{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-af0f88ecbb5d9646", "name": "Possibly dead Python function: resolve_jurisdiction", "shortDescription": {"text": "Possibly dead Python function: resolve_jurisdiction"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa7ddba00560f301", "name": "Possibly dead Python function: key", "shortDescription": {"text": "Possibly dead Python function: key"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d63da3583b14afc0", "name": "Dockerfile runs as root: Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-de3c1f217d72a063", "name": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-27924aa79fa4a517", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 36 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8e1f8980a64e721b", "name": "Agent authority lacks a verifier contract: .cursor/commands/openspec-archive.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .cursor/commands/openspec-archive.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-41cacbfefd1b3849", "name": "Agent authority lacks a verifier contract: .cursor/commands/openspec-apply.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .cursor/commands/openspec-apply.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8e7071a06d020e75", "name": "Agent authority lacks a verifier contract: .cursor/commands/openspec-proposal.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .cursor/commands/openspec-proposal.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2f1b6a2e4a509188", "name": "Legacy-named symbol `too_old` in tests/test_wallet_flow.py:127", "shortDescription": {"text": "Legacy-named symbol `too_old` in tests/test_wallet_flow.py:127"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7e22b298be39cf0b", "name": "Commented-code block (6 lines) in tests/test_risk.py:187", "shortDescription": {"text": "Commented-code block (6 lines) in tests/test_risk.py:187"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-253f488b0e621e3e", "name": "Blocking `urllib.request.urlopen(...)` inside `async def estimate_p_model` \u2014 src/crypto_news_parser/llm_adapter.py:124", "shortDescription": {"text": "Blocking `urllib.request.urlopen(...)` inside `async def estimate_p_model` \u2014 src/crypto_news_parser/llm_adapter.py:124"}, "fullDescription": {"text": "Sync I/O inside an async function blocks the event loop. While `urllib.request.urlopen(...)` is running, *all* other coroutines on this loop are paused \u2014 silent throughput collapse under concurrency. Use the async equivalent (`httpx.AsyncClient`, `asyncio.sleep`, `aiofiles`) or wrap with `await asyncio.to_thread(...)`."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c2f8a13658c1f7c2", "name": "Blocking `urllib.request.urlopen(...)` inside `async def refine` \u2014 src/crypto_news_parser/llm_adapter.py:178", "shortDescription": {"text": "Blocking `urllib.request.urlopen(...)` inside `async def refine` \u2014 src/crypto_news_parser/llm_adapter.py:178"}, "fullDescription": {"text": "Sync I/O inside an async function blocks the event loop. While `urllib.request.urlopen(...)` is running, *all* other coroutines on this loop are paused \u2014 silent throughput collapse under concurrency. Use the async equivalent (`httpx.AsyncClient`, `asyncio.sleep`, `aiofiles`) or wrap with `await asyncio.to_thread(...)`."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "high", "confidence": 1.0}}, {"id": "scanner-88749408b120dd46", "name": "Blocking `urllib.request.urlopen(...)` inside `async def estimate_p_model` \u2014 src/crypto_news_parser/llm_adapter.py:241", "shortDescription": {"text": "Blocking `urllib.request.urlopen(...)` inside `async def estimate_p_model` \u2014 src/crypto_news_parser/llm_adapter.py:241"}, "fullDescription": {"text": "Sync I/O inside an async function blocks the event loop. While `urllib.request.urlopen(...)` is running, *all* other coroutines on this loop are paused \u2014 silent throughput collapse under concurrency. Use the async equivalent (`httpx.AsyncClient`, `asyncio.sleep`, `aiofiles`) or wrap with `await asyncio.to_thread(...)`."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d7f395a0af978b4d", "name": "Stub function `estimate_p_model` (body is just `pass`/`return`) \u2014 src/crypto_news_parser/llm_adapter.py:81", "shortDescription": {"text": "Stub function `estimate_p_model` (body is just `pass`/`return`) \u2014 src/crypto_news_parser/llm_adapter.py:81"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c1a23b38831ef0c1", "name": "Legacy-named symbol `model_copy` in src/crypto_news_parser/main.py:595", "shortDescription": {"text": "Legacy-named symbol `model_copy` in src/crypto_news_parser/main.py:595"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b334d875f2339fa1", "name": "5 env vars used in code but missing from .env.example", "shortDescription": {"text": "5 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `ALERT_MIN_TIER`, `DB_PATH`, `PAPER_FEE`, `PAPER_STAKE`, `RUN_GOLDEN_STRICT`. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-49c98f7cedd9c977", "name": "Near-duplicate function bodies in 4 places", "shortDescription": {"text": "Near-duplicate function bodies in 4 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nsrc/crypto_news_parser/llm_adapter.py:refine, src/crypto_news_parser/llm_adapter.py:refine, src/crypto_news_parser/llm_adapter.py:refine, src/crypto_news_parser/llm_adapter.py:refine\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nsrc/crypto_news_parser/models.py:validate_text, src/crypto_news_parser/models.py:validate_text\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-47003029c59cef13", "name": "FastAPI POST `parse` without auth dependency \u2014 src/crypto_news_parser/main.py:274", "shortDescription": {"text": "FastAPI POST `parse` without auth dependency \u2014 src/crypto_news_parser/main.py:274"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-833f9e77052c8655", "name": "FastAPI POST `feedback` without auth dependency \u2014 src/crypto_news_parser/main.py:410", "shortDescription": {"text": "FastAPI POST `feedback` without auth dependency \u2014 src/crypto_news_parser/main.py:410"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2a1dbb3bd4b14209", "name": "FastAPI POST `parse_url` without auth dependency \u2014 src/crypto_news_parser/main.py:453", "shortDescription": {"text": "FastAPI POST `parse_url` without auth dependency \u2014 src/crypto_news_parser/main.py:453"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c32122473143c8e2", "name": "FastAPI POST `signal` without auth dependency \u2014 src/crypto_news_parser/main.py:520", "shortDescription": {"text": "FastAPI POST `signal` without auth dependency \u2014 src/crypto_news_parser/main.py:520"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6ed3ca0113f0ae5e", "name": "FastAPI POST `risk` without auth dependency \u2014 src/crypto_news_parser/main.py:586", "shortDescription": {"text": "FastAPI POST `risk` without auth dependency \u2014 src/crypto_news_parser/main.py:586"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-050763113fb1d01e", "name": "FastAPI POST `release_deployed` without auth dependency \u2014 src/crypto_news_parser/main.py:618", "shortDescription": {"text": "FastAPI POST `release_deployed` without auth dependency \u2014 src/crypto_news_parser/main.py:618"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-349d4c198c472fef", "name": "FastAPI POST `reset_deployed` without auth dependency \u2014 src/crypto_news_parser/main.py:632", "shortDescription": {"text": "FastAPI POST `reset_deployed` without auth dependency \u2014 src/crypto_news_parser/main.py:632"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2823b603ed670c05", "name": "FastAPI POST `flow_scan` without auth dependency \u2014 src/crypto_news_parser/main.py:673", "shortDescription": {"text": "FastAPI POST `flow_scan` without auth dependency \u2014 src/crypto_news_parser/main.py:673"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cb77fdb5a9f2128f", "name": "FastAPI POST `track_market_endpoint` without auth dependency \u2014 src/crypto_news_parser/main.py:741", "shortDescription": {"text": "FastAPI POST `track_market_endpoint` without auth dependency \u2014 src/crypto_news_parser/main.py:741"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f149cc708680289b", "name": "FastAPI POST `poll_resolutions` without auth dependency \u2014 src/crypto_news_parser/main.py:820", "shortDescription": {"text": "FastAPI POST `poll_resolutions` without auth dependency \u2014 src/crypto_news_parser/main.py:820"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`src/crypto_news_parser/main.py` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-21d4e3431aa9b5dc", "name": "Unused endpoint: POST /parse", "shortDescription": {"text": "Unused endpoint: POST /parse"}, "fullDescription": {"text": "`src/crypto_news_parser/main.py` declares `POST /parse` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8f95d7ec49f00406", "name": "Unused endpoint: POST /feedback", "shortDescription": {"text": "Unused endpoint: POST /feedback"}, "fullDescription": {"text": "`src/crypto_news_parser/main.py` declares `POST /feedback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-183d1b9765e3b4fd", "name": "Unused endpoint: POST /parse_url", "shortDescription": {"text": "Unused endpoint: POST /parse_url"}, "fullDescription": {"text": "`src/crypto_news_parser/main.py` declares `POST /parse_url` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-067fd482fe4bf558", "name": "Unused endpoint: POST /signal", "shortDescription": {"text": "Unused endpoint: POST /signal"}, "fullDescription": {"text": "`src/crypto_news_parser/main.py` declares `POST /signal` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9d1c83e32faac0a7", "name": "Unused endpoint: POST /risk", "shortDescription": {"text": "Unused endpoint: POST /risk"}, "fullDescription": {"text": "`src/crypto_news_parser/main.py` declares `POST /risk` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6d2d3f3917a745e1", "name": "Unused endpoint: GET /deployed", "shortDescription": {"text": "Unused endpoint: GET /deployed"}, "fullDescription": {"text": "`src/crypto_news_parser/main.py` declares `GET /deployed` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-70e35cb9d154fb6e", "name": "Unused endpoint: POST /deployed/release", "shortDescription": {"text": "Unused endpoint: POST /deployed/release"}, "fullDescription": {"text": "`src/crypto_news_parser/main.py` declares `POST /deployed/release` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-065f8554fa5054c1", "name": "Unused endpoint: POST /deployed/reset", "shortDescription": {"text": "Unused endpoint: POST /deployed/reset"}, "fullDescription": {"text": "`src/crypto_news_parser/main.py` declares `POST /deployed/reset` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-57ade8d885b4811b", "name": "Unused endpoint: POST /flow-scan", "shortDescription": {"text": "Unused endpoint: POST /flow-scan"}, "fullDescription": {"text": "`src/crypto_news_parser/main.py` declares `POST /flow-scan` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d504b80adc9409ec", "name": "Unused endpoint: GET /dashboard", "shortDescription": {"text": "Unused endpoint: GET /dashboard"}, "fullDescription": {"text": "`src/crypto_news_parser/main.py` declares `GET /dashboard` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7b4a62e900f04ac1", "name": "Unused endpoint: GET /dashboard/data", "shortDescription": {"text": "Unused endpoint: GET /dashboard/data"}, "fullDescription": {"text": "`src/crypto_news_parser/main.py` declares `GET /dashboard/data` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f48481b458c4bf3b", "name": "Unused endpoint: GET /flow-calibration", "shortDescription": {"text": "Unused endpoint: GET /flow-calibration"}, "fullDescription": {"text": "`src/crypto_news_parser/main.py` declares `GET /flow-calibration` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-850dec66e9f15f23", "name": "Unused endpoint: POST /track-market", "shortDescription": {"text": "Unused endpoint: POST /track-market"}, "fullDescription": {"text": "`src/crypto_news_parser/main.py` declares `POST /track-market` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bd857eee01083876", "name": "Unused endpoint: POST /poll-resolutions", "shortDescription": {"text": "Unused endpoint: POST /poll-resolutions"}, "fullDescription": {"text": "`src/crypto_news_parser/main.py` declares `POST /poll-resolutions` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/21283"}, "properties": {"repository": "Timaroc13/polymarket-engine", "repoUrl": "https://github.com/Timaroc13/polymarket-engine", "branch": "main"}, "results": [{"ruleId": "scanner-af0f88ecbb5d9646", "level": "note", "message": {"text": "Possibly dead Python function: resolve_jurisdiction"}, "properties": {"repobilityId": "d668b96a9afc14a9", "scanner": "scanner-primary", "fingerprint": "af0f88ecbb5d9646", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/crypto_news_parser/parser.py:274"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa7ddba00560f301", "level": "note", "message": {"text": "Possibly dead Python function: key"}, "properties": {"repobilityId": "82ad9f64418e6fec", "scanner": "scanner-primary", "fingerprint": "aa7ddba00560f301", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/crypto_news_parser/parser.py:1057"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d63da3583b14afc0", "level": "warning", "message": {"text": "Dockerfile runs as root: Dockerfile"}, "properties": {"repobilityId": "a2ed1bd120e507db", "scanner": "scanner-primary", "fingerprint": "d63da3583b14afc0", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-de3c1f217d72a063", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "properties": {"repobilityId": "1de0ecd007803dbd", "scanner": "scanner-primary", "fingerprint": "de3c1f217d72a063", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ae16880318b99912", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 14}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "04f57d208548fcef", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "f8ef48fe44a73524", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "31454bfde9d17843", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "97e7489199210b8d", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "82ea49adbf6c938f", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "a9d7f1da79e26a9f", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "edac48796e3c660d", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8e1f8980a64e721b", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .cursor/commands/openspec-archive.md"}, "properties": {"repobilityId": "093ad1a5dc11d782", "scanner": "scanner-primary", "fingerprint": "8e1f8980a64e721b", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "cursor_rule"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".cursor/commands/openspec-archive.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-41cacbfefd1b3849", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .cursor/commands/openspec-apply.md"}, "properties": {"repobilityId": "8efd890b5296cfa2", "scanner": "scanner-primary", "fingerprint": "41cacbfefd1b3849", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "cursor_rule"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".cursor/commands/openspec-apply.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8e7071a06d020e75", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .cursor/commands/openspec-proposal.md"}, "properties": {"repobilityId": "9a765d9347134ce0", "scanner": "scanner-primary", "fingerprint": "8e7071a06d020e75", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "cursor_rule"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".cursor/commands/openspec-proposal.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2f1b6a2e4a509188", "level": "note", "message": {"text": "Legacy-named symbol `too_old` in tests/test_wallet_flow.py:127"}, "properties": {"repobilityId": "4b83b0a7c90264d0", "scanner": "scanner-primary", "fingerprint": "2f1b6a2e4a509188", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-7e22b298be39cf0b", "level": "none", "message": {"text": "Commented-code block (6 lines) in tests/test_risk.py:187"}, "properties": {"repobilityId": "69bda23ceef51d23", "scanner": "scanner-primary", "fingerprint": "7e22b298be39cf0b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-253f488b0e621e3e", "level": "error", "message": {"text": "Blocking `urllib.request.urlopen(...)` inside `async def estimate_p_model` \u2014 src/crypto_news_parser/llm_adapter.py:124"}, "properties": {"repobilityId": "0f3e575896318297", "scanner": "scanner-primary", "fingerprint": "253f488b0e621e3e", "layer": "quality", "severity": "high", "confidence": 1.0, "tags": ["integrity", "sync-io-in-async", "performance"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/crypto_news_parser/llm_adapter.py"}, "region": {"startLine": 124}}}]}, {"ruleId": "scanner-c2f8a13658c1f7c2", "level": "error", "message": {"text": "Blocking `urllib.request.urlopen(...)` inside `async def refine` \u2014 src/crypto_news_parser/llm_adapter.py:178"}, "properties": {"repobilityId": "0773362841ad1817", "scanner": "scanner-primary", "fingerprint": "c2f8a13658c1f7c2", "layer": "quality", "severity": "high", "confidence": 1.0, "tags": ["integrity", "sync-io-in-async", "performance"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/crypto_news_parser/llm_adapter.py"}, "region": {"startLine": 178}}}]}, {"ruleId": "scanner-88749408b120dd46", "level": "error", "message": {"text": "Blocking `urllib.request.urlopen(...)` inside `async def estimate_p_model` \u2014 src/crypto_news_parser/llm_adapter.py:241"}, "properties": {"repobilityId": "6ddcfc156d398e6e", "scanner": "scanner-primary", "fingerprint": "88749408b120dd46", "layer": "quality", "severity": "high", "confidence": 1.0, "tags": ["integrity", "sync-io-in-async", "performance"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/crypto_news_parser/llm_adapter.py"}, "region": {"startLine": 241}}}]}, {"ruleId": "scanner-d7f395a0af978b4d", "level": "note", "message": {"text": "Stub function `estimate_p_model` (body is just `pass`/`return`) \u2014 src/crypto_news_parser/llm_adapter.py:81"}, "properties": {"repobilityId": "ed35564ced0ec01b", "scanner": "scanner-primary", "fingerprint": "d7f395a0af978b4d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-c1a23b38831ef0c1", "level": "note", "message": {"text": "Legacy-named symbol `model_copy` in src/crypto_news_parser/main.py:595"}, "properties": {"repobilityId": "00bfbe248443508a", "scanner": "scanner-primary", "fingerprint": "c1a23b38831ef0c1", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-b334d875f2339fa1", "level": "note", "message": {"text": "5 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "faa38682016f5d53", "scanner": "scanner-primary", "fingerprint": "b334d875f2339fa1", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "bbe20256b18ff8bc", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "b408280c9b9ebfa7", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "f438c3e1e9bbd6df", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-47003029c59cef13", "level": "error", "message": {"text": "FastAPI POST `parse` without auth dependency \u2014 src/crypto_news_parser/main.py:274"}, "properties": {"repobilityId": "366660da194c0cef", "scanner": "scanner-primary", "fingerprint": "47003029c59cef13", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/crypto_news_parser/main.py"}, "region": {"startLine": 274}}}]}, {"ruleId": "scanner-833f9e77052c8655", "level": "error", "message": {"text": "FastAPI POST `feedback` without auth dependency \u2014 src/crypto_news_parser/main.py:410"}, "properties": {"repobilityId": "18ad7388cc41ea19", "scanner": "scanner-primary", "fingerprint": "833f9e77052c8655", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/crypto_news_parser/main.py"}, "region": {"startLine": 410}}}]}, {"ruleId": "scanner-2a1dbb3bd4b14209", "level": "error", "message": {"text": "FastAPI POST `parse_url` without auth dependency \u2014 src/crypto_news_parser/main.py:453"}, "properties": {"repobilityId": "49f6807b7cfa32dc", "scanner": "scanner-primary", "fingerprint": "2a1dbb3bd4b14209", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/crypto_news_parser/main.py"}, "region": {"startLine": 453}}}]}, {"ruleId": "scanner-c32122473143c8e2", "level": "error", "message": {"text": "FastAPI POST `signal` without auth dependency \u2014 src/crypto_news_parser/main.py:520"}, "properties": {"repobilityId": "90b3c9b2d39418c5", "scanner": "scanner-primary", "fingerprint": "c32122473143c8e2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/crypto_news_parser/main.py"}, "region": {"startLine": 520}}}]}, {"ruleId": "scanner-6ed3ca0113f0ae5e", "level": "error", "message": {"text": "FastAPI POST `risk` without auth dependency \u2014 src/crypto_news_parser/main.py:586"}, "properties": {"repobilityId": "5ae507954caa21b7", "scanner": "scanner-primary", "fingerprint": "6ed3ca0113f0ae5e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/crypto_news_parser/main.py"}, "region": {"startLine": 586}}}]}, {"ruleId": "scanner-050763113fb1d01e", "level": "error", "message": {"text": "FastAPI POST `release_deployed` without auth dependency \u2014 src/crypto_news_parser/main.py:618"}, "properties": {"repobilityId": "d343e769edbe7f17", "scanner": "scanner-primary", "fingerprint": "050763113fb1d01e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/crypto_news_parser/main.py"}, "region": {"startLine": 618}}}]}, {"ruleId": "scanner-349d4c198c472fef", "level": "error", "message": {"text": "FastAPI POST `reset_deployed` without auth dependency \u2014 src/crypto_news_parser/main.py:632"}, "properties": {"repobilityId": "eabb5f15592bed5b", "scanner": "scanner-primary", "fingerprint": "349d4c198c472fef", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/crypto_news_parser/main.py"}, "region": {"startLine": 632}}}]}, {"ruleId": "scanner-2823b603ed670c05", "level": "error", "message": {"text": "FastAPI POST `flow_scan` without auth dependency \u2014 src/crypto_news_parser/main.py:673"}, "properties": {"repobilityId": "7e74ddbd01ed6656", "scanner": "scanner-primary", "fingerprint": "2823b603ed670c05", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/crypto_news_parser/main.py"}, "region": {"startLine": 673}}}]}, {"ruleId": "scanner-cb77fdb5a9f2128f", "level": "error", "message": {"text": "FastAPI POST `track_market_endpoint` without auth dependency \u2014 src/crypto_news_parser/main.py:741"}, "properties": {"repobilityId": "ca4066c7b99a189f", "scanner": "scanner-primary", "fingerprint": "cb77fdb5a9f2128f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/crypto_news_parser/main.py"}, "region": {"startLine": 741}}}]}, {"ruleId": "scanner-f149cc708680289b", "level": "error", "message": {"text": "FastAPI POST `poll_resolutions` without auth dependency \u2014 src/crypto_news_parser/main.py:820"}, "properties": {"repobilityId": "8df3964241b5a333", "scanner": "scanner-primary", "fingerprint": "f149cc708680289b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/crypto_news_parser/main.py"}, "region": {"startLine": 820}}}]}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "798f491b3c9cce35", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-21d4e3431aa9b5dc", "level": "note", "message": {"text": "Unused endpoint: POST /parse"}, "properties": {"repobilityId": "feb2db221273bf17", "scanner": "scanner-primary", "fingerprint": "21d4e3431aa9b5dc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8f95d7ec49f00406", "level": "note", "message": {"text": "Unused endpoint: POST /feedback"}, "properties": {"repobilityId": "5d18fd66631a2a19", "scanner": "scanner-primary", "fingerprint": "8f95d7ec49f00406", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-183d1b9765e3b4fd", "level": "note", "message": {"text": "Unused endpoint: POST /parse_url"}, "properties": {"repobilityId": "23588e4245ace215", "scanner": "scanner-primary", "fingerprint": "183d1b9765e3b4fd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-067fd482fe4bf558", "level": "note", "message": {"text": "Unused endpoint: POST /signal"}, "properties": {"repobilityId": "dae853a2c294b819", "scanner": "scanner-primary", "fingerprint": "067fd482fe4bf558", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9d1c83e32faac0a7", "level": "note", "message": {"text": "Unused endpoint: POST /risk"}, "properties": {"repobilityId": "1ef9732b06ac033f", "scanner": "scanner-primary", "fingerprint": "9d1c83e32faac0a7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6d2d3f3917a745e1", "level": "note", "message": {"text": "Unused endpoint: GET /deployed"}, "properties": {"repobilityId": "71c7b2fea75a9530", "scanner": "scanner-primary", "fingerprint": "6d2d3f3917a745e1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-70e35cb9d154fb6e", "level": "note", "message": {"text": "Unused endpoint: POST /deployed/release"}, "properties": {"repobilityId": "94dd5954e05d7634", "scanner": "scanner-primary", "fingerprint": "70e35cb9d154fb6e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-065f8554fa5054c1", "level": "note", "message": {"text": "Unused endpoint: POST /deployed/reset"}, "properties": {"repobilityId": "dbc98fb0cacae196", "scanner": "scanner-primary", "fingerprint": "065f8554fa5054c1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-57ade8d885b4811b", "level": "note", "message": {"text": "Unused endpoint: POST /flow-scan"}, "properties": {"repobilityId": "93185fd7c5376188", "scanner": "scanner-primary", "fingerprint": "57ade8d885b4811b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d504b80adc9409ec", "level": "note", "message": {"text": "Unused endpoint: GET /dashboard"}, "properties": {"repobilityId": "355c128af03ae6ab", "scanner": "scanner-primary", "fingerprint": "d504b80adc9409ec", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7b4a62e900f04ac1", "level": "note", "message": {"text": "Unused endpoint: GET /dashboard/data"}, "properties": {"repobilityId": "e4080e6ca5ed0237", "scanner": "scanner-primary", "fingerprint": "7b4a62e900f04ac1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f48481b458c4bf3b", "level": "note", "message": {"text": "Unused endpoint: GET /flow-calibration"}, "properties": {"repobilityId": "02d2223d893d9f9c", "scanner": "scanner-primary", "fingerprint": "f48481b458c4bf3b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-850dec66e9f15f23", "level": "note", "message": {"text": "Unused endpoint: POST /track-market"}, "properties": {"repobilityId": "bd54f2ca37134a78", "scanner": "scanner-primary", "fingerprint": "850dec66e9f15f23", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bd857eee01083876", "level": "note", "message": {"text": "Unused endpoint: POST /poll-resolutions"}, "properties": {"repobilityId": "2b8790cd93519e12", "scanner": "scanner-primary", "fingerprint": "bd857eee01083876", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}