{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-86bd2b0aa87a635d", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/TenantSwitcher.tsx:72", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/TenantSwitcher.tsx:72"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b400940da61887b0", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/ChatPanel.tsx:254", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/ChatPanel.tsx:254"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ae56fa994bbd328a", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/planning/MedewerkerLabel.tsx:30", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/planning/MedewerkerLabel.tsx:30"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1ff2a099c26f5a13", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/planning/AfspraakBlock.tsx:96", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/planning/AfspraakBlock.tsx:96"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-11326fb031c90469", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 apps/web/src/app/layout.tsx:16", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 apps/web/src/app/layout.tsx:16"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ce35b0335525a9a4", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/overdracht/page.tsx:395", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/overdracht/page.tsx:395"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4b05228ad2c2f5f8", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/dashboard/page.tsx:353", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/dashboard/page.tsx:353"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-694fc490f14251c5", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/rapportages/page.tsx:299", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/rapportages/page.tsx:299"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c65965aab2dba2c5", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/mic-meldingen/page.tsx:494", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/mic-meldingen/page.tsx:494"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-fda61cf69de17542", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/codelijsten/page.tsx:184", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/codelijsten/page.tsx:184"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9c27b7cb45e6dccd", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/mic-trends/page.tsx:294", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/mic-trends/page.tsx:294"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d6b6e98adb7219ac", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/berichten/page.tsx:206", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/berichten/page.tsx:206"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-770aedd6a95faadd", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/ecd/[id]/zorgplan/page.tsx:672", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/ecd/[id]/zorgplan/page.tsx:672"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2d89f631fd86ab66", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/signaleringen/page.tsx:257", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/signaleringen/page.tsx:257"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-95e050aa44a9b9ef", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/planning/dagplanning/page.tsx:388", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/planning/dagplanning/page.tsx:388"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e146f59eb1eb3057", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/vandaag/page.tsx:163", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/vandaag/page.tsx:163"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-af84de362d6294f4", "name": "Stray `console.log` in TS/JS \u2014 services/ecd/src/routes/ai-settings.ts:44", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 services/ecd/src/routes/ai-settings.ts:44"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3f425f09a2aba046", "name": "Privileged port 10 in use", "shortDescription": {"text": "Privileged port 10 in use"}, "fullDescription": {"text": "Port 10 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cff44f412b6fa355", "name": "Privileged port 7 in use", "shortDescription": {"text": "Privileged port 7 in use"}, "fullDescription": {"text": "Port 7 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-89eab07b953f06e7", "name": "Privileged port 30 in use", "shortDescription": {"text": "Privileged port 30 in use"}, "fullDescription": {"text": "Port 30 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0a5aa084a1dce47d", "name": "Privileged port 11 in use", "shortDescription": {"text": "Privileged port 11 in use"}, "fullDescription": {"text": "Port 11 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e4730979abffa66b", "name": "Privileged port 17 in use", "shortDescription": {"text": "Privileged port 17 in use"}, "fullDescription": {"text": "Port 17 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bf3d181d23b26f76", "name": "Privileged port 16 in use", "shortDescription": {"text": "Privileged port 16 in use"}, "fullDescription": {"text": "Port 16 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c947ed0387dd77b7", "name": "Privileged port 14 in use", "shortDescription": {"text": "Privileged port 14 in use"}, "fullDescription": {"text": "Port 14 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-085943872640c49f", "name": "Privileged port 23 in use", "shortDescription": {"text": "Privileged port 23 in use"}, "fullDescription": {"text": "Port 23 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2594da86fd011854", "name": "Privileged port 13 in use", "shortDescription": {"text": "Privileged port 13 in use"}, "fullDescription": {"text": "Port 13 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3f53fedf57ce2caa", "name": "Privileged port 19 in use", "shortDescription": {"text": "Privileged port 19 in use"}, "fullDescription": {"text": "Port 19 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4936e96ee6dbf927", "name": "Insecure pattern 'node_child_process' in apps/web/next.config.mjs:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in apps/web/next.config.mjs:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6321b99140465d43", "name": "Insecure pattern 'dangerous_innerhtml' in apps/web/src/app/layout.tsx:16", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in apps/web/src/app/layout.tsx:16"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-32303b80aef32a91", "name": "Insecure pattern 'local_storage_auth_token' in apps/web/src/app/login/page.tsx:57", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in apps/web/src/app/login/page.tsx:57"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b2cd78c232f51913", "name": "Insecure pattern 'local_storage_auth_token' in apps/web/src/lib/api.ts:107", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in apps/web/src/lib/api.ts:107"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-09bfb12d0bd5c38e", "name": "Possible secret in scripts/seed-medplum.mjs", "shortDescription": {"text": "Possible secret in scripts/seed-medplum.mjs"}, "fullDescription": {"text": "Detected pattern matching password_literal. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-8172a454e11bfcb9", "name": "Possible secret in scripts/test-tenant-isolation.mjs", "shortDescription": {"text": "Possible secret in scripts/test-tenant-isolation.mjs"}, "fullDescription": {"text": "Detected pattern matching password_literal. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-001c907476f47017", "name": "Insecure pattern 'cors_wildcard' in services/ecd/src/app.ts:63", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in services/ecd/src/app.ts:63"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-796cff60e7bca12b", "name": "Insecure pattern 'cors_wildcard' in services/facturatie/src/index.ts:19", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in services/facturatie/src/index.ts:19"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9e4ddbe172edfe52", "name": "Insecure pattern 'cors_wildcard' in services/planning/src/app.ts:26", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in services/planning/src/app.ts:26"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1140db970a23db81", "name": "Insecure pattern 'cors_wildcard' in services/workflow-bridge/src/app.ts:20", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in services/workflow-bridge/src/app.ts:20"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-61ca18d164db7cf8", "name": "Possible secret in infra/scripts/augment-vvt-data.mjs", "shortDescription": {"text": "Possible secret in infra/scripts/augment-vvt-data.mjs"}, "fullDescription": {"text": "Detected pattern matching password_literal. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-28c4a04bd807da0c", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "appleboy/ssh-action@v1.0.3 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-27924aa79fa4a517", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/upload-artifact@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1838a141491ce38c", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-43180284aa0b81d5", "name": "Very large file: infra/scripts/seed.sh (1293 lines)", "shortDescription": {"text": "Very large file: infra/scripts/seed.sh (1293 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea3b5e389d8c9c0f", "name": "Low test-to-source ratio", "shortDescription": {"text": "Low test-to-source ratio"}, "fullDescription": {"text": "34 tests / 242 src (ratio 0.14)."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ce86778bdbd6dd71", "name": "Node manifest has dependencies but no lockfile: adapters/ons-import/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: adapters/ons-import/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4a9eb7dc7c6e3880", "name": "Node manifest has dependencies but no lockfile: apps/web/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: apps/web/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5f3913d16f97a515", "name": "Node manifest has dependencies but no lockfile: packages/shared-domain/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/shared-domain/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1b7c82ffff29113c", "name": "Node manifest has dependencies but no lockfile: packages/shared-config/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/shared-config/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-36fe6cdeb59e47d7", "name": "Node manifest has dependencies but no lockfile: packages/shared-ui/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/shared-ui/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-423c675d5c44fcd6", "name": "Node manifest has dependencies but no lockfile: packages/shared-test/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/shared-test/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-10a1d6c7a5015379", "name": "Node manifest has dependencies but no lockfile: services/ecd/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: services/ecd/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-38de99938422d5e9", "name": "Node manifest has dependencies but no lockfile: services/facturatie/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: services/facturatie/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4b1d0f1f7b3affc3", "name": "Node manifest has dependencies but no lockfile: services/planning/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: services/planning/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-615876dd84ce6b8d", "name": "Node manifest has dependencies but no lockfile: services/workflow-bridge/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: services/workflow-bridge/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 231 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 179 placeholder/mock markers across 55 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing lockfile. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6d34890aa3bee162", "name": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/src/components/ChatPanel.tsx:141", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/src/components/ChatPanel.tsx:141"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dea8ebf20b325851", "name": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/src/app/api/auth/login/route.ts:66", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/src/app/api/auth/login/route.ts:66"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-209c81fe4aa787a8", "name": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/test-tenant-isolation.mjs:55", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/test-tenant-isolation.mjs:55"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8e06389e2edfe659", "name": "`fetch()` without try/.catch or AbortSignal \u2014 services/ecd/src/lib/medplum-client.ts:50", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/ecd/src/lib/medplum-client.ts:50"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-37417993a238afba", "name": "`fetch()` without try/.catch or AbortSignal \u2014 services/ecd/src/lib/timer-service.ts:78", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/ecd/src/lib/timer-service.ts:78"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c3c7326d3fb0ed72", "name": "`fetch()` without try/.catch or AbortSignal \u2014 services/ecd/src/lib/ollama-client.ts:116", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/ecd/src/lib/ollama-client.ts:116"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d78e1b6582ad91c4", "name": "`fetch()` without try/.catch or AbortSignal \u2014 services/ecd/src/routes/ai.ts:251", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/ecd/src/routes/ai.ts:251"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-52d495758171bedb", "name": "`fetch()` without try/.catch or AbortSignal \u2014 services/ecd/src/routes/documenten.ts:86", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/ecd/src/routes/documenten.ts:86"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-700e35c705ffc0fe", "name": "`fetch()` without try/.catch or AbortSignal \u2014 services/ecd/src/routes/zorgplan.ts:349", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/ecd/src/routes/zorgplan.ts:349"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0e971c6f4dad5c1a", "name": "`fetch()` without try/.catch or AbortSignal \u2014 services/ecd/src/routes/tenants.ts:304", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/ecd/src/routes/tenants.ts:304"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8cdc5220f4e57595", "name": "`fetch()` without try/.catch or AbortSignal \u2014 services/planning/src/lib/medplum-client.ts:50", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/planning/src/lib/medplum-client.ts:50"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-864b19ba448dc3c2", "name": "`fetch()` without try/.catch or AbortSignal \u2014 services/planning/src/routes/dienst-config.ts:50", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/planning/src/routes/dienst-config.ts:50"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c7bd76281ba6918b", "name": "`fetch()` without try/.catch or AbortSignal \u2014 services/planning/src/routes/planning-engine.ts:73", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/planning/src/routes/planning-engine.ts:73"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ca3c455fc34a6d2c", "name": "`fetch()` without try/.catch or AbortSignal \u2014 services/planning/src/routes/bezetting.ts:27", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/planning/src/routes/bezetting.ts:27"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1a82e4abbbb079c9", "name": "`fetch()` without try/.catch or AbortSignal \u2014 infra/scripts/augment-vvt-data.mjs:46", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 infra/scripts/augment-vvt-data.mjs:46"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9996447513897762", "name": "30 env vars used in code but missing from .env.example", "shortDescription": {"text": "30 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `CI`, `E2E_BASE_URL`, `ECD_SERVICE_URL`, `FACTURATIE_SERVICE_URL`, `FLOWABLE_ADMIN_PASSWORD`, `FLOWABLE_ADMIN_USER`, `FLOWABLE_BASE_URL`, `GIT_SHA` + 22 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a6851ff80ff1db0c", "name": "Dangling fetch: GET /api/ecd/api/admin/ai-settings (apps/web/src/components/ChatPanel.tsx:69)", "shortDescription": {"text": "Dangling fetch: GET /api/ecd/api/admin/ai-settings (apps/web/src/components/ChatPanel.tsx:69)"}, "fullDescription": {"text": "`apps/web/src/components/ChatPanel.tsx:69` calls `GET /api/ecd/api/admin/ai-settings` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/ecd/api/admin/ai-settings`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-894df61aca6e8535", "name": "Dangling fetch: POST /api/ecd/api/ai/chat (apps/web/src/components/ChatPanel.tsx:141)", "shortDescription": {"text": "Dangling fetch: POST /api/ecd/api/ai/chat (apps/web/src/components/ChatPanel.tsx:141)"}, "fullDescription": {"text": "`apps/web/src/components/ChatPanel.tsx:141` calls `POST /api/ecd/api/ai/chat` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/ecd/api/ai/chat`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d17e6c7d71e226ba", "name": "Dangling fetch: POST /api/auth/login (apps/web/src/app/login/page.tsx:43)", "shortDescription": {"text": "Dangling fetch: POST /api/auth/login (apps/web/src/app/login/page.tsx:43)"}, "fullDescription": {"text": "`apps/web/src/app/login/page.tsx:43` calls `POST /api/auth/login` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/auth/login`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0af3f6f60f598dd6", "name": "Dangling fetch: GET /api/workflow/api/bpmn-templates/${templateId} (apps/web/src/app/admin/workflows/canvas/page.tsx:319", "shortDescription": {"text": "Dangling fetch: GET /api/workflow/api/bpmn-templates/${templateId} (apps/web/src/app/admin/workflows/canvas/page.tsx:319)"}, "fullDescription": {"text": "`apps/web/src/app/admin/workflows/canvas/page.tsx:319` calls `GET /api/workflow/api/bpmn-templates/${templateId}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/workflow/api/bpmn-templates/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7f671173d156b52b", "name": "Dangling fetch: GET /api/master${cleanPath} (apps/web/src/lib/master-api.ts:20)", "shortDescription": {"text": "Dangling fetch: GET /api/master${cleanPath} (apps/web/src/lib/master-api.ts:20)"}, "fullDescription": {"text": "`apps/web/src/lib/master-api.ts:20` calls `GET /api/master${cleanPath}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/master/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2c0b2157923829d3", "name": "Dangling fetch: GET /api/ecd/api/tenant-features (apps/web/src/lib/features.ts:73)", "shortDescription": {"text": "Dangling fetch: GET /api/ecd/api/tenant-features (apps/web/src/lib/features.ts:73)"}, "fullDescription": {"text": "`apps/web/src/lib/features.ts:73` calls `GET /api/ecd/api/tenant-features` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/ecd/api/tenant-features`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-291f8910baee69d6", "name": "Dangling fetch: POST /api/mic-meldingen (services/ecd/src/__tests__/mic-melding.test.ts:33)", "shortDescription": {"text": "Dangling fetch: POST /api/mic-meldingen (services/ecd/src/__tests__/mic-melding.test.ts:33)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/mic-melding.test.ts:33` calls `POST /api/mic-meldingen` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/mic-meldingen`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2f11ca6a72f400f5", "name": "Dangling fetch: POST /api/mic-meldingen (services/ecd/src/__tests__/mic-melding.test.ts:49)", "shortDescription": {"text": "Dangling fetch: POST /api/mic-meldingen (services/ecd/src/__tests__/mic-melding.test.ts:49)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/mic-melding.test.ts:49` calls `POST /api/mic-meldingen` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/mic-meldingen`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4f555255884d099f", "name": "Dangling fetch: POST /api/mic-meldingen (services/ecd/src/__tests__/mic-melding.test.ts:63)", "shortDescription": {"text": "Dangling fetch: POST /api/mic-meldingen (services/ecd/src/__tests__/mic-melding.test.ts:63)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/mic-melding.test.ts:63` calls `POST /api/mic-meldingen` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/mic-meldingen`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9c3b5e826e807dda", "name": "Dangling fetch: POST /api/mic-meldingen (services/ecd/src/__tests__/mic-melding.test.ts:77)", "shortDescription": {"text": "Dangling fetch: POST /api/mic-meldingen (services/ecd/src/__tests__/mic-melding.test.ts:77)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/mic-melding.test.ts:77` calls `POST /api/mic-meldingen` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/mic-meldingen`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d942945bdb9f6a3f", "name": "Dangling fetch: POST /api/mic-meldingen (services/ecd/src/__tests__/mic-melding.test.ts:95)", "shortDescription": {"text": "Dangling fetch: POST /api/mic-meldingen (services/ecd/src/__tests__/mic-melding.test.ts:95)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/mic-melding.test.ts:95` calls `POST /api/mic-meldingen` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/mic-meldingen`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0c4918aed66a61f5", "name": "Dangling fetch: GET /api/mic-meldingen (services/ecd/src/__tests__/mic-melding.test.ts:123)", "shortDescription": {"text": "Dangling fetch: GET /api/mic-meldingen (services/ecd/src/__tests__/mic-melding.test.ts:123)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/mic-melding.test.ts:123` calls `GET /api/mic-meldingen` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/mic-meldingen`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9e94b608505a6b67", "name": "Dangling fetch: POST /api/clients/p1/rapportages (services/ecd/src/__tests__/rapportage.test.ts:26)", "shortDescription": {"text": "Dangling fetch: POST /api/clients/p1/rapportages (services/ecd/src/__tests__/rapportage.test.ts:26)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/rapportage.test.ts:26` calls `POST /api/clients/p1/rapportages` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/clients/p1/rapportages`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8238ff09ece98e59", "name": "Dangling fetch: POST /api/clients/p1/rapportages (services/ecd/src/__tests__/rapportage.test.ts:38)", "shortDescription": {"text": "Dangling fetch: POST /api/clients/p1/rapportages (services/ecd/src/__tests__/rapportage.test.ts:38)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/rapportage.test.ts:38` calls `POST /api/clients/p1/rapportages` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/clients/p1/rapportages`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-285f88959d80424c", "name": "Dangling fetch: POST /api/clients/p1/rapportages (services/ecd/src/__tests__/rapportage.test.ts:54)", "shortDescription": {"text": "Dangling fetch: POST /api/clients/p1/rapportages (services/ecd/src/__tests__/rapportage.test.ts:54)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/rapportage.test.ts:54` calls `POST /api/clients/p1/rapportages` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/clients/p1/rapportages`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e38dc496880a3651", "name": "Dangling fetch: POST /api/clients/p1/rapportages (services/ecd/src/__tests__/rapportage.test.ts:68)", "shortDescription": {"text": "Dangling fetch: POST /api/clients/p1/rapportages (services/ecd/src/__tests__/rapportage.test.ts:68)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/rapportage.test.ts:68` calls `POST /api/clients/p1/rapportages` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/clients/p1/rapportages`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9caa0ef5e396a55d", "name": "Dangling fetch: POST /api/clients/p1/rapportages (services/ecd/src/__tests__/rapportage.test.ts:94)", "shortDescription": {"text": "Dangling fetch: POST /api/clients/p1/rapportages (services/ecd/src/__tests__/rapportage.test.ts:94)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/rapportage.test.ts:94` calls `POST /api/clients/p1/rapportages` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/clients/p1/rapportages`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-48236c075b8830b0", "name": "Dangling fetch: GET /api/clients/p1/rapportages (services/ecd/src/__tests__/rapportage.test.ts:111)", "shortDescription": {"text": "Dangling fetch: GET /api/clients/p1/rapportages (services/ecd/src/__tests__/rapportage.test.ts:111)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/rapportage.test.ts:111` calls `GET /api/clients/p1/rapportages` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/clients/p1/rapportages`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4d4bc932731f58b5", "name": "Dangling fetch: GET /api/clients/p1/rapportages?_count=50&date=ge2026-06-01 (services/ecd/src/__tests__/rapportage.test.", "shortDescription": {"text": "Dangling fetch: GET /api/clients/p1/rapportages?_count=50&date=ge2026-06-01 (services/ecd/src/__tests__/rapportage.test.ts:126)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/rapportage.test.ts:126` calls `GET /api/clients/p1/rapportages?_count=50&date=ge2026-06-01` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/clients/p1/rapportages`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9b01b64382231c17", "name": "Dangling fetch: POST /api/clients (services/ecd/src/__tests__/client.test.ts:34)", "shortDescription": {"text": "Dangling fetch: POST /api/clients (services/ecd/src/__tests__/client.test.ts:34)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/client.test.ts:34` calls `POST /api/clients` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/clients`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c98224923092f1f5", "name": "Dangling fetch: POST /api/clients (services/ecd/src/__tests__/client.test.ts:63)", "shortDescription": {"text": "Dangling fetch: POST /api/clients (services/ecd/src/__tests__/client.test.ts:63)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/client.test.ts:63` calls `POST /api/clients` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/clients`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-327403ddb3290800", "name": "Dangling fetch: POST /api/clients (services/ecd/src/__tests__/client.test.ts:93)", "shortDescription": {"text": "Dangling fetch: POST /api/clients (services/ecd/src/__tests__/client.test.ts:93)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/client.test.ts:93` calls `POST /api/clients` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/clients`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0881d9172e8835b4", "name": "Dangling fetch: PUT /api/clients/patient-1 (services/ecd/src/__tests__/client.test.ts:106)", "shortDescription": {"text": "Dangling fetch: PUT /api/clients/patient-1 (services/ecd/src/__tests__/client.test.ts:106)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/client.test.ts:106` calls `PUT /api/clients/patient-1` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/clients/patient-1`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c625f78ef4dd6556", "name": "Dangling fetch: GET /api/clients (services/ecd/src/__tests__/client.test.ts:130)", "shortDescription": {"text": "Dangling fetch: GET /api/clients (services/ecd/src/__tests__/client.test.ts:130)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/client.test.ts:130` calls `GET /api/clients` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/clients`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ee356e6005ef6203", "name": "Dangling fetch: GET /api/clients/abc (services/ecd/src/__tests__/client.test.ts:145)", "shortDescription": {"text": "Dangling fetch: GET /api/clients/abc (services/ecd/src/__tests__/client.test.ts:145)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/client.test.ts:145` calls `GET /api/clients/abc` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/clients/abc`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6fbf73d12bdbac4f", "name": "Dangling fetch: DELETE /api/clients/del-1 (services/ecd/src/__tests__/client.test.ts:173)", "shortDescription": {"text": "Dangling fetch: DELETE /api/clients/del-1 (services/ecd/src/__tests__/client.test.ts:173)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/client.test.ts:173` calls `DELETE /api/clients/del-1` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/clients/del-1`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-48d2cb9e72803d4f", "name": "Dangling fetch: GET /api/admin/custom-fields (services/ecd/src/__tests__/configuratie.test.ts:89)", "shortDescription": {"text": "Dangling fetch: GET /api/admin/custom-fields (services/ecd/src/__tests__/configuratie.test.ts:89)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/configuratie.test.ts:89` calls `GET /api/admin/custom-fields` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/admin/custom-fields`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2bc620411bde3eec", "name": "Dangling fetch: POST /api/admin/custom-fields (services/ecd/src/__tests__/configuratie.test.ts:99)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/custom-fields (services/ecd/src/__tests__/configuratie.test.ts:99)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/configuratie.test.ts:99` calls `POST /api/admin/custom-fields` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/admin/custom-fields`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-45dc663023670fb1", "name": "Dangling fetch: POST /api/admin/custom-fields (services/ecd/src/__tests__/configuratie.test.ts:118)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/custom-fields (services/ecd/src/__tests__/configuratie.test.ts:118)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/configuratie.test.ts:118` calls `POST /api/admin/custom-fields` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/admin/custom-fields`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-95517aec41709152", "name": "Dangling fetch: POST /api/admin/custom-fields (services/ecd/src/__tests__/configuratie.test.ts:128)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/custom-fields (services/ecd/src/__tests__/configuratie.test.ts:128)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/configuratie.test.ts:128` calls `POST /api/admin/custom-fields` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/admin/custom-fields`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e0265f6eafa96d99", "name": "Dangling fetch: GET /api/admin/validation-rules (services/ecd/src/__tests__/configuratie.test.ts:146)", "shortDescription": {"text": "Dangling fetch: GET /api/admin/validation-rules (services/ecd/src/__tests__/configuratie.test.ts:146)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/configuratie.test.ts:146` calls `GET /api/admin/validation-rules` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/admin/validation-rules`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f3e8c93a7aaa9ebd", "name": "Dangling fetch: POST /api/admin/validation-rules (services/ecd/src/__tests__/configuratie.test.ts:156)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/validation-rules (services/ecd/src/__tests__/configuratie.test.ts:156)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/configuratie.test.ts:156` calls `POST /api/admin/validation-rules` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/admin/validation-rules`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-02cf4a8226656cd3", "name": "Dangling fetch: POST /api/admin/validation-rules (services/ecd/src/__tests__/configuratie.test.ts:174)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/validation-rules (services/ecd/src/__tests__/configuratie.test.ts:174)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/configuratie.test.ts:174` calls `POST /api/admin/validation-rules` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/admin/validation-rules`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6bf72dbbb1c09ed8", "name": "Dangling fetch: POST /api/admin/validation-rules (services/ecd/src/__tests__/configuratie.test.ts:184)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/validation-rules (services/ecd/src/__tests__/configuratie.test.ts:184)"}, "fullDescription": {"text": "`services/ecd/src/__tests__/configuratie.test.ts:184` calls `POST /api/admin/validation-rules` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/admin/validation-rules`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b876e6fb5b3fd099", "name": "Dangling fetch: POST /api/afspraken (services/planning/src/__tests__/app.test.ts:74)", "shortDescription": {"text": "Dangling fetch: POST /api/afspraken (services/planning/src/__tests__/app.test.ts:74)"}, "fullDescription": {"text": "`services/planning/src/__tests__/app.test.ts:74` calls `POST /api/afspraken` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/afspraken`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cbd0774c5773b232", "name": "Dangling fetch: POST /api/afspraken (services/planning/src/__tests__/app.test.ts:98)", "shortDescription": {"text": "Dangling fetch: POST /api/afspraken (services/planning/src/__tests__/app.test.ts:98)"}, "fullDescription": {"text": "`services/planning/src/__tests__/app.test.ts:98` calls `POST /api/afspraken` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/afspraken`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d78048e6b58f0249", "name": "Dangling fetch: POST /api/afspraken (services/planning/src/__tests__/app.test.ts:120)", "shortDescription": {"text": "Dangling fetch: POST /api/afspraken (services/planning/src/__tests__/app.test.ts:120)"}, "fullDescription": {"text": "`services/planning/src/__tests__/app.test.ts:120` calls `POST /api/afspraken` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/afspraken`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-56815823bdb97493", "name": "Unused endpoint: GET /api/tenant-features", "shortDescription": {"text": "Unused endpoint: GET /api/tenant-features"}, "fullDescription": {"text": "`services/ecd/src/app.ts` declares `GET /api/tenant-features` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b8073f7bf758f6d0", "name": "Unused endpoint: USE /api/*", "shortDescription": {"text": "Unused endpoint: USE /api/*"}, "fullDescription": {"text": "`services/ecd/src/app.ts` declares `USE /api/*` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-16412f1341a07586", "name": "Unused endpoint: GET /api/master/check-admin", "shortDescription": {"text": "Unused endpoint: GET /api/master/check-admin"}, "fullDescription": {"text": "`services/ecd/src/app.ts` declares `GET /api/master/check-admin` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a5ccb1c62506dbd", "name": "Unused endpoint: USE /api/master/*", "shortDescription": {"text": "Unused endpoint: USE /api/master/*"}, "fullDescription": {"text": "`services/ecd/src/app.ts` declares `USE /api/master/*` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`services/ecd/src/routes/tenant-settings.ts` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2ab9bf5db6820af4", "name": "Unused endpoint: GET /models", "shortDescription": {"text": "Unused endpoint: GET /models"}, "fullDescription": {"text": "`services/ecd/src/routes/ai.ts` declares `GET /models` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a6f48e60c30777ab", "name": "Unused endpoint: GET /config", "shortDescription": {"text": "Unused endpoint: GET /config"}, "fullDescription": {"text": "`services/ecd/src/routes/ai.ts` declares `GET /config` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7d2c56c613802d65", "name": "Unused endpoint: PUT /config", "shortDescription": {"text": "Unused endpoint: PUT /config"}, "fullDescription": {"text": "`services/ecd/src/routes/ai.ts` declares `PUT /config` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8e1fadad2500f063", "name": "Unused endpoint: POST /ask", "shortDescription": {"text": "Unused endpoint: POST /ask"}, "fullDescription": {"text": "`services/ecd/src/routes/ai.ts` declares `POST /ask` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5b5dc7a75a543a74", "name": "Unused endpoint: POST /summarize-rapportages", "shortDescription": {"text": "Unused endpoint: POST /summarize-rapportages"}, "fullDescription": {"text": "`services/ecd/src/routes/ai.ts` declares `POST /summarize-rapportages` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cff8da5fbc19c76d", "name": "Unused endpoint: POST /chat", "shortDescription": {"text": "Unused endpoint: POST /chat"}, "fullDescription": {"text": "`services/ecd/src/routes/ai.ts` declares `POST /chat` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-67d28fa8cd6bb12f", "name": "Unused endpoint: PUT /", "shortDescription": {"text": "Unused endpoint: PUT /"}, "fullDescription": {"text": "`services/ecd/src/routes/feature-flags.ts` declares `PUT /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ca5756175765b49d", "name": "Unused endpoint: GET /:id", "shortDescription": {"text": "Unused endpoint: GET /:id"}, "fullDescription": {"text": "`services/ecd/src/routes/organisatie.ts` declares `GET /:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-35194d3d2137eceb", "name": "Unused endpoint: POST /locaties", "shortDescription": {"text": "Unused endpoint: POST /locaties"}, "fullDescription": {"text": "`services/ecd/src/routes/organisatie.ts` declares `POST /locaties` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8d5b2b188d08ca82", "name": "Unused endpoint: PUT /:id", "shortDescription": {"text": "Unused endpoint: PUT /:id"}, "fullDescription": {"text": "`services/ecd/src/routes/organisatie.ts` declares `PUT /:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a61c112b611f4bb", "name": "Unused endpoint: DELETE /:id", "shortDescription": {"text": "Unused endpoint: DELETE /:id"}, "fullDescription": {"text": "`services/ecd/src/routes/organisatie.ts` declares `DELETE /:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a009b1a56794f45", "name": "Unused endpoint: POST /", "shortDescription": {"text": "Unused endpoint: POST /"}, "fullDescription": {"text": "`services/ecd/src/routes/productie.ts` declares `POST /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e0a8390ddb0ad54c", "name": "Unused endpoint: GET /samenvatting", "shortDescription": {"text": "Unused endpoint: GET /samenvatting"}, "fullDescription": {"text": "`services/ecd/src/routes/productie.ts` declares `GET /samenvatting` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c5718a89854e7bdd", "name": "Unused endpoint: GET /clients/:patientId/responses", "shortDescription": {"text": "Unused endpoint: GET /clients/:patientId/responses"}, "fullDescription": {"text": "`services/ecd/src/routes/vragenlijsten.ts` declares `GET /clients/:patientId/responses` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-45e9bf9f1df86ea7", "name": "Unused endpoint: POST /clients/:patientId/responses", "shortDescription": {"text": "Unused endpoint: POST /clients/:patientId/responses"}, "fullDescription": {"text": "`services/ecd/src/routes/vragenlijsten.ts` declares `POST /clients/:patientId/responses` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5c3bc50588d3bbfa", "name": "Unused endpoint: GET /:patientId/toedieningen", "shortDescription": {"text": "Unused endpoint: GET /:patientId/toedieningen"}, "fullDescription": {"text": "`services/ecd/src/routes/toediening.ts` declares `GET /:patientId/toedieningen` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0421bccead41282e", "name": "Unused endpoint: GET /:patientId/toedienlijst", "shortDescription": {"text": "Unused endpoint: GET /:patientId/toedienlijst"}, "fullDescription": {"text": "`services/ecd/src/routes/toediening.ts` declares `GET /:patientId/toedienlijst` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e1423d70e5488a17", "name": "Unused endpoint: POST /:patientId/toedieningen", "shortDescription": {"text": "Unused endpoint: POST /:patientId/toedieningen"}, "fullDescription": {"text": "`services/ecd/src/routes/toediening.ts` declares `POST /:patientId/toedieningen` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-39bbac8dbf00a5b7", "name": "Unused endpoint: GET /:patientId/mdo", "shortDescription": {"text": "Unused endpoint: GET /:patientId/mdo"}, "fullDescription": {"text": "`services/ecd/src/routes/mdo.ts` declares `GET /:patientId/mdo` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4379da8de72fa165", "name": "Unused endpoint: POST /:patientId/mdo", "shortDescription": {"text": "Unused endpoint: POST /:patientId/mdo"}, "fullDescription": {"text": "`services/ecd/src/routes/mdo.ts` declares `POST /:patientId/mdo` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e12be0a8be938fb5", "name": "Unused endpoint: PUT /:patientId/mdo/:id", "shortDescription": {"text": "Unused endpoint: PUT /:patientId/mdo/:id"}, "fullDescription": {"text": "`services/ecd/src/routes/mdo.ts` declares `PUT /:patientId/mdo/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-61427173b6043c35", "name": "Unused endpoint: POST /:patientId/mdo/:mdoId/verslag", "shortDescription": {"text": "Unused endpoint: POST /:patientId/mdo/:mdoId/verslag"}, "fullDescription": {"text": "`services/ecd/src/routes/mdo.ts` declares `POST /:patientId/mdo/:mdoId/verslag` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9630d39f953a327c", "name": "Unused endpoint: GET /types", "shortDescription": {"text": "Unused endpoint: GET /types"}, "fullDescription": {"text": "`services/ecd/src/routes/vbm.ts` declares `GET /types` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b91e563582a6df77", "name": "Unused endpoint: GET /:patientId/vbm", "shortDescription": {"text": "Unused endpoint: GET /:patientId/vbm"}, "fullDescription": {"text": "`services/ecd/src/routes/vbm.ts` declares `GET /:patientId/vbm` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6c7dab7ea5ff5e73", "name": "Unused endpoint: POST /:patientId/vbm", "shortDescription": {"text": "Unused endpoint: POST /:patientId/vbm"}, "fullDescription": {"text": "`services/ecd/src/routes/vbm.ts` declares `POST /:patientId/vbm` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a0a41deaacda8315", "name": "Unused endpoint: POST /:patientId/vbm/:vbmId/evaluatie", "shortDescription": {"text": "Unused endpoint: POST /:patientId/vbm/:vbmId/evaluatie"}, "fullDescription": {"text": "`services/ecd/src/routes/vbm.ts` declares `POST /:patientId/vbm/:vbmId/evaluatie` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a36631e6ed5141fa", "name": "Unused endpoint: PUT /:patientId/vbm/:id/beeindigen", "shortDescription": {"text": "Unused endpoint: PUT /:patientId/vbm/:id/beeindigen"}, "fullDescription": {"text": "`services/ecd/src/routes/vbm.ts` declares `PUT /:patientId/vbm/:id/beeindigen` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dca68bcf2eac0fb7", "name": "Unused endpoint: GET /:patientId/medicatie-overzicht", "shortDescription": {"text": "Unused endpoint: GET /:patientId/medicatie-overzicht"}, "fullDescription": {"text": "`services/ecd/src/routes/medicatie-overzicht.ts` declares `GET /:patientId/medicatie-overzicht` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c9871265a983a6b4", "name": "Unused endpoint: POST /:patientId/medicatie-overzicht", "shortDescription": {"text": "Unused endpoint: POST /:patientId/medicatie-overzicht"}, "fullDescription": {"text": "`services/ecd/src/routes/medicatie-overzicht.ts` declares `POST /:patientId/medicatie-overzicht` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-65301c78e66b31a9", "name": "Unused endpoint: PUT /:patientId/medicatie-overzicht/:id", "shortDescription": {"text": "Unused endpoint: PUT /:patientId/medicatie-overzicht/:id"}, "fullDescription": {"text": "`services/ecd/src/routes/medicatie-overzicht.ts` declares `PUT /:patientId/medicatie-overzicht/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5f7b6f1e9d29f097", "name": "Unused endpoint: DELETE /:patientId/medicatie-overzicht/:id", "shortDescription": {"text": "Unused endpoint: DELETE /:patientId/medicatie-overzicht/:id"}, "fullDescription": {"text": "`services/ecd/src/routes/medicatie-overzicht.ts` declares `DELETE /:patientId/medicatie-overzicht/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7e334e17d82c37de", "name": "Unused endpoint: GET /clients/:clientId/documenten", "shortDescription": {"text": "Unused endpoint: GET /clients/:clientId/documenten"}, "fullDescription": {"text": "`services/ecd/src/routes/documenten.ts` declares `GET /clients/:clientId/documenten` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1dfc13731526d2d0", "name": "Unused endpoint: POST /clients/:clientId/documenten", "shortDescription": {"text": "Unused endpoint: POST /clients/:clientId/documenten"}, "fullDescription": {"text": "`services/ecd/src/routes/documenten.ts` declares `POST /clients/:clientId/documenten` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-953cbcf48e64a946", "name": "Unused endpoint: GET /:clientId/verzekering", "shortDescription": {"text": "Unused endpoint: GET /:clientId/verzekering"}, "fullDescription": {"text": "`services/ecd/src/routes/coverage.ts` declares `GET /:clientId/verzekering` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-069e3fde9aee8307", "name": "Unused endpoint: POST /:clientId/verzekering", "shortDescription": {"text": "Unused endpoint: POST /:clientId/verzekering"}, "fullDescription": {"text": "`services/ecd/src/routes/coverage.ts` declares `POST /:clientId/verzekering` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3de9acdeb9901d2c", "name": "Unused endpoint: PUT /:clientId/verzekering/:coverageId", "shortDescription": {"text": "Unused endpoint: PUT /:clientId/verzekering/:coverageId"}, "fullDescription": {"text": "`services/ecd/src/routes/coverage.ts` declares `PUT /:clientId/verzekering/:coverageId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4e63fe03579274be", "name": "Unused endpoint: GET /overzicht", "shortDescription": {"text": "Unused endpoint: GET /overzicht"}, "fullDescription": {"text": "`services/ecd/src/routes/vaccinatie.ts` declares `GET /overzicht` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-608d33f1665b28a2", "name": "Unused endpoint: GET /:patientId/vaccinaties", "shortDescription": {"text": "Unused endpoint: GET /:patientId/vaccinaties"}, "fullDescription": {"text": "`services/ecd/src/routes/vaccinatie.ts` declares `GET /:patientId/vaccinaties` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-060ad5cd918fb408", "name": "Unused endpoint: GET /:patientId/vaccinaties/:id", "shortDescription": {"text": "Unused endpoint: GET /:patientId/vaccinaties/:id"}, "fullDescription": {"text": "`services/ecd/src/routes/vaccinatie.ts` declares `GET /:patientId/vaccinaties/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3817cb6dd1194fc8", "name": "Unused endpoint: POST /:patientId/vaccinaties", "shortDescription": {"text": "Unused endpoint: POST /:patientId/vaccinaties"}, "fullDescription": {"text": "`services/ecd/src/routes/vaccinatie.ts` declares `POST /:patientId/vaccinaties` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2b5f603512e21e74", "name": "Unused endpoint: PUT /:patientId/vaccinaties/:id", "shortDescription": {"text": "Unused endpoint: PUT /:patientId/vaccinaties/:id"}, "fullDescription": {"text": "`services/ecd/src/routes/vaccinatie.ts` declares `PUT /:patientId/vaccinaties/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5b035e28f83ef139", "name": "Unused endpoint: DELETE /:patientId/vaccinaties/:id", "shortDescription": {"text": "Unused endpoint: DELETE /:patientId/vaccinaties/:id"}, "fullDescription": {"text": "`services/ecd/src/routes/vaccinatie.ts` declares `DELETE /:patientId/vaccinaties/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-02b023f84ff53c43", "name": "Unused endpoint: PATCH /:id/gelezen", "shortDescription": {"text": "Unused endpoint: PATCH /:id/gelezen"}, "fullDescription": {"text": "`services/ecd/src/routes/berichten.ts` declares `PATCH /:id/gelezen` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e77718daba3fe62e", "name": "Unused endpoint: GET /medicatie-voorschriften", "shortDescription": {"text": "Unused endpoint: GET /medicatie-voorschriften"}, "fullDescription": {"text": "`services/ecd/src/routes/medicatie.ts` declares `GET /medicatie-voorschriften` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-54e732f482e6800a", "name": "Unused endpoint: GET /clients/:clientId/medicatie", "shortDescription": {"text": "Unused endpoint: GET /clients/:clientId/medicatie"}, "fullDescription": {"text": "`services/ecd/src/routes/medicatie.ts` declares `GET /clients/:clientId/medicatie` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/22223"}, "properties": {"repository": "vierkant14/openzorg", "repoUrl": "https://github.com/vierkant14/openzorg", "branch": "main"}, "results": [{"ruleId": "scanner-86bd2b0aa87a635d", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/TenantSwitcher.tsx:72"}, "properties": {"repobilityId": "e3c0aea27776eba3", "scanner": "scanner-primary", "fingerprint": "86bd2b0aa87a635d", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-b400940da61887b0", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/ChatPanel.tsx:254"}, "properties": {"repobilityId": "00cf031720c282be", "scanner": "scanner-primary", "fingerprint": "b400940da61887b0", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-ae56fa994bbd328a", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/planning/MedewerkerLabel.tsx:30"}, "properties": {"repobilityId": "5c526b500e4d31a7", "scanner": "scanner-primary", "fingerprint": "ae56fa994bbd328a", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-1ff2a099c26f5a13", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/planning/AfspraakBlock.tsx:96"}, "properties": {"repobilityId": "ed2a64b5c7815ab7", "scanner": "scanner-primary", "fingerprint": "1ff2a099c26f5a13", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-11326fb031c90469", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 apps/web/src/app/layout.tsx:16"}, "properties": {"repobilityId": "eff0c5cb869a98ef", "scanner": "scanner-primary", "fingerprint": "11326fb031c90469", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-ce35b0335525a9a4", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/overdracht/page.tsx:395"}, "properties": {"repobilityId": "7ec0bca81ac319ed", "scanner": "scanner-primary", "fingerprint": "ce35b0335525a9a4", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-4b05228ad2c2f5f8", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/dashboard/page.tsx:353"}, "properties": {"repobilityId": "2aee4b7948db1786", "scanner": "scanner-primary", "fingerprint": "4b05228ad2c2f5f8", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-694fc490f14251c5", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/rapportages/page.tsx:299"}, "properties": {"repobilityId": "d5425faa90c45c28", "scanner": "scanner-primary", "fingerprint": "694fc490f14251c5", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-c65965aab2dba2c5", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/mic-meldingen/page.tsx:494"}, "properties": {"repobilityId": "a4035c7fb6c253b0", "scanner": "scanner-primary", "fingerprint": "c65965aab2dba2c5", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-fda61cf69de17542", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/codelijsten/page.tsx:184"}, "properties": {"repobilityId": "6b7196b72902c561", "scanner": "scanner-primary", "fingerprint": "fda61cf69de17542", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-9c27b7cb45e6dccd", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/mic-trends/page.tsx:294"}, "properties": {"repobilityId": "cfa7169300f9556e", "scanner": "scanner-primary", "fingerprint": "9c27b7cb45e6dccd", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-d6b6e98adb7219ac", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/berichten/page.tsx:206"}, "properties": {"repobilityId": "267bed7b49ff45b9", "scanner": "scanner-primary", "fingerprint": "d6b6e98adb7219ac", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-770aedd6a95faadd", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/ecd/[id]/zorgplan/page.tsx:672"}, "properties": {"repobilityId": "f6b3f7729bf74310", "scanner": "scanner-primary", "fingerprint": "770aedd6a95faadd", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-2d89f631fd86ab66", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/signaleringen/page.tsx:257"}, "properties": {"repobilityId": "e4c6d61a58e18033", "scanner": "scanner-primary", "fingerprint": "2d89f631fd86ab66", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-95e050aa44a9b9ef", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/planning/dagplanning/page.tsx:388"}, "properties": {"repobilityId": "6281cd009c54e4f3", "scanner": "scanner-primary", "fingerprint": "95e050aa44a9b9ef", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-e146f59eb1eb3057", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/vandaag/page.tsx:163"}, "properties": {"repobilityId": "c74bdfd98b91c901", "scanner": "scanner-primary", "fingerprint": "e146f59eb1eb3057", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-af84de362d6294f4", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 services/ecd/src/routes/ai-settings.ts:44"}, "properties": {"repobilityId": "0e7372c49be68831", "scanner": "scanner-primary", "fingerprint": "af84de362d6294f4", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3f425f09a2aba046", "level": "warning", "message": {"text": "Privileged port 10 in use"}, "properties": {"repobilityId": "735372d6b5594915", "scanner": "scanner-primary", "fingerprint": "3f425f09a2aba046", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker-compose.unraid.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cff44f412b6fa355", "level": "warning", "message": {"text": "Privileged port 7 in use"}, "properties": {"repobilityId": "428a6faecc63b5d6", "scanner": "scanner-primary", "fingerprint": "cff44f412b6fa355", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "infra/scripts/seed.sh"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-89eab07b953f06e7", "level": "warning", "message": {"text": "Privileged port 30 in use"}, "properties": {"repobilityId": "54f172e7d16fc662", "scanner": "scanner-primary", "fingerprint": "89eab07b953f06e7", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "infra/scripts/seed-planning.sh"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0a5aa084a1dce47d", "level": "warning", "message": {"text": "Privileged port 11 in use"}, "properties": {"repobilityId": "5b3038c67fabb4c8", "scanner": "scanner-primary", "fingerprint": "0a5aa084a1dce47d", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "infra/scripts/seed-planning.sh"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e4730979abffa66b", "level": "warning", "message": {"text": "Privileged port 17 in use"}, "properties": {"repobilityId": "0bf38fb8f89ec589", "scanner": "scanner-primary", "fingerprint": "e4730979abffa66b", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "infra/scripts/seed-planning.sh"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bf3d181d23b26f76", "level": "warning", "message": {"text": "Privileged port 16 in use"}, "properties": {"repobilityId": "d31009168c502ace", "scanner": "scanner-primary", "fingerprint": "bf3d181d23b26f76", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "infra/scripts/seed-planning.sh"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c947ed0387dd77b7", "level": "warning", "message": {"text": "Privileged port 14 in use"}, "properties": {"repobilityId": "2dbd4b719a1412ff", "scanner": "scanner-primary", "fingerprint": "c947ed0387dd77b7", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "infra/scripts/seed-planning.sh"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-085943872640c49f", "level": "warning", "message": {"text": "Privileged port 23 in use"}, "properties": {"repobilityId": "a1230e3dfc4becfa", "scanner": "scanner-primary", "fingerprint": "085943872640c49f", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "infra/scripts/seed-planning.sh"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2594da86fd011854", "level": "warning", "message": {"text": "Privileged port 13 in use"}, "properties": {"repobilityId": "79d721e4d6f64798", "scanner": "scanner-primary", "fingerprint": "2594da86fd011854", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "infra/scripts/seed-planning.sh"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3f53fedf57ce2caa", "level": "warning", "message": {"text": "Privileged port 19 in use"}, "properties": {"repobilityId": "a6b5b06deac36eac", "scanner": "scanner-primary", "fingerprint": "3f53fedf57ce2caa", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "infra/scripts/seed-planning-config.sh"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-4936e96ee6dbf927", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in apps/web/next.config.mjs:1"}, "properties": {"repobilityId": "437b87b0f9a003b5", "scanner": "scanner-primary", "fingerprint": "4936e96ee6dbf927", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/next.config.mjs"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6321b99140465d43", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in apps/web/src/app/layout.tsx:16"}, "properties": {"repobilityId": "346ebefd3b315f3f", "scanner": "scanner-primary", "fingerprint": "6321b99140465d43", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/src/app/layout.tsx"}, "region": {"startLine": 16}}}]}, {"ruleId": "scanner-32303b80aef32a91", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in apps/web/src/app/login/page.tsx:57"}, "properties": {"repobilityId": "cb74d7d9d7d9a018", "scanner": "scanner-primary", "fingerprint": "32303b80aef32a91", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/src/app/login/page.tsx"}, "region": {"startLine": 57}}}]}, {"ruleId": "scanner-b2cd78c232f51913", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in apps/web/src/lib/api.ts:107"}, "properties": {"repobilityId": "fe176b4484ff2bd4", "scanner": "scanner-primary", "fingerprint": "b2cd78c232f51913", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/src/lib/api.ts"}, "region": {"startLine": 107}}}]}, {"ruleId": "scanner-09bfb12d0bd5c38e", "level": "error", "message": {"text": "Possible secret in scripts/seed-medplum.mjs"}, "properties": {"repobilityId": "7be762b532bcb308", "scanner": "scanner-primary", "fingerprint": "09bfb12d0bd5c38e", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/seed-medplum.mjs"}, "region": {"startLine": 19}}}]}, {"ruleId": "scanner-8172a454e11bfcb9", "level": "error", "message": {"text": "Possible secret in scripts/test-tenant-isolation.mjs"}, "properties": {"repobilityId": "20c2750f180aa121", "scanner": "scanner-primary", "fingerprint": "8172a454e11bfcb9", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/test-tenant-isolation.mjs"}, "region": {"startLine": 27}}}]}, {"ruleId": "scanner-001c907476f47017", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in services/ecd/src/app.ts:63"}, "properties": {"repobilityId": "e951f7a89c699b98", "scanner": "scanner-primary", "fingerprint": "001c907476f47017", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "services/ecd/src/app.ts"}, "region": {"startLine": 63}}}]}, {"ruleId": "scanner-796cff60e7bca12b", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in services/facturatie/src/index.ts:19"}, "properties": {"repobilityId": "37be9f0eedccd7ec", "scanner": "scanner-primary", "fingerprint": "796cff60e7bca12b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "services/facturatie/src/index.ts"}, "region": {"startLine": 19}}}]}, {"ruleId": "scanner-9e4ddbe172edfe52", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in services/planning/src/app.ts:26"}, "properties": {"repobilityId": "dac28d09ad6d97a3", "scanner": "scanner-primary", "fingerprint": "9e4ddbe172edfe52", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "services/planning/src/app.ts"}, "region": {"startLine": 26}}}]}, {"ruleId": "scanner-1140db970a23db81", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in services/workflow-bridge/src/app.ts:20"}, "properties": {"repobilityId": "b2609929f86295eb", "scanner": "scanner-primary", "fingerprint": "1140db970a23db81", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "services/workflow-bridge/src/app.ts"}, "region": {"startLine": 20}}}]}, {"ruleId": "scanner-61ca18d164db7cf8", "level": "error", "message": {"text": "Possible secret in infra/scripts/augment-vvt-data.mjs"}, "properties": {"repobilityId": "4b08fb8850b3de53", "scanner": "scanner-primary", "fingerprint": "61ca18d164db7cf8", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "infra/scripts/augment-vvt-data.mjs"}, "region": {"startLine": 18}}}]}, {"ruleId": "scanner-28c4a04bd807da0c", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "0bc463708914950e", "scanner": "scanner-primary", "fingerprint": "28c4a04bd807da0c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy.yml"}, "region": {"startLine": 30}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "bd7f3c1c34d83159", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 140}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "bd7f3c1c34d83159", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 148}}}]}, {"ruleId": "scanner-1838a141491ce38c", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "b8fd4f5048f96576", "scanner": "scanner-primary", "fingerprint": "1838a141491ce38c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-43180284aa0b81d5", "level": "note", "message": {"text": "Very large file: infra/scripts/seed.sh (1293 lines)"}, "properties": {"repobilityId": "6ef719ed3490da38", "scanner": "scanner-primary", "fingerprint": "43180284aa0b81d5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ea3b5e389d8c9c0f", "level": "note", "message": {"text": "Low test-to-source ratio"}, "properties": {"repobilityId": "ef7b2552cc00a375", "scanner": "scanner-primary", "fingerprint": "ea3b5e389d8c9c0f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["tests"]}}, {"ruleId": "scanner-ce86778bdbd6dd71", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: adapters/ons-import/package.json"}, "properties": {"repobilityId": "60065428a58983c1", "scanner": "scanner-primary", "fingerprint": "ce86778bdbd6dd71", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "adapters/ons-import/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4a9eb7dc7c6e3880", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: apps/web/package.json"}, "properties": {"repobilityId": "6c1704bf24cf19ac", "scanner": "scanner-primary", "fingerprint": "4a9eb7dc7c6e3880", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5f3913d16f97a515", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/shared-domain/package.json"}, "properties": {"repobilityId": "18f5a0daa26141eb", "scanner": "scanner-primary", "fingerprint": "5f3913d16f97a515", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/shared-domain/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1b7c82ffff29113c", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/shared-config/package.json"}, "properties": {"repobilityId": "418b61151dd78d12", "scanner": "scanner-primary", "fingerprint": "1b7c82ffff29113c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/shared-config/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-36fe6cdeb59e47d7", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/shared-ui/package.json"}, "properties": {"repobilityId": "30bb53285d5548e2", "scanner": "scanner-primary", "fingerprint": "36fe6cdeb59e47d7", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/shared-ui/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-423c675d5c44fcd6", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/shared-test/package.json"}, "properties": {"repobilityId": "b66fc38e88ec2ba2", "scanner": "scanner-primary", "fingerprint": "423c675d5c44fcd6", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/shared-test/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-10a1d6c7a5015379", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: services/ecd/package.json"}, "properties": {"repobilityId": "a4c36f6b31c72fcc", "scanner": "scanner-primary", "fingerprint": "10a1d6c7a5015379", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "services/ecd/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-38de99938422d5e9", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: services/facturatie/package.json"}, "properties": {"repobilityId": "bbe5fc8d0e00b0e9", "scanner": "scanner-primary", "fingerprint": "38de99938422d5e9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "services/facturatie/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4b1d0f1f7b3affc3", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: services/planning/package.json"}, "properties": {"repobilityId": "f17e502ea7dca564", "scanner": "scanner-primary", "fingerprint": "4b1d0f1f7b3affc3", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "services/planning/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-615876dd84ce6b8d", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: services/workflow-bridge/package.json"}, "properties": {"repobilityId": "2b2828669231ad37", "scanner": "scanner-primary", "fingerprint": "615876dd84ce6b8d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "services/workflow-bridge/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "b352bc50a63a5d0e", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "f49a109bf4bfaf6f", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "0b73ce62a2c0ca0f", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "0ec0c2024c18e174", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "d3177bd8e956cd37", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "274f6b1fa09eeebc", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-6d34890aa3bee162", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/src/components/ChatPanel.tsx:141"}, "properties": {"repobilityId": "04d18fe023e40737", "scanner": "scanner-primary", "fingerprint": "6d34890aa3bee162", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-dea8ebf20b325851", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/src/app/api/auth/login/route.ts:66"}, "properties": {"repobilityId": "dc7e91b46b24a71b", "scanner": "scanner-primary", "fingerprint": "dea8ebf20b325851", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-209c81fe4aa787a8", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/test-tenant-isolation.mjs:55"}, "properties": {"repobilityId": "e268ff96b4f66613", "scanner": "scanner-primary", "fingerprint": "209c81fe4aa787a8", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-8e06389e2edfe659", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/ecd/src/lib/medplum-client.ts:50"}, "properties": {"repobilityId": "dfdc387aaf5730cf", "scanner": "scanner-primary", "fingerprint": "8e06389e2edfe659", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-37417993a238afba", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/ecd/src/lib/timer-service.ts:78"}, "properties": {"repobilityId": "e11ce423056f1081", "scanner": "scanner-primary", "fingerprint": "37417993a238afba", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-c3c7326d3fb0ed72", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/ecd/src/lib/ollama-client.ts:116"}, "properties": {"repobilityId": "41adbdd61c6407e8", "scanner": "scanner-primary", "fingerprint": "c3c7326d3fb0ed72", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-d78e1b6582ad91c4", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/ecd/src/routes/ai.ts:251"}, "properties": {"repobilityId": "c8f78f0eb5ae6284", "scanner": "scanner-primary", "fingerprint": "d78e1b6582ad91c4", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-52d495758171bedb", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/ecd/src/routes/documenten.ts:86"}, "properties": {"repobilityId": "cf0dbbb7480b12c8", "scanner": "scanner-primary", "fingerprint": "52d495758171bedb", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-700e35c705ffc0fe", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/ecd/src/routes/zorgplan.ts:349"}, "properties": {"repobilityId": "9adff2deaad721d2", "scanner": "scanner-primary", "fingerprint": "700e35c705ffc0fe", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-0e971c6f4dad5c1a", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/ecd/src/routes/tenants.ts:304"}, "properties": {"repobilityId": "5dd8451c6a3ce5ca", "scanner": "scanner-primary", "fingerprint": "0e971c6f4dad5c1a", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-8cdc5220f4e57595", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/planning/src/lib/medplum-client.ts:50"}, "properties": {"repobilityId": "4932f1c3bf54d0fc", "scanner": "scanner-primary", "fingerprint": "8cdc5220f4e57595", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-864b19ba448dc3c2", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/planning/src/routes/dienst-config.ts:50"}, "properties": {"repobilityId": "d0cecfdd1651e1a9", "scanner": "scanner-primary", "fingerprint": "864b19ba448dc3c2", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-c7bd76281ba6918b", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/planning/src/routes/planning-engine.ts:73"}, "properties": {"repobilityId": "0cf4c50d045feaf1", "scanner": "scanner-primary", "fingerprint": "c7bd76281ba6918b", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-ca3c455fc34a6d2c", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 services/planning/src/routes/bezetting.ts:27"}, "properties": {"repobilityId": "38eb80a7b50daf70", "scanner": "scanner-primary", "fingerprint": "ca3c455fc34a6d2c", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-1a82e4abbbb079c9", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 infra/scripts/augment-vvt-data.mjs:46"}, "properties": {"repobilityId": "2e20b510fdea367a", "scanner": "scanner-primary", "fingerprint": "1a82e4abbbb079c9", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-9996447513897762", "level": "note", "message": {"text": "30 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "b3285186f72a5bb9", "scanner": "scanner-primary", "fingerprint": "9996447513897762", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-a6851ff80ff1db0c", "level": "error", "message": {"text": "Dangling fetch: GET /api/ecd/api/admin/ai-settings (apps/web/src/components/ChatPanel.tsx:69)"}, "properties": {"repobilityId": "16661a87fd5e4d0a", "scanner": "scanner-primary", "fingerprint": "a6851ff80ff1db0c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-894df61aca6e8535", "level": "error", "message": {"text": "Dangling fetch: POST /api/ecd/api/ai/chat (apps/web/src/components/ChatPanel.tsx:141)"}, "properties": {"repobilityId": "ce59588642328b4c", "scanner": "scanner-primary", "fingerprint": "894df61aca6e8535", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-d17e6c7d71e226ba", "level": "error", "message": {"text": "Dangling fetch: POST /api/auth/login (apps/web/src/app/login/page.tsx:43)"}, "properties": {"repobilityId": "42133966f6c439a5", "scanner": "scanner-primary", "fingerprint": "d17e6c7d71e226ba", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-0af3f6f60f598dd6", "level": "error", "message": {"text": "Dangling fetch: GET /api/workflow/api/bpmn-templates/${templateId} (apps/web/src/app/admin/workflows/canvas/page.tsx:319)"}, "properties": {"repobilityId": "dadbaadb01fa5f9e", "scanner": "scanner-primary", "fingerprint": "0af3f6f60f598dd6", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-7f671173d156b52b", "level": "error", "message": {"text": "Dangling fetch: GET /api/master${cleanPath} (apps/web/src/lib/master-api.ts:20)"}, "properties": {"repobilityId": "748829898d996fab", "scanner": "scanner-primary", "fingerprint": "7f671173d156b52b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-2c0b2157923829d3", "level": "error", "message": {"text": "Dangling fetch: GET /api/ecd/api/tenant-features (apps/web/src/lib/features.ts:73)"}, "properties": {"repobilityId": "f21873130d79e9d1", "scanner": "scanner-primary", "fingerprint": "2c0b2157923829d3", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-291f8910baee69d6", "level": "error", "message": {"text": "Dangling fetch: POST /api/mic-meldingen (services/ecd/src/__tests__/mic-melding.test.ts:33)"}, "properties": {"repobilityId": "74239b53e15febae", "scanner": "scanner-primary", "fingerprint": "291f8910baee69d6", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-2f11ca6a72f400f5", "level": "error", "message": {"text": "Dangling fetch: POST /api/mic-meldingen (services/ecd/src/__tests__/mic-melding.test.ts:49)"}, "properties": {"repobilityId": "1a37377742b5e818", "scanner": "scanner-primary", "fingerprint": "2f11ca6a72f400f5", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-4f555255884d099f", "level": "error", "message": {"text": "Dangling fetch: POST /api/mic-meldingen (services/ecd/src/__tests__/mic-melding.test.ts:63)"}, "properties": {"repobilityId": "7eb75dfd57914754", "scanner": "scanner-primary", "fingerprint": "4f555255884d099f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-9c3b5e826e807dda", "level": "error", "message": {"text": "Dangling fetch: POST /api/mic-meldingen (services/ecd/src/__tests__/mic-melding.test.ts:77)"}, "properties": {"repobilityId": "5d0d92f496e89c0f", "scanner": "scanner-primary", "fingerprint": "9c3b5e826e807dda", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-d942945bdb9f6a3f", "level": "error", "message": {"text": "Dangling fetch: POST /api/mic-meldingen (services/ecd/src/__tests__/mic-melding.test.ts:95)"}, "properties": {"repobilityId": "4133cbb03b2fa873", "scanner": "scanner-primary", "fingerprint": "d942945bdb9f6a3f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-0c4918aed66a61f5", "level": "error", "message": {"text": "Dangling fetch: GET /api/mic-meldingen (services/ecd/src/__tests__/mic-melding.test.ts:123)"}, "properties": {"repobilityId": "9b4039db32a86269", "scanner": "scanner-primary", "fingerprint": "0c4918aed66a61f5", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-9e94b608505a6b67", "level": "error", "message": {"text": "Dangling fetch: POST /api/clients/p1/rapportages (services/ecd/src/__tests__/rapportage.test.ts:26)"}, "properties": {"repobilityId": "1a9679394be209cc", "scanner": "scanner-primary", "fingerprint": "9e94b608505a6b67", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-8238ff09ece98e59", "level": "error", "message": {"text": "Dangling fetch: POST /api/clients/p1/rapportages (services/ecd/src/__tests__/rapportage.test.ts:38)"}, "properties": {"repobilityId": "6aa56041ae859d36", "scanner": "scanner-primary", "fingerprint": "8238ff09ece98e59", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-285f88959d80424c", "level": "error", "message": {"text": "Dangling fetch: POST /api/clients/p1/rapportages (services/ecd/src/__tests__/rapportage.test.ts:54)"}, "properties": {"repobilityId": "9388b48fa248e131", "scanner": "scanner-primary", "fingerprint": "285f88959d80424c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-e38dc496880a3651", "level": "error", "message": {"text": "Dangling fetch: POST /api/clients/p1/rapportages (services/ecd/src/__tests__/rapportage.test.ts:68)"}, "properties": {"repobilityId": "00d7dd0785e966da", "scanner": "scanner-primary", "fingerprint": "e38dc496880a3651", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-9caa0ef5e396a55d", "level": "error", "message": {"text": "Dangling fetch: POST /api/clients/p1/rapportages (services/ecd/src/__tests__/rapportage.test.ts:94)"}, "properties": {"repobilityId": "a6060c04d93d5571", "scanner": "scanner-primary", "fingerprint": "9caa0ef5e396a55d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-48236c075b8830b0", "level": "error", "message": {"text": "Dangling fetch: GET /api/clients/p1/rapportages (services/ecd/src/__tests__/rapportage.test.ts:111)"}, "properties": {"repobilityId": "5304be4655528d06", "scanner": "scanner-primary", "fingerprint": "48236c075b8830b0", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-4d4bc932731f58b5", "level": "error", "message": {"text": "Dangling fetch: GET /api/clients/p1/rapportages?_count=50&date=ge2026-06-01 (services/ecd/src/__tests__/rapportage.test.ts:126)"}, "properties": {"repobilityId": "6f74a619d1f29ff6", "scanner": "scanner-primary", "fingerprint": "4d4bc932731f58b5", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-9b01b64382231c17", "level": "error", "message": {"text": "Dangling fetch: POST /api/clients (services/ecd/src/__tests__/client.test.ts:34)"}, "properties": {"repobilityId": "e9a12e7c85a35c92", "scanner": "scanner-primary", "fingerprint": "9b01b64382231c17", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-c98224923092f1f5", "level": "error", "message": {"text": "Dangling fetch: POST /api/clients (services/ecd/src/__tests__/client.test.ts:63)"}, "properties": {"repobilityId": "1dfa7d4a23e84f20", "scanner": "scanner-primary", "fingerprint": "c98224923092f1f5", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-327403ddb3290800", "level": "error", "message": {"text": "Dangling fetch: POST /api/clients (services/ecd/src/__tests__/client.test.ts:93)"}, "properties": {"repobilityId": "f7781f573bfeba67", "scanner": "scanner-primary", "fingerprint": "327403ddb3290800", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-0881d9172e8835b4", "level": "error", "message": {"text": "Dangling fetch: PUT /api/clients/patient-1 (services/ecd/src/__tests__/client.test.ts:106)"}, "properties": {"repobilityId": "30a404f13e548f39", "scanner": "scanner-primary", "fingerprint": "0881d9172e8835b4", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-c625f78ef4dd6556", "level": "error", "message": {"text": "Dangling fetch: GET /api/clients (services/ecd/src/__tests__/client.test.ts:130)"}, "properties": {"repobilityId": "b7eef6b992371044", "scanner": "scanner-primary", "fingerprint": "c625f78ef4dd6556", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-ee356e6005ef6203", "level": "error", "message": {"text": "Dangling fetch: GET /api/clients/abc (services/ecd/src/__tests__/client.test.ts:145)"}, "properties": {"repobilityId": "0abed8063b95920c", "scanner": "scanner-primary", "fingerprint": "ee356e6005ef6203", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-6fbf73d12bdbac4f", "level": "error", "message": {"text": "Dangling fetch: DELETE /api/clients/del-1 (services/ecd/src/__tests__/client.test.ts:173)"}, "properties": {"repobilityId": "4a4de3855b7fb8ad", "scanner": "scanner-primary", "fingerprint": "6fbf73d12bdbac4f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-48d2cb9e72803d4f", "level": "error", "message": {"text": "Dangling fetch: GET /api/admin/custom-fields (services/ecd/src/__tests__/configuratie.test.ts:89)"}, "properties": {"repobilityId": "21488b51ad397d7f", "scanner": "scanner-primary", "fingerprint": "48d2cb9e72803d4f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-2bc620411bde3eec", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/custom-fields (services/ecd/src/__tests__/configuratie.test.ts:99)"}, "properties": {"repobilityId": "5894f27cb7a3148b", "scanner": "scanner-primary", "fingerprint": "2bc620411bde3eec", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-45dc663023670fb1", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/custom-fields (services/ecd/src/__tests__/configuratie.test.ts:118)"}, "properties": {"repobilityId": "c52bcf6420e5551d", "scanner": "scanner-primary", "fingerprint": "45dc663023670fb1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-95517aec41709152", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/custom-fields (services/ecd/src/__tests__/configuratie.test.ts:128)"}, "properties": {"repobilityId": "996294ef9f347dd0", "scanner": "scanner-primary", "fingerprint": "95517aec41709152", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-e0265f6eafa96d99", "level": "error", "message": {"text": "Dangling fetch: GET /api/admin/validation-rules (services/ecd/src/__tests__/configuratie.test.ts:146)"}, "properties": {"repobilityId": "92a554acfdbc967f", "scanner": "scanner-primary", "fingerprint": "e0265f6eafa96d99", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-f3e8c93a7aaa9ebd", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/validation-rules (services/ecd/src/__tests__/configuratie.test.ts:156)"}, "properties": {"repobilityId": "9acaef51c40ebd0a", "scanner": "scanner-primary", "fingerprint": "f3e8c93a7aaa9ebd", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-02cf4a8226656cd3", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/validation-rules (services/ecd/src/__tests__/configuratie.test.ts:174)"}, "properties": {"repobilityId": "1ad2adb7af354461", "scanner": "scanner-primary", "fingerprint": "02cf4a8226656cd3", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-6bf72dbbb1c09ed8", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/validation-rules (services/ecd/src/__tests__/configuratie.test.ts:184)"}, "properties": {"repobilityId": "19ad15b6d369e551", "scanner": "scanner-primary", "fingerprint": "6bf72dbbb1c09ed8", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-b876e6fb5b3fd099", "level": "error", "message": {"text": "Dangling fetch: POST /api/afspraken (services/planning/src/__tests__/app.test.ts:74)"}, "properties": {"repobilityId": "4874b381d2e04874", "scanner": "scanner-primary", "fingerprint": "b876e6fb5b3fd099", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-cbd0774c5773b232", "level": "error", "message": {"text": "Dangling fetch: POST /api/afspraken (services/planning/src/__tests__/app.test.ts:98)"}, "properties": {"repobilityId": "cca9613325a5a68e", "scanner": "scanner-primary", "fingerprint": "cbd0774c5773b232", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-d78048e6b58f0249", "level": "error", "message": {"text": "Dangling fetch: POST /api/afspraken (services/planning/src/__tests__/app.test.ts:120)"}, "properties": {"repobilityId": "52e9c534b6ea8586", "scanner": "scanner-primary", "fingerprint": "d78048e6b58f0249", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-56815823bdb97493", "level": "note", "message": {"text": "Unused endpoint: GET /api/tenant-features"}, "properties": {"repobilityId": "5e341e1d025b6e08", "scanner": "scanner-primary", "fingerprint": "56815823bdb97493", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b8073f7bf758f6d0", "level": "note", "message": {"text": "Unused endpoint: USE /api/*"}, "properties": {"repobilityId": "e68c8a1bddeb2f78", "scanner": "scanner-primary", "fingerprint": "b8073f7bf758f6d0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-16412f1341a07586", "level": "note", "message": {"text": "Unused endpoint: GET /api/master/check-admin"}, "properties": {"repobilityId": "6d4cd9a934d25212", "scanner": "scanner-primary", "fingerprint": "16412f1341a07586", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a5ccb1c62506dbd", "level": "note", "message": {"text": "Unused endpoint: USE /api/master/*"}, "properties": {"repobilityId": "cc171f9f8acc2cc7", "scanner": "scanner-primary", "fingerprint": "7a5ccb1c62506dbd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "b38cb9ae0cd19a12", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2ab9bf5db6820af4", "level": "note", "message": {"text": "Unused endpoint: GET /models"}, "properties": {"repobilityId": "bdce95abbfa9d1f2", "scanner": "scanner-primary", "fingerprint": "2ab9bf5db6820af4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a6f48e60c30777ab", "level": "note", "message": {"text": "Unused endpoint: GET /config"}, "properties": {"repobilityId": "cec81c962ad35b77", "scanner": "scanner-primary", "fingerprint": "a6f48e60c30777ab", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7d2c56c613802d65", "level": "note", "message": {"text": "Unused endpoint: PUT /config"}, "properties": {"repobilityId": "bec05611b6b4da7a", "scanner": "scanner-primary", "fingerprint": "7d2c56c613802d65", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8e1fadad2500f063", "level": "note", "message": {"text": "Unused endpoint: POST /ask"}, "properties": {"repobilityId": "7bfca7d9b5ef9b66", "scanner": "scanner-primary", "fingerprint": "8e1fadad2500f063", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5b5dc7a75a543a74", "level": "note", "message": {"text": "Unused endpoint: POST /summarize-rapportages"}, "properties": {"repobilityId": "3cd461fa4dd4521d", "scanner": "scanner-primary", "fingerprint": "5b5dc7a75a543a74", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cff8da5fbc19c76d", "level": "note", "message": {"text": "Unused endpoint: POST /chat"}, "properties": {"repobilityId": "74c2ba27ac8456b6", "scanner": "scanner-primary", "fingerprint": "cff8da5fbc19c76d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-67d28fa8cd6bb12f", "level": "note", "message": {"text": "Unused endpoint: PUT /"}, "properties": {"repobilityId": "d1f574bd2e665d1e", "scanner": "scanner-primary", "fingerprint": "67d28fa8cd6bb12f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ca5756175765b49d", "level": "note", "message": {"text": "Unused endpoint: GET /:id"}, "properties": {"repobilityId": "c765d0863daff164", "scanner": "scanner-primary", "fingerprint": "ca5756175765b49d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-35194d3d2137eceb", "level": "note", "message": {"text": "Unused endpoint: POST /locaties"}, "properties": {"repobilityId": "7231f9c8b8f821ae", "scanner": "scanner-primary", "fingerprint": "35194d3d2137eceb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8d5b2b188d08ca82", "level": "note", "message": {"text": "Unused endpoint: PUT /:id"}, "properties": {"repobilityId": "73e9d7baefd520ee", "scanner": "scanner-primary", "fingerprint": "8d5b2b188d08ca82", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a61c112b611f4bb", "level": "note", "message": {"text": "Unused endpoint: DELETE /:id"}, "properties": {"repobilityId": "370cca9e48cca54d", "scanner": "scanner-primary", "fingerprint": "7a61c112b611f4bb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a009b1a56794f45", "level": "note", "message": {"text": "Unused endpoint: POST /"}, "properties": {"repobilityId": "3bbf9aec1f51cf32", "scanner": "scanner-primary", "fingerprint": "7a009b1a56794f45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e0a8390ddb0ad54c", "level": "note", "message": {"text": "Unused endpoint: GET /samenvatting"}, "properties": {"repobilityId": "3ce377ed1594aa76", "scanner": "scanner-primary", "fingerprint": "e0a8390ddb0ad54c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c5718a89854e7bdd", "level": "note", "message": {"text": "Unused endpoint: GET /clients/:patientId/responses"}, "properties": {"repobilityId": "b07dea0d692a06f7", "scanner": "scanner-primary", "fingerprint": "c5718a89854e7bdd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-45e9bf9f1df86ea7", "level": "note", "message": {"text": "Unused endpoint: POST /clients/:patientId/responses"}, "properties": {"repobilityId": "147086e255594a20", "scanner": "scanner-primary", "fingerprint": "45e9bf9f1df86ea7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5c3bc50588d3bbfa", "level": "note", "message": {"text": "Unused endpoint: GET /:patientId/toedieningen"}, "properties": {"repobilityId": "2b288b8764a30b10", "scanner": "scanner-primary", "fingerprint": "5c3bc50588d3bbfa", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0421bccead41282e", "level": "note", "message": {"text": "Unused endpoint: GET /:patientId/toedienlijst"}, "properties": {"repobilityId": "a94d2b3b716a22a7", "scanner": "scanner-primary", "fingerprint": "0421bccead41282e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e1423d70e5488a17", "level": "note", "message": {"text": "Unused endpoint: POST /:patientId/toedieningen"}, "properties": {"repobilityId": "c1464c38189c9693", "scanner": "scanner-primary", "fingerprint": "e1423d70e5488a17", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-39bbac8dbf00a5b7", "level": "note", "message": {"text": "Unused endpoint: GET /:patientId/mdo"}, "properties": {"repobilityId": "c66bc2123f18291c", "scanner": "scanner-primary", "fingerprint": "39bbac8dbf00a5b7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4379da8de72fa165", "level": "note", "message": {"text": "Unused endpoint: POST /:patientId/mdo"}, "properties": {"repobilityId": "1ca7b7d7a9703f17", "scanner": "scanner-primary", "fingerprint": "4379da8de72fa165", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e12be0a8be938fb5", "level": "note", "message": {"text": "Unused endpoint: PUT /:patientId/mdo/:id"}, "properties": {"repobilityId": "1264a506790e37b6", "scanner": "scanner-primary", "fingerprint": "e12be0a8be938fb5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-61427173b6043c35", "level": "note", "message": {"text": "Unused endpoint: POST /:patientId/mdo/:mdoId/verslag"}, "properties": {"repobilityId": "ce15b4998ecef49b", "scanner": "scanner-primary", "fingerprint": "61427173b6043c35", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9630d39f953a327c", "level": "note", "message": {"text": "Unused endpoint: GET /types"}, "properties": {"repobilityId": "9f34d569cd98771c", "scanner": "scanner-primary", "fingerprint": "9630d39f953a327c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b91e563582a6df77", "level": "note", "message": {"text": "Unused endpoint: GET /:patientId/vbm"}, "properties": {"repobilityId": "544a30ca863abe81", "scanner": "scanner-primary", "fingerprint": "b91e563582a6df77", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6c7dab7ea5ff5e73", "level": "note", "message": {"text": "Unused endpoint: POST /:patientId/vbm"}, "properties": {"repobilityId": "cbc7160acb723e9a", "scanner": "scanner-primary", "fingerprint": "6c7dab7ea5ff5e73", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a0a41deaacda8315", "level": "note", "message": {"text": "Unused endpoint: POST /:patientId/vbm/:vbmId/evaluatie"}, "properties": {"repobilityId": "49b66460f1ae0b42", "scanner": "scanner-primary", "fingerprint": "a0a41deaacda8315", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a36631e6ed5141fa", "level": "note", "message": {"text": "Unused endpoint: PUT /:patientId/vbm/:id/beeindigen"}, "properties": {"repobilityId": "e5e807bad8857e68", "scanner": "scanner-primary", "fingerprint": "a36631e6ed5141fa", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dca68bcf2eac0fb7", "level": "note", "message": {"text": "Unused endpoint: GET /:patientId/medicatie-overzicht"}, "properties": {"repobilityId": "3cac12b6c55423cf", "scanner": "scanner-primary", "fingerprint": "dca68bcf2eac0fb7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c9871265a983a6b4", "level": "note", "message": {"text": "Unused endpoint: POST /:patientId/medicatie-overzicht"}, "properties": {"repobilityId": "be9f0abb15a2d7d3", "scanner": "scanner-primary", "fingerprint": "c9871265a983a6b4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-65301c78e66b31a9", "level": "note", "message": {"text": "Unused endpoint: PUT /:patientId/medicatie-overzicht/:id"}, "properties": {"repobilityId": "df85472efc707b2f", "scanner": "scanner-primary", "fingerprint": "65301c78e66b31a9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5f7b6f1e9d29f097", "level": "note", "message": {"text": "Unused endpoint: DELETE /:patientId/medicatie-overzicht/:id"}, "properties": {"repobilityId": "35ef4bf0fdf700ae", "scanner": "scanner-primary", "fingerprint": "5f7b6f1e9d29f097", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7e334e17d82c37de", "level": "note", "message": {"text": "Unused endpoint: GET /clients/:clientId/documenten"}, "properties": {"repobilityId": "cb050decd0adef8d", "scanner": "scanner-primary", "fingerprint": "7e334e17d82c37de", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1dfc13731526d2d0", "level": "note", "message": {"text": "Unused endpoint: POST /clients/:clientId/documenten"}, "properties": {"repobilityId": "06a4fab61b62f64b", "scanner": "scanner-primary", "fingerprint": "1dfc13731526d2d0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-953cbcf48e64a946", "level": "note", "message": {"text": "Unused endpoint: GET /:clientId/verzekering"}, "properties": {"repobilityId": "fb4f2bf1859e0c3b", "scanner": "scanner-primary", "fingerprint": "953cbcf48e64a946", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-069e3fde9aee8307", "level": "note", "message": {"text": "Unused endpoint: POST /:clientId/verzekering"}, "properties": {"repobilityId": "51cadbf7a60b6fb6", "scanner": "scanner-primary", "fingerprint": "069e3fde9aee8307", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3de9acdeb9901d2c", "level": "note", "message": {"text": "Unused endpoint: PUT /:clientId/verzekering/:coverageId"}, "properties": {"repobilityId": "d826a1d61b4687bf", "scanner": "scanner-primary", "fingerprint": "3de9acdeb9901d2c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4e63fe03579274be", "level": "note", "message": {"text": "Unused endpoint: GET /overzicht"}, "properties": {"repobilityId": "33f61af3142779e7", "scanner": "scanner-primary", "fingerprint": "4e63fe03579274be", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-608d33f1665b28a2", "level": "note", "message": {"text": "Unused endpoint: GET /:patientId/vaccinaties"}, "properties": {"repobilityId": "52033d054d9291ed", "scanner": "scanner-primary", "fingerprint": "608d33f1665b28a2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-060ad5cd918fb408", "level": "note", "message": {"text": "Unused endpoint: GET /:patientId/vaccinaties/:id"}, "properties": {"repobilityId": "df06a24f38462ed1", "scanner": "scanner-primary", "fingerprint": "060ad5cd918fb408", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3817cb6dd1194fc8", "level": "note", "message": {"text": "Unused endpoint: POST /:patientId/vaccinaties"}, "properties": {"repobilityId": "09ef079fb7b29358", "scanner": "scanner-primary", "fingerprint": "3817cb6dd1194fc8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2b5f603512e21e74", "level": "note", "message": {"text": "Unused endpoint: PUT /:patientId/vaccinaties/:id"}, "properties": {"repobilityId": "20f4fc375ab2c54d", "scanner": "scanner-primary", "fingerprint": "2b5f603512e21e74", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5b035e28f83ef139", "level": "note", "message": {"text": "Unused endpoint: DELETE /:patientId/vaccinaties/:id"}, "properties": {"repobilityId": "1bc5fd8a2def1671", "scanner": "scanner-primary", "fingerprint": "5b035e28f83ef139", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-02b023f84ff53c43", "level": "note", "message": {"text": "Unused endpoint: PATCH /:id/gelezen"}, "properties": {"repobilityId": "d5ffd130e480c6c2", "scanner": "scanner-primary", "fingerprint": "02b023f84ff53c43", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e77718daba3fe62e", "level": "note", "message": {"text": "Unused endpoint: GET /medicatie-voorschriften"}, "properties": {"repobilityId": "ada970a6dda86c19", "scanner": "scanner-primary", "fingerprint": "e77718daba3fe62e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-54e732f482e6800a", "level": "note", "message": {"text": "Unused endpoint: GET /clients/:clientId/medicatie"}, "properties": {"repobilityId": "5277135092326ecf", "scanner": "scanner-primary", "fingerprint": "54e732f482e6800a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}