry mined assumption checks: vibedeckx/vibedeckx"}, "fullDescription": {"text": "Comment chain pattern product: assumption_checks\nRepo: vibedeckx/vibedeckx\nThread: vibedeckx/vibedeckx#3\nOutcome: claimed_resolved_unverified\nThread label: thread_has_human_issue_and_fix_context\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, repo_has_isolated_helicopter_views, link_quality_high_confidence, high_risk_human_feedback_label\nChain evidence:\nIssue/PR evidence chain: vibedeckx/vibedeckx#3\nRepo: vibedeckx/vibedeckx\nThread label: thread_has_human_issue_and_fix_context\nOutcome: claimed_resolved_unverified\nComment count: 1\nLinked commit count: 1\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 1\nLabels: {'security_auth_secret': 1}\nPolarities: {'bad': 1}\nChanged file labels: {'api_or_backend': 1}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-67e78e1f66ce5467\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"security_auth_secret\",\n    \"polarity\": \"bad\",\n    \"url\": \"https:/"}, "properties": {"scanner": "foundry_dataset", "category": "practices", "severity": "medium", "confidence": 0.62, "cwe": "", "owasp": ""}}, {"id": "foundry_bad_chain", "name": "Foundry mined bad chains: vibedeckx/vibedeckx", "shortDescription": {"text": "Foundry mined bad chains: vibedeckx/vibedeckx"}, "fullDescription": {"text": "Comment chain pattern product: bad_chains\nRepo: vibedeckx/vibedeckx\nThread: vibedeckx/vibedeckx#2\nOutcome: not_resolved_or_not_observed\nThread label: thread_has_human_issue_without_fix_context\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, repo_has_isolated_helicopter_views, link_quality_unresolved, high_risk_human_feedback_label\nChain evidence:\nIssue/PR evidence chain: vibedeckx/vibedeckx#2\nRepo: vibedeckx/vibedeckx\nThread label: thread_has_human_issue_without_fix_context\nOutcome: not_resolved_or_not_observed\nComment count: 2\nLinked commit count: 0\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 20\nLabels: {'security_auth_secret': 1, 'api_integration_gap': 1}\nPolarities: {'bad': 2}\nChanged file labels: {'ui_or_frontend': 20}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-4cb7403fc1f1c8ec\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"security_auth_secret\",\n    \"polarity\": "}, "properties": {"scanner": "foundry_dataset", "category": "practices", "severity": "high", "confidence": 0.84, "cwe": "", "owasp": ""}}, {"id": "foundry_auth_guardrail_gap", "name": "Foundry mined security auth guardrail gaps: vibedeckx/vibedeckx", "shortDescription": {"text": "Foundry mined security auth guardrail gaps: vibedeckx/vibedeckx"}, "fullDescription": {"text": "Graph query export: Security/auth changes without enough guardrails\nQuery id: security_auth_guardrail_gaps\nQuery type: motif_query\nIntent: Assumption-check security/auth examples requiring stronger tests or CI.\nMotif: security_auth_without_guardrails\nTraining usage: assumption_check\nGraph gold label: supported_by_high_confidence_link\nRepo: vibedeckx/vibedeckx\nThread: vibedeckx/vibedeckx#3\nEvidence:\nGraph motif: Security/auth change without enough guardrails\nMotif id: security_auth_without_guardrails\nPolarity: bad\nTraining usage: assumption_check\nSeverity: critical\nRepo: vibedeckx/vibedeckx\nThread: vibedeckx/vibedeckx#3\nGraph gold label: supported_by_high_confidence_link\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: vibedeckx/vibedeckx#3\nRepo: vibedeckx/vibedeckx\nIssue/PR number: 3\nGraph consistency label: supported_by_high_confidence_link\nNodes: 11\nEdges: 15\nNode types: {'link_quality': 3, 'thread': 1, 'repo': 1, 'comment': 1, 'pr_file': 1, 'comment_chain': 1, 'commi"}, "properties": {"scanner": "foundry_dataset", "category": "auth", "severity": "critical", "confidence": 0.78, "cwe": "", "owasp": ""}}, {"id": "scanner-c9eba30c8392eb0a", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/settings/settings-shell.tsx:218", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/settings/settings-shell.tsx:218"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2706ab4571a7d872", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/settings/settings-dialog.tsx:198", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/settings/settings-dialog.tsx:198"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c08a52a51516440b", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/layout/app-sidebar.tsx:126", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/layout/app-sidebar.tsx:126"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1218bbf04bc49caf", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/layout/completion-notifications-menu.t", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/layout/completion-notifications-menu.tsx:154"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6792b56ce1561a5e", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/layout/page-header.tsx:23", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/layout/page-header.tsx:23"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-119c8dbe232eb463", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/agent/vpaste-chip.tsx:30", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/agent/vpaste-chip.tsx:30"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-98ff7825d598d104", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/agent/web-fetch-tools.tsx:55", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/agent/web-fetch-tools.tsx:55"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-720013e488d42022", "name": "TODO/FIXME marker in shipping code \u2014 apps/vibedeckx-ui/components/agent/agent-conversation.tsx:95", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 apps/vibedeckx-ui/components/agent/agent-conversation.tsx:95"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d0a75e6b0c5c2a37", "name": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/components/agent/agent-conversation.tsx:516", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/components/agent/agent-conversation.tsx:516"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4b3f5f5f4153503b", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/agent/session-history-dropdown.tsx:190", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/agent/session-history-dropdown.tsx:190"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a2907788eca217f9", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/agent/skill-tools.tsx:37", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/agent/skill-tools.tsx:37"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0fe919a247a9247b", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/task/task-row.tsx:93", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/task/task-row.tsx:93"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-54aeeb1406d2e842", "name": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/components/conversation/main-conversation.tsx:48", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/components/conversation/main-conversation.tsx:48"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-183a2e4cba2e5c2c", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/files/file-preview.tsx:250", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/files/file-preview.tsx:250"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a5256b75c9584ee8", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/terminal/terminal-panel.tsx:140", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/terminal/terminal-panel.tsx:140"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-77d7661b0b2ee006", "name": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/components/executor/executor-output.tsx:48", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/components/executor/executor-output.tsx:48"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7d1422fdf598299c", "name": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/components/executor/executor-item.tsx:91", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/components/executor/executor-item.tsx:91"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-285bb428236f675b", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/diff/commit-selector.tsx:47", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/diff/commit-selector.tsx:47"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d869cd00fe2cf443", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/diff/file-diff.tsx:40", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/diff/file-diff.tsx:40"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6d5348521be80602", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 apps/vibedeckx-ui/components/ai-elements/code-block.tsx:114", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 apps/vibedeckx-ui/components/ai-elements/code-block.tsx:114"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3a9b735945aec408", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/ai-elements/queue.tsx:178", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/ai-elements/queue.tsx:178"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d131015e281826c7", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/ai-elements/prompt-input.tsx:342", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/ai-elements/prompt-input.tsx:342"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b47550fd0a8e2a47", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/ai-elements/inline-citation.tsx:257", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/ai-elements/inline-citation.tsx:257"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9bb21f9786e1f83e", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/project/create-worktree-dialog.tsx:225", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/project/create-worktree-dialog.tsx:225"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-858f2067b97f8421", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/project/remote-directory-browser.tsx:1", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/project/remote-directory-browser.tsx:134"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-181f9958d4ecce3f", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/project/project-card.tsx:291", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/project/project-card.tsx:291"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-24cdea83c85ffb00", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/project/create-project-dialog.tsx:287", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/project/create-project-dialog.tsx:287"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2f87e34d399b259d", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/project/project-settings-form.tsx:442", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/project/project-settings-form.tsx:442"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ebb2ee56829fee99", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 apps/vibedeckx-ui/app/layout.tsx:65", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 apps/vibedeckx-ui/app/layout.tsx:65"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-12eb0102e2344fec", "name": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/hooks/use-executor-logs.ts:81", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/hooks/use-executor-logs.ts:81"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6d377af6e691a4dd", "name": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/hooks/use-executors.ts:108", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/hooks/use-executors.ts:108"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-70f3ca0c57b8cd7b", "name": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/hooks/use-agent-session.ts:265", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/hooks/use-agent-session.ts:265"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-285473dc03079163", "name": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/hooks/use-chat-session.ts:253", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/hooks/use-chat-session.ts:253"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9631aab1a60f1ef1", "name": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/hooks/executor-logs-context.tsx:89", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/hooks/executor-logs-context.tsx:89"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f96437a6ee23ef19", "name": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/hooks/use-completion-notifications.ts:138", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/hooks/use-completion-notifications.ts:138"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-63e4b75b300b9621", "name": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/instrumentation.ts:15", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/instrumentation.ts:15"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-125290b5efa01cda", "name": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/event-bus.ts:24", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/event-bus.ts:24"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6f02078436fcd59b", "name": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/reverse-connect-manager.ts:79", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/reverse-connect-manager.ts:79"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d3e1dc2d545fbefa", "name": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/process-manager.ts:64", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/process-manager.ts:64"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a4a368b3989bda7c", "name": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/agent-session-manager.ts:187", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/agent-session-manager.ts:187"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8b59f0a7c219a7a5", "name": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/reverse-connect-client.ts:42", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/reverse-connect-client.ts:42"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c4a8546d22db03ea", "name": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/command.ts:135", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/command.ts:135"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4569d41569a5a4b7", "name": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/server.ts:138", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/server.ts:138"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4861a5b1b7dce80f", "name": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/chat-session-manager.ts:227", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/chat-session-manager.ts:227"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-510739e268fc5692", "name": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/browser-manager.ts:122", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/browser-manager.ts:122"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aff7066a87c37dd3", "name": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/utils/remote-proxy.ts:91", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/utils/remote-proxy.ts:91"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e39d730e7a1be9f2", "name": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/providers/codex-provider.ts:44", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/providers/codex-provider.ts:44"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2634b2ce39ff4eef", "name": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/providers/claude-code-provider.ts:28", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/providers/claude-code-provider.ts:28"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-988613b055082aa8", "name": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/browser-routes.ts:112", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/browser-routes.ts:112"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-24d88de12b4197f3", "name": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/terminal-routes.ts:180", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/terminal-routes.ts:180"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dc0fcba6f6c55786", "name": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/executor-stream-handlers.ts:109", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/executor-stream-handlers.ts:109"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-408079223c76fde3", "name": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/reverse-connect-routes.ts:38", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/reverse-connect-routes.ts:38"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-31871fdaca0fa83b", "name": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/websocket-routes.ts:62", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/websocket-routes.ts:62"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9d9b98941735820c", "name": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/settings-routes.ts:118", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/settings-routes.ts:118"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8b64d015a2bad6a6", "name": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/browser-proxy-routes.ts:492", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/browser-proxy-routes.ts:492"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8eccd08094155bc4", "name": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/process-routes.ts:74", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/process-routes.ts:74"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0d6d662825c0d6a7", "name": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/worktree-routes.ts:116", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/worktree-routes.ts:116"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9407734cce283124", "name": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/agent-session-routes.ts:167", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/agent-session-routes.ts:167"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d55bd8d2cb00b558", "name": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/plugins/shared-services.ts:51", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/plugins/shared-services.ts:51"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-55c1469e4a245f27", "name": "Insecure pattern 'dangerous_innerhtml' in apps/vibedeckx-ui/components/ai-elements/code-block.tsx:114", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in apps/vibedeckx-ui/components/ai-elements/code-block.tsx:114"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fb18e8bea57f6f94", "name": "Insecure pattern 'dangerous_innerhtml' in apps/vibedeckx-ui/app/layout.tsx:65", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in apps/vibedeckx-ui/app/layout.tsx:65"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6ddb459a27b5354d", "name": "Insecure pattern 'node_child_process' in packages/vibedeckx/src/process-manager.ts:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in packages/vibedeckx/src/process-manager.ts:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-95db8ef9313bf07b", "name": "Insecure pattern 'node_child_process' in packages/vibedeckx/src/dialog.ts:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in packages/vibedeckx/src/dialog.ts:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-461aa64725d7e268", "name": "Insecure pattern 'node_child_process' in packages/vibedeckx/src/agent-session-manager.ts:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in packages/vibedeckx/src/agent-session-manager.ts:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-33a7795c897da106", "name": "Insecure pattern 'cors_wildcard' in packages/vibedeckx/src/server.ts:146", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in packages/vibedeckx/src/server.ts:146"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6b580f0972fb7bd3", "name": "Insecure pattern 'node_child_process' in packages/vibedeckx/src/utils/worktree-paths.ts:3", "shortDescription": {"text": "Insecure pattern 'node_child_process' in packages/vibedeckx/src/utils/worktree-paths.ts:3"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-98aa4a309bb8c175", "name": "Insecure pattern 'node_child_process' in packages/vibedeckx/src/providers/codex-provider.ts:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in packages/vibedeckx/src/providers/codex-provider.ts:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-674411e63192ae9d", "name": "Insecure pattern 'node_child_process' in packages/vibedeckx/src/providers/claude-code-provider.ts:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in packages/vibedeckx/src/providers/claude-code-provider.ts:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-73b6f9704958ad5a", "name": "Insecure pattern 'exec_used' in packages/vibedeckx/src/routes/project-routes.ts:306", "shortDescription": {"text": "Insecure pattern 'exec_used' in packages/vibedeckx/src/routes/project-routes.ts:306"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fc32502ff14cfa66", "name": "Insecure pattern 'node_child_process' in packages/vibedeckx/src/routes/project-routes.ts:5", "shortDescription": {"text": "Insecure pattern 'node_child_process' in packages/vibedeckx/src/routes/project-routes.ts:5"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ac3bf87e223070f4", "name": "Insecure pattern 'cors_wildcard' in packages/vibedeckx/src/routes/event-routes.ts:55", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in packages/vibedeckx/src/routes/event-routes.ts:55"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-46c644c6227e4d4a", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/upload-artifact@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1838a141491ce38c", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-be55e936fb753833", "name": "package.json defines install-time lifecycle scripts", "shortDescription": {"text": "package.json defines install-time lifecycle scripts"}, "fullDescription": {"text": "preinstall/install/postinstall/prepare scripts execute during dependency installation. Review them carefully for network calls, obfuscation, shell execution, or credential access."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1ebdf89ff14bbdfe", "name": "Very large file: apps/vibedeckx-ui/components/auth/landing-page.tsx (1956 lines)", "shortDescription": {"text": "Very large file: apps/vibedeckx-ui/components/auth/landing-page.tsx (1956 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7767a11fa8fd8420", "name": "Very large file: apps/vibedeckx-ui/lib/api.ts (1648 lines)", "shortDescription": {"text": "Very large file: apps/vibedeckx-ui/lib/api.ts (1648 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-285f2bdd31183ba0", "name": "Very large file: packages/vibedeckx/src/agent-session-manager.ts (1488 lines)", "shortDescription": {"text": "Very large file: packages/vibedeckx/src/agent-session-manager.ts (1488 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5e3451fde538c9c0", "name": "Very large file: packages/vibedeckx/src/chat-session-manager.ts (2449 lines)", "shortDescription": {"text": "Very large file: packages/vibedeckx/src/chat-session-manager.ts (2449 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cec7e46936dc5479", "name": "Very large file: packages/vibedeckx/src/storage/sqlite.ts (1932 lines)", "shortDescription": {"text": "Very large file: packages/vibedeckx/src/storage/sqlite.ts (1932 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "6 test file(s) for 255 source file(s) (ratio 0.02). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c20be56956c4599f", "name": "Node manifest has dependencies but no lockfile: packages/vibedeckx-win32-x64/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/vibedeckx-win32-x64/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-229553a691e66ea3", "name": "Node manifest has dependencies but no lockfile: packages/vibedeckx-darwin-arm64/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/vibedeckx-darwin-arm64/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3bdb666d48eb6176", "name": "Node manifest has dependencies but no lockfile: packages/vibedeckx-linux-x64/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/vibedeckx-linux-x64/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 314 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 86 placeholder/mock markers across 34 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9d79c4077342a7d0", "name": "Runtime service client appears to use placeholder configuration", "shortDescription": {"text": "Runtime service client appears to use placeholder configuration"}, "fullDescription": {"text": "A runtime source file appears to wire Supabase/Firebase/AI/payment-style clients to placeholder URLs, keys, or fallback values. In the Fable corpus this often means the UI/API shape is present while the backend service is not actually configured."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, lockfile. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license, lockfile. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6692eea86b8ab29e", "name": "Commented-code block (5 lines) in apps/vibedeckx-ui/components/agent/agent-conversation.tsx:135", "shortDescription": {"text": "Commented-code block (5 lines) in apps/vibedeckx-ui/components/agent/agent-conversation.tsx:135"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7ad73f62620e5c0a", "name": "Commented-code block (5 lines) in apps/vibedeckx-ui/components/agent/session-history-dropdown.tsx:57", "shortDescription": {"text": "Commented-code block (5 lines) in apps/vibedeckx-ui/components/agent/session-history-dropdown.tsx:57"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7f310455ddd24e93", "name": "Commented-code block (6 lines) in apps/vibedeckx-ui/components/files/file-preview.tsx:99", "shortDescription": {"text": "Commented-code block (6 lines) in apps/vibedeckx-ui/components/files/file-preview.tsx:99"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2699d856eef2f708", "name": "Commented-code block (7 lines) in apps/vibedeckx-ui/components/executor/executor-output.tsx:190", "shortDescription": {"text": "Commented-code block (7 lines) in apps/vibedeckx-ui/components/executor/executor-output.tsx:190"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-70a3b5da0e883a2f", "name": "Commented-code block (5 lines) in apps/vibedeckx-ui/components/executor/executor-item.tsx:99", "shortDescription": {"text": "Commented-code block (5 lines) in apps/vibedeckx-ui/components/executor/executor-item.tsx:99"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5cefe91950ab346d", "name": "Commented-code block (7 lines) in apps/vibedeckx-ui/app/page.tsx:119", "shortDescription": {"text": "Commented-code block (7 lines) in apps/vibedeckx-ui/app/page.tsx:119"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-fe0b7b2e8f044743", "name": "Commented-code block (5 lines) in apps/vibedeckx-ui/lib/api.ts:203", "shortDescription": {"text": "Commented-code block (5 lines) in apps/vibedeckx-ui/lib/api.ts:203"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7ae8fc828852e85d", "name": "`fetch()` without try/.catch or AbortSignal \u2014 apps/vibedeckx-ui/lib/api.ts:48", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/vibedeckx-ui/lib/api.ts:48"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-16159c665f53db0f", "name": "Commented-code block (6 lines) in apps/vibedeckx-ui/lib/workspace-status.test.ts:137", "shortDescription": {"text": "Commented-code block (6 lines) in apps/vibedeckx-ui/lib/workspace-status.test.ts:137"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-479333dd8d8ff13d", "name": "Commented-code block (5 lines) in apps/vibedeckx-ui/hooks/use-worktrees.ts:17", "shortDescription": {"text": "Commented-code block (5 lines) in apps/vibedeckx-ui/hooks/use-worktrees.ts:17"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f306a569c6ff37ac", "name": "Commented-code block (5 lines) in apps/vibedeckx-ui/hooks/use-marker-keyboard-nav.ts:4", "shortDescription": {"text": "Commented-code block (5 lines) in apps/vibedeckx-ui/hooks/use-marker-keyboard-nav.ts:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4e6417c07bac7dd7", "name": "Commented-code block (6 lines) in apps/vibedeckx-ui/hooks/use-agent-session.ts:376", "shortDescription": {"text": "Commented-code block (6 lines) in apps/vibedeckx-ui/hooks/use-agent-session.ts:376"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-77affce6f337685c", "name": "`fetch()` without try/.catch or AbortSignal \u2014 apps/vibedeckx-ui/hooks/use-agent-session.ts:108", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/vibedeckx-ui/hooks/use-agent-session.ts:108"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a945bbe0273dd11a", "name": "`fetch()` without try/.catch or AbortSignal \u2014 apps/vibedeckx-ui/hooks/use-chat-session.ts:90", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/vibedeckx-ui/hooks/use-chat-session.ts:90"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f7e6d4ce2baed8f4", "name": "Commented-code block (5 lines) in apps/vibedeckx-ui/hooks/use-branch-activity.test.ts:34", "shortDescription": {"text": "Commented-code block (5 lines) in apps/vibedeckx-ui/hooks/use-branch-activity.test.ts:34"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e2ee3bef2b4bb289", "name": "Commented-code block (5 lines) in apps/vibedeckx-ui/hooks/use-completion-notifications.ts:13", "shortDescription": {"text": "Commented-code block (5 lines) in apps/vibedeckx-ui/hooks/use-completion-notifications.ts:13"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3939eb50a80df926", "name": "Commented-code block (6 lines) in packages/vibedeckx/src/agent-session-manager.ts:229", "shortDescription": {"text": "Commented-code block (6 lines) in packages/vibedeckx/src/agent-session-manager.ts:229"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cd155529e9d941be", "name": "`fetch()` without try/.catch or AbortSignal \u2014 packages/vibedeckx/src/reverse-connect-client.ts:173", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/vibedeckx/src/reverse-connect-client.ts:173"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-29a61a7128ded508", "name": "Commented-code block (11 lines) in packages/vibedeckx/src/command.ts:114", "shortDescription": {"text": "Commented-code block (11 lines) in packages/vibedeckx/src/command.ts:114"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d614e67af007fe46", "name": "Commented-code block (5 lines) in packages/vibedeckx/src/server.ts:48", "shortDescription": {"text": "Commented-code block (5 lines) in packages/vibedeckx/src/server.ts:48"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2df5e9f1eeca8654", "name": "Commented-code block (7 lines) in packages/vibedeckx/src/chat-session-manager.ts:278", "shortDescription": {"text": "Commented-code block (7 lines) in packages/vibedeckx/src/chat-session-manager.ts:278"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-684bf33be7d5d812", "name": "`fetch()` without try/.catch or AbortSignal \u2014 packages/vibedeckx/src/utils/remote-proxy.ts:88", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/vibedeckx/src/utils/remote-proxy.ts:88"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4f74f120966a2004", "name": "Commented-code block (5 lines) in packages/vibedeckx/src/routes/executor-routes.ts:8", "shortDescription": {"text": "Commented-code block (5 lines) in packages/vibedeckx/src/routes/executor-routes.ts:8"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-36c1271a4a46eee3", "name": "Commented-code block (6 lines) in packages/vibedeckx/src/routes/terminal-routes.ts:222", "shortDescription": {"text": "Commented-code block (6 lines) in packages/vibedeckx/src/routes/terminal-routes.ts:222"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-69ed5784c9be45fe", "name": "Commented-code block (5 lines) in packages/vibedeckx/src/routes/websocket-routes.ts:171", "shortDescription": {"text": "Commented-code block (5 lines) in packages/vibedeckx/src/routes/websocket-routes.ts:171"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8b9f11dea48d99fb", "name": "`fetch()` without try/.catch or AbortSignal \u2014 packages/vibedeckx/src/routes/settings-routes.ts:158", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/vibedeckx/src/routes/settings-routes.ts:158"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3e378f03c0bb72b5", "name": "Commented-code block (6 lines) in packages/vibedeckx/src/routes/browser-proxy-routes.ts:253", "shortDescription": {"text": "Commented-code block (6 lines) in packages/vibedeckx/src/routes/browser-proxy-routes.ts:253"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-14285d2122be61cd", "name": "`fetch()` without try/.catch or AbortSignal \u2014 packages/vibedeckx/src/routes/browser-proxy-routes.ts:106", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/vibedeckx/src/routes/browser-proxy-routes.ts:106"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e389a5325763af21", "name": "Commented-code block (5 lines) in packages/vibedeckx/src/routes/branch-activity-routes.ts:88", "shortDescription": {"text": "Commented-code block (5 lines) in packages/vibedeckx/src/routes/branch-activity-routes.ts:88"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5d62399be6286ea8", "name": "Commented-code block (5 lines) in packages/vibedeckx/src/routes/agent-session-routes.ts:32", "shortDescription": {"text": "Commented-code block (5 lines) in packages/vibedeckx/src/routes/agent-session-routes.ts:32"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5b609a86662be8d3", "name": "Commented-code block (10 lines) in packages/vibedeckx/src/plugins/shared-services.ts:96", "shortDescription": {"text": "Commented-code block (10 lines) in packages/vibedeckx/src/plugins/shared-services.ts:96"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-92d7b6830d321840", "name": "Unused endpoint: OPTIONS /*", "shortDescription": {"text": "Unused endpoint: OPTIONS /*"}, "fullDescription": {"text": "`packages/vibedeckx/src/server.ts` declares `OPTIONS /*` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7aa4b2518cbbbfa2", "name": "Unused endpoint: GET /api/config", "shortDescription": {"text": "Unused endpoint: GET /api/config"}, "fullDescription": {"text": "`packages/vibedeckx/src/server.ts` declares `GET /api/config` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3b94923f366fed0e", "name": "Unused endpoint: GET /api/projects", "shortDescription": {"text": "Unused endpoint: GET /api/projects"}, "fullDescription": {"text": "`packages/vibedeckx/src/routes/project-routes.ts` declares `GET /api/projects` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-93f41488d82ae3b2", "name": "Unused endpoint: POST /api/dialog/select-folder", "shortDescription": {"text": "Unused endpoint: POST /api/dialog/select-folder"}, "fullDescription": {"text": "`packages/vibedeckx/src/routes/project-routes.ts` declares `POST /api/dialog/select-folder` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ca409df5c58a3acb", "name": "Unused endpoint: GET /api/settings/proxy", "shortDescription": {"text": "Unused endpoint: GET /api/settings/proxy"}, "fullDescription": {"text": "`packages/vibedeckx/src/routes/settings-routes.ts` declares `GET /api/settings/proxy` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5c5618ac61014f30", "name": "Unused endpoint: GET /api/settings/chat-provider", "shortDescription": {"text": "Unused endpoint: GET /api/settings/chat-provider"}, "fullDescription": {"text": "`packages/vibedeckx/src/routes/settings-routes.ts` declares `GET /api/settings/chat-provider` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b3d2bf498d0843f8", "name": "Unused endpoint: GET /api/settings/terminal", "shortDescription": {"text": "Unused endpoint: GET /api/settings/terminal"}, "fullDescription": {"text": "`packages/vibedeckx/src/routes/settings-routes.ts` declares `GET /api/settings/terminal` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d40f65144ec255e8", "name": "Unused endpoint: GET /api/settings/conversation", "shortDescription": {"text": "Unused endpoint: GET /api/settings/conversation"}, "fullDescription": {"text": "`packages/vibedeckx/src/routes/settings-routes.ts` declares `GET /api/settings/conversation` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c3c4aad67099794e", "name": "Unused endpoint: GET /api/executor-processes/running", "shortDescription": {"text": "Unused endpoint: GET /api/executor-processes/running"}, "fullDescription": {"text": "`packages/vibedeckx/src/routes/process-routes.ts` declares `GET /api/executor-processes/running` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-95322da25eed4d22", "name": "Unused endpoint: GET /api/remote-servers", "shortDescription": {"text": "Unused endpoint: GET /api/remote-servers"}, "fullDescription": {"text": "`packages/vibedeckx/src/routes/remote-server-routes.ts` declares `GET /api/remote-servers` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e47ff33f50d81527", "name": "Unused endpoint: POST /api/remote-servers", "shortDescription": {"text": "Unused endpoint: POST /api/remote-servers"}, "fullDescription": {"text": "`packages/vibedeckx/src/routes/remote-server-routes.ts` declares `POST /api/remote-servers` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e7095e7afa6f36f9", "name": "Unused endpoint: GET /api/agent-providers", "shortDescription": {"text": "Unused endpoint: GET /api/agent-providers"}, "fullDescription": {"text": "`packages/vibedeckx/src/routes/agent-session-routes.ts` declares `GET /api/agent-providers` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/22184"}, "properties": {"repository": "vibedeckx/vibedeckx", "repoUrl": "https://github.com/vibedeckx/vibedeckx", "branch": "main"}, "results": [{"ruleId": "foundry_unresolved_feedback", "level": "warning", "message": {"text": "Foundry mined unresolved feedback: vibedeckx/vibedeckx"}, "properties": {"repobilityId": 467407, "scanner": "foundry_dataset", "fingerprint": "5605d3ced7b45982b9f9c115c37ee5be7b36d9d8acf390fba79ec74d2afa62cd", "category": "practices", "severity": "medium", "confidence": 0.7, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Human feedback without linked fix evidence", "intent": "Negative/unresolved examples that should not be hallucinated into fixes.", "labels": {"ui_or_frontend": 20, "api_integration_gap": 1, "security_auth_secret": 1, "mostly follows blueprint": 1, "issue_or_pull_request_thread": 1, "not_resolved_or_not_observed": 4, "blueprint_human_gap_disagreement": 1, "human_reported_issue_no_linked_fix": 2, "thread_has_human_issue_without_fix_context": 2}, "source": "graph_query_export", "motif_id": "unlinked_feedback_needs_evidence", "outcomes": {"not_resolved_or_not_observed": 8}, "polarity": "bad", "query_id": "unresolved_feedback", "severity": "medium", "ci_labels": {}, "synthetic": false, "edge_count": 76, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 2, "thread_has_comment": 2, "thread_touches_file": 20, "alignment_uses_comment": 1, "alignment_uses_finding": 1, "chain_has_link_quality": 5, "comment_aligns_finding": 1, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 12, "thread_has_comment_chain": 2, "comment_chain_touches_file": 24, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 2}, "node_count": 35, "node_types": {"repo": 1, "thread": 1, "comment": 2, "pr_file": 20, "alignment": 1, "fix_outcome": 1, "issue_chain": 1, "link_quality": 5, "comment_chain": 2, "blueprint_finding": 1}, "query_type": "motif_query", "thread_key": "vibedeckx/vibedeckx#2", "issue_number": "2", "quality_tiers": {"unresolved": 4, "assumption_check": 1}, "repo_full_name": "vibedeckx/vibedeckx", "training_usage": "negative_or_unresolved", "source_motif_id": "graph-pattern-motif-thread-b803442dd3ca4586", "graph_gold_label": "assumption_check", "changed_file_labels": {"ui_or_frontend": 100}}, "text": "Graph query export: Human feedback without linked fix evidence\nQuery id: unresolved_feedback\nQuery type: motif_query\nIntent: Negative/unresolved examples that should not be hallucinated into fixes.\nMotif: unlinked_feedback_needs_evidence\nTraining usage: negative_or_unresolved\nGraph gold label: assumption_check\nRepo: vibedeckx/vibedeckx\nThread: vibedeckx/vibedeckx#2\nEvidence:\nGraph motif: Human feedback exists without a linked fix\nMotif id: unlinked_feedback_needs_evidence\nPolarity: bad\nTraining usage: negative_or_unresolved\nSeverity: medium\nRepo: vibedeckx/vibedeckx\nThread: vibedeckx/vibedeckx#2\nGraph gold label: assumption_check\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: vibedeckx/vibedeckx#2\nRepo: vibedeckx/vibedeckx\nIssue/PR number: 2\nGraph consistency label: assumption_check\nNodes: 35\nEdges: 76\nNode types: {'pr_file': 20, 'link_quality': 5, 'comment': 2, 'comment_chain': 2, 'thread': 1, 'repo': 1, 'issue_chain': 1, 'fix_outcome': 1, 'alignment': 1, 'blueprint_finding': 1}\nEdge types: {'comment_chain_touches_file': 24, 'thread_touches_file': 20, 'issue_chain_touches_file': 12, 'chain_has_link_quality': 5, 'thread_has_comment': 2, 'thread_has_comment_chain': 2, 'comment_has_chain': 2, 'issue_chain_has_comment_chain': 2, 'repo_has_thread': 1, 'thread_has_issue_chain': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1, 'alignment_uses_comment': 1, 'alignment_uses_finding': 1, 'comment_aligns_finding': 1}\nLabels: {'ui_or_frontend': 20, 'not_resolved_or_not_observed': 4, 'human_reported_issue_no_linked_fix': 2, 'thread_has_human_issue_without_fix_context': 2, 'issue_or_pull_request_thread': 1, 'security_auth_secret': 1, 'api_integration_gap': 1, 'blueprint_human_gap_disagreement': 1, 'mostly follows blueprint': 1}\nOutcomes: {'not_resolved_or_not_observed': 8}\nQuality tiers: {'unresolved': 4, 'assumption_check': 1}\nCI labels: {}\nCurriculum targets:\n- Teach models to preserve unresolved human feedback instead of hallucinating fixes.\n- Build issue-to-regression examples where no accepted fix exists yet.\nAssumption checks:\n- Can a commit be linked by issue number, SHA, changed path, or time window?\n- If no link exists, is this explicitly labelled unresolved?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/vibedeckx/vibedeckx", "source_id": "graph-query-motif_query-ab72476499ec54f5", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/unresolved_feedback/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "vibedeckx/vibedeckx", "source_dataset": "graph_queries/unresolved_feedback", "training_usage": "negative_or_unresolved"}}}, {"ruleId": "foundry_unresolved_feedback", "level": "warning", "message": {"text": "Foundry mined unresolved feedback: vibedeckx/vibedeckx"}, "properties": {"repobilityId": 467406, "scanner": "foundry_dataset", "fingerprint": "6d463f3909449b1d207f5b6ee5c41a6a08c7eff53704b2bd111c733fb0f3881d", "category": "practices", "severity": "medium", "confidence": 0.7, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Human feedback without linked fix evidence", "intent": "Negative/unresolved examples that should not be hallucinated into fixes.", "labels": {"test_or_ci": 1, "api_or_backend": 12, "docs_or_claims": 3, "ui_or_frontend": 32, "source_or_other": 5, "human_feedback_general": 1, "unlinked_human_feedback": 1, "thread_needs_classification": 2, "issue_or_pull_request_thread": 1, "ambiguous_needs_more_evidence": 3}, "source": "graph_query_export", "motif_id": "unlinked_feedback_needs_evidence", "outcomes": {"ambiguous_needs_more_evidence": 6}, "polarity": "bad", "query_id": "unresolved_feedback", "severity": "medium", "ci_labels": {}, "synthetic": false, "edge_count": 88, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "thread_touches_file": 53, "chain_has_link_quality": 3, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 12, "thread_has_comment_chain": 1, "comment_chain_touches_file": 12, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 62, "node_types": {"repo": 1, "thread": 1, "comment": 1, "pr_file": 53, "fix_outcome": 1, "issue_chain": 1, "link_quality": 3, "comment_chain": 1}, "query_type": "motif_query", "thread_key": "vibedeckx/vibedeckx#1", "issue_number": "1", "quality_tiers": {"unresolved": 3}, "repo_full_name": "vibedeckx/vibedeckx", "training_usage": "negative_or_unresolved", "source_motif_id": "graph-pattern-motif-thread-ae4568a0ed39abb1", "graph_gold_label": "needs_more_evidence", "changed_file_labels": {"test_or_ci": 4, "api_or_backend": 48, "docs_or_claims": 12, "ui_or_frontend": 128, "source_or_other": 20}}, "text": "Graph query export: Human feedback without linked fix evidence\nQuery id: unresolved_feedback\nQuery type: motif_query\nIntent: Negative/unresolved examples that should not be hallucinated into fixes.\nMotif: unlinked_feedback_needs_evidence\nTraining usage: negative_or_unresolved\nGraph gold label: needs_more_evidence\nRepo: vibedeckx/vibedeckx\nThread: vibedeckx/vibedeckx#1\nEvidence:\nGraph motif: Human feedback exists without a linked fix\nMotif id: unlinked_feedback_needs_evidence\nPolarity: bad\nTraining usage: negative_or_unresolved\nSeverity: medium\nRepo: vibedeckx/vibedeckx\nThread: vibedeckx/vibedeckx#1\nGraph gold label: needs_more_evidence\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: vibedeckx/vibedeckx#1\nRepo: vibedeckx/vibedeckx\nIssue/PR number: 1\nGraph consistency label: needs_more_evidence\nNodes: 62\nEdges: 88\nNode types: {'pr_file': 53, 'link_quality': 3, 'thread': 1, 'repo': 1, 'comment': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'thread_touches_file': 53, 'comment_chain_touches_file': 12, 'issue_chain_touches_file': 12, 'chain_has_link_quality': 3, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'ui_or_frontend': 32, 'api_or_backend': 12, 'source_or_other': 5, 'docs_or_claims': 3, 'ambiguous_needs_more_evidence': 3, 'thread_needs_classification': 2, 'issue_or_pull_request_thread': 1, 'human_feedback_general': 1, 'test_or_ci': 1, 'unlinked_human_feedback': 1}\nOutcomes: {'ambiguous_needs_more_evidence': 6}\nQuality tiers: {'unresolved': 3}\nCI labels: {}\nCurriculum targets:\n- Teach models to preserve unresolved human feedback instead of hallucinating fixes.\n- Build issue-to-regression examples where no accepted fix exists yet.\nAssumption checks:\n- Can a commit be linked by issue number, SHA, changed path, or time window?\n- If no link exists, is this explicitly labelled unresolved?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/vibedeckx/vibedeckx", "source_id": "graph-query-motif_query-dcca17684eae12bc", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/unresolved_feedback/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "vibedeckx/vibedeckx", "source_dataset": "graph_queries/unresolved_feedback", "training_usage": "negative_or_unresolved"}}}, {"ruleId": "foundry_blueprint_gap", "level": "warning", "message": {"text": "Foundry mined blueprint gap alignment: vibedeckx/vibedeckx"}, "properties": {"repobilityId": 450101, "scanner": "foundry_dataset", "fingerprint": "6d31ee2de1ddf3401f33b83526ec34b2c5c7009e3cc9713211b97ea4e8ac6aeb", "category": "tech_debt", "severity": "medium", "confidence": 0.7, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Human feedback aligned with blueprint or architecture gaps", "intent": "Curriculum-gap examples connecting issue threads to helicopter-view gaps.", "labels": {"ui_or_frontend": 20, "api_integration_gap": 1, "security_auth_secret": 1, "mostly follows blueprint": 1, "issue_or_pull_request_thread": 1, "not_resolved_or_not_observed": 4, "blueprint_human_gap_disagreement": 1, "human_reported_issue_no_linked_fix": 2, "thread_has_human_issue_without_fix_context": 2}, "source": "graph_query_export", "motif_id": "blueprint_gap_alignment", "outcomes": {"not_resolved_or_not_observed": 8}, "polarity": "mixed", "query_id": "blueprint_gap_alignment", "severity": "medium", "ci_labels": {}, "synthetic": false, "edge_count": 76, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 2, "thread_has_comment": 2, "thread_touches_file": 20, "alignment_uses_comment": 1, "alignment_uses_finding": 1, "chain_has_link_quality": 5, "comment_aligns_finding": 1, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 12, "thread_has_comment_chain": 2, "comment_chain_touches_file": 24, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 2}, "node_count": 35, "node_types": {"repo": 1, "thread": 1, "comment": 2, "pr_file": 20, "alignment": 1, "fix_outcome": 1, "issue_chain": 1, "link_quality": 5, "comment_chain": 2, "blueprint_finding": 1}, "query_type": "motif_query", "thread_key": "vibedeckx/vibedeckx#2", "issue_number": "2", "quality_tiers": {"unresolved": 4, "assumption_check": 1}, "repo_full_name": "vibedeckx/vibedeckx", "training_usage": "curriculum_gap", "source_motif_id": "graph-pattern-motif-thread-ef38b14dd6a03eb4", "graph_gold_label": "assumption_check", "changed_file_labels": {"ui_or_frontend": 100}}, "text": "Graph query export: Human feedback aligned with blueprint or architecture gaps\nQuery id: blueprint_gap_alignment\nQuery type: motif_query\nIntent: Curriculum-gap examples connecting issue threads to helicopter-view gaps.\nMotif: blueprint_gap_alignment\nTraining usage: curriculum_gap\nGraph gold label: assumption_check\nRepo: vibedeckx/vibedeckx\nThread: vibedeckx/vibedeckx#2\nEvidence:\nGraph motif: Human feedback aligns with blueprint or architecture gaps\nMotif id: blueprint_gap_alignment\nPolarity: mixed\nTraining usage: curriculum_gap\nSeverity: medium\nRepo: vibedeckx/vibedeckx\nThread: vibedeckx/vibedeckx#2\nGraph gold label: assumption_check\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: vibedeckx/vibedeckx#2\nRepo: vibedeckx/vibedeckx\nIssue/PR number: 2\nGraph consistency label: assumption_check\nNodes: 35\nEdges: 76\nNode types: {'pr_file': 20, 'link_quality': 5, 'comment': 2, 'comment_chain': 2, 'thread': 1, 'repo': 1, 'issue_chain': 1, 'fix_outcome': 1, 'alignment': 1, 'blueprint_finding': 1}\nEdge types: {'comment_chain_touches_file': 24, 'thread_touches_file': 20, 'issue_chain_touches_file': 12, 'chain_has_link_quality': 5, 'thread_has_comment': 2, 'thread_has_comment_chain': 2, 'comment_has_chain': 2, 'issue_chain_has_comment_chain': 2, 'repo_has_thread': 1, 'thread_has_issue_chain': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1, 'alignment_uses_comment': 1, 'alignment_uses_finding': 1, 'comment_aligns_finding': 1}\nLabels: {'ui_or_frontend': 20, 'not_resolved_or_not_observed': 4, 'human_reported_issue_no_linked_fix': 2, 'thread_has_human_issue_without_fix_context': 2, 'issue_or_pull_request_thread': 1, 'security_auth_secret': 1, 'api_integration_gap': 1, 'blueprint_human_gap_disagreement': 1, 'mostly follows blueprint': 1}\nOutcomes: {'not_resolved_or_not_observed': 8}\nQuality tiers: {'unresolved': 4, 'assumption_check': 1}\nCI labels: {}\nCurriculum targets:\n- Use helicopter-view architecture/schema/design evidence beside issue threads.\n- Teach models to compare requested product class against implementation layers.\nAssumption checks:\n- Which blueprint layer is absent: frontend, API, data, auth, tests, or deployment?\n- Does human feedback confirm the same architectural gap?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/vibedeckx/vibedeckx", "source_id": "graph-query-motif_query-da085aaee51a0bd8", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/blueprint_gap_alignment/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "vibedeckx/vibedeckx", "source_dataset": "graph_queries/blueprint_gap_alignment", "training_usage": "curriculum_gap"}}}, {"ruleId": "foundry_assumption_check", "level": "warning", "message": {"text": "Foundry mined assumption checks: vibedeckx/vibedeckx"}, "properties": {"repobilityId": 439702, "scanner": "foundry_dataset", "fingerprint": "8e43a32dd5d02eb2d74b32d008a4872bcdcc4688a13a3160277d4ccaa0862d30", "category": "practices", "severity": "medium", "confidence": 0.62, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "comment_chain_pattern_product", "source": "comment_chain_pattern_miner", "product": "assumption_checks", "synthetic": false, "thread_key": "vibedeckx/vibedeckx#3", "human_labels": ["api_or_backend", "security_auth_secret"], "issue_number": "3", "thread_label": "thread_has_human_issue_and_fix_context", "outcome_label": "claimed_resolved_unverified", "source_backed": true, "max_confidence": 0.842, "repo_full_name": "vibedeckx/vibedeckx", "training_usage": "gold_candidate", "confidence_tier": "high_confidence", "source_chain_id": "evidence-chain-issue_chain-f5fce61eeb13e624", "helicopter_views": {"graphs": 2, "schemas": 2}, "artifact_families": {"ci": 1, "docs": 3, "tests": 3, "schemas": 1}, "source_chain_kind": "issue_chain", "changed_file_count": 1, "source_graph_label": "source_backed_multi_signal_graph", "changed_file_labels": {"api_or_backend": 1}, "linked_commit_count": 1, "helicopter_view_count": 4, "source_artifact_count": 8, "classification_reasons": ["source_graph_has_real_artifacts", "source_graph_has_verification_artifacts", "repo_has_isolated_helicopter_views", "link_quality_high_confidence", "high_risk_human_feedback_label"], "linked_ci_commit_count": 0, "verification_artifact_count": 5, "design_schema_api_artifact_count": 1}, "text": "Comment chain pattern product: assumption_checks\nRepo: vibedeckx/vibedeckx\nThread: vibedeckx/vibedeckx#3\nOutcome: claimed_resolved_unverified\nThread label: thread_has_human_issue_and_fix_context\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, repo_has_isolated_helicopter_views, link_quality_high_confidence, high_risk_human_feedback_label\nChain evidence:\nIssue/PR evidence chain: vibedeckx/vibedeckx#3\nRepo: vibedeckx/vibedeckx\nThread label: thread_has_human_issue_and_fix_context\nOutcome: claimed_resolved_unverified\nComment count: 1\nLinked commit count: 1\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 1\nLabels: {'security_auth_secret': 1}\nPolarities: {'bad': 1}\nChanged file labels: {'api_or_backend': 1}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-67e78e1f66ce5467\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"security_auth_secret\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.com/vibedeckx/vibedeckx/pull/3\",\n    \"text\": \"GitHub feedback: security_auth_secret\\nPolarity: bad\\nKind: pull_request_body\\nRepo: vibedeckx/vibedeckx\\nAuthor: wjx (User)\\nURL: https://github.com/vibedeckx/vibedeckx/pull/3\\nTitle: fix(security): require auth and registered project for /api/path/upload\\nBody:\\n### Motivation\\n- Close an arbitrary file-write vector where `/api/path/upload` accepted a caller-controlled filesystem `path` and performed writes without enforcing authentication or verifying the path belonged to a registered project.\\n\\n### Description\\n- Added an authentication guard by calling `requireAuth(req, reply)` at the top of the `/api/path/upload` handler and returning early when authentication fails.\\n- Added a registered-project lookup using `fastify.storage.projects.getByPath(projectPath)` and return `404` if the supplied `path` is not a known project to prevent attacker-selected filesystem roots.\\n- Resolve the upload base with the stored project record via `resolveWorktreePath(project.path ?? projectPath, branch ?? null)` before calling the shared `writeUploadedFiles` helper; changes are in `packages/vibedeckx/src/routes/file-routes.ts`.\\n\\n### Testing\\n- Built the package with `pnpm --filter vibedeckx build`, and the bu\"\n  }\n]\nChanged files:\n[\n  {\n    \"id\": \"github-pr-file-file-f9f37986e12a0b22\",\n    \"filename\": \"packages/vibedeckx/src/routes/file-routes.ts\",\n    \"label\": \"api_or_backend\",\n    \"status\": \"modified\",\n    \"additions\": 9,\n    \"deletions\": 1,\n    \"changes\": 10,\n    \"blob_url\": \"https://github.com/vibedeckx/vibedeckx/blob/15744c99260ad7aad49b0419e7ae5fc397c9b199/packages%2Fvibedeckx%2Fsrc%2Froutes%2Ffile-routes.ts\"\n  }\n]\nLinked chain ids:\n[\"evidence-chain-comment_to_commit-e4a77f338141cb0a\"]\nSource graph evidence:\nSource evidence repo graph summary\nRepo: vibedeckx/vibedeckx\nGraph label: source_backed_multi_signal_graph\nNodes: 16\nEdges: 24\nNode types: {\"cooccurrence_profile\": 1, \"github_repo_s\n[truncated by importer]", "source": "foundry_mined_dataset", "repo_url": "https://github.com/vibedeckx/vibedeckx", "source_id": "comment-chain-pattern-assumption_checks-3a22333df484cb3e", "synthetic": false, "gold_label": "", "graph_label": "source_backed_multi_signal_graph", "source_path": "/data/distillate/foundry_data/comment_chain_patterns/assumption_checks/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "vibedeckx/vibedeckx", "source_dataset": "comment_chain_patterns/assumption_checks", "training_usage": "gold_candidate"}}}, {"ruleId": "foundry_assumption_check", "level": "warning", "message": {"text": "Foundry mined assumption checks: vibedeckx/vibedeckx"}, "properties": {"repobilityId": 439701, "scanner": "foundry_dataset", "fingerprint": "1c07d4aad4311ef994d2b08fb53374d7a11bd47cfc9c75d02f2d48acb9e7ba4f", "category": "practices", "severity": "medium", "confidence": 0.62, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "comment_chain_pattern_product", "source": "comment_chain_pattern_miner", "product": "assumption_checks", "synthetic": false, "thread_key": "vibedeckx/vibedeckx#1", "human_labels": ["api_or_backend", "docs_or_claims", "human_feedback_general", "source_or_other", "test_or_ci", "ui_or_frontend"], "issue_number": "1", "thread_label": "thread_needs_classification", "outcome_label": "ambiguous_needs_more_evidence", "source_backed": true, "max_confidence": 0.0, "repo_full_name": "vibedeckx/vibedeckx", "training_usage": "negative_or_unresolved", "confidence_tier": "unresolved", "source_chain_id": "evidence-chain-issue_chain-6b5c7fe43d8ad15c", "helicopter_views": {"graphs": 2, "schemas": 2}, "artifact_families": {"ci": 1, "docs": 3, "tests": 3, "schemas": 1}, "source_chain_kind": "issue_chain", "changed_file_count": 53, "source_graph_label": "source_backed_multi_signal_graph", "changed_file_labels": {"test_or_ci": 1, "api_or_backend": 12, "docs_or_claims": 3, "ui_or_frontend": 32, "source_or_other": 5}, "linked_commit_count": 0, "helicopter_view_count": 4, "source_artifact_count": 8, "classification_reasons": ["source_graph_has_real_artifacts", "source_graph_has_verification_artifacts", "repo_has_isolated_helicopter_views", "link_quality_unresolved"], "linked_ci_commit_count": 0, "verification_artifact_count": 5, "design_schema_api_artifact_count": 1}, "text": "Comment chain pattern product: assumption_checks\nRepo: vibedeckx/vibedeckx\nThread: vibedeckx/vibedeckx#1\nOutcome: ambiguous_needs_more_evidence\nThread label: thread_needs_classification\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, repo_has_isolated_helicopter_views, link_quality_unresolved\nChain evidence:\nIssue/PR evidence chain: vibedeckx/vibedeckx#1\nRepo: vibedeckx/vibedeckx\nThread label: thread_needs_classification\nOutcome: ambiguous_needs_more_evidence\nComment count: 1\nLinked commit count: 0\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 53\nLabels: {'human_feedback_general': 1}\nPolarities: {'neutral': 1}\nChanged file labels: {'test_or_ci': 1, 'docs_or_claims': 3, 'ui_or_frontend': 32, 'api_or_backend': 12, 'source_or_other': 5}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-3de97960a0414460\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"human_feedback_general\",\n    \"polarity\": \"neutral\",\n    \"url\": \"https://github.com/vibedeckx/vibedeckx/pull/1\",\n    \"text\": \"GitHub feedback: human_feedback_general\\nPolarity: neutral\\nKind: pull_request_body\\nRepo: vibedeckx/vibedeckx\\nAuthor: wjx (User)\\nURL: https://github.com/vibedeckx/vibedeckx/pull/1\\nTitle: Feat/multi remote\\nBody:\\n\"\n  }\n]\nChanged files:\n[\n  {\n    \"id\": \"github-pr-file-file-16c3f035790b3ec8\",\n    \"filename\": \".github/workflows/release.yml\",\n    \"label\": \"test_or_ci\",\n    \"status\": \"added\",\n    \"additions\": 151,\n    \"deletions\": 0,\n    \"changes\": 151,\n    \"blob_url\": \"https://github.com/vibedeckx/vibedeckx/blob/66701d0a8942aa9f8e92cc68640178396ced1c1c/.github%2Fworkflows%2Frelease.yml\"\n  },\n  {\n    \"id\": \"github-pr-file-file-ef06543c1ca47836\",\n    \"filename\": \"README.md\",\n    \"label\": \"docs_or_claims\",\n    \"status\": \"modified\",\n    \"additions\": 30,\n    \"deletions\": 0,\n    \"changes\": 30,\n    \"blob_url\": \"https://github.com/vibedeckx/vibedeckx/blob/66701d0a8942aa9f8e92cc68640178396ced1c1c/README.md\"\n  },\n  {\n    \"id\": \"github-pr-file-file-33c2c63bba0039bb\",\n    \"filename\": \"apps/vibedeckx-ui/components/agent/agent-conversation.tsx\",\n    \"label\": \"ui_or_frontend\",\n    \"status\": \"modified\",\n    \"additions\": 143,\n    \"deletions\": 46,\n    \"changes\": 189,\n    \"blob_url\": \"https://github.com/vibedeckx/vibedeckx/blob/66701d0a8942aa9f8e92cc68640178396ced1c1c/apps%2Fvibedeckx-ui%2Fcomponents%2Fagent%2Fagent-conversation.tsx\"\n  },\n  {\n    \"id\": \"github-pr-file-file-050e617807d02b64\",\n    \"filename\": \"apps/vibedeckx-ui/components/agent/agent-message.tsx\",\n    \"label\": \"ui_or_frontend\",\n    \"status\": \"modified\",\n    \"additions\": 95,\n    \"deletions\": 10,\n    \"changes\": 105,\n    \"blob_url\": \"https://github.com/vibedeckx/vibedeckx/blob/66701d0a8942aa9f8e92cc68640178396ced1c1c/apps%2Fvibedeckx-ui%2Fcomponents%2Fagent%2Fagent-message.tsx\"\n  },\n  {\n    \"id\": \"github-pr-file-file-9d7a03057dd14676\",\n    \"filename\": \"apps/vibedeckx-ui/components/agent/approval-re\n[truncated by importer]", "source": "foundry_mined_dataset", "repo_url": "https://github.com/vibedeckx/vibedeckx", "source_id": "comment-chain-pattern-assumption_checks-103296463442b094", "synthetic": false, "gold_label": "", "graph_label": "source_backed_multi_signal_graph", "source_path": "/data/distillate/foundry_data/comment_chain_patterns/assumption_checks/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "vibedeckx/vibedeckx", "source_dataset": "comment_chain_patterns/assumption_checks", "training_usage": "negative_or_unresolved"}}}, {"ruleId": "foundry_bad_chain", "level": "error", "message": {"text": "Foundry mined bad chains: vibedeckx/vibedeckx"}, "properties": {"repobilityId": 445117, "scanner": "foundry_dataset", "fingerprint": "bad2706b9af2db3bca535440730768655e00d96ffc070a1715d744f5a9509e1d", "category": "practices", "severity": "high", "confidence": 0.84, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "comment_chain_pattern_product", "source": "comment_chain_pattern_miner", "product": "bad_chains", "synthetic": false, "thread_key": "vibedeckx/vibedeckx#2", "human_labels": ["api_integration_gap", "security_auth_secret", "ui_or_frontend"], "issue_number": "2", "thread_label": "thread_has_human_issue_without_fix_context", "outcome_label": "not_resolved_or_not_observed", "source_backed": true, "max_confidence": 0.0, "repo_full_name": "vibedeckx/vibedeckx", "training_usage": "negative_or_unresolved", "confidence_tier": "unresolved", "source_chain_id": "evidence-chain-issue_chain-536698d082407055", "helicopter_views": {"graphs": 2, "schemas": 2}, "artifact_families": {"ci": 1, "docs": 3, "tests": 3, "schemas": 1}, "source_chain_kind": "issue_chain", "changed_file_count": 20, "source_graph_label": "source_backed_multi_signal_graph", "changed_file_labels": {"ui_or_frontend": 20}, "linked_commit_count": 0, "helicopter_view_count": 4, "source_artifact_count": 8, "classification_reasons": ["source_graph_has_real_artifacts", "source_graph_has_verification_artifacts", "repo_has_isolated_helicopter_views", "link_quality_unresolved", "high_risk_human_feedback_label"], "linked_ci_commit_count": 0, "verification_artifact_count": 5, "design_schema_api_artifact_count": 1}, "text": "Comment chain pattern product: bad_chains\nRepo: vibedeckx/vibedeckx\nThread: vibedeckx/vibedeckx#2\nOutcome: not_resolved_or_not_observed\nThread label: thread_has_human_issue_without_fix_context\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, repo_has_isolated_helicopter_views, link_quality_unresolved, high_risk_human_feedback_label\nChain evidence:\nIssue/PR evidence chain: vibedeckx/vibedeckx#2\nRepo: vibedeckx/vibedeckx\nThread label: thread_has_human_issue_without_fix_context\nOutcome: not_resolved_or_not_observed\nComment count: 2\nLinked commit count: 0\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 20\nLabels: {'security_auth_secret': 1, 'api_integration_gap': 1}\nPolarities: {'bad': 2}\nChanged file labels: {'ui_or_frontend': 20}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-4cb7403fc1f1c8ec\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"security_auth_secret\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.com/vibedeckx/vibedeckx/pull/2\",\n    \"text\": \"GitHub feedback: security_auth_secret\\nPolarity: bad\\nKind: pull_request_body\\nRepo: vibedeckx/vibedeckx\\nAuthor: wjx (User)\\nURL: https://github.com/vibedeckx/vibedeckx/pull/2\\nTitle: Redesign global UI and project components\\nBody:\\n- Updated global design tokens and system branding for a cohesive visual identity.\\n- Refined the layout and styling of the header, sidebar, and workspace panels.\\n- Redesigned core views including the landing page, sign-in page, and settings.\\n- Enhanced UI components for codeblocks, conversation panels, and agent headers.\\n- Updated the visual presentation of the files view, project cards, and task sections.\\n- Refined the executor and diff panels for improved clarity.\\n\\n[v0 Session](https://v0.app/chat/LPWdEYqAJ5L)\"\n  },\n  {\n    \"id\": \"github-feedback-comment-f63212677541ac91\",\n    \"kind\": \"issue_comment\",\n    \"label\": \"api_integration_gap\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.com/vibedeckx/vibedeckx/pull/2#issuecomment-4067502504\",\n    \"text\": \"GitHub feedback: api_integration_gap\\nPolarity: bad\\nKind: issue_comment\\nRepo: vibedeckx/vibedeckx\\nAuthor: vercel[bot] (Bot)\\nURL: https://github.com/vibedeckx/vibedeckx/pull/2#issuecomment-4067502504\\nTitle: \\nBody:\\n[vc]: #Mxvn01eN/+/zw8SmI7laf7PDlxYh5ca409kdp6stPm0=:eyJpc01vbm9yZXBvIjp0cnVlLCJ0eXBlIjoiZ2l0aHViIiwicHJvamVjdHMiOlt7Im5hbWUiOiJ2MC12aWJlZGVja3giLCJwcm9qZWN0SWQiOiJwcmpfUDdBZGtkOUxkMzU0Nk9tdWVuS0xia2c4eFJ2RiIsInYwIjp0cnVlLCJsaXZlRmVlZGJhY2siOnsicmVzb2x2ZWQiOjAsInVucmVzb2x2ZWQiOjAsInRvdGFsIjowLCJsaW5rIjoiIn0sImluc3BlY3RvclVybCI6Imh0dHBzOi8vdmVyY2VsLmNvbS9qZXNzZXMtcHJvamVjdHMtZTFjNDllNTAvdjAtdmliZWRlY2t4L0F1anc0cnQzOXNQMWV1c05Rbm5wWUR1eDdTRTMiLCJwcmV2aWV3VXJsIjoiIiwibmV4dENvbW1pdFN0YXR1cyI6IkZBSUxFRCJ9XSwicmVxdWVzdFJldmlld1VybCI6Imh0dHBzOi8vdmVyY2VsLmNvbS92ZXJjZWwtYWdlbnQvcmVxdWVzdC1yZXZpZXc/b3duZXI9d2p4JnJlcG89dmliZWRlY2t4JnByPTIifQ==\\nThe latest update\n[truncated by importer]", "source": "foundry_mined_dataset", "repo_url": "https://github.com/vibedeckx/vibedeckx", "source_id": "comment-chain-pattern-bad_chains-1ef142942c2f2011", "synthetic": false, "gold_label": "", "graph_label": "source_backed_multi_signal_graph", "source_path": "/data/distillate/foundry_data/comment_chain_patterns/bad_chains/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "vibedeckx/vibedeckx", "source_dataset": "comment_chain_patterns/bad_chains", "training_usage": "negative_or_unresolved"}}}, {"ruleId": "foundry_auth_guardrail_gap", "level": "error", "message": {"text": "Foundry mined security auth guardrail gaps: vibedeckx/vibedeckx"}, "properties": {"repobilityId": 456425, "scanner": "foundry_dataset", "fingerprint": "40211c1c31ac4c8a38baa8139269237ec4998ddf76ee34e4aba296048ba6854e", "category": "auth", "severity": "critical", "confidence": 0.78, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Security/auth changes without enough guardrails", "intent": "Assumption-check security/auth examples requiring stronger tests or CI.", "labels": {"bug_fix": 1, "api_or_backend": 1, "security_auth_secret": 1, "claimed_resolved_unverified": 3, "issue_or_pull_request_thread": 1, "human_reported_issue_then_fix_attempt": 1, "thread_has_human_issue_and_fix_context": 2}, "source": "graph_query_export", "motif_id": "security_auth_without_guardrails", "outcomes": {"claimed_resolved_unverified": 6}, "polarity": "bad", "query_id": "security_auth_guardrail_gaps", "severity": "critical", "ci_labels": {}, "synthetic": false, "edge_count": 15, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "thread_touches_file": 1, "chain_has_link_quality": 3, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 1, "thread_has_comment_chain": 1, "comment_chain_links_commit": 1, "comment_chain_touches_file": 1, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 11, "node_types": {"repo": 1, "commit": 1, "thread": 1, "comment": 1, "pr_file": 1, "fix_outcome": 1, "issue_chain": 1, "link_quality": 3, "comment_chain": 1}, "query_type": "motif_query", "thread_key": "vibedeckx/vibedeckx#3", "issue_number": "3", "quality_tiers": {"high_confidence": 3}, "repo_full_name": "vibedeckx/vibedeckx", "training_usage": "assumption_check", "source_motif_id": "graph-pattern-motif-thread-cc48d8ea65031381", "graph_gold_label": "supported_by_high_confidence_link", "changed_file_labels": {"api_or_backend": 4}}, "text": "Graph query export: Security/auth changes without enough guardrails\nQuery id: security_auth_guardrail_gaps\nQuery type: motif_query\nIntent: Assumption-check security/auth examples requiring stronger tests or CI.\nMotif: security_auth_without_guardrails\nTraining usage: assumption_check\nGraph gold label: supported_by_high_confidence_link\nRepo: vibedeckx/vibedeckx\nThread: vibedeckx/vibedeckx#3\nEvidence:\nGraph motif: Security/auth change without enough guardrails\nMotif id: security_auth_without_guardrails\nPolarity: bad\nTraining usage: assumption_check\nSeverity: critical\nRepo: vibedeckx/vibedeckx\nThread: vibedeckx/vibedeckx#3\nGraph gold label: supported_by_high_confidence_link\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: vibedeckx/vibedeckx#3\nRepo: vibedeckx/vibedeckx\nIssue/PR number: 3\nGraph consistency label: supported_by_high_confidence_link\nNodes: 11\nEdges: 15\nNode types: {'link_quality': 3, 'thread': 1, 'repo': 1, 'comment': 1, 'pr_file': 1, 'comment_chain': 1, 'commit': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'chain_has_link_quality': 3, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_touches_file': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'comment_chain_links_commit': 1, 'comment_chain_touches_file': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'issue_chain_touches_file': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'claimed_resolved_unverified': 3, 'thread_has_human_issue_and_fix_context': 2, 'issue_or_pull_request_thread': 1, 'security_auth_secret': 1, 'api_or_backend': 1, 'human_reported_issue_then_fix_attempt': 1, 'bug_fix': 1}\nOutcomes: {'claimed_resolved_unverified': 6}\nQuality tiers: {'high_confidence': 3}\nCI labels: {}\nCurriculum targets:\n- Train auth boundary repair with tests, permission matrices, and secret-handling checks.\n- Keep risky auth changes separate from ordinary bug-fix examples.\nAssumption checks:\n- Are auth/permission paths covered by tests?\n- Are secrets, CORS, or access rules verified rather than summarized?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/vibedeckx/vibedeckx", "source_id": "graph-query-motif_query-8b6d7147812774c0", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/security_auth_guardrail_gaps/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "vibedeckx/vibedeckx", "source_dataset": "graph_queries/security_auth_guardrail_gaps", "training_usage": "assumption_check"}}}, {"ruleId": "foundry_auth_guardrail_gap", "level": "error", "message": {"text": "Foundry mined security auth guardrail gaps: vibedeckx/vibedeckx"}, "properties": {"repobilityId": 456424, "scanner": "foundry_dataset", "fingerprint": "85c7c9b1870aa0f6159f231a32d701c42e56a6b3f4404ea402cfe8d807702bb1", "category": "auth", "severity": "critical", "confidence": 0.78, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Security/auth changes without enough guardrails", "intent": "Assumption-check security/auth examples requiring stronger tests or CI.", "labels": {"ui_or_frontend": 20, "api_integration_gap": 1, "security_auth_secret": 1, "mostly follows blueprint": 1, "issue_or_pull_request_thread": 1, "not_resolved_or_not_observed": 4, "blueprint_human_gap_disagreement": 1, "human_reported_issue_no_linked_fix": 2, "thread_has_human_issue_without_fix_context": 2}, "source": "graph_query_export", "motif_id": "security_auth_without_guardrails", "outcomes": {"not_resolved_or_not_observed": 8}, "polarity": "bad", "query_id": "security_auth_guardrail_gaps", "severity": "critical", "ci_labels": {}, "synthetic": false, "edge_count": 76, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 2, "thread_has_comment": 2, "thread_touches_file": 20, "alignment_uses_comment": 1, "alignment_uses_finding": 1, "chain_has_link_quality": 5, "comment_aligns_finding": 1, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 12, "thread_has_comment_chain": 2, "comment_chain_touches_file": 24, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 2}, "node_count": 35, "node_types": {"repo": 1, "thread": 1, "comment": 2, "pr_file": 20, "alignment": 1, "fix_outcome": 1, "issue_chain": 1, "link_quality": 5, "comment_chain": 2, "blueprint_finding": 1}, "query_type": "motif_query", "thread_key": "vibedeckx/vibedeckx#2", "issue_number": "2", "quality_tiers": {"unresolved": 4, "assumption_check": 1}, "repo_full_name": "vibedeckx/vibedeckx", "training_usage": "assumption_check", "source_motif_id": "graph-pattern-motif-thread-0bc08e884d3017a9", "graph_gold_label": "assumption_check", "changed_file_labels": {"ui_or_frontend": 100}}, "text": "Graph query export: Security/auth changes without enough guardrails\nQuery id: security_auth_guardrail_gaps\nQuery type: motif_query\nIntent: Assumption-check security/auth examples requiring stronger tests or CI.\nMotif: security_auth_without_guardrails\nTraining usage: assumption_check\nGraph gold label: assumption_check\nRepo: vibedeckx/vibedeckx\nThread: vibedeckx/vibedeckx#2\nEvidence:\nGraph motif: Security/auth change without enough guardrails\nMotif id: security_auth_without_guardrails\nPolarity: bad\nTraining usage: assumption_check\nSeverity: critical\nRepo: vibedeckx/vibedeckx\nThread: vibedeckx/vibedeckx#2\nGraph gold label: assumption_check\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: vibedeckx/vibedeckx#2\nRepo: vibedeckx/vibedeckx\nIssue/PR number: 2\nGraph consistency label: assumption_check\nNodes: 35\nEdges: 76\nNode types: {'pr_file': 20, 'link_quality': 5, 'comment': 2, 'comment_chain': 2, 'thread': 1, 'repo': 1, 'issue_chain': 1, 'fix_outcome': 1, 'alignment': 1, 'blueprint_finding': 1}\nEdge types: {'comment_chain_touches_file': 24, 'thread_touches_file': 20, 'issue_chain_touches_file': 12, 'chain_has_link_quality': 5, 'thread_has_comment': 2, 'thread_has_comment_chain': 2, 'comment_has_chain': 2, 'issue_chain_has_comment_chain': 2, 'repo_has_thread': 1, 'thread_has_issue_chain': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1, 'alignment_uses_comment': 1, 'alignment_uses_finding': 1, 'comment_aligns_finding': 1}\nLabels: {'ui_or_frontend': 20, 'not_resolved_or_not_observed': 4, 'human_reported_issue_no_linked_fix': 2, 'thread_has_human_issue_without_fix_context': 2, 'issue_or_pull_request_thread': 1, 'security_auth_secret': 1, 'api_integration_gap': 1, 'blueprint_human_gap_disagreement': 1, 'mostly follows blueprint': 1}\nOutcomes: {'not_resolved_or_not_observed': 8}\nQuality tiers: {'unresolved': 4, 'assumption_check': 1}\nCI labels: {}\nCurriculum targets:\n- Train auth boundary repair with tests, permission matrices, and secret-handling checks.\n- Keep risky auth changes separate from ordinary bug-fix examples.\nAssumption checks:\n- Are auth/permission paths covered by tests?\n- Are secrets, CORS, or access rules verified rather than summarized?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/vibedeckx/vibedeckx", "source_id": "graph-query-motif_query-038536e1cdee8774", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/security_auth_guardrail_gaps/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "vibedeckx/vibedeckx", "source_dataset": "graph_queries/security_auth_guardrail_gaps", "training_usage": "assumption_check"}}}, {"ruleId": "scanner-c9eba30c8392eb0a", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/settings/settings-shell.tsx:218"}, "properties": {"repobilityId": "0467605fa34415d5", "scanner": "scanner-primary", "fingerprint": "c9eba30c8392eb0a", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-2706ab4571a7d872", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/settings/settings-dialog.tsx:198"}, "properties": {"repobilityId": "083ac9bd78aeb035", "scanner": "scanner-primary", "fingerprint": "2706ab4571a7d872", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-c08a52a51516440b", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/layout/app-sidebar.tsx:126"}, "properties": {"repobilityId": "fc64b659a6d83b3c", "scanner": "scanner-primary", "fingerprint": "c08a52a51516440b", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-1218bbf04bc49caf", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/layout/completion-notifications-menu.tsx:154"}, "properties": {"repobilityId": "11add5b5e9fe52ab", "scanner": "scanner-primary", "fingerprint": "1218bbf04bc49caf", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-6792b56ce1561a5e", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/layout/page-header.tsx:23"}, "properties": {"repobilityId": "36143459c6bde323", "scanner": "scanner-primary", "fingerprint": "6792b56ce1561a5e", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-119c8dbe232eb463", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/agent/vpaste-chip.tsx:30"}, "properties": {"repobilityId": "6658f812427d30dc", "scanner": "scanner-primary", "fingerprint": "119c8dbe232eb463", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-98ff7825d598d104", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/agent/web-fetch-tools.tsx:55"}, "properties": {"repobilityId": "f4ba0002bbb2d672", "scanner": "scanner-primary", "fingerprint": "98ff7825d598d104", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-720013e488d42022", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 apps/vibedeckx-ui/components/agent/agent-conversation.tsx:95"}, "properties": {"repobilityId": "1a1bda7146688637", "scanner": "scanner-primary", "fingerprint": "720013e488d42022", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-d0a75e6b0c5c2a37", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/components/agent/agent-conversation.tsx:516"}, "properties": {"repobilityId": "0cc7bbc30675f9c7", "scanner": "scanner-primary", "fingerprint": "d0a75e6b0c5c2a37", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4b3f5f5f4153503b", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/agent/session-history-dropdown.tsx:190"}, "properties": {"repobilityId": "0896e2a70d4eb5c7", "scanner": "scanner-primary", "fingerprint": "4b3f5f5f4153503b", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-a2907788eca217f9", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/agent/skill-tools.tsx:37"}, "properties": {"repobilityId": "3c8c991a0d6214b7", "scanner": "scanner-primary", "fingerprint": "a2907788eca217f9", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-0fe919a247a9247b", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/task/task-row.tsx:93"}, "properties": {"repobilityId": "19b4788a9909f8ff", "scanner": "scanner-primary", "fingerprint": "0fe919a247a9247b", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-54aeeb1406d2e842", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/components/conversation/main-conversation.tsx:48"}, "properties": {"repobilityId": "86986828d3162399", "scanner": "scanner-primary", "fingerprint": "54aeeb1406d2e842", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-183a2e4cba2e5c2c", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/files/file-preview.tsx:250"}, "properties": {"repobilityId": "427af96d8fa17a32", "scanner": "scanner-primary", "fingerprint": "183a2e4cba2e5c2c", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-a5256b75c9584ee8", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/terminal/terminal-panel.tsx:140"}, "properties": {"repobilityId": "acbc14705cc5cc75", "scanner": "scanner-primary", "fingerprint": "a5256b75c9584ee8", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-77d7661b0b2ee006", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/components/executor/executor-output.tsx:48"}, "properties": {"repobilityId": "41df93b8fe21aebf", "scanner": "scanner-primary", "fingerprint": "77d7661b0b2ee006", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7d1422fdf598299c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/components/executor/executor-item.tsx:91"}, "properties": {"repobilityId": "d85e7a655c5e13e0", "scanner": "scanner-primary", "fingerprint": "7d1422fdf598299c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-285bb428236f675b", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/diff/commit-selector.tsx:47"}, "properties": {"repobilityId": "3b8eca9baeac5467", "scanner": "scanner-primary", "fingerprint": "285bb428236f675b", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-d869cd00fe2cf443", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/diff/file-diff.tsx:40"}, "properties": {"repobilityId": "0437d4786785b4d6", "scanner": "scanner-primary", "fingerprint": "d869cd00fe2cf443", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-6d5348521be80602", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 apps/vibedeckx-ui/components/ai-elements/code-block.tsx:114"}, "properties": {"repobilityId": "858ca3a6044cdd28", "scanner": "scanner-primary", "fingerprint": "6d5348521be80602", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-3a9b735945aec408", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/ai-elements/queue.tsx:178"}, "properties": {"repobilityId": "00339408005410f4", "scanner": "scanner-primary", "fingerprint": "3a9b735945aec408", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-d131015e281826c7", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/ai-elements/prompt-input.tsx:342"}, "properties": {"repobilityId": "b81d721843bce0cc", "scanner": "scanner-primary", "fingerprint": "d131015e281826c7", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-b47550fd0a8e2a47", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/ai-elements/inline-citation.tsx:257"}, "properties": {"repobilityId": "b6ab81027d535cb3", "scanner": "scanner-primary", "fingerprint": "b47550fd0a8e2a47", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-9bb21f9786e1f83e", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/project/create-worktree-dialog.tsx:225"}, "properties": {"repobilityId": "0970137f6674ec75", "scanner": "scanner-primary", "fingerprint": "9bb21f9786e1f83e", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-858f2067b97f8421", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/project/remote-directory-browser.tsx:134"}, "properties": {"repobilityId": "3d2665dbb508b622", "scanner": "scanner-primary", "fingerprint": "858f2067b97f8421", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-181f9958d4ecce3f", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/project/project-card.tsx:291"}, "properties": {"repobilityId": "8b73b9eaad30fac4", "scanner": "scanner-primary", "fingerprint": "181f9958d4ecce3f", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-24cdea83c85ffb00", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/project/create-project-dialog.tsx:287"}, "properties": {"repobilityId": "034b911b63ece79d", "scanner": "scanner-primary", "fingerprint": "24cdea83c85ffb00", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-2f87e34d399b259d", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/vibedeckx-ui/components/project/project-settings-form.tsx:442"}, "properties": {"repobilityId": "f2a2eee528c10dab", "scanner": "scanner-primary", "fingerprint": "2f87e34d399b259d", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-ebb2ee56829fee99", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 apps/vibedeckx-ui/app/layout.tsx:65"}, "properties": {"repobilityId": "41109935e1f7b9dc", "scanner": "scanner-primary", "fingerprint": "ebb2ee56829fee99", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-12eb0102e2344fec", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/hooks/use-executor-logs.ts:81"}, "properties": {"repobilityId": "2fba327a4a05163f", "scanner": "scanner-primary", "fingerprint": "12eb0102e2344fec", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-6d377af6e691a4dd", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/hooks/use-executors.ts:108"}, "properties": {"repobilityId": "e7520aa89679b830", "scanner": "scanner-primary", "fingerprint": "6d377af6e691a4dd", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-70f3ca0c57b8cd7b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/hooks/use-agent-session.ts:265"}, "properties": {"repobilityId": "60d6315f39675a8b", "scanner": "scanner-primary", "fingerprint": "70f3ca0c57b8cd7b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-285473dc03079163", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/hooks/use-chat-session.ts:253"}, "properties": {"repobilityId": "2571094067857daa", "scanner": "scanner-primary", "fingerprint": "285473dc03079163", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9631aab1a60f1ef1", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/hooks/executor-logs-context.tsx:89"}, "properties": {"repobilityId": "79e901b24df2fdc5", "scanner": "scanner-primary", "fingerprint": "9631aab1a60f1ef1", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f96437a6ee23ef19", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/vibedeckx-ui/hooks/use-completion-notifications.ts:138"}, "properties": {"repobilityId": "bcccff60a51da226", "scanner": "scanner-primary", "fingerprint": "f96437a6ee23ef19", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-63e4b75b300b9621", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/instrumentation.ts:15"}, "properties": {"repobilityId": "05fcb098e3d7f142", "scanner": "scanner-primary", "fingerprint": "63e4b75b300b9621", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-125290b5efa01cda", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/event-bus.ts:24"}, "properties": {"repobilityId": "bb1ee5195cab6fea", "scanner": "scanner-primary", "fingerprint": "125290b5efa01cda", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-6f02078436fcd59b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/reverse-connect-manager.ts:79"}, "properties": {"repobilityId": "6dc0e2454fce361a", "scanner": "scanner-primary", "fingerprint": "6f02078436fcd59b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d3e1dc2d545fbefa", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/process-manager.ts:64"}, "properties": {"repobilityId": "4c54486e562193aa", "scanner": "scanner-primary", "fingerprint": "d3e1dc2d545fbefa", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a4a368b3989bda7c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/agent-session-manager.ts:187"}, "properties": {"repobilityId": "37c6111dd66e6370", "scanner": "scanner-primary", "fingerprint": "a4a368b3989bda7c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8b59f0a7c219a7a5", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/reverse-connect-client.ts:42"}, "properties": {"repobilityId": "8253dae0dad6b73d", "scanner": "scanner-primary", "fingerprint": "8b59f0a7c219a7a5", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c4a8546d22db03ea", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/command.ts:135"}, "properties": {"repobilityId": "94791226e87c6d61", "scanner": "scanner-primary", "fingerprint": "c4a8546d22db03ea", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4569d41569a5a4b7", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/server.ts:138"}, "properties": {"repobilityId": "46e98d346e6e8b9e", "scanner": "scanner-primary", "fingerprint": "4569d41569a5a4b7", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4861a5b1b7dce80f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/chat-session-manager.ts:227"}, "properties": {"repobilityId": "3d048487aa323699", "scanner": "scanner-primary", "fingerprint": "4861a5b1b7dce80f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-510739e268fc5692", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/browser-manager.ts:122"}, "properties": {"repobilityId": "cc4af936c4ed0d11", "scanner": "scanner-primary", "fingerprint": "510739e268fc5692", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-aff7066a87c37dd3", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/utils/remote-proxy.ts:91"}, "properties": {"repobilityId": "fc6e3b05989b2b85", "scanner": "scanner-primary", "fingerprint": "aff7066a87c37dd3", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e39d730e7a1be9f2", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/providers/codex-provider.ts:44"}, "properties": {"repobilityId": "5057225b950d7cbd", "scanner": "scanner-primary", "fingerprint": "e39d730e7a1be9f2", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2634b2ce39ff4eef", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/providers/claude-code-provider.ts:28"}, "properties": {"repobilityId": "6d3b294ca1d7baeb", "scanner": "scanner-primary", "fingerprint": "2634b2ce39ff4eef", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-988613b055082aa8", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/browser-routes.ts:112"}, "properties": {"repobilityId": "f461514d1f0b4f52", "scanner": "scanner-primary", "fingerprint": "988613b055082aa8", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-24d88de12b4197f3", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/terminal-routes.ts:180"}, "properties": {"repobilityId": "b278249dadd3bc67", "scanner": "scanner-primary", "fingerprint": "24d88de12b4197f3", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-dc0fcba6f6c55786", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/executor-stream-handlers.ts:109"}, "properties": {"repobilityId": "57a767eaf2837c68", "scanner": "scanner-primary", "fingerprint": "dc0fcba6f6c55786", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-408079223c76fde3", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/reverse-connect-routes.ts:38"}, "properties": {"repobilityId": "4b16b59fd7d35dca", "scanner": "scanner-primary", "fingerprint": "408079223c76fde3", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-31871fdaca0fa83b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/websocket-routes.ts:62"}, "properties": {"repobilityId": "5f895b5060ce6dea", "scanner": "scanner-primary", "fingerprint": "31871fdaca0fa83b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9d9b98941735820c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/settings-routes.ts:118"}, "properties": {"repobilityId": "9a0581b9d8901441", "scanner": "scanner-primary", "fingerprint": "9d9b98941735820c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8b64d015a2bad6a6", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/browser-proxy-routes.ts:492"}, "properties": {"repobilityId": "f4433031f6c6dc47", "scanner": "scanner-primary", "fingerprint": "8b64d015a2bad6a6", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8eccd08094155bc4", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/process-routes.ts:74"}, "properties": {"repobilityId": "7e9bd9511c6d679b", "scanner": "scanner-primary", "fingerprint": "8eccd08094155bc4", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0d6d662825c0d6a7", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/worktree-routes.ts:116"}, "properties": {"repobilityId": "efdc1879596df273", "scanner": "scanner-primary", "fingerprint": "0d6d662825c0d6a7", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9407734cce283124", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/routes/agent-session-routes.ts:167"}, "properties": {"repobilityId": "598860e77dc8dfad", "scanner": "scanner-primary", "fingerprint": "9407734cce283124", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d55bd8d2cb00b558", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/vibedeckx/src/plugins/shared-services.ts:51"}, "properties": {"repobilityId": "6393b5b20a961bef", "scanner": "scanner-primary", "fingerprint": "d55bd8d2cb00b558", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-55c1469e4a245f27", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in apps/vibedeckx-ui/components/ai-elements/code-block.tsx:114"}, "properties": {"repobilityId": "5e8ae8d94ac5c873", "scanner": "scanner-primary", "fingerprint": "55c1469e4a245f27", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/vibedeckx-ui/components/ai-elements/code-block.tsx"}, "region": {"startLine": 114}}}]}, {"ruleId": "scanner-fb18e8bea57f6f94", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in apps/vibedeckx-ui/app/layout.tsx:65"}, "properties": {"repobilityId": "b4b84741f625bd7d", "scanner": "scanner-primary", "fingerprint": "fb18e8bea57f6f94", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/vibedeckx-ui/app/layout.tsx"}, "region": {"startLine": 65}}}]}, {"ruleId": "scanner-6ddb459a27b5354d", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in packages/vibedeckx/src/process-manager.ts:1"}, "properties": {"repobilityId": "42d6f029e6d5c393", "scanner": "scanner-primary", "fingerprint": "6ddb459a27b5354d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/vibedeckx/src/process-manager.ts"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-95db8ef9313bf07b", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in packages/vibedeckx/src/dialog.ts:1"}, "properties": {"repobilityId": "71240cd07b8a6b9b", "scanner": "scanner-primary", "fingerprint": "95db8ef9313bf07b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/vibedeckx/src/dialog.ts"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-461aa64725d7e268", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in packages/vibedeckx/src/agent-session-manager.ts:1"}, "properties": {"repobilityId": "e04ed6e1feba61a5", "scanner": "scanner-primary", "fingerprint": "461aa64725d7e268", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/vibedeckx/src/agent-session-manager.ts"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-33a7795c897da106", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in packages/vibedeckx/src/server.ts:146"}, "properties": {"repobilityId": "036efda48c104488", "scanner": "scanner-primary", "fingerprint": "33a7795c897da106", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/vibedeckx/src/server.ts"}, "region": {"startLine": 146}}}]}, {"ruleId": "scanner-6b580f0972fb7bd3", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in packages/vibedeckx/src/utils/worktree-paths.ts:3"}, "properties": {"repobilityId": "f00f8bb4a64ca33b", "scanner": "scanner-primary", "fingerprint": "6b580f0972fb7bd3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/vibedeckx/src/utils/worktree-paths.ts"}, "region": {"startLine": 3}}}]}, {"ruleId": "scanner-98aa4a309bb8c175", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in packages/vibedeckx/src/providers/codex-provider.ts:1"}, "properties": {"repobilityId": "da6607bc813e1ca5", "scanner": "scanner-primary", "fingerprint": "98aa4a309bb8c175", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/vibedeckx/src/providers/codex-provider.ts"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-674411e63192ae9d", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in packages/vibedeckx/src/providers/claude-code-provider.ts:1"}, "properties": {"repobilityId": "32297058b94d81cb", "scanner": "scanner-primary", "fingerprint": "674411e63192ae9d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/vibedeckx/src/providers/claude-code-provider.ts"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-73b6f9704958ad5a", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in packages/vibedeckx/src/routes/project-routes.ts:306"}, "properties": {"repobilityId": "72e05dc78b858145", "scanner": "scanner-primary", "fingerprint": "73b6f9704958ad5a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/vibedeckx/src/routes/project-routes.ts"}, "region": {"startLine": 306}}}]}, {"ruleId": "scanner-fc32502ff14cfa66", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in packages/vibedeckx/src/routes/project-routes.ts:5"}, "properties": {"repobilityId": "c4b4366101192270", "scanner": "scanner-primary", "fingerprint": "fc32502ff14cfa66", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/vibedeckx/src/routes/project-routes.ts"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-ac3bf87e223070f4", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in packages/vibedeckx/src/routes/event-routes.ts:55"}, "properties": {"repobilityId": "de0ac2efe23ec281", "scanner": "scanner-primary", "fingerprint": "ac3bf87e223070f4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/vibedeckx/src/routes/event-routes.ts"}, "region": {"startLine": 55}}}]}, {"ruleId": "scanner-46c644c6227e4d4a", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "5ab0c5bd71e63ad8", "scanner": "scanner-primary", "fingerprint": "46c644c6227e4d4a", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yml"}, "region": {"startLine": 118}}}]}, {"ruleId": "scanner-46c644c6227e4d4a", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "5ab0c5bd71e63ad8", "scanner": "scanner-primary", "fingerprint": "46c644c6227e4d4a", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yml"}, "region": {"startLine": 124}}}]}, {"ruleId": "scanner-46c644c6227e4d4a", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "b0f359fc82dc1097", "scanner": "scanner-primary", "fingerprint": "46c644c6227e4d4a", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yml"}, "region": {"startLine": 137}}}]}, {"ruleId": "scanner-46c644c6227e4d4a", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "f0dc584a111ffc00", "scanner": "scanner-primary", "fingerprint": "46c644c6227e4d4a", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yml"}, "region": {"startLine": 195}}}]}, {"ruleId": "scanner-46c644c6227e4d4a", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "b0f359fc82dc1097", "scanner": "scanner-primary", "fingerprint": "46c644c6227e4d4a", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yml"}, "region": {"startLine": 215}}}]}, {"ruleId": "scanner-1838a141491ce38c", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "b8fd4f5048f96576", "scanner": "scanner-primary", "fingerprint": "1838a141491ce38c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-be55e936fb753833", "level": "note", "message": {"text": "package.json defines install-time lifecycle scripts"}, "properties": {"repobilityId": "f2750d98562e666a", "scanner": "scanner-primary", "fingerprint": "be55e936fb753833", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "npm", "install-scripts"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/vibedeckx/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1ebdf89ff14bbdfe", "level": "note", "message": {"text": "Very large file: apps/vibedeckx-ui/components/auth/landing-page.tsx (1956 lines)"}, "properties": {"repobilityId": "409431e1bfe19982", "scanner": "scanner-primary", "fingerprint": "1ebdf89ff14bbdfe", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-7767a11fa8fd8420", "level": "note", "message": {"text": "Very large file: apps/vibedeckx-ui/lib/api.ts (1648 lines)"}, "properties": {"repobilityId": "f097a05e4abd47a8", "scanner": "scanner-primary", "fingerprint": "7767a11fa8fd8420", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-285f2bdd31183ba0", "level": "note", "message": {"text": "Very large file: packages/vibedeckx/src/agent-session-manager.ts (1488 lines)"}, "properties": {"repobilityId": "927f410a1ca1063e", "scanner": "scanner-primary", "fingerprint": "285f2bdd31183ba0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-5e3451fde538c9c0", "level": "note", "message": {"text": "Very large file: packages/vibedeckx/src/chat-session-manager.ts (2449 lines)"}, "properties": {"repobilityId": "6b3236f5120c6c16", "scanner": "scanner-primary", "fingerprint": "5e3451fde538c9c0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-cec7e46936dc5479", "level": "note", "message": {"text": "Very large file: packages/vibedeckx/src/storage/sqlite.ts (1932 lines)"}, "properties": {"repobilityId": "29f14c521554a952", "scanner": "scanner-primary", "fingerprint": "cec7e46936dc5479", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "79b112810b914603", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-c20be56956c4599f", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/vibedeckx-win32-x64/package.json"}, "properties": {"repobilityId": "023342502f28b803", "scanner": "scanner-primary", "fingerprint": "c20be56956c4599f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/vibedeckx-win32-x64/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-229553a691e66ea3", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/vibedeckx-darwin-arm64/package.json"}, "properties": {"repobilityId": "8d27f27d6896b6fb", "scanner": "scanner-primary", "fingerprint": "229553a691e66ea3", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/vibedeckx-darwin-arm64/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3bdb666d48eb6176", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/vibedeckx-linux-x64/package.json"}, "properties": {"repobilityId": "b7fd3c7e117ab9d6", "scanner": "scanner-primary", "fingerprint": "3bdb666d48eb6176", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/vibedeckx-linux-x64/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "6472f53225dc9a73", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "46a3d4d3cd1fa2ae", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-9d79c4077342a7d0", "level": "warning", "message": {"text": "Runtime service client appears to use placeholder configuration"}, "properties": {"repobilityId": "1ba92832841486d5", "scanner": "scanner-primary", "fingerprint": "9d79c4077342a7d0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "runtime-config", "service-client", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "46795cae7f640630", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "6cc622d1f3636d49", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "a82af49a401265c2", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "7abfd83afe90a596", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "d38ba21ff54c1e4b", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-6692eea86b8ab29e", "level": "none", "message": {"text": "Commented-code block (5 lines) in apps/vibedeckx-ui/components/agent/agent-conversation.tsx:135"}, "properties": {"repobilityId": "6ccc2f4858f7609d", "scanner": "scanner-primary", "fingerprint": "6692eea86b8ab29e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7ad73f62620e5c0a", "level": "none", "message": {"text": "Commented-code block (5 lines) in apps/vibedeckx-ui/components/agent/session-history-dropdown.tsx:57"}, "properties": {"repobilityId": "15ca9e6e58b7b35f", "scanner": "scanner-primary", "fingerprint": "7ad73f62620e5c0a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7f310455ddd24e93", "level": "none", "message": {"text": "Commented-code block (6 lines) in apps/vibedeckx-ui/components/files/file-preview.tsx:99"}, "properties": {"repobilityId": "25a9f06afb5a8b6a", "scanner": "scanner-primary", "fingerprint": "7f310455ddd24e93", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2699d856eef2f708", "level": "none", "message": {"text": "Commented-code block (7 lines) in apps/vibedeckx-ui/components/executor/executor-output.tsx:190"}, "properties": {"repobilityId": "2e0801ee2d5aafe6", "scanner": "scanner-primary", "fingerprint": "2699d856eef2f708", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-70a3b5da0e883a2f", "level": "none", "message": {"text": "Commented-code block (5 lines) in apps/vibedeckx-ui/components/executor/executor-item.tsx:99"}, "properties": {"repobilityId": "790c93bb410baab6", "scanner": "scanner-primary", "fingerprint": "70a3b5da0e883a2f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5cefe91950ab346d", "level": "none", "message": {"text": "Commented-code block (7 lines) in apps/vibedeckx-ui/app/page.tsx:119"}, "properties": {"repobilityId": "1e4fe7fb584c27ed", "scanner": "scanner-primary", "fingerprint": "5cefe91950ab346d", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-fe0b7b2e8f044743", "level": "none", "message": {"text": "Commented-code block (5 lines) in apps/vibedeckx-ui/lib/api.ts:203"}, "properties": {"repobilityId": "27b5edab814614a8", "scanner": "scanner-primary", "fingerprint": "fe0b7b2e8f044743", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7ae8fc828852e85d", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/vibedeckx-ui/lib/api.ts:48"}, "properties": {"repobilityId": "310aafcafaf7ef6b", "scanner": "scanner-primary", "fingerprint": "7ae8fc828852e85d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-16159c665f53db0f", "level": "none", "message": {"text": "Commented-code block (6 lines) in apps/vibedeckx-ui/lib/workspace-status.test.ts:137"}, "properties": {"repobilityId": "83d6d9aa520bf79c", "scanner": "scanner-primary", "fingerprint": "16159c665f53db0f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-479333dd8d8ff13d", "level": "none", "message": {"text": "Commented-code block (5 lines) in apps/vibedeckx-ui/hooks/use-worktrees.ts:17"}, "properties": {"repobilityId": "960f02fcf5e80d42", "scanner": "scanner-primary", "fingerprint": "479333dd8d8ff13d", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f306a569c6ff37ac", "level": "none", "message": {"text": "Commented-code block (5 lines) in apps/vibedeckx-ui/hooks/use-marker-keyboard-nav.ts:4"}, "properties": {"repobilityId": "f69f4d26d78182ce", "scanner": "scanner-primary", "fingerprint": "f306a569c6ff37ac", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4e6417c07bac7dd7", "level": "none", "message": {"text": "Commented-code block (6 lines) in apps/vibedeckx-ui/hooks/use-agent-session.ts:376"}, "properties": {"repobilityId": "2f1ac33964deb337", "scanner": "scanner-primary", "fingerprint": "4e6417c07bac7dd7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-77affce6f337685c", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/vibedeckx-ui/hooks/use-agent-session.ts:108"}, "properties": {"repobilityId": "5514e1d33d28addf", "scanner": "scanner-primary", "fingerprint": "77affce6f337685c", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-a945bbe0273dd11a", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/vibedeckx-ui/hooks/use-chat-session.ts:90"}, "properties": {"repobilityId": "54ab75346269524e", "scanner": "scanner-primary", "fingerprint": "a945bbe0273dd11a", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-f7e6d4ce2baed8f4", "level": "none", "message": {"text": "Commented-code block (5 lines) in apps/vibedeckx-ui/hooks/use-branch-activity.test.ts:34"}, "properties": {"repobilityId": "3a1563662b92fa4f", "scanner": "scanner-primary", "fingerprint": "f7e6d4ce2baed8f4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e2ee3bef2b4bb289", "level": "none", "message": {"text": "Commented-code block (5 lines) in apps/vibedeckx-ui/hooks/use-completion-notifications.ts:13"}, "properties": {"repobilityId": "599b3eed287a736f", "scanner": "scanner-primary", "fingerprint": "e2ee3bef2b4bb289", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3939eb50a80df926", "level": "none", "message": {"text": "Commented-code block (6 lines) in packages/vibedeckx/src/agent-session-manager.ts:229"}, "properties": {"repobilityId": "c648e44f1562dad1", "scanner": "scanner-primary", "fingerprint": "3939eb50a80df926", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-cd155529e9d941be", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/vibedeckx/src/reverse-connect-client.ts:173"}, "properties": {"repobilityId": "dc9b152366c552cf", "scanner": "scanner-primary", "fingerprint": "cd155529e9d941be", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-29a61a7128ded508", "level": "none", "message": {"text": "Commented-code block (11 lines) in packages/vibedeckx/src/command.ts:114"}, "properties": {"repobilityId": "dab717cbe132aaef", "scanner": "scanner-primary", "fingerprint": "29a61a7128ded508", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d614e67af007fe46", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/vibedeckx/src/server.ts:48"}, "properties": {"repobilityId": "11c7839af29101a0", "scanner": "scanner-primary", "fingerprint": "d614e67af007fe46", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2df5e9f1eeca8654", "level": "none", "message": {"text": "Commented-code block (7 lines) in packages/vibedeckx/src/chat-session-manager.ts:278"}, "properties": {"repobilityId": "e62b587f2c41d2be", "scanner": "scanner-primary", "fingerprint": "2df5e9f1eeca8654", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-684bf33be7d5d812", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/vibedeckx/src/utils/remote-proxy.ts:88"}, "properties": {"repobilityId": "3f4187958a744f84", "scanner": "scanner-primary", "fingerprint": "684bf33be7d5d812", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-4f74f120966a2004", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/vibedeckx/src/routes/executor-routes.ts:8"}, "properties": {"repobilityId": "01fa020a8983a30d", "scanner": "scanner-primary", "fingerprint": "4f74f120966a2004", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-36c1271a4a46eee3", "level": "none", "message": {"text": "Commented-code block (6 lines) in packages/vibedeckx/src/routes/terminal-routes.ts:222"}, "properties": {"repobilityId": "f05b4ee13e381f14", "scanner": "scanner-primary", "fingerprint": "36c1271a4a46eee3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-69ed5784c9be45fe", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/vibedeckx/src/routes/websocket-routes.ts:171"}, "properties": {"repobilityId": "c041e3d4bcc8f13c", "scanner": "scanner-primary", "fingerprint": "69ed5784c9be45fe", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8b9f11dea48d99fb", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/vibedeckx/src/routes/settings-routes.ts:158"}, "properties": {"repobilityId": "423302423ce23923", "scanner": "scanner-primary", "fingerprint": "8b9f11dea48d99fb", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-3e378f03c0bb72b5", "level": "none", "message": {"text": "Commented-code block (6 lines) in packages/vibedeckx/src/routes/browser-proxy-routes.ts:253"}, "properties": {"repobilityId": "6616de8626dc1c91", "scanner": "scanner-primary", "fingerprint": "3e378f03c0bb72b5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-14285d2122be61cd", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/vibedeckx/src/routes/browser-proxy-routes.ts:106"}, "properties": {"repobilityId": "027ff06311742b4e", "scanner": "scanner-primary", "fingerprint": "14285d2122be61cd", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-e389a5325763af21", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/vibedeckx/src/routes/branch-activity-routes.ts:88"}, "properties": {"repobilityId": "1e88ef48a7ee0410", "scanner": "scanner-primary", "fingerprint": "e389a5325763af21", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5d62399be6286ea8", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/vibedeckx/src/routes/agent-session-routes.ts:32"}, "properties": {"repobilityId": "3f0fc151d3058b91", "scanner": "scanner-primary", "fingerprint": "5d62399be6286ea8", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5b609a86662be8d3", "level": "none", "message": {"text": "Commented-code block (10 lines) in packages/vibedeckx/src/plugins/shared-services.ts:96"}, "properties": {"repobilityId": "b4199ec14da9f73a", "scanner": "scanner-primary", "fingerprint": "5b609a86662be8d3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-92d7b6830d321840", "level": "note", "message": {"text": "Unused endpoint: OPTIONS /*"}, "properties": {"repobilityId": "706d33d34cf92859", "scanner": "scanner-primary", "fingerprint": "92d7b6830d321840", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7aa4b2518cbbbfa2", "level": "note", "message": {"text": "Unused endpoint: GET /api/config"}, "properties": {"repobilityId": "374e7c455b4ee307", "scanner": "scanner-primary", "fingerprint": "7aa4b2518cbbbfa2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3b94923f366fed0e", "level": "note", "message": {"text": "Unused endpoint: GET /api/projects"}, "properties": {"repobilityId": "eee3529c2158d461", "scanner": "scanner-primary", "fingerprint": "3b94923f366fed0e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-93f41488d82ae3b2", "level": "note", "message": {"text": "Unused endpoint: POST /api/dialog/select-folder"}, "properties": {"repobilityId": "e064c60060cdc394", "scanner": "scanner-primary", "fingerprint": "93f41488d82ae3b2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ca409df5c58a3acb", "level": "note", "message": {"text": "Unused endpoint: GET /api/settings/proxy"}, "properties": {"repobilityId": "b75c4d270706bca8", "scanner": "scanner-primary", "fingerprint": "ca409df5c58a3acb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5c5618ac61014f30", "level": "note", "message": {"text": "Unused endpoint: GET /api/settings/chat-provider"}, "properties": {"repobilityId": "b803ea2a5e08b401", "scanner": "scanner-primary", "fingerprint": "5c5618ac61014f30", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b3d2bf498d0843f8", "level": "note", "message": {"text": "Unused endpoint: GET /api/settings/terminal"}, "properties": {"repobilityId": "8c927f9903f42ce6", "scanner": "scanner-primary", "fingerprint": "b3d2bf498d0843f8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d40f65144ec255e8", "level": "note", "message": {"text": "Unused endpoint: GET /api/settings/conversation"}, "properties": {"repobilityId": "eba52e559fcf84cc", "scanner": "scanner-primary", "fingerprint": "d40f65144ec255e8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c3c4aad67099794e", "level": "note", "message": {"text": "Unused endpoint: GET /api/executor-processes/running"}, "properties": {"repobilityId": "0ed8733bb273d9d0", "scanner": "scanner-primary", "fingerprint": "c3c4aad67099794e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-95322da25eed4d22", "level": "note", "message": {"text": "Unused endpoint: GET /api/remote-servers"}, "properties": {"repobilityId": "b7dc5d55f0814535", "scanner": "scanner-primary", "fingerprint": "95322da25eed4d22", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e47ff33f50d81527", "level": "note", "message": {"text": "Unused endpoint: POST /api/remote-servers"}, "properties": {"repobilityId": "3d399b51f410efab", "scanner": "scanner-primary", "fingerprint": "e47ff33f50d81527", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e7095e7afa6f36f9", "level": "note", "message": {"text": "Unused endpoint: GET /api/agent-providers"}, "properties": {"repobilityId": "c46f2d9ddf7fd85e", "scanner": "scanner-primary", "fingerprint": "e7095e7afa6f36f9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}