{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-07373e63b7fc0c03", "name": "Privileged port 993 in use", "shortDescription": {"text": "Privileged port 993 in use"}, "fullDescription": {"text": "Port 993 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4c336955389adf2d", "name": "Privileged port 30 in use", "shortDescription": {"text": "Privileged port 30 in use"}, "fullDescription": {"text": "Port 30 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-518a6be6a05a578a", "name": "Privileged port 248 in use", "shortDescription": {"text": "Privileged port 248 in use"}, "fullDescription": {"text": "Port 248 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-20d3a518366c04ef", "name": "Privileged port 1000 in use", "shortDescription": {"text": "Privileged port 1000 in use"}, "fullDescription": {"text": "Port 1000 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-86b372850a794fa1", "name": "Docker base image is tag-pinned but not digest-pinned: docker.io/library/python:3.14-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: docker.io/library/python:3.14-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-305b17145571bb7b", "name": "Docker base image is tag-pinned but not digest-pinned: docker.io/library/python:3.14-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: docker.io/library/python:3.14-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0736ca0c63851f4a", "name": "Docker base image is tag-pinned but not digest-pinned: python:3.14-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.14-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a3b44bb7dd6990c2", "name": "Possible secret in apps/base/erpnext/helm-release.yaml", "shortDescription": {"text": "Possible secret in apps/base/erpnext/helm-release.yaml"}, "fullDescription": {"text": "Detected pattern matching password_literal. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-8530da5284c8bf7c", "name": "Possible secret in apps/base/frappe-crm/helm-release.yaml", "shortDescription": {"text": "Possible secret in apps/base/frappe-crm/helm-release.yaml"}, "fullDescription": {"text": "Detected pattern matching password_literal. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-5c1cfbedf4e9f68b", "name": "Insecure pattern 'weak_hash' in clusters/dev/flux-system/gotk-components.yaml:4828", "shortDescription": {"text": "Insecure pattern 'weak_hash' in clusters/dev/flux-system/gotk-components.yaml:4828"}, "fullDescription": {"text": "Found a known-risky pattern (weak_hash). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-237e02d7f7e8247a", "name": "Possible secret in clusters/homelab/vars.yaml", "shortDescription": {"text": "Possible secret in clusters/homelab/vars.yaml"}, "fullDescription": {"text": "Detected pattern matching generic_api_key. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-25558c8dbb963151", "name": "Insecure pattern 'weak_hash' in clusters/homelab/flux-system/gotk-components.yaml:4828", "shortDescription": {"text": "Insecure pattern 'weak_hash' in clusters/homelab/flux-system/gotk-components.yaml:4828"}, "fullDescription": {"text": "Found a known-risky pattern (weak_hash). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dcb0c68df1e4a733", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-94de7a4a6ffdbe23", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-367cef8b9abb3000", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-65a716a27d2be993", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8a05ee13872a4c70", "name": "GitHub Action tracks a moving branch", "shortDescription": {"text": "GitHub Action tracks a moving branch"}, "fullDescription": {"text": "Diixtra/diixtra-forge/.github/workflows/code-quality.yaml@main can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d743e17076271003", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9e016ac4b48e3f55", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a824c25d3e0b54df", "name": "Network/subprocess call without timeout or try/except \u2014 scripts/talos-render.py:98", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/talos-render.py:98"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-62b452a4dafccf39", "name": "Commented-code block (7 lines) in apps/base/warm-model-controller/src/main.py:66", "shortDescription": {"text": "Commented-code block (7 lines) in apps/base/warm-model-controller/src/main.py:66"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/25408"}, "properties": {"repository": "Diixtra/diixtra-forge", "repoUrl": "https://github.com/Diixtra/diixtra-forge", "branch": "main"}, "results": [{"ruleId": "scanner-07373e63b7fc0c03", "level": "warning", "message": {"text": "Privileged port 993 in use"}, "properties": {"repobilityId": "a36e56a26353e9ee", "scanner": "scanner-primary", "fingerprint": "07373e63b7fc0c03", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/chainsaw/compositions/web-service/claim-auth.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4c336955389adf2d", "level": "warning", "message": {"text": "Privileged port 30 in use"}, "properties": {"repobilityId": "54f172e7d16fc662", "scanner": "scanner-primary", "fingerprint": "4c336955389adf2d", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/talos-upgrade.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-518a6be6a05a578a", "level": "warning", "message": {"text": "Privileged port 248 in use"}, "properties": {"repobilityId": "68af450f318299bb", "scanner": "scanner-primary", "fingerprint": "518a6be6a05a578a", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "infrastructure/base/cert-manager/network-policy.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-20d3a518366c04ef", "level": "warning", "message": {"text": "Privileged port 1000 in use"}, "properties": {"repobilityId": "5ac9fc9372cfe169", "scanner": "scanner-primary", "fingerprint": "20d3a518366c04ef", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/base/forgejo/helm-release.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-86b372850a794fa1", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: docker.io/library/python:3.14-slim"}, "properties": {"repobilityId": "6b4b34c2a9da877d", "scanner": "scanner-primary", "fingerprint": "86b372850a794fa1", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/base/warm-model-controller/src/Dockerfile"}, "region": {"startLine": 8}}}]}, {"ruleId": "scanner-86b372850a794fa1", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: docker.io/library/python:3.14-slim"}, "properties": {"repobilityId": "6fc291503b598def", "scanner": "scanner-primary", "fingerprint": "86b372850a794fa1", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/base/warm-model-controller/src/Dockerfile"}, "region": {"startLine": 27}}}]}, {"ruleId": "scanner-305b17145571bb7b", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: docker.io/library/python:3.14-slim"}, "properties": {"repobilityId": "cfe5cd6585f42ea7", "scanner": "scanner-primary", "fingerprint": "305b17145571bb7b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/base/workos-webhook-receiver/src/Dockerfile"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-305b17145571bb7b", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: docker.io/library/python:3.14-slim"}, "properties": {"repobilityId": "64a0b4940dce0c3f", "scanner": "scanner-primary", "fingerprint": "305b17145571bb7b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/base/workos-webhook-receiver/src/Dockerfile"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-0736ca0c63851f4a", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.14-slim"}, "properties": {"repobilityId": "093f05caf3e61ed7", "scanner": "scanner-primary", "fingerprint": "0736ca0c63851f4a", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "platform/base/truenas-app-updater/Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a3b44bb7dd6990c2", "level": "error", "message": {"text": "Possible secret in apps/base/erpnext/helm-release.yaml"}, "properties": {"repobilityId": "2173c0bde27872cc", "scanner": "scanner-primary", "fingerprint": "a3b44bb7dd6990c2", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/base/erpnext/helm-release.yaml"}, "region": {"startLine": 308}}}]}, {"ruleId": "scanner-8530da5284c8bf7c", "level": "error", "message": {"text": "Possible secret in apps/base/frappe-crm/helm-release.yaml"}, "properties": {"repobilityId": "cb3333db2d216d7f", "scanner": "scanner-primary", "fingerprint": "8530da5284c8bf7c", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/base/frappe-crm/helm-release.yaml"}, "region": {"startLine": 324}}}]}, {"ruleId": "scanner-5c1cfbedf4e9f68b", "level": "warning", "message": {"text": "Insecure pattern 'weak_hash' in clusters/dev/flux-system/gotk-components.yaml:4828"}, "properties": {"repobilityId": "36056c68f1f40e38", "scanner": "scanner-primary", "fingerprint": "5c1cfbedf4e9f68b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "weak_hash"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "clusters/dev/flux-system/gotk-components.yaml"}, "region": {"startLine": 4828}}}]}, {"ruleId": "scanner-237e02d7f7e8247a", "level": "error", "message": {"text": "Possible secret in clusters/homelab/vars.yaml"}, "properties": {"repobilityId": "a73c1247c6ec6962", "scanner": "scanner-primary", "fingerprint": "237e02d7f7e8247a", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "clusters/homelab/vars.yaml"}, "region": {"startLine": 255}}}]}, {"ruleId": "scanner-25558c8dbb963151", "level": "warning", "message": {"text": "Insecure pattern 'weak_hash' in clusters/homelab/flux-system/gotk-components.yaml:4828"}, "properties": {"repobilityId": "9aa937a6b2e5bbdc", "scanner": "scanner-primary", "fingerprint": "25558c8dbb963151", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "weak_hash"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "clusters/homelab/flux-system/gotk-components.yaml"}, "region": {"startLine": 4828}}}]}, {"ruleId": "scanner-dcb0c68df1e4a733", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "2fed97ae60a63f4c", "scanner": "scanner-primary", "fingerprint": "dcb0c68df1e4a733", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/build-truenas-app-updater.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-94de7a4a6ffdbe23", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "dcab35547705e3bc", "scanner": "scanner-primary", "fingerprint": "94de7a4a6ffdbe23", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/build-workos-webhook-receiver.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-367cef8b9abb3000", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "00d535333d9d6f83", "scanner": "scanner-primary", "fingerprint": "367cef8b9abb3000", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/revert.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-65a716a27d2be993", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "3133a88ce98acc76", "scanner": "scanner-primary", "fingerprint": "65a716a27d2be993", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/scorecard.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8a05ee13872a4c70", "level": "error", "message": {"text": "GitHub Action tracks a moving branch"}, "properties": {"repobilityId": "4cc620ecaf49bd4a", "scanner": "scanner-primary", "fingerprint": "8a05ee13872a4c70", "layer": "cicd", "severity": "high", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/code-quality-call.yaml"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-d743e17076271003", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "7a875ced5ae53f14", "scanner": "scanner-primary", "fingerprint": "d743e17076271003", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/port-auto-merge.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9e016ac4b48e3f55", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "d5d23da7bc658a47", "scanner": "scanner-primary", "fingerprint": "9e016ac4b48e3f55", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/build-warm-model-controller.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "b320f28aa896c52d", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-a824c25d3e0b54df", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/talos-render.py:98"}, "properties": {"repobilityId": "97387ff21e750b89", "scanner": "scanner-primary", "fingerprint": "a824c25d3e0b54df", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-62b452a4dafccf39", "level": "none", "message": {"text": "Commented-code block (7 lines) in apps/base/warm-model-controller/src/main.py:66"}, "properties": {"repobilityId": "5f6e86fe59b99db9", "scanner": "scanner-primary", "fingerprint": "62b452a4dafccf39", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}]}]}