{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-175b3902c32c7f81", "name": "Stray `console.log` in TS/JS \u2014 server.js:37", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 server.js:37"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-506be2b95088f5d3", "name": "git log failed \u2014 history analysis incomplete", "shortDescription": {"text": "git log failed \u2014 history analysis incomplete"}, "fullDescription": {"text": "fatal: not a git repository (or any parent up to mount point /data)\nStopping at filesystem boundary (GIT_DISCOVERY_ACROSS_FILESYSTEM not set)."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-55dfb6137fb760b6", "name": "Insecure pattern 'direct_innerhtml_assignment' in guide.html:718", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in guide.html:718"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3d380b2723745d78", "name": "Insecure pattern 'direct_innerhtml_assignment' in about.html:548", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in about.html:548"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-06f07fa9aee2dcf4", "name": "Insecure pattern 'direct_innerhtml_assignment' in terms.html:360", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in terms.html:360"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7c1fdb42157e6c63", "name": "Insecure pattern 'direct_innerhtml_assignment' in analyzer.html:1250", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in analyzer.html:1250"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-53f554a96524d331", "name": "Insecure pattern 'cors_wildcard' in server.js:18", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in server.js:18"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-802c0c31c0a4ca53", "name": "Insecure pattern 'direct_innerhtml_assignment' in index.html:1218", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in index.html:1218"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0a53135b17d2d928", "name": "Insecure pattern 'direct_innerhtml_assignment' in stats.html:228", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in stats.html:228"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-de3b053a67b659d6", "name": "Insecure pattern 'direct_innerhtml_assignment' in review.html:426", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in review.html:426"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-092d18a151819704", "name": "Insecure pattern 'direct_innerhtml_assignment' in glossary.html:546", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in glossary.html:546"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-371db5cd066e9d90", "name": "Insecure pattern 'direct_innerhtml_assignment' in picks.html:726", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in picks.html:726"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8afbd4ca66255f78", "name": "Insecure pattern 'direct_innerhtml_assignment' in today.html:459", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in today.html:459"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3958751c0d8435be", "name": "Insecure pattern 'insert_adjacent_html' in today.html:481", "shortDescription": {"text": "Insecure pattern 'insert_adjacent_html' in today.html:481"}, "fullDescription": {"text": "Found a known-risky pattern (insert_adjacent_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "0 test file(s) for 2 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-faccb9061e9b52a0", "name": "No README detected", "shortDescription": {"text": "No README detected"}, "fullDescription": {"text": "No README file was found. Generated repos without README context are hard to operate, validate, or safely hand off."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 12 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci, operator-readme. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-67bf5799f82afdf0", "name": "`fetch()` without try/.catch or AbortSignal \u2014 check-eps.mjs:14", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 check-eps.mjs:14"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1b5a76780c3df9aa", "name": "1 env vars used in code but missing from .env.example", "shortDescription": {"text": "1 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `PORT`. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a21259c2c697a806", "name": "Unused endpoint: ALL /api/kv/:action/:key(*)", "shortDescription": {"text": "Unused endpoint: ALL /api/kv/:action/:key(*)"}, "fullDescription": {"text": "`server.js` declares `ALL /api/kv/:action/:key(*)` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-58eb3284fcfb3c38", "name": "Unused endpoint: POST /api/kv/:action", "shortDescription": {"text": "Unused endpoint: POST /api/kv/:action"}, "fullDescription": {"text": "`server.js` declares `POST /api/kv/:action` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/13041"}, "properties": {"repository": "leh7477/stock-app", "repoUrl": "https://github.com/leh7477/stock-app", "branch": "main"}, "results": [{"ruleId": "scanner-175b3902c32c7f81", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 server.js:37"}, "properties": {"repobilityId": "a9deebb5fdc93edc", "scanner": "scanner-primary", "fingerprint": "175b3902c32c7f81", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-506be2b95088f5d3", "level": "none", "message": {"text": "git log failed \u2014 history analysis incomplete"}, "properties": {"repobilityId": "b424308a11bb9b22", "scanner": "scanner-primary", "fingerprint": "506be2b95088f5d3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["git", "tooling"]}}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-55dfb6137fb760b6", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in guide.html:718"}, "properties": {"repobilityId": "c80a464fd4802714", "scanner": "scanner-primary", "fingerprint": "55dfb6137fb760b6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "guide.html"}, "region": {"startLine": 718}}}]}, {"ruleId": "scanner-3d380b2723745d78", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in about.html:548"}, "properties": {"repobilityId": "2fd71b61ec7ccf47", "scanner": "scanner-primary", "fingerprint": "3d380b2723745d78", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "about.html"}, "region": {"startLine": 548}}}]}, {"ruleId": "scanner-06f07fa9aee2dcf4", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in terms.html:360"}, "properties": {"repobilityId": "689f4428aa485aff", "scanner": "scanner-primary", "fingerprint": "06f07fa9aee2dcf4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "terms.html"}, "region": {"startLine": 360}}}]}, {"ruleId": "scanner-7c1fdb42157e6c63", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in analyzer.html:1250"}, "properties": {"repobilityId": "04ef03c72cc4fdb5", "scanner": "scanner-primary", "fingerprint": "7c1fdb42157e6c63", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "analyzer.html"}, "region": {"startLine": 1250}}}]}, {"ruleId": "scanner-53f554a96524d331", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in server.js:18"}, "properties": {"repobilityId": "0d9bca6c0839725e", "scanner": "scanner-primary", "fingerprint": "53f554a96524d331", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "server.js"}, "region": {"startLine": 18}}}]}, {"ruleId": "scanner-802c0c31c0a4ca53", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in index.html:1218"}, "properties": {"repobilityId": "f91708437a3a5445", "scanner": "scanner-primary", "fingerprint": "802c0c31c0a4ca53", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "index.html"}, "region": {"startLine": 1218}}}]}, {"ruleId": "scanner-0a53135b17d2d928", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in stats.html:228"}, "properties": {"repobilityId": "132f956cd130d2b4", "scanner": "scanner-primary", "fingerprint": "0a53135b17d2d928", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "stats.html"}, "region": {"startLine": 228}}}]}, {"ruleId": "scanner-de3b053a67b659d6", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in review.html:426"}, "properties": {"repobilityId": "82d3505a91b61c3b", "scanner": "scanner-primary", "fingerprint": "de3b053a67b659d6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "review.html"}, "region": {"startLine": 426}}}]}, {"ruleId": "scanner-092d18a151819704", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in glossary.html:546"}, "properties": {"repobilityId": "447c2c104415112f", "scanner": "scanner-primary", "fingerprint": "092d18a151819704", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "glossary.html"}, "region": {"startLine": 546}}}]}, {"ruleId": "scanner-371db5cd066e9d90", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in picks.html:726"}, "properties": {"repobilityId": "e12fd02dd2655719", "scanner": "scanner-primary", "fingerprint": "371db5cd066e9d90", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "picks.html"}, "region": {"startLine": 726}}}]}, {"ruleId": "scanner-8afbd4ca66255f78", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in today.html:459"}, "properties": {"repobilityId": "718d1615d828bc6c", "scanner": "scanner-primary", "fingerprint": "8afbd4ca66255f78", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "today.html"}, "region": {"startLine": 459}}}]}, {"ruleId": "scanner-3958751c0d8435be", "level": "warning", "message": {"text": "Insecure pattern 'insert_adjacent_html' in today.html:481"}, "properties": {"repobilityId": "ec539d1689de2dfd", "scanner": "scanner-primary", "fingerprint": "3958751c0d8435be", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "insert_adjacent_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "today.html"}, "region": {"startLine": 481}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "5dbafe4dc53622e6", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-faccb9061e9b52a0", "level": "note", "message": {"text": "No README detected"}, "properties": {"repobilityId": "91004ab4e9f2a2ed", "scanner": "scanner-primary", "fingerprint": "faccb9061e9b52a0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["docs", "readme", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "e79464865419adcd", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "warning", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "fc10ce40f013ee23", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-67bf5799f82afdf0", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 check-eps.mjs:14"}, "properties": {"repobilityId": "46f8cdc7d863f70a", "scanner": "scanner-primary", "fingerprint": "67bf5799f82afdf0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-1b5a76780c3df9aa", "level": "none", "message": {"text": "1 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "d04379b337b44a15", "scanner": "scanner-primary", "fingerprint": "1b5a76780c3df9aa", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-a21259c2c697a806", "level": "note", "message": {"text": "Unused endpoint: ALL /api/kv/:action/:key(*)"}, "properties": {"repobilityId": "0908ebe6f7438059", "scanner": "scanner-primary", "fingerprint": "a21259c2c697a806", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-58eb3284fcfb3c38", "level": "note", "message": {"text": "Unused endpoint: POST /api/kv/:action"}, "properties": {"repobilityId": "e70941394ce4add2", "scanner": "scanner-primary", "fingerprint": "58eb3284fcfb3c38", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}