{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-8725d1d55f6f8ac4", "name": "Possibly dead Python function: set_tz", "shortDescription": {"text": "Possibly dead Python function: set_tz"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cebb5e718bf8a15e", "name": "Possibly dead Python function: code_severity", "shortDescription": {"text": "Possibly dead Python function: code_severity"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-259f79d16dabeabe", "name": "Possibly dead Python function: reset_accumulators_on_purge", "shortDescription": {"text": "Possibly dead Python function: reset_accumulators_on_purge"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-51b3a7f9210fbfb4", "name": "Possibly dead Python function: hourly_bar_chart", "shortDescription": {"text": "Possibly dead Python function: hourly_bar_chart"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-47250a2ad5cc16d9", "name": "Possibly dead Python function: emit", "shortDescription": {"text": "Possibly dead Python function: emit"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7fcef8f22e306b10", "name": "Possibly dead Python function: init_online_schema", "shortDescription": {"text": "Possibly dead Python function: init_online_schema"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a84540458a604724", "name": "Possibly dead Python function: delete_observation", "shortDescription": {"text": "Possibly dead Python function: delete_observation"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-01eeab09caad505f", "name": "Possibly dead Python function: update_continues_to", "shortDescription": {"text": "Possibly dead Python function: update_continues_to"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-50e5653a666fff31", "name": "Possibly dead Python function: has_segments", "shortDescription": {"text": "Possibly dead Python function: has_segments"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-402ee1f147cb6d2a", "name": "Possibly dead Python function: fire_verify", "shortDescription": {"text": "Possibly dead Python function: fire_verify"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f4c39f3f1ef35723", "name": "Possibly dead Python function: compute_register_stats", "shortDescription": {"text": "Possibly dead Python function: compute_register_stats"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-99ebc11ee8e21828", "name": "Possibly dead Python function: run_pipeline", "shortDescription": {"text": "Possibly dead Python function: run_pipeline"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b0db6b051f775b58", "name": "Possibly dead Python function: clear_index_cache", "shortDescription": {"text": "Possibly dead Python function: clear_index_cache"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e6c78da03aa7fe05", "name": "Possibly dead Python function: invalidate_cache", "shortDescription": {"text": "Possibly dead Python function: invalidate_cache"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3770a455f514cad6", "name": "Possibly dead Python function: search_manual_docs", "shortDescription": {"text": "Possibly dead Python function: search_manual_docs"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-35d42bfb0979e9e3", "name": "Possibly dead Python function: invalidate_cache", "shortDescription": {"text": "Possibly dead Python function: invalidate_cache"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a0184608ee5db3e7", "name": "Privileged port 10 in use", "shortDescription": {"text": "Privileged port 10 in use"}, "fullDescription": {"text": "Port 10 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d51c640c2d324dd0", "name": "Privileged port 218 in use", "shortDescription": {"text": "Privileged port 218 in use"}, "fullDescription": {"text": "Port 218 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3c7f00806b026261", "name": "Privileged port 21 in use", "shortDescription": {"text": "Privileged port 21 in use"}, "fullDescription": {"text": "Port 21 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bd8ff00fed40e0f0", "name": "Privileged port 5 in use", "shortDescription": {"text": "Privileged port 5 in use"}, "fullDescription": {"text": "Port 5 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0ddd79a67e0a8ebd", "name": "Privileged port 272 in use", "shortDescription": {"text": "Privileged port 272 in use"}, "fullDescription": {"text": "Port 272 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7487cb1a7ffa6111", "name": "Privileged port 24 in use", "shortDescription": {"text": "Privileged port 24 in use"}, "fullDescription": {"text": "Port 24 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7e9b16ab072e766e", "name": "Insecure pattern 'direct_innerhtml_assignment' in web/static/bootstrap.bundle.min.js:6", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in web/static/bootstrap.bundle.min.js:6"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f0811f1e25aa2ffb", "name": "Insecure pattern 'domparser_html_parse' in web/static/bootstrap.bundle.min.js:6", "shortDescription": {"text": "Insecure pattern 'domparser_html_parse' in web/static/bootstrap.bundle.min.js:6"}, "fullDescription": {"text": "Found a known-risky pattern (domparser_html_parse). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ae67748e3d09f8ea", "name": "Insecure pattern 'direct_innerhtml_assignment' in knowledge_base/equipment/cummins_kta50_pcc3300/pcc3300_fault_codes_v2_", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in knowledge_base/equipment/cummins_kta50_pcc3300/pcc3300_fault_codes_v2_3.html:1940"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-38de955f1b2d3d3d", "name": "Very large file: web/routes.py (2524 lines)", "shortDescription": {"text": "Very large file: web/routes.py (2524 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea3b5e389d8c9c0f", "name": "Low test-to-source ratio", "shortDescription": {"text": "Low test-to-source ratio"}, "fullDescription": {"text": "7 tests / 59 src (ratio 0.12)."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 5 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8659a04d4f16bdee", "name": "Commented-code block (5 lines) in analytics/metrics.py:416", "shortDescription": {"text": "Commented-code block (5 lines) in analytics/metrics.py:416"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nanalytics/serializer.py:to_json, analytics/serializer.py:to_markdown\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-76a2f6818267a9a8", "name": "Near-duplicate function bodies in 8 places", "shortDescription": {"text": "Near-duplicate function bodies in 8 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nanalytics/source.py:get_whitelist_history, analytics/source.py:get_enum_periods, analytics/source.py:get_fault_periods, analytics/source.py:get_data_gaps\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-46969939caf8120b", "name": "Near-duplicate function bodies in 9 places", "shortDescription": {"text": "Near-duplicate function bodies in 9 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nanalytics/contract.py:to_dict, analytics/contract.py:to_dict, analytics/contract.py:to_dict, analytics/contract.py:to_dict\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be46ea126aa5d8dc", "name": "Near-duplicate function bodies in 3 places", "shortDescription": {"text": "Near-duplicate function bodies in 3 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\ncorpus/worker.py:stop, corpus/qwen_worker.py:stop, online/engine.py:stop\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bd3b6cae37a0d9fe", "name": "FastAPI POST `analyze_run` without auth dependency \u2014 web/routes.py:103", "shortDescription": {"text": "FastAPI POST `analyze_run` without auth dependency \u2014 web/routes.py:103"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-20f89e4b48f512ec", "name": "FastAPI POST `analyze_stream` without auth dependency \u2014 web/routes.py:137", "shortDescription": {"text": "FastAPI POST `analyze_stream` without auth dependency \u2014 web/routes.py:137"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c513975c94ce53e9", "name": "FastAPI POST `delete_analysis_run` without auth dependency \u2014 web/routes.py:340", "shortDescription": {"text": "FastAPI POST `delete_analysis_run` without auth dependency \u2014 web/routes.py:340"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c0081b7098f94df5", "name": "FastAPI POST `api_log_clear` without auth dependency \u2014 web/routes.py:371", "shortDescription": {"text": "FastAPI POST `api_log_clear` without auth dependency \u2014 web/routes.py:371"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-59596b05fdeb44b1", "name": "FastAPI POST `analyze_run_agent` without auth dependency \u2014 web/routes.py:562", "shortDescription": {"text": "FastAPI POST `analyze_run_agent` without auth dependency \u2014 web/routes.py:562"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5247521395fc6ea6", "name": "FastAPI POST `kb_upload` without auth dependency \u2014 web/routes.py:860", "shortDescription": {"text": "FastAPI POST `kb_upload` without auth dependency \u2014 web/routes.py:860"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-948c82ad1fb19bb1", "name": "FastAPI POST `kb_delete_file` without auth dependency \u2014 web/routes.py:896", "shortDescription": {"text": "FastAPI POST `kb_delete_file` without auth dependency \u2014 web/routes.py:896"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5c563f68c85e4dc1", "name": "FastAPI POST `update_status_line_interval` without auth dependency \u2014 web/routes.py:948", "shortDescription": {"text": "FastAPI POST `update_status_line_interval` without auth dependency \u2014 web/routes.py:948"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-360b849680788901", "name": "FastAPI POST `update_llm_settings` without auth dependency \u2014 web/routes.py:957", "shortDescription": {"text": "FastAPI POST `update_llm_settings` without auth dependency \u2014 web/routes.py:957"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e3114a7faad28d7a", "name": "FastAPI POST `update_ai_routing` without auth dependency \u2014 web/routes.py:979", "shortDescription": {"text": "FastAPI POST `update_ai_routing` without auth dependency \u2014 web/routes.py:979"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-52ae73a034e8425c", "name": "FastAPI POST `ai_playground_run` without auth dependency \u2014 web/routes.py:1005", "shortDescription": {"text": "FastAPI POST `ai_playground_run` without auth dependency \u2014 web/routes.py:1005"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b1f9a15dfa8aef24", "name": "FastAPI POST `update_claude_settings` without auth dependency \u2014 web/routes.py:1111", "shortDescription": {"text": "FastAPI POST `update_claude_settings` without auth dependency \u2014 web/routes.py:1111"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-80d270e8116f2b82", "name": "FastAPI POST `qwen_toggle` without auth dependency \u2014 web/routes.py:1129", "shortDescription": {"text": "FastAPI POST `qwen_toggle` without auth dependency \u2014 web/routes.py:1129"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a547cf6f72f7a9fd", "name": "FastAPI POST `analytics_verify_toggle` without auth dependency \u2014 web/routes.py:1146", "shortDescription": {"text": "FastAPI POST `analytics_verify_toggle` without auth dependency \u2014 web/routes.py:1146"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3833afd271acb1b7", "name": "FastAPI POST `corpus_toggle` without auth dependency \u2014 web/routes.py:1158", "shortDescription": {"text": "FastAPI POST `corpus_toggle` without auth dependency \u2014 web/routes.py:1158"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d72ea62d6a4af8de", "name": "FastAPI POST `update_timezone` without auth dependency \u2014 web/routes.py:1174", "shortDescription": {"text": "FastAPI POST `update_timezone` without auth dependency \u2014 web/routes.py:1174"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-65318120436bfe63", "name": "FastAPI POST `update_equipment` without auth dependency \u2014 web/routes.py:1187", "shortDescription": {"text": "FastAPI POST `update_equipment` without auth dependency \u2014 web/routes.py:1187"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5f9aac82ec11178d", "name": "FastAPI POST `toggle_equipment` without auth dependency \u2014 web/routes.py:1212", "shortDescription": {"text": "FastAPI POST `toggle_equipment` without auth dependency \u2014 web/routes.py:1212"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-de10216ea2424641", "name": "FastAPI POST `delete_equipment` without auth dependency \u2014 web/routes.py:1223", "shortDescription": {"text": "FastAPI POST `delete_equipment` without auth dependency \u2014 web/routes.py:1223"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6727d0f615aaf1d1", "name": "FastAPI POST `clear_equipment` without auth dependency \u2014 web/routes.py:1233", "shortDescription": {"text": "FastAPI POST `clear_equipment` without auth dependency \u2014 web/routes.py:1233"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-37c59ba7cf8adc53", "name": "FastAPI POST `sync_equipment` without auth dependency \u2014 web/routes.py:1239", "shortDescription": {"text": "FastAPI POST `sync_equipment` without auth dependency \u2014 web/routes.py:1239"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a53c4b727a67357a", "name": "FastAPI POST `analytics_config_upload` without auth dependency \u2014 web/routes.py:1297", "shortDescription": {"text": "FastAPI POST `analytics_config_upload` without auth dependency \u2014 web/routes.py:1297"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9be59d7e827ef2a5", "name": "FastAPI POST `online_start` without auth dependency \u2014 web/routes.py:1366", "shortDescription": {"text": "FastAPI POST `online_start` without auth dependency \u2014 web/routes.py:1366"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2df7550e9d3fbba2", "name": "FastAPI POST `online_stop` without auth dependency \u2014 web/routes.py:1396", "shortDescription": {"text": "FastAPI POST `online_stop` without auth dependency \u2014 web/routes.py:1396"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c49d95dc29b90adc", "name": "FastAPI POST `online_corpus_toggle` without auth dependency \u2014 web/routes.py:1412", "shortDescription": {"text": "FastAPI POST `online_corpus_toggle` without auth dependency \u2014 web/routes.py:1412"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-11fbaafbee7663ea", "name": "FastAPI POST `online_qwen_toggle` without auth dependency \u2014 web/routes.py:1428", "shortDescription": {"text": "FastAPI POST `online_qwen_toggle` without auth dependency \u2014 web/routes.py:1428"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-abd9983057c53c54", "name": "FastAPI POST `online_clear_claude_analysis` without auth dependency \u2014 web/routes.py:1444", "shortDescription": {"text": "FastAPI POST `online_clear_claude_analysis` without auth dependency \u2014 web/routes.py:1444"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-57e2baa66ca4bf70", "name": "FastAPI POST `online_clear_qwen_analysis` without auth dependency \u2014 web/routes.py:1453", "shortDescription": {"text": "FastAPI POST `online_clear_qwen_analysis` without auth dependency \u2014 web/routes.py:1453"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2e75aa388efdd58f", "name": "FastAPI POST `online_start_multi` without auth dependency \u2014 web/routes.py:1462", "shortDescription": {"text": "FastAPI POST `online_start_multi` without auth dependency \u2014 web/routes.py:1462"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ab58b38ef5b17d4e", "name": "FastAPI POST `online_segment_analyze` without auth dependency \u2014 web/routes.py:1850", "shortDescription": {"text": "FastAPI POST `online_segment_analyze` without auth dependency \u2014 web/routes.py:1850"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-92061a3039c2f70a", "name": "FastAPI POST `online_delete_segments` without auth dependency \u2014 web/routes.py:1891", "shortDescription": {"text": "FastAPI POST `online_delete_segments` without auth dependency \u2014 web/routes.py:1891"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cb676158d8b2e245", "name": "FastAPI POST `online_clear` without auth dependency \u2014 web/routes.py:1922", "shortDescription": {"text": "FastAPI POST `online_clear` without auth dependency \u2014 web/routes.py:1922"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f6da7f101c8ed7ff", "name": "FastAPI POST `set_source_mode_route` without auth dependency \u2014 web/routes.py:2502", "shortDescription": {"text": "FastAPI POST `set_source_mode_route` without auth dependency \u2014 web/routes.py:2502"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-75bbcaee0417aaca", "name": "FastAPI POST `set_history_sync_interval` without auth dependency \u2014 web/routes.py:2514", "shortDescription": {"text": "FastAPI POST `set_history_sync_interval` without auth dependency \u2014 web/routes.py:2514"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`web/routes.py` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6d93f6ad14064cf9", "name": "Unused endpoint: GET /report/{report_id}", "shortDescription": {"text": "Unused endpoint: GET /report/{report_id}"}, "fullDescription": {"text": "`web/routes.py` declares `GET /report/{report_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bc558e1bd171e40f", "name": "Unused endpoint: GET /history/{router_sn}/{equip_type}/{panel_id}", "shortDescription": {"text": "Unused endpoint: GET /history/{router_sn}/{equip_type}/{panel_id}"}, "fullDescription": {"text": "`web/routes.py` declares `GET /history/{router_sn}/{equip_type}/{panel_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72a90c9eabe0d9b3", "name": "Unused endpoint: GET /analyze", "shortDescription": {"text": "Unused endpoint: GET /analyze"}, "fullDescription": {"text": "`web/routes.py` declares `GET /analyze` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fca11d494725d7c3", "name": "Unused endpoint: POST /analyze", "shortDescription": {"text": "Unused endpoint: POST /analyze"}, "fullDescription": {"text": "`web/routes.py` declares `POST /analyze` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1647a6533f8d9bb3", "name": "Unused endpoint: POST /analyze/stream", "shortDescription": {"text": "Unused endpoint: POST /analyze/stream"}, "fullDescription": {"text": "`web/routes.py` declares `POST /analyze/stream` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa44293c97ffa043", "name": "Unused endpoint: GET /analysis/{run_id}", "shortDescription": {"text": "Unused endpoint: GET /analysis/{run_id}"}, "fullDescription": {"text": "`web/routes.py` declares `GET /analysis/{run_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a434c80787f7a73f", "name": "Unused endpoint: GET /analysis/{run_id}/md", "shortDescription": {"text": "Unused endpoint: GET /analysis/{run_id}/md"}, "fullDescription": {"text": "`web/routes.py` declares `GET /analysis/{run_id}/md` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-afc064028ae39ea9", "name": "Unused endpoint: GET /history", "shortDescription": {"text": "Unused endpoint: GET /history"}, "fullDescription": {"text": "`web/routes.py` declares `GET /history` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c4fcc547455ef811", "name": "Unused endpoint: POST /history/delete/{run_id}", "shortDescription": {"text": "Unused endpoint: POST /history/delete/{run_id}"}, "fullDescription": {"text": "`web/routes.py` declares `POST /history/delete/{run_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fe9a2fccde85686a", "name": "Unused endpoint: GET /history-v2/{router_sn}/{equip_type}/{panel_id}", "shortDescription": {"text": "Unused endpoint: GET /history-v2/{router_sn}/{equip_type}/{panel_id}"}, "fullDescription": {"text": "`web/routes.py` declares `GET /history-v2/{router_sn}/{equip_type}/{panel_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-81327b7bef38b5d6", "name": "Unused endpoint: GET /log", "shortDescription": {"text": "Unused endpoint: GET /log"}, "fullDescription": {"text": "`web/routes.py` declares `GET /log` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1ee169aa5640a319", "name": "Unused endpoint: GET /api/log", "shortDescription": {"text": "Unused endpoint: GET /api/log"}, "fullDescription": {"text": "`web/routes.py` declares `GET /api/log` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c73c4f1e41dbe1e9", "name": "Unused endpoint: POST /api/log/clear", "shortDescription": {"text": "Unused endpoint: POST /api/log/clear"}, "fullDescription": {"text": "`web/routes.py` declares `POST /api/log/clear` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-da35e12d9e5cbff9", "name": "Unused endpoint: POST /analyze/run", "shortDescription": {"text": "Unused endpoint: POST /analyze/run"}, "fullDescription": {"text": "`web/routes.py` declares `POST /analyze/run` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7b0bc4b318458b1a", "name": "Unused endpoint: GET /knowledge", "shortDescription": {"text": "Unused endpoint: GET /knowledge"}, "fullDescription": {"text": "`web/routes.py` declares `GET /knowledge` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-00eafab1477d4a23", "name": "Unused endpoint: GET /knowledge/{kb_path}/faultref", "shortDescription": {"text": "Unused endpoint: GET /knowledge/{kb_path}/faultref"}, "fullDescription": {"text": "`web/routes.py` declares `GET /knowledge/{kb_path}/faultref` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ff5c2ae46c0d0a70", "name": "Unused endpoint: GET /knowledge/{kb_path}/files", "shortDescription": {"text": "Unused endpoint: GET /knowledge/{kb_path}/files"}, "fullDescription": {"text": "`web/routes.py` declares `GET /knowledge/{kb_path}/files` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aad649e9d3b630c1", "name": "Unused endpoint: GET /knowledge/{kb_path}/download/{filename}", "shortDescription": {"text": "Unused endpoint: GET /knowledge/{kb_path}/download/{filename}"}, "fullDescription": {"text": "`web/routes.py` declares `GET /knowledge/{kb_path}/download/{filename}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3fdc0db1a495b9d6", "name": "Unused endpoint: POST /knowledge/{kb_path}/upload", "shortDescription": {"text": "Unused endpoint: POST /knowledge/{kb_path}/upload"}, "fullDescription": {"text": "`web/routes.py` declares `POST /knowledge/{kb_path}/upload` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-88ec566e8ca91ec9", "name": "Unused endpoint: POST /knowledge/{kb_path}/delete", "shortDescription": {"text": "Unused endpoint: POST /knowledge/{kb_path}/delete"}, "fullDescription": {"text": "`web/routes.py` declares `POST /knowledge/{kb_path}/delete` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-512ccb0fd0b230ba", "name": "Unused endpoint: GET /settings", "shortDescription": {"text": "Unused endpoint: GET /settings"}, "fullDescription": {"text": "`web/routes.py` declares `GET /settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1c5209b538e3e62b", "name": "Unused endpoint: POST /settings/status-line-interval", "shortDescription": {"text": "Unused endpoint: POST /settings/status-line-interval"}, "fullDescription": {"text": "`web/routes.py` declares `POST /settings/status-line-interval` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-787159ba08e85991", "name": "Unused endpoint: POST /settings/llm", "shortDescription": {"text": "Unused endpoint: POST /settings/llm"}, "fullDescription": {"text": "`web/routes.py` declares `POST /settings/llm` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-98dbe522d34f5b07", "name": "Unused endpoint: POST /settings/ai-routing", "shortDescription": {"text": "Unused endpoint: POST /settings/ai-routing"}, "fullDescription": {"text": "`web/routes.py` declares `POST /settings/ai-routing` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0bd23b36a6242a22", "name": "Unused endpoint: GET /ai-playground", "shortDescription": {"text": "Unused endpoint: GET /ai-playground"}, "fullDescription": {"text": "`web/routes.py` declares `GET /ai-playground` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-db6e99b1852428b6", "name": "Unused endpoint: POST /ai-playground/run", "shortDescription": {"text": "Unused endpoint: POST /ai-playground/run"}, "fullDescription": {"text": "`web/routes.py` declares `POST /ai-playground/run` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-45b02239d0d081f5", "name": "Unused endpoint: POST /settings/claude", "shortDescription": {"text": "Unused endpoint: POST /settings/claude"}, "fullDescription": {"text": "`web/routes.py` declares `POST /settings/claude` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e315070a533ffc9c", "name": "Unused endpoint: POST /settings/qwen-toggle", "shortDescription": {"text": "Unused endpoint: POST /settings/qwen-toggle"}, "fullDescription": {"text": "`web/routes.py` declares `POST /settings/qwen-toggle` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2fa2d803e9f08d6e", "name": "Unused endpoint: POST /settings/analytics-verify-toggle", "shortDescription": {"text": "Unused endpoint: POST /settings/analytics-verify-toggle"}, "fullDescription": {"text": "`web/routes.py` declares `POST /settings/analytics-verify-toggle` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3284027823d801e9", "name": "Unused endpoint: POST /settings/corpus-toggle", "shortDescription": {"text": "Unused endpoint: POST /settings/corpus-toggle"}, "fullDescription": {"text": "`web/routes.py` declares `POST /settings/corpus-toggle` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-30bd1297f35af88a", "name": "Unused endpoint: POST /settings/timezone", "shortDescription": {"text": "Unused endpoint: POST /settings/timezone"}, "fullDescription": {"text": "`web/routes.py` declares `POST /settings/timezone` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72d9bee2d678e3da", "name": "Unused endpoint: POST /settings/equipment/update", "shortDescription": {"text": "Unused endpoint: POST /settings/equipment/update"}, "fullDescription": {"text": "`web/routes.py` declares `POST /settings/equipment/update` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-750b4352825b3f3f", "name": "Unused endpoint: POST /settings/equipment/toggle", "shortDescription": {"text": "Unused endpoint: POST /settings/equipment/toggle"}, "fullDescription": {"text": "`web/routes.py` declares `POST /settings/equipment/toggle` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4e09939cff01b035", "name": "Unused endpoint: POST /settings/equipment/delete", "shortDescription": {"text": "Unused endpoint: POST /settings/equipment/delete"}, "fullDescription": {"text": "`web/routes.py` declares `POST /settings/equipment/delete` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2fef12e8778b7783", "name": "Unused endpoint: POST /settings/equipment/clear", "shortDescription": {"text": "Unused endpoint: POST /settings/equipment/clear"}, "fullDescription": {"text": "`web/routes.py` declares `POST /settings/equipment/clear` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-29a7959d28cfec94", "name": "Unused endpoint: POST /settings/sync", "shortDescription": {"text": "Unused endpoint: POST /settings/sync"}, "fullDescription": {"text": "`web/routes.py` declares `POST /settings/sync` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0d98e7f1a518a605", "name": "Unused endpoint: GET /knowledge/{kb_path}/analytics-config", "shortDescription": {"text": "Unused endpoint: GET /knowledge/{kb_path}/analytics-config"}, "fullDescription": {"text": "`web/routes.py` declares `GET /knowledge/{kb_path}/analytics-config` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-69332d44b743a536", "name": "Unused endpoint: GET /knowledge/{kb_path}/analytics-config/download/{filename}", "shortDescription": {"text": "Unused endpoint: GET /knowledge/{kb_path}/analytics-config/download/{filename}"}, "fullDescription": {"text": "`web/routes.py` declares `GET /knowledge/{kb_path}/analytics-config/download/{filename}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e72fcb639f47f563", "name": "Unused endpoint: POST /knowledge/{kb_path}/analytics-config/upload", "shortDescription": {"text": "Unused endpoint: POST /knowledge/{kb_path}/analytics-config/upload"}, "fullDescription": {"text": "`web/routes.py` declares `POST /knowledge/{kb_path}/analytics-config/upload` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-362cb56ed5320503", "name": "Unused endpoint: GET /online", "shortDescription": {"text": "Unused endpoint: GET /online"}, "fullDescription": {"text": "`web/routes.py` declares `GET /online` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a2e49214dc45c271", "name": "Unused endpoint: POST /online/start", "shortDescription": {"text": "Unused endpoint: POST /online/start"}, "fullDescription": {"text": "`web/routes.py` declares `POST /online/start` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b191e03396d51e78", "name": "Unused endpoint: POST /online/stop", "shortDescription": {"text": "Unused endpoint: POST /online/stop"}, "fullDescription": {"text": "`web/routes.py` declares `POST /online/stop` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e43f590e13f40c2d", "name": "Unused endpoint: POST /online/corpus-toggle", "shortDescription": {"text": "Unused endpoint: POST /online/corpus-toggle"}, "fullDescription": {"text": "`web/routes.py` declares `POST /online/corpus-toggle` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-787af5144df07efc", "name": "Unused endpoint: POST /online/qwen-toggle", "shortDescription": {"text": "Unused endpoint: POST /online/qwen-toggle"}, "fullDescription": {"text": "`web/routes.py` declares `POST /online/qwen-toggle` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ec4a7eaedaae00ea", "name": "Unused endpoint: POST /online/clear-claude-analysis", "shortDescription": {"text": "Unused endpoint: POST /online/clear-claude-analysis"}, "fullDescription": {"text": "`web/routes.py` declares `POST /online/clear-claude-analysis` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8558542a8069244c", "name": "Unused endpoint: POST /online/clear-qwen-analysis", "shortDescription": {"text": "Unused endpoint: POST /online/clear-qwen-analysis"}, "fullDescription": {"text": "`web/routes.py` declares `POST /online/clear-qwen-analysis` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-064f0f695c5918de", "name": "Unused endpoint: POST /online/start-multi", "shortDescription": {"text": "Unused endpoint: POST /online/start-multi"}, "fullDescription": {"text": "`web/routes.py` declares `POST /online/start-multi` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-201ba901e1ed5458", "name": "Unused endpoint: GET /api/pipeline/status", "shortDescription": {"text": "Unused endpoint: GET /api/pipeline/status"}, "fullDescription": {"text": "`web/routes.py` declares `GET /api/pipeline/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c2a919548018392", "name": "Unused endpoint: GET /online/calendar/{router_sn}/{equip_type}/{panel_id}", "shortDescription": {"text": "Unused endpoint: GET /online/calendar/{router_sn}/{equip_type}/{panel_id}"}, "fullDescription": {"text": "`web/routes.py` declares `GET /online/calendar/{router_sn}/{equip_type}/{panel_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/23589"}, "properties": {"repository": "zergont/cg-analytics", "repoUrl": "https://github.com/zergont/cg-analytics", "branch": "main"}, "results": [{"ruleId": "scanner-8725d1d55f6f8ac4", "level": "note", "message": {"text": "Possibly dead Python function: set_tz"}, "properties": {"repobilityId": "adfac1d5c3ea43c4", "scanner": "scanner-primary", "fingerprint": "8725d1d55f6f8ac4", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "config.py:90"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cebb5e718bf8a15e", "level": "note", "message": {"text": "Possibly dead Python function: code_severity"}, "properties": {"repobilityId": "5c4ee27cf700672f", "scanner": "scanner-primary", "fingerprint": "cebb5e718bf8a15e", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "analytics/config.py:123"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-259f79d16dabeabe", "level": "note", "message": {"text": "Possibly dead Python function: reset_accumulators_on_purge"}, "properties": {"repobilityId": "2d5195fb28581ef1", "scanner": "scanner-primary", "fingerprint": "259f79d16dabeabe", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "analytics/accumulators.py:52"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-51b3a7f9210fbfb4", "level": "note", "message": {"text": "Possibly dead Python function: hourly_bar_chart"}, "properties": {"repobilityId": "6b38571294987ddf", "scanner": "scanner-primary", "fingerprint": "51b3a7f9210fbfb4", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent/charts.py:97"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-47250a2ad5cc16d9", "level": "note", "message": {"text": "Possibly dead Python function: emit"}, "properties": {"repobilityId": "fecc700ec874b669", "scanner": "scanner-primary", "fingerprint": "47250a2ad5cc16d9", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/log_buffer.py:21"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7fcef8f22e306b10", "level": "note", "message": {"text": "Possibly dead Python function: init_online_schema"}, "properties": {"repobilityId": "38babf917a7dbc80", "scanner": "scanner-primary", "fingerprint": "7fcef8f22e306b10", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "online/db.py:29"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a84540458a604724", "level": "note", "message": {"text": "Possibly dead Python function: delete_observation"}, "properties": {"repobilityId": "c1aaa60f9062f035", "scanner": "scanner-primary", "fingerprint": "a84540458a604724", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "online/db.py:116"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-01eeab09caad505f", "level": "note", "message": {"text": "Possibly dead Python function: update_continues_to"}, "properties": {"repobilityId": "12c44b943158cd44", "scanner": "scanner-primary", "fingerprint": "01eeab09caad505f", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "online/db.py:339"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-50e5653a666fff31", "level": "note", "message": {"text": "Possibly dead Python function: has_segments"}, "properties": {"repobilityId": "442d0cf3c40d1e3b", "scanner": "scanner-primary", "fingerprint": "50e5653a666fff31", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "online/db.py:661"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-402ee1f147cb6d2a", "level": "note", "message": {"text": "Possibly dead Python function: fire_verify"}, "properties": {"repobilityId": "66c1ea92592b67a2", "scanner": "scanner-primary", "fingerprint": "402ee1f147cb6d2a", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "online/verifier.py:152"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f4c39f3f1ef35723", "level": "note", "message": {"text": "Possibly dead Python function: compute_register_stats"}, "properties": {"repobilityId": "aec40fac8da365d3", "scanner": "scanner-primary", "fingerprint": "f4c39f3f1ef35723", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pipeline/aggregator.py:168"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-99ebc11ee8e21828", "level": "note", "message": {"text": "Possibly dead Python function: run_pipeline"}, "properties": {"repobilityId": "0c60b7ad1c7923ce", "scanner": "scanner-primary", "fingerprint": "99ebc11ee8e21828", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pipeline/runner.py:64"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b0db6b051f775b58", "level": "note", "message": {"text": "Possibly dead Python function: clear_index_cache"}, "properties": {"repobilityId": "ee8e981d88f8d8a4", "scanner": "scanner-primary", "fingerprint": "b0db6b051f775b58", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "knowledge/retriever.py:23"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e6c78da03aa7fe05", "level": "note", "message": {"text": "Possibly dead Python function: invalidate_cache"}, "properties": {"repobilityId": "a0615864915b00fa", "scanner": "scanner-primary", "fingerprint": "e6c78da03aa7fe05", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "knowledge/retriever.py:116"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3770a455f514cad6", "level": "note", "message": {"text": "Possibly dead Python function: search_manual_docs"}, "properties": {"repobilityId": "28a61de6c20d2032", "scanner": "scanner-primary", "fingerprint": "3770a455f514cad6", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "knowledge/retriever.py:124"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-35d42bfb0979e9e3", "level": "note", "message": {"text": "Possibly dead Python function: invalidate_cache"}, "properties": {"repobilityId": "a0615864915b00fa", "scanner": "scanner-primary", "fingerprint": "35d42bfb0979e9e3", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "knowledge/loader.py:71"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a0184608ee5db3e7", "level": "warning", "message": {"text": "Privileged port 10 in use"}, "properties": {"repobilityId": "735372d6b5594915", "scanner": "scanner-primary", "fingerprint": "a0184608ee5db3e7", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "config.example.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d51c640c2d324dd0", "level": "warning", "message": {"text": "Privileged port 218 in use"}, "properties": {"repobilityId": "92f8a694bba7e896", "scanner": "scanner-primary", "fingerprint": "d51c640c2d324dd0", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "config.example.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3c7f00806b026261", "level": "warning", "message": {"text": "Privileged port 21 in use"}, "properties": {"repobilityId": "d920b7cd1b1a16dc", "scanner": "scanner-primary", "fingerprint": "3c7f00806b026261", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "config.example.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bd8ff00fed40e0f0", "level": "warning", "message": {"text": "Privileged port 5 in use"}, "properties": {"repobilityId": "a8f80b4866464301", "scanner": "scanner-primary", "fingerprint": "bd8ff00fed40e0f0", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "config.example.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0ddd79a67e0a8ebd", "level": "warning", "message": {"text": "Privileged port 272 in use"}, "properties": {"repobilityId": "24e0b4ce85cdd134", "scanner": "scanner-primary", "fingerprint": "0ddd79a67e0a8ebd", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "knowledge_base/equipment/cummins_kta50_pcc3300/analytics/thresholds.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7487cb1a7ffa6111", "level": "warning", "message": {"text": "Privileged port 24 in use"}, "properties": {"repobilityId": "a6356ba91a17fcb8", "scanner": "scanner-primary", "fingerprint": "7487cb1a7ffa6111", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "knowledge_base/equipment/cummins_kta50_pcc3300/analytics/thresholds.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-7e9b16ab072e766e", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in web/static/bootstrap.bundle.min.js:6"}, "properties": {"repobilityId": "eb41a82545d17bed", "scanner": "scanner-primary", "fingerprint": "7e9b16ab072e766e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/static/bootstrap.bundle.min.js"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-f0811f1e25aa2ffb", "level": "warning", "message": {"text": "Insecure pattern 'domparser_html_parse' in web/static/bootstrap.bundle.min.js:6"}, "properties": {"repobilityId": "2180b98718540e19", "scanner": "scanner-primary", "fingerprint": "f0811f1e25aa2ffb", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "domparser_html_parse"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/static/bootstrap.bundle.min.js"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-ae67748e3d09f8ea", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in knowledge_base/equipment/cummins_kta50_pcc3300/pcc3300_fault_codes_v2_3.html:1940"}, "properties": {"repobilityId": "37242b71c8f586d4", "scanner": "scanner-primary", "fingerprint": "ae67748e3d09f8ea", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "knowledge_base/equipment/cummins_kta50_pcc3300/pcc3300_fault_codes_v2_3.html"}, "region": {"startLine": 1940}}}]}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-38de955f1b2d3d3d", "level": "note", "message": {"text": "Very large file: web/routes.py (2524 lines)"}, "properties": {"repobilityId": "cd091a014db6d409", "scanner": "scanner-primary", "fingerprint": "38de955f1b2d3d3d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ea3b5e389d8c9c0f", "level": "note", "message": {"text": "Low test-to-source ratio"}, "properties": {"repobilityId": "ef7b2552cc00a375", "scanner": "scanner-primary", "fingerprint": "ea3b5e389d8c9c0f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["tests"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "42da0f40eba1420f", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "8cf61a30a2a779b0", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "05ff83de6088a6c8", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8659a04d4f16bdee", "level": "none", "message": {"text": "Commented-code block (5 lines) in analytics/metrics.py:416"}, "properties": {"repobilityId": "fa2b5d671af2427e", "scanner": "scanner-primary", "fingerprint": "8659a04d4f16bdee", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "a791704664abdd6a", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-76a2f6818267a9a8", "level": "note", "message": {"text": "Near-duplicate function bodies in 8 places"}, "properties": {"repobilityId": "2be2989183101dac", "scanner": "scanner-primary", "fingerprint": "76a2f6818267a9a8", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-46969939caf8120b", "level": "note", "message": {"text": "Near-duplicate function bodies in 9 places"}, "properties": {"repobilityId": "9d27dde76c45b0de", "scanner": "scanner-primary", "fingerprint": "46969939caf8120b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "606d9c18edc0d62c", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "0bd73cef2b99f3ab", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "f5ee2d0a614805f5", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "3c443dcafa547a96", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "fe73c9d81459a343", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "7849d64e989e4b5c", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "054992811ba8a2d5", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-bd3b6cae37a0d9fe", "level": "error", "message": {"text": "FastAPI POST `analyze_run` without auth dependency \u2014 web/routes.py:103"}, "properties": {"repobilityId": "409e21807d0e6cbf", "scanner": "scanner-primary", "fingerprint": "bd3b6cae37a0d9fe", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 103}}}]}, {"ruleId": "scanner-20f89e4b48f512ec", "level": "error", "message": {"text": "FastAPI POST `analyze_stream` without auth dependency \u2014 web/routes.py:137"}, "properties": {"repobilityId": "0df091882fea2a9e", "scanner": "scanner-primary", "fingerprint": "20f89e4b48f512ec", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 137}}}]}, {"ruleId": "scanner-c513975c94ce53e9", "level": "error", "message": {"text": "FastAPI POST `delete_analysis_run` without auth dependency \u2014 web/routes.py:340"}, "properties": {"repobilityId": "e4c62077e41b52be", "scanner": "scanner-primary", "fingerprint": "c513975c94ce53e9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 340}}}]}, {"ruleId": "scanner-c0081b7098f94df5", "level": "error", "message": {"text": "FastAPI POST `api_log_clear` without auth dependency \u2014 web/routes.py:371"}, "properties": {"repobilityId": "08d8ec0c269f983a", "scanner": "scanner-primary", "fingerprint": "c0081b7098f94df5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 371}}}]}, {"ruleId": "scanner-59596b05fdeb44b1", "level": "error", "message": {"text": "FastAPI POST `analyze_run_agent` without auth dependency \u2014 web/routes.py:562"}, "properties": {"repobilityId": "83bf7a69864e3987", "scanner": "scanner-primary", "fingerprint": "59596b05fdeb44b1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 562}}}]}, {"ruleId": "scanner-5247521395fc6ea6", "level": "error", "message": {"text": "FastAPI POST `kb_upload` without auth dependency \u2014 web/routes.py:860"}, "properties": {"repobilityId": "e417e830e5f6c13d", "scanner": "scanner-primary", "fingerprint": "5247521395fc6ea6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 860}}}]}, {"ruleId": "scanner-948c82ad1fb19bb1", "level": "error", "message": {"text": "FastAPI POST `kb_delete_file` without auth dependency \u2014 web/routes.py:896"}, "properties": {"repobilityId": "f6e758197bde650b", "scanner": "scanner-primary", "fingerprint": "948c82ad1fb19bb1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 896}}}]}, {"ruleId": "scanner-5c563f68c85e4dc1", "level": "error", "message": {"text": "FastAPI POST `update_status_line_interval` without auth dependency \u2014 web/routes.py:948"}, "properties": {"repobilityId": "0b415a283b39ec9d", "scanner": "scanner-primary", "fingerprint": "5c563f68c85e4dc1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 948}}}]}, {"ruleId": "scanner-360b849680788901", "level": "error", "message": {"text": "FastAPI POST `update_llm_settings` without auth dependency \u2014 web/routes.py:957"}, "properties": {"repobilityId": "99fe49599617b696", "scanner": "scanner-primary", "fingerprint": "360b849680788901", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 957}}}]}, {"ruleId": "scanner-e3114a7faad28d7a", "level": "error", "message": {"text": "FastAPI POST `update_ai_routing` without auth dependency \u2014 web/routes.py:979"}, "properties": {"repobilityId": "31906a9f6bce3b50", "scanner": "scanner-primary", "fingerprint": "e3114a7faad28d7a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 979}}}]}, {"ruleId": "scanner-52ae73a034e8425c", "level": "error", "message": {"text": "FastAPI POST `ai_playground_run` without auth dependency \u2014 web/routes.py:1005"}, "properties": {"repobilityId": "3b2d55bd8c570900", "scanner": "scanner-primary", "fingerprint": "52ae73a034e8425c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 1005}}}]}, {"ruleId": "scanner-b1f9a15dfa8aef24", "level": "error", "message": {"text": "FastAPI POST `update_claude_settings` without auth dependency \u2014 web/routes.py:1111"}, "properties": {"repobilityId": "fa637276f192e2bb", "scanner": "scanner-primary", "fingerprint": "b1f9a15dfa8aef24", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 1111}}}]}, {"ruleId": "scanner-80d270e8116f2b82", "level": "error", "message": {"text": "FastAPI POST `qwen_toggle` without auth dependency \u2014 web/routes.py:1129"}, "properties": {"repobilityId": "c981c1d6fb68cc29", "scanner": "scanner-primary", "fingerprint": "80d270e8116f2b82", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 1129}}}]}, {"ruleId": "scanner-a547cf6f72f7a9fd", "level": "error", "message": {"text": "FastAPI POST `analytics_verify_toggle` without auth dependency \u2014 web/routes.py:1146"}, "properties": {"repobilityId": "5b00ed1240fdc193", "scanner": "scanner-primary", "fingerprint": "a547cf6f72f7a9fd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 1146}}}]}, {"ruleId": "scanner-3833afd271acb1b7", "level": "error", "message": {"text": "FastAPI POST `corpus_toggle` without auth dependency \u2014 web/routes.py:1158"}, "properties": {"repobilityId": "5037d73901851902", "scanner": "scanner-primary", "fingerprint": "3833afd271acb1b7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 1158}}}]}, {"ruleId": "scanner-d72ea62d6a4af8de", "level": "error", "message": {"text": "FastAPI POST `update_timezone` without auth dependency \u2014 web/routes.py:1174"}, "properties": {"repobilityId": "33f8f80934242bbc", "scanner": "scanner-primary", "fingerprint": "d72ea62d6a4af8de", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 1174}}}]}, {"ruleId": "scanner-65318120436bfe63", "level": "error", "message": {"text": "FastAPI POST `update_equipment` without auth dependency \u2014 web/routes.py:1187"}, "properties": {"repobilityId": "b985cf650c15b28b", "scanner": "scanner-primary", "fingerprint": "65318120436bfe63", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 1187}}}]}, {"ruleId": "scanner-5f9aac82ec11178d", "level": "error", "message": {"text": "FastAPI POST `toggle_equipment` without auth dependency \u2014 web/routes.py:1212"}, "properties": {"repobilityId": "c280767247871347", "scanner": "scanner-primary", "fingerprint": "5f9aac82ec11178d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 1212}}}]}, {"ruleId": "scanner-de10216ea2424641", "level": "error", "message": {"text": "FastAPI POST `delete_equipment` without auth dependency \u2014 web/routes.py:1223"}, "properties": {"repobilityId": "401994a40f5261ae", "scanner": "scanner-primary", "fingerprint": "de10216ea2424641", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 1223}}}]}, {"ruleId": "scanner-6727d0f615aaf1d1", "level": "error", "message": {"text": "FastAPI POST `clear_equipment` without auth dependency \u2014 web/routes.py:1233"}, "properties": {"repobilityId": "4230d2c726881a4a", "scanner": "scanner-primary", "fingerprint": "6727d0f615aaf1d1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 1233}}}]}, {"ruleId": "scanner-37c59ba7cf8adc53", "level": "error", "message": {"text": "FastAPI POST `sync_equipment` without auth dependency \u2014 web/routes.py:1239"}, "properties": {"repobilityId": "fddeb5c6df2bbabe", "scanner": "scanner-primary", "fingerprint": "37c59ba7cf8adc53", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 1239}}}]}, {"ruleId": "scanner-a53c4b727a67357a", "level": "error", "message": {"text": "FastAPI POST `analytics_config_upload` without auth dependency \u2014 web/routes.py:1297"}, "properties": {"repobilityId": "7f66d9445cc9c6f1", "scanner": "scanner-primary", "fingerprint": "a53c4b727a67357a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 1297}}}]}, {"ruleId": "scanner-9be59d7e827ef2a5", "level": "error", "message": {"text": "FastAPI POST `online_start` without auth dependency \u2014 web/routes.py:1366"}, "properties": {"repobilityId": "2a6d932b793aaa5b", "scanner": "scanner-primary", "fingerprint": "9be59d7e827ef2a5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 1366}}}]}, {"ruleId": "scanner-2df7550e9d3fbba2", "level": "error", "message": {"text": "FastAPI POST `online_stop` without auth dependency \u2014 web/routes.py:1396"}, "properties": {"repobilityId": "be232dbe1364b35a", "scanner": "scanner-primary", "fingerprint": "2df7550e9d3fbba2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 1396}}}]}, {"ruleId": "scanner-c49d95dc29b90adc", "level": "error", "message": {"text": "FastAPI POST `online_corpus_toggle` without auth dependency \u2014 web/routes.py:1412"}, "properties": {"repobilityId": "6505b4b8379e6a1e", "scanner": "scanner-primary", "fingerprint": "c49d95dc29b90adc", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 1412}}}]}, {"ruleId": "scanner-11fbaafbee7663ea", "level": "error", "message": {"text": "FastAPI POST `online_qwen_toggle` without auth dependency \u2014 web/routes.py:1428"}, "properties": {"repobilityId": "73c43d907c9dc520", "scanner": "scanner-primary", "fingerprint": "11fbaafbee7663ea", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 1428}}}]}, {"ruleId": "scanner-abd9983057c53c54", "level": "error", "message": {"text": "FastAPI POST `online_clear_claude_analysis` without auth dependency \u2014 web/routes.py:1444"}, "properties": {"repobilityId": "51bdd0e8d951acc5", "scanner": "scanner-primary", "fingerprint": "abd9983057c53c54", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 1444}}}]}, {"ruleId": "scanner-57e2baa66ca4bf70", "level": "error", "message": {"text": "FastAPI POST `online_clear_qwen_analysis` without auth dependency \u2014 web/routes.py:1453"}, "properties": {"repobilityId": "503fcf285232161c", "scanner": "scanner-primary", "fingerprint": "57e2baa66ca4bf70", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 1453}}}]}, {"ruleId": "scanner-2e75aa388efdd58f", "level": "error", "message": {"text": "FastAPI POST `online_start_multi` without auth dependency \u2014 web/routes.py:1462"}, "properties": {"repobilityId": "384a603382b6bd94", "scanner": "scanner-primary", "fingerprint": "2e75aa388efdd58f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 1462}}}]}, {"ruleId": "scanner-ab58b38ef5b17d4e", "level": "error", "message": {"text": "FastAPI POST `online_segment_analyze` without auth dependency \u2014 web/routes.py:1850"}, "properties": {"repobilityId": "37ab2e1e0dab7da2", "scanner": "scanner-primary", "fingerprint": "ab58b38ef5b17d4e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 1850}}}]}, {"ruleId": "scanner-92061a3039c2f70a", "level": "error", "message": {"text": "FastAPI POST `online_delete_segments` without auth dependency \u2014 web/routes.py:1891"}, "properties": {"repobilityId": "f875423922e38cbd", "scanner": "scanner-primary", "fingerprint": "92061a3039c2f70a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 1891}}}]}, {"ruleId": "scanner-cb676158d8b2e245", "level": "error", "message": {"text": "FastAPI POST `online_clear` without auth dependency \u2014 web/routes.py:1922"}, "properties": {"repobilityId": "43d1051f55930755", "scanner": "scanner-primary", "fingerprint": "cb676158d8b2e245", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 1922}}}]}, {"ruleId": "scanner-f6da7f101c8ed7ff", "level": "error", "message": {"text": "FastAPI POST `set_source_mode_route` without auth dependency \u2014 web/routes.py:2502"}, "properties": {"repobilityId": "2a66a46677c3cd50", "scanner": "scanner-primary", "fingerprint": "f6da7f101c8ed7ff", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 2502}}}]}, {"ruleId": "scanner-75bbcaee0417aaca", "level": "error", "message": {"text": "FastAPI POST `set_history_sync_interval` without auth dependency \u2014 web/routes.py:2514"}, "properties": {"repobilityId": "451ac9ec4d157815", "scanner": "scanner-primary", "fingerprint": "75bbcaee0417aaca", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/routes.py"}, "region": {"startLine": 2514}}}]}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "1e10c7aa4a28f26b", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6d93f6ad14064cf9", "level": "note", "message": {"text": "Unused endpoint: GET /report/{report_id}"}, "properties": {"repobilityId": "30658a647cb8229a", "scanner": "scanner-primary", "fingerprint": "6d93f6ad14064cf9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bc558e1bd171e40f", "level": "note", "message": {"text": "Unused endpoint: GET /history/{router_sn}/{equip_type}/{panel_id}"}, "properties": {"repobilityId": "03c9564a549836b3", "scanner": "scanner-primary", "fingerprint": "bc558e1bd171e40f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-72a90c9eabe0d9b3", "level": "note", "message": {"text": "Unused endpoint: GET /analyze"}, "properties": {"repobilityId": "7fef57c51a2d07ac", "scanner": "scanner-primary", "fingerprint": "72a90c9eabe0d9b3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fca11d494725d7c3", "level": "note", "message": {"text": "Unused endpoint: POST /analyze"}, "properties": {"repobilityId": "addc3a3c15d3ff12", "scanner": "scanner-primary", "fingerprint": "fca11d494725d7c3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1647a6533f8d9bb3", "level": "note", "message": {"text": "Unused endpoint: POST /analyze/stream"}, "properties": {"repobilityId": "8cd811c92305165e", "scanner": "scanner-primary", "fingerprint": "1647a6533f8d9bb3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-aa44293c97ffa043", "level": "note", "message": {"text": "Unused endpoint: GET /analysis/{run_id}"}, "properties": {"repobilityId": "802d2ce68b14ec8e", "scanner": "scanner-primary", "fingerprint": "aa44293c97ffa043", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a434c80787f7a73f", "level": "note", "message": {"text": "Unused endpoint: GET /analysis/{run_id}/md"}, "properties": {"repobilityId": "2c4af64a3ff2115a", "scanner": "scanner-primary", "fingerprint": "a434c80787f7a73f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-afc064028ae39ea9", "level": "note", "message": {"text": "Unused endpoint: GET /history"}, "properties": {"repobilityId": "57fb1892387074a9", "scanner": "scanner-primary", "fingerprint": "afc064028ae39ea9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c4fcc547455ef811", "level": "note", "message": {"text": "Unused endpoint: POST /history/delete/{run_id}"}, "properties": {"repobilityId": "2fdb436a266febd6", "scanner": "scanner-primary", "fingerprint": "c4fcc547455ef811", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fe9a2fccde85686a", "level": "note", "message": {"text": "Unused endpoint: GET /history-v2/{router_sn}/{equip_type}/{panel_id}"}, "properties": {"repobilityId": "44f502341d5b7d21", "scanner": "scanner-primary", "fingerprint": "fe9a2fccde85686a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-81327b7bef38b5d6", "level": "note", "message": {"text": "Unused endpoint: GET /log"}, "properties": {"repobilityId": "1625c60ff8c901cc", "scanner": "scanner-primary", "fingerprint": "81327b7bef38b5d6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1ee169aa5640a319", "level": "note", "message": {"text": "Unused endpoint: GET /api/log"}, "properties": {"repobilityId": "fb11cd60849823f4", "scanner": "scanner-primary", "fingerprint": "1ee169aa5640a319", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c73c4f1e41dbe1e9", "level": "note", "message": {"text": "Unused endpoint: POST /api/log/clear"}, "properties": {"repobilityId": "ed23014f6dce3378", "scanner": "scanner-primary", "fingerprint": "c73c4f1e41dbe1e9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-da35e12d9e5cbff9", "level": "note", "message": {"text": "Unused endpoint: POST /analyze/run"}, "properties": {"repobilityId": "62c34fd65c424acf", "scanner": "scanner-primary", "fingerprint": "da35e12d9e5cbff9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7b0bc4b318458b1a", "level": "note", "message": {"text": "Unused endpoint: GET /knowledge"}, "properties": {"repobilityId": "c8192a37d91eb0cd", "scanner": "scanner-primary", "fingerprint": "7b0bc4b318458b1a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-00eafab1477d4a23", "level": "note", "message": {"text": "Unused endpoint: GET /knowledge/{kb_path}/faultref"}, "properties": {"repobilityId": "807d222dda137111", "scanner": "scanner-primary", "fingerprint": "00eafab1477d4a23", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ff5c2ae46c0d0a70", "level": "note", "message": {"text": "Unused endpoint: GET /knowledge/{kb_path}/files"}, "properties": {"repobilityId": "40a1b5b454cfcd2d", "scanner": "scanner-primary", "fingerprint": "ff5c2ae46c0d0a70", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-aad649e9d3b630c1", "level": "note", "message": {"text": "Unused endpoint: GET /knowledge/{kb_path}/download/{filename}"}, "properties": {"repobilityId": "5bf70e1844076a35", "scanner": "scanner-primary", "fingerprint": "aad649e9d3b630c1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3fdc0db1a495b9d6", "level": "note", "message": {"text": "Unused endpoint: POST /knowledge/{kb_path}/upload"}, "properties": {"repobilityId": "cc4c8e0ea6dd30d4", "scanner": "scanner-primary", "fingerprint": "3fdc0db1a495b9d6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-88ec566e8ca91ec9", "level": "note", "message": {"text": "Unused endpoint: POST /knowledge/{kb_path}/delete"}, "properties": {"repobilityId": "90f9d197235bd6d4", "scanner": "scanner-primary", "fingerprint": "88ec566e8ca91ec9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-512ccb0fd0b230ba", "level": "note", "message": {"text": "Unused endpoint: GET /settings"}, "properties": {"repobilityId": "9089552c512716b0", "scanner": "scanner-primary", "fingerprint": "512ccb0fd0b230ba", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1c5209b538e3e62b", "level": "note", "message": {"text": "Unused endpoint: POST /settings/status-line-interval"}, "properties": {"repobilityId": "8da666e5ddb09196", "scanner": "scanner-primary", "fingerprint": "1c5209b538e3e62b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-787159ba08e85991", "level": "note", "message": {"text": "Unused endpoint: POST /settings/llm"}, "properties": {"repobilityId": "3528568bf614cb65", "scanner": "scanner-primary", "fingerprint": "787159ba08e85991", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-98dbe522d34f5b07", "level": "note", "message": {"text": "Unused endpoint: POST /settings/ai-routing"}, "properties": {"repobilityId": "10d4658eba7502ae", "scanner": "scanner-primary", "fingerprint": "98dbe522d34f5b07", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0bd23b36a6242a22", "level": "note", "message": {"text": "Unused endpoint: GET /ai-playground"}, "properties": {"repobilityId": "a70aa86cfad519a5", "scanner": "scanner-primary", "fingerprint": "0bd23b36a6242a22", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-db6e99b1852428b6", "level": "note", "message": {"text": "Unused endpoint: POST /ai-playground/run"}, "properties": {"repobilityId": "50155b82d3292faa", "scanner": "scanner-primary", "fingerprint": "db6e99b1852428b6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-45b02239d0d081f5", "level": "note", "message": {"text": "Unused endpoint: POST /settings/claude"}, "properties": {"repobilityId": "73f7f2871127be83", "scanner": "scanner-primary", "fingerprint": "45b02239d0d081f5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e315070a533ffc9c", "level": "note", "message": {"text": "Unused endpoint: POST /settings/qwen-toggle"}, "properties": {"repobilityId": "81886b959f289b9f", "scanner": "scanner-primary", "fingerprint": "e315070a533ffc9c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2fa2d803e9f08d6e", "level": "note", "message": {"text": "Unused endpoint: POST /settings/analytics-verify-toggle"}, "properties": {"repobilityId": "1d52656b23682e78", "scanner": "scanner-primary", "fingerprint": "2fa2d803e9f08d6e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3284027823d801e9", "level": "note", "message": {"text": "Unused endpoint: POST /settings/corpus-toggle"}, "properties": {"repobilityId": "3a8b89f9f8777904", "scanner": "scanner-primary", "fingerprint": "3284027823d801e9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-30bd1297f35af88a", "level": "note", "message": {"text": "Unused endpoint: POST /settings/timezone"}, "properties": {"repobilityId": "a933c1ad0d0c1112", "scanner": "scanner-primary", "fingerprint": "30bd1297f35af88a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-72d9bee2d678e3da", "level": "note", "message": {"text": "Unused endpoint: POST /settings/equipment/update"}, "properties": {"repobilityId": "217183267147329f", "scanner": "scanner-primary", "fingerprint": "72d9bee2d678e3da", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-750b4352825b3f3f", "level": "note", "message": {"text": "Unused endpoint: POST /settings/equipment/toggle"}, "properties": {"repobilityId": "3406ead692aa8f14", "scanner": "scanner-primary", "fingerprint": "750b4352825b3f3f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4e09939cff01b035", "level": "note", "message": {"text": "Unused endpoint: POST /settings/equipment/delete"}, "properties": {"repobilityId": "8010b25131b4b8fb", "scanner": "scanner-primary", "fingerprint": "4e09939cff01b035", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2fef12e8778b7783", "level": "note", "message": {"text": "Unused endpoint: POST /settings/equipment/clear"}, "properties": {"repobilityId": "03ec7cff6617a234", "scanner": "scanner-primary", "fingerprint": "2fef12e8778b7783", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-29a7959d28cfec94", "level": "note", "message": {"text": "Unused endpoint: POST /settings/sync"}, "properties": {"repobilityId": "59dc61440af46c33", "scanner": "scanner-primary", "fingerprint": "29a7959d28cfec94", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0d98e7f1a518a605", "level": "note", "message": {"text": "Unused endpoint: GET /knowledge/{kb_path}/analytics-config"}, "properties": {"repobilityId": "b5840f1b423ac4f2", "scanner": "scanner-primary", "fingerprint": "0d98e7f1a518a605", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-69332d44b743a536", "level": "note", "message": {"text": "Unused endpoint: GET /knowledge/{kb_path}/analytics-config/download/{filename}"}, "properties": {"repobilityId": "be6000caa0f83891", "scanner": "scanner-primary", "fingerprint": "69332d44b743a536", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e72fcb639f47f563", "level": "note", "message": {"text": "Unused endpoint: POST /knowledge/{kb_path}/analytics-config/upload"}, "properties": {"repobilityId": "4cd68ea50ec81586", "scanner": "scanner-primary", "fingerprint": "e72fcb639f47f563", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-362cb56ed5320503", "level": "note", "message": {"text": "Unused endpoint: GET /online"}, "properties": {"repobilityId": "b8c0fdcf0c9a63f1", "scanner": "scanner-primary", "fingerprint": "362cb56ed5320503", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a2e49214dc45c271", "level": "note", "message": {"text": "Unused endpoint: POST /online/start"}, "properties": {"repobilityId": "2f06df954d823496", "scanner": "scanner-primary", "fingerprint": "a2e49214dc45c271", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b191e03396d51e78", "level": "note", "message": {"text": "Unused endpoint: POST /online/stop"}, "properties": {"repobilityId": "0e592cbb92992d02", "scanner": "scanner-primary", "fingerprint": "b191e03396d51e78", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e43f590e13f40c2d", "level": "note", "message": {"text": "Unused endpoint: POST /online/corpus-toggle"}, "properties": {"repobilityId": "2fd5dec3e4389799", "scanner": "scanner-primary", "fingerprint": "e43f590e13f40c2d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-787af5144df07efc", "level": "note", "message": {"text": "Unused endpoint: POST /online/qwen-toggle"}, "properties": {"repobilityId": "53683237c8885a29", "scanner": "scanner-primary", "fingerprint": "787af5144df07efc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ec4a7eaedaae00ea", "level": "note", "message": {"text": "Unused endpoint: POST /online/clear-claude-analysis"}, "properties": {"repobilityId": "4291da551d5c7b32", "scanner": "scanner-primary", "fingerprint": "ec4a7eaedaae00ea", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8558542a8069244c", "level": "note", "message": {"text": "Unused endpoint: POST /online/clear-qwen-analysis"}, "properties": {"repobilityId": "493c944c6f732356", "scanner": "scanner-primary", "fingerprint": "8558542a8069244c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-064f0f695c5918de", "level": "note", "message": {"text": "Unused endpoint: POST /online/start-multi"}, "properties": {"repobilityId": "87b4bcde6cd1bdc7", "scanner": "scanner-primary", "fingerprint": "064f0f695c5918de", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-201ba901e1ed5458", "level": "note", "message": {"text": "Unused endpoint: GET /api/pipeline/status"}, "properties": {"repobilityId": "b48862518624c615", "scanner": "scanner-primary", "fingerprint": "201ba901e1ed5458", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2c2a919548018392", "level": "note", "message": {"text": "Unused endpoint: GET /online/calendar/{router_sn}/{equip_type}/{panel_id}"}, "properties": {"repobilityId": "0d40c99a0102c13a", "scanner": "scanner-primary", "fingerprint": "2c2a919548018392", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}