{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "foundry_assumption_check", "name": "Foundry mined assumption checks: VicenteHenriquez/ttolive", "shortDescription": {"text": "Foundry mined assumption checks: VicenteHenriquez/ttolive"}, "fullDescription": {"text": "Comment chain pattern product: assumption_checks\nRepo: VicenteHenriquez/ttolive\nThread: VicenteHenriquez/ttolive#1\nOutcome: ambiguous_needs_more_evidence\nThread label: thread_has_human_issue_and_fix_context\nSource graph label: github_or_motif_graph_without_source_files\nReasons: link_quality_high_confidence, high_risk_human_feedback_label\nChain evidence:\nIssue/PR evidence chain: VicenteHenriquez/ttolive#1\nRepo: VicenteHenriquez/ttolive\nThread label: thread_has_human_issue_and_fix_context\nOutcome: ambiguous_needs_more_evidence\nComment count: 1\nLinked commit count: 2\nLinked CI commit count: 1\nLinked CI labels: {'ci_pending_or_incomplete': 1}\nChanged file count: 1\nLabels: {'test_ci_gap': 1}\nPolarities: {'bad': 1}\nChanged file labels: {'test_or_ci': 1}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-d920e028153ad5d0\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"test_ci_gap\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.com/VicenteHenriquez/ttolive/pull/1\",\n    \"text\": \"GitHub fee"}, "properties": {"scanner": "foundry_dataset", "category": "practices", "severity": "medium", "confidence": 0.62, "cwe": "", "owasp": ""}}, {"id": "foundry_test_ci_gap", "name": "Foundry mined test ci gap after feedback: VicenteHenriquez/ttolive", "shortDescription": {"text": "Foundry mined test ci gap after feedback: VicenteHenriquez/ttolive"}, "fullDescription": {"text": "Graph query export: Feedback exposes missing tests or CI\nQuery id: test_ci_gap_after_feedback\nQuery type: motif_query\nIntent: Hard negatives for feedback/fix chains without adequate guardrails.\nMotif: test_ci_gap_after_feedback\nTraining usage: hard_negative\nGraph gold label: supported_by_high_confidence_link\nRepo: VicenteHenriquez/ttolive\nThread: VicenteHenriquez/ttolive#1\nEvidence:\nGraph motif: Feedback or fix context exposes missing test/CI guardrails\nMotif id: test_ci_gap_after_feedback\nPolarity: bad\nTraining usage: hard_negative\nSeverity: high\nRepo: VicenteHenriquez/ttolive\nThread: VicenteHenriquez/ttolive#1\nGraph gold label: supported_by_high_confidence_link\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: VicenteHenriquez/ttolive#1\nRepo: VicenteHenriquez/ttolive\nIssue/PR number: 1\nGraph consistency label: supported_by_high_confidence_link\nNodes: 13\nEdges: 17\nNode types: {'link_quality': 3, 'commit': 2, 'thread': 1, 'repo': 1, 'comment': 1, 'pr_file': 1, 'comment_c"}, "properties": {"scanner": "foundry_dataset", "category": "testing", "severity": "high", "confidence": 0.78, "cwe": "", "owasp": ""}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-388fefbf1a75fe0b", "name": "Insecure pattern 'direct_innerhtml_assignment' in game.js:1061", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in game.js:1061"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "0 test file(s) for 2 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-faccb9061e9b52a0", "name": "No README detected", "shortDescription": {"text": "No README detected"}, "fullDescription": {"text": "No README file was found. Generated repos without README context are hard to operate, validate, or safely hand off."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, operator-readme. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/22180"}, "properties": {"repository": "VicenteHenriquez/ttolive", "repoUrl": "https://github.com/VicenteHenriquez/ttolive", "branch": "main"}, "results": [{"ruleId": "foundry_assumption_check", "level": "warning", "message": {"text": "Foundry mined assumption checks: VicenteHenriquez/ttolive"}, "properties": {"repobilityId": 301261, "scanner": "foundry_dataset", "fingerprint": "194ef67978ff365d6fc11a9ff5f204a0a8998457077543de58f8d5c0822b525c", "category": "practices", "severity": "medium", "confidence": 0.62, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "comment_chain_pattern_product", "source": "comment_chain_pattern_miner", "product": "assumption_checks", "synthetic": false, "thread_key": "VicenteHenriquez/ttolive#1", "human_labels": ["test_ci_gap", "test_or_ci"], "issue_number": "1", "thread_label": "thread_has_human_issue_and_fix_context", "outcome_label": "ambiguous_needs_more_evidence", "source_backed": false, "max_confidence": 0.86, "repo_full_name": "VicenteHenriquez/ttolive", "training_usage": "gold_candidate", "confidence_tier": "high_confidence", "source_chain_id": "evidence-chain-issue_chain-16f9d2177f38a8d7", "helicopter_views": {}, "artifact_families": {}, "source_chain_kind": "issue_chain", "changed_file_count": 1, "source_graph_label": "github_or_motif_graph_without_source_files", "changed_file_labels": {"test_or_ci": 1}, "linked_commit_count": 2, "helicopter_view_count": 0, "source_artifact_count": 0, "classification_reasons": ["link_quality_high_confidence", "high_risk_human_feedback_label"], "linked_ci_commit_count": 1, "verification_artifact_count": 0, "design_schema_api_artifact_count": 0}, "text": "Comment chain pattern product: assumption_checks\nRepo: VicenteHenriquez/ttolive\nThread: VicenteHenriquez/ttolive#1\nOutcome: ambiguous_needs_more_evidence\nThread label: thread_has_human_issue_and_fix_context\nSource graph label: github_or_motif_graph_without_source_files\nReasons: link_quality_high_confidence, high_risk_human_feedback_label\nChain evidence:\nIssue/PR evidence chain: VicenteHenriquez/ttolive#1\nRepo: VicenteHenriquez/ttolive\nThread label: thread_has_human_issue_and_fix_context\nOutcome: ambiguous_needs_more_evidence\nComment count: 1\nLinked commit count: 2\nLinked CI commit count: 1\nLinked CI labels: {'ci_pending_or_incomplete': 1}\nChanged file count: 1\nLabels: {'test_ci_gap': 1}\nPolarities: {'bad': 1}\nChanged file labels: {'test_or_ci': 1}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-d920e028153ad5d0\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"test_ci_gap\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.com/VicenteHenriquez/ttolive/pull/1\",\n    \"text\": \"GitHub feedback: test_ci_gap\\nPolarity: bad\\nKind: pull_request_body\\nRepo: VicenteHenriquez/ttolive\\nAuthor: Copilot (Bot)\\nURL: https://github.com/VicenteHenriquez/ttolive/pull/1\\nTitle: Harden Vercel deploy workflow token resolution\\nBody:\\nThe `deploy` Actions job was failing because the Vercel CLI received an invalid/missing token at runtime. This updates token resolution in the workflow to support both expected secret names and fail early with a clear error when neither is configured.\\n\\n- **Deployment auth resolution**\\n  - Updated deploy step to resolve token from `VERCEL_TOKEN` **or** `VERCEL_ACCESS_TOKEN`.\\n  - Avoids hard dependency on a single secret key name.\\n\\n- **Fail-fast guardrail**\\n  - Added an explicit pre-check in the deploy step that exits with a clear message when no token is available.\\n  - Prevents opaque CLI auth failures and improves diagnosability.\\n\\n- **Deploy command usage**\\n  - Continues invoking `vercel deploy --prod --yes`, now with the resolved token variable.\\n\\n```yaml\\n- name: Deploy\\n  env:\\n    VERCEL_TOKEN: ${{ secrets.VERCEL_TOKEN || secrets.VERCEL_ACCESS_TOKEN }}\\n  run: |\\n    if [ -z \\\"$VERCEL_TOKEN\\\" ]; then\\n      echo \\\"Missing Vercel token. Configure VERCEL_TOK\"\n  }\n]\nChanged files:\n[\n  {\n    \"id\": \"github-pr-file-file-15aac98aa6be36fb\",\n    \"filename\": \".github/workflows/deploy.yml\",\n    \"label\": \"test_or_ci\",\n    \"status\": \"modified\",\n    \"additions\": 8,\n    \"deletions\": 1,\n    \"changes\": 9,\n    \"blob_url\": \"https://github.com/VicenteHenriquez/ttolive/blob/f145fdea8ac56d724cfde312211991557793a1b8/.github%2Fworkflows%2Fdeploy.yml\"\n  }\n]\nLinked chain ids:\n[\"evidence-chain-comment_to_commit-b7431b19584ff922\"]\nSource graph evidence:\nSource evidence repo graph summary\nRepo: VicenteHenriquez/ttolive\nGraph label: github_or_motif_graph_without_source_files\nNodes: 4\nEdges: 4\nNode types: {\"cooccurrence_profile\": 1, \"github_repo_summary\": 1, \"repo\": 1, \"source_bundle\": 1}\nEdge types: {\"repo_has_cooccurr\n[truncated by importer]", "source": "foundry_mined_dataset", "repo_url": "https://github.com/VicenteHenriquez/ttolive", "source_id": "comment-chain-pattern-assumption_checks-4950f4ab706d93f4", "synthetic": false, "gold_label": "", "graph_label": "github_or_motif_graph_without_source_files", "source_path": "/data/distillate/foundry_data/comment_chain_patterns/assumption_checks/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "VicenteHenriquez/ttolive", "source_dataset": "comment_chain_patterns/assumption_checks", "training_usage": "gold_candidate"}}}, {"ruleId": "foundry_test_ci_gap", "level": "error", "message": {"text": "Foundry mined test ci gap after feedback: VicenteHenriquez/ttolive"}, "properties": {"repobilityId": 336871, "scanner": "foundry_dataset", "fingerprint": "bccbde5e0ebeb4975faa9946c2852ab0a624a51739aa74b0b3c6903457432f9f", "category": "testing", "severity": "high", "confidence": 0.78, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Feedback exposes missing tests or CI", "intent": "Hard negatives for feedback/fix chains without adequate guardrails.", "labels": {"test_or_ci": 1, "test_ci_gap": 1, "verification_or_tests": 2, "ci_pending_or_incomplete": 1, "issue_or_pull_request_thread": 1, "ambiguous_needs_more_evidence": 3, "comment_has_related_commit_context": 1, "thread_has_human_issue_and_fix_context": 2}, "source": "graph_query_export", "motif_id": "test_ci_gap_after_feedback", "outcomes": {"ambiguous_needs_more_evidence": 6}, "polarity": "bad", "query_id": "test_ci_gap_after_feedback", "severity": "high", "ci_labels": {"ci_pending_or_incomplete": 2}, "synthetic": false, "edge_count": 17, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "thread_touches_file": 1, "comment_chain_has_ci": 1, "chain_has_link_quality": 3, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 1, "thread_has_comment_chain": 1, "comment_chain_links_commit": 2, "comment_chain_touches_file": 1, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 13, "node_types": {"repo": 1, "commit": 2, "thread": 1, "comment": 1, "pr_file": 1, "ci_summary": 1, "fix_outcome": 1, "issue_chain": 1, "link_quality": 3, "comment_chain": 1}, "query_type": "motif_query", "thread_key": "VicenteHenriquez/ttolive#1", "issue_number": "1", "quality_tiers": {"high_confidence": 3}, "repo_full_name": "VicenteHenriquez/ttolive", "training_usage": "hard_negative", "source_motif_id": "graph-pattern-motif-thread-87125ad286081c74", "graph_gold_label": "supported_by_high_confidence_link", "changed_file_labels": {"test_or_ci": 4}}, "text": "Graph query export: Feedback exposes missing tests or CI\nQuery id: test_ci_gap_after_feedback\nQuery type: motif_query\nIntent: Hard negatives for feedback/fix chains without adequate guardrails.\nMotif: test_ci_gap_after_feedback\nTraining usage: hard_negative\nGraph gold label: supported_by_high_confidence_link\nRepo: VicenteHenriquez/ttolive\nThread: VicenteHenriquez/ttolive#1\nEvidence:\nGraph motif: Feedback or fix context exposes missing test/CI guardrails\nMotif id: test_ci_gap_after_feedback\nPolarity: bad\nTraining usage: hard_negative\nSeverity: high\nRepo: VicenteHenriquez/ttolive\nThread: VicenteHenriquez/ttolive#1\nGraph gold label: supported_by_high_confidence_link\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: VicenteHenriquez/ttolive#1\nRepo: VicenteHenriquez/ttolive\nIssue/PR number: 1\nGraph consistency label: supported_by_high_confidence_link\nNodes: 13\nEdges: 17\nNode types: {'link_quality': 3, 'commit': 2, 'thread': 1, 'repo': 1, 'comment': 1, 'pr_file': 1, 'comment_chain': 1, 'ci_summary': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'chain_has_link_quality': 3, 'comment_chain_links_commit': 2, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_touches_file': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'comment_chain_has_ci': 1, 'comment_chain_touches_file': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'issue_chain_touches_file': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'ambiguous_needs_more_evidence': 3, 'verification_or_tests': 2, 'thread_has_human_issue_and_fix_context': 2, 'issue_or_pull_request_thread': 1, 'test_ci_gap': 1, 'test_or_ci': 1, 'comment_has_related_commit_context': 1, 'ci_pending_or_incomplete': 1}\nOutcomes: {'ambiguous_needs_more_evidence': 6}\nQuality tiers: {'high_confidence': 3}\nCI labels: {'ci_pending_or_incomplete': 2}\nCurriculum targets:\n- Turn human feedback into regression tests and CI gates.\n- Penalize fixes that do not add or exercise verification for affected workflows.\nAssumption checks:\n- Did the fix add tests for the exact complaint?\n- Does CI run those tests, or is verification only implied?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/VicenteHenriquez/ttolive", "source_id": "graph-query-motif_query-12932dfef657f227", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/test_ci_gap_after_feedback/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "VicenteHenriquez/ttolive", "source_dataset": "graph_queries/test_ci_gap_after_feedback", "training_usage": "hard_negative"}}}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-388fefbf1a75fe0b", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in game.js:1061"}, "properties": {"repobilityId": "445f52e914ad7d37", "scanner": "scanner-primary", "fingerprint": "388fefbf1a75fe0b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "game.js"}, "region": {"startLine": 1061}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "1031123baf97e049", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-faccb9061e9b52a0", "level": "note", "message": {"text": "No README detected"}, "properties": {"repobilityId": "30c915cf9dcc0c7b", "scanner": "scanner-primary", "fingerprint": "faccb9061e9b52a0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["docs", "readme", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "42e1100986208861", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "60b2fd68232355bd", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}]}]}