{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-7a4504258575bdc4", "name": "TODO/FIXME marker in shipping code \u2014 src/components/CreateRoomModal.vue:277", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 src/components/CreateRoomModal.vue:277"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-829a4aeeca4b26a3", "name": "TODO/FIXME marker in shipping code \u2014 src/components/chat/ChatWidget.vue:256", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 src/components/chat/ChatWidget.vue:256"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7f5d7c167da45f4e", "name": "TODO/FIXME marker in shipping code \u2014 src/components/chat/ChatWindow.vue:396", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 src/components/chat/ChatWindow.vue:396"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0c7915a8c23998ee", "name": "TODO/FIXME marker in shipping code \u2014 src/components/tasks/KanbanBoard.vue:235", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 src/components/tasks/KanbanBoard.vue:235"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ac5e92acbbd8ff88", "name": "Icon-only button without accessible name \u2014 src/components/tasks/TaskDetailModal.vue:79", "shortDescription": {"text": "Icon-only button without accessible name \u2014 src/components/tasks/TaskDetailModal.vue:79"}, "fullDescription": {"text": "A `<button>` whose only child is a single glyph or symbol needs `title=` or `aria-label=` so screen readers (and tooltips on hover) work.\n\nWhy: P3 in CHECKLIST.md \u2014 icon-only buttons skipped a title.\nRule id: fq.button.no-label"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-375c52e6a2fd3529", "name": "TODO/FIXME marker in shipping code \u2014 src/components/modules/ActivitiesView.vue:5218", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 src/components/modules/ActivitiesView.vue:5218"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-38bcd25f883a7090", "name": "Icon-only button without accessible name \u2014 src/components/forms/ActivityFormModal.vue:359", "shortDescription": {"text": "Icon-only button without accessible name \u2014 src/components/forms/ActivityFormModal.vue:359"}, "fullDescription": {"text": "A `<button>` whose only child is a single glyph or symbol needs `title=` or `aria-label=` so screen readers (and tooltips on hover) work.\n\nWhy: P3 in CHECKLIST.md \u2014 icon-only buttons skipped a title.\nRule id: fq.button.no-label"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-39c4981db7213e73", "name": "TODO/FIXME marker in shipping code \u2014 src/pages/BoardsPage.vue:252", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 src/pages/BoardsPage.vue:252"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-dfb540be1ca3433a", "name": "Runtime dotenv file present in repo: .env.development", "shortDescription": {"text": "Runtime dotenv file present in repo: .env.development"}, "fullDescription": {"text": "`.env.development` looks like a runtime dotenv file. No high-confidence secret value was matched, but runtime dotenv files often drift into live credentials. Move real values to a secret manager and keep only `.env.example` style templates in source control."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cdde2538539152d7", "name": "Insecure pattern 'direct_innerhtml_assignment' in gems-fragmentada-vertical.html:260", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in gems-fragmentada-vertical.html:260"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7c7da70cfe901e99", "name": "Insecure pattern 'direct_innerhtml_assignment' in gems-mantis.html:131", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in gems-mantis.html:131"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-748b135f57fda20e", "name": "Insecure pattern 'direct_innerhtml_assignment' in gems-fragmentada-demo.html:382", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in gems-fragmentada-demo.html:382"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-59ef200108cd76ec", "name": "Insecure pattern 'direct_innerhtml_assignment' in gems-costos-demo.html:256", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in gems-costos-demo.html:256"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-250a55251381bc8b", "name": "Insecure pattern 'direct_innerhtml_assignment' in gems-mantis-vertical.html:126", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in gems-mantis-vertical.html:126"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8e4061ab153c0b76", "name": "Insecure pattern 'direct_innerhtml_assignment' in gems-costos-vertical.html:222", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in gems-costos-vertical.html:222"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-65c240e9d0414cc7", "name": "Insecure pattern 'local_storage_auth_token' in src/stores/auth.ts:213", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in src/stores/auth.ts:213"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-258d92c23f36c641", "name": "Insecure pattern 'vue_v_html' in src/components/prospects/ProspectConversation.vue:33", "shortDescription": {"text": "Insecure pattern 'vue_v_html' in src/components/prospects/ProspectConversation.vue:33"}, "fullDescription": {"text": "Found a known-risky pattern (vue_v_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9274335bbba1dd5a", "name": "Insecure pattern 'vue_v_html' in src/components/prospects/ProspectSummary.vue:18", "shortDescription": {"text": "Insecure pattern 'vue_v_html' in src/components/prospects/ProspectSummary.vue:18"}, "fullDescription": {"text": "Found a known-risky pattern (vue_v_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cd4353ea9df15d15", "name": "Insecure pattern 'direct_outerhtml_assignment' in src/components/wiki/WikiEditor.vue:171", "shortDescription": {"text": "Insecure pattern 'direct_outerhtml_assignment' in src/components/wiki/WikiEditor.vue:171"}, "fullDescription": {"text": "Found a known-risky pattern (direct_outerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-202f867c75db2f0e", "name": "Insecure pattern 'domparser_html_parse' in src/components/wiki/WikiEditor.vue:166", "shortDescription": {"text": "Insecure pattern 'domparser_html_parse' in src/components/wiki/WikiEditor.vue:166"}, "fullDescription": {"text": "Found a known-risky pattern (domparser_html_parse). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fd2d30649b7b1c13", "name": "Insecure pattern 'vue_v_html' in src/components/wiki/WikiContent.vue:2", "shortDescription": {"text": "Insecure pattern 'vue_v_html' in src/components/wiki/WikiContent.vue:2"}, "fullDescription": {"text": "Found a known-risky pattern (vue_v_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a595e5e73708ede4", "name": "Insecure pattern 'vue_v_html' in src/components/forms/ActivityFormModal.vue:314", "shortDescription": {"text": "Insecure pattern 'vue_v_html' in src/components/forms/ActivityFormModal.vue:314"}, "fullDescription": {"text": "Found a known-risky pattern (vue_v_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b47c59c3e43fef15", "name": "Insecure pattern 'local_storage_auth_token' in src/services/authHeaders.ts:41", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in src/services/authHeaders.ts:41"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ba760a258b7dec5e", "name": "Insecure pattern 'local_storage_auth_token' in src/services/authService.ts:72", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in src/services/authService.ts:72"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-28c4a04bd807da0c", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ad6701f0a8405e22", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5ecba37f7a51e364", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/setup-node@v3 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "0 test file(s) for 72 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-11825279136b53a3", "name": "CI is configured but no tests are detected", "shortDescription": {"text": "CI is configured but no tests are detected"}, "fullDescription": {"text": "A CI pipeline exists, but the scan found no test files to gate. Opus labeled this generated-code pattern as config theater: release machinery exists, but it has little behavioral signal."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, tests. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license, tests. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bea357a6497a2d5d", "name": "Agent authority lacks a verifier contract: CLAUDE.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: CLAUDE.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2c5f98b152cddb6d", "name": "Agent authority lacks a verifier contract: .claude/launch.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/launch.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7b184ff81a10298b", "name": "Commented-code block (5 lines) in src/stores/theme.ts:64", "shortDescription": {"text": "Commented-code block (5 lines) in src/stores/theme.ts:64"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ae31a912e444e9c8", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/reportsOverviewService.ts:50", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/reportsOverviewService.ts:50"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-02ec00f5362da6fa", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/userService.ts:145", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/userService.ts:145"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-210d45fd22b94561", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/authHeaders.ts:29", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/authHeaders.ts:29"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-daca359ffeca8c3f", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/chatService.ts:187", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/chatService.ts:187"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-270d2f0e63044326", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/ticketService.ts:27", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/ticketService.ts:27"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-de3c533e1977434b", "name": "Unused endpoint: GET /avatars", "shortDescription": {"text": "Unused endpoint: GET /avatars"}, "fullDescription": {"text": "`src/services/avatarService.ts` declares `GET /avatars` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-897e09906521bec3", "name": "Unused endpoint: GET /avatars/user", "shortDescription": {"text": "Unused endpoint: GET /avatars/user"}, "fullDescription": {"text": "`src/services/avatarService.ts` declares `GET /avatars/user` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5383ab72ec22f540", "name": "Unused endpoint: PUT /avatars/user", "shortDescription": {"text": "Unused endpoint: PUT /avatars/user"}, "fullDescription": {"text": "`src/services/avatarService.ts` declares `PUT /avatars/user` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2ac4c5a997c00390", "name": "Unused endpoint: DELETE /avatars/user", "shortDescription": {"text": "Unused endpoint: DELETE /avatars/user"}, "fullDescription": {"text": "`src/services/avatarService.ts` declares `DELETE /avatars/user` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4e4ab99927ecb757", "name": "Unused endpoint: POST /avatars/upload-photo", "shortDescription": {"text": "Unused endpoint: POST /avatars/upload-photo"}, "fullDescription": {"text": "`src/services/avatarService.ts` declares `POST /avatars/upload-photo` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-152ad529b10a6a7c", "name": "Unused endpoint: DELETE /avatars/photo", "shortDescription": {"text": "Unused endpoint: DELETE /avatars/photo"}, "fullDescription": {"text": "`src/services/avatarService.ts` declares `DELETE /avatars/photo` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f83a34a970710cae", "name": "Unused endpoint: GET /avatars/stats", "shortDescription": {"text": "Unused endpoint: GET /avatars/stats"}, "fullDescription": {"text": "`src/services/avatarService.ts` declares `GET /avatars/stats` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8fdbacfe9430a6ed", "name": "Unused endpoint: POST /auth/login", "shortDescription": {"text": "Unused endpoint: POST /auth/login"}, "fullDescription": {"text": "`src/services/authService.ts` declares `POST /auth/login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f482a683253c5509", "name": "Unused endpoint: POST /auth/register-org", "shortDescription": {"text": "Unused endpoint: POST /auth/register-org"}, "fullDescription": {"text": "`src/services/authService.ts` declares `POST /auth/register-org` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c25c877105f4ce5f", "name": "Unused endpoint: POST /auth/verify-2fa", "shortDescription": {"text": "Unused endpoint: POST /auth/verify-2fa"}, "fullDescription": {"text": "`src/services/authService.ts` declares `POST /auth/verify-2fa` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c059f57186114027", "name": "Unused endpoint: POST /auth/logout", "shortDescription": {"text": "Unused endpoint: POST /auth/logout"}, "fullDescription": {"text": "`src/services/authService.ts` declares `POST /auth/logout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-021eacddceea7c7c", "name": "Unused endpoint: POST /auth/verify-token", "shortDescription": {"text": "Unused endpoint: POST /auth/verify-token"}, "fullDescription": {"text": "`src/services/authService.ts` declares `POST /auth/verify-token` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-647ec4a4f702c47a", "name": "Unused endpoint: POST /auth/select-org", "shortDescription": {"text": "Unused endpoint: POST /auth/select-org"}, "fullDescription": {"text": "`src/services/authService.ts` declares `POST /auth/select-org` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9c44c940210b007b", "name": "Unused endpoint: GET /auth/memberships", "shortDescription": {"text": "Unused endpoint: GET /auth/memberships"}, "fullDescription": {"text": "`src/services/authService.ts` declares `GET /auth/memberships` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9143464946a01de5", "name": "Unused endpoint: PUT /auth/profile", "shortDescription": {"text": "Unused endpoint: PUT /auth/profile"}, "fullDescription": {"text": "`src/services/authService.ts` declares `PUT /auth/profile` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-acfc2ed20c4bb703", "name": "Unused endpoint: PUT /auth/change-password", "shortDescription": {"text": "Unused endpoint: PUT /auth/change-password"}, "fullDescription": {"text": "`src/services/authService.ts` declares `PUT /auth/change-password` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e2fe5b92648ca462", "name": "Unused endpoint: POST /auth/forgot-password", "shortDescription": {"text": "Unused endpoint: POST /auth/forgot-password"}, "fullDescription": {"text": "`src/services/authService.ts` declares `POST /auth/forgot-password` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-deb8df763a50c73a", "name": "Unused endpoint: POST /auth/reset-password", "shortDescription": {"text": "Unused endpoint: POST /auth/reset-password"}, "fullDescription": {"text": "`src/services/authService.ts` declares `POST /auth/reset-password` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-88a29b8a5c158e5b", "name": "Unused endpoint: GET /roles", "shortDescription": {"text": "Unused endpoint: GET /roles"}, "fullDescription": {"text": "`src/services/rolesService.ts` declares `GET /roles` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-078b3f8a9311d56a", "name": "Unused endpoint: POST /roles", "shortDescription": {"text": "Unused endpoint: POST /roles"}, "fullDescription": {"text": "`src/services/rolesService.ts` declares `POST /roles` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6b95b7f414083427", "name": "Unused endpoint: GET /admin/organizations", "shortDescription": {"text": "Unused endpoint: GET /admin/organizations"}, "fullDescription": {"text": "`src/services/adminService.ts` declares `GET /admin/organizations` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-07ef5d265df423f3", "name": "Unused endpoint: POST /admin/organizations", "shortDescription": {"text": "Unused endpoint: POST /admin/organizations"}, "fullDescription": {"text": "`src/services/adminService.ts` declares `POST /admin/organizations` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6f174755b2041b5b", "name": "Unused endpoint: GET /admin/super-admins", "shortDescription": {"text": "Unused endpoint: GET /admin/super-admins"}, "fullDescription": {"text": "`src/services/adminService.ts` declares `GET /admin/super-admins` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-52106b43a72b4141", "name": "Unused endpoint: GET /admin/audit-logs", "shortDescription": {"text": "Unused endpoint: GET /admin/audit-logs"}, "fullDescription": {"text": "`src/services/adminService.ts` declares `GET /admin/audit-logs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/19169"}, "properties": {"repository": "sebastianpg12/FrontendGemsCRM", "repoUrl": "https://github.com/sebastianpg12/FrontendGemsCRM", "branch": "main"}, "results": [{"ruleId": "scanner-7a4504258575bdc4", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 src/components/CreateRoomModal.vue:277"}, "properties": {"repobilityId": "4404ff02e0251bd1", "scanner": "scanner-primary", "fingerprint": "7a4504258575bdc4", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-829a4aeeca4b26a3", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 src/components/chat/ChatWidget.vue:256"}, "properties": {"repobilityId": "eda22f2cbe9cc26c", "scanner": "scanner-primary", "fingerprint": "829a4aeeca4b26a3", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-7f5d7c167da45f4e", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 src/components/chat/ChatWindow.vue:396"}, "properties": {"repobilityId": "31d0fe8ff9601233", "scanner": "scanner-primary", "fingerprint": "7f5d7c167da45f4e", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-0c7915a8c23998ee", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 src/components/tasks/KanbanBoard.vue:235"}, "properties": {"repobilityId": "79eadd1353094ca7", "scanner": "scanner-primary", "fingerprint": "0c7915a8c23998ee", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-ac5e92acbbd8ff88", "level": "note", "message": {"text": "Icon-only button without accessible name \u2014 src/components/tasks/TaskDetailModal.vue:79"}, "properties": {"repobilityId": "7078bf83c7535a38", "scanner": "scanner-primary", "fingerprint": "ac5e92acbbd8ff88", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.button.no-label"]}}, {"ruleId": "scanner-375c52e6a2fd3529", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 src/components/modules/ActivitiesView.vue:5218"}, "properties": {"repobilityId": "840a3d9eea434ea9", "scanner": "scanner-primary", "fingerprint": "375c52e6a2fd3529", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-38bcd25f883a7090", "level": "note", "message": {"text": "Icon-only button without accessible name \u2014 src/components/forms/ActivityFormModal.vue:359"}, "properties": {"repobilityId": "94c5083fa24e9ec0", "scanner": "scanner-primary", "fingerprint": "38bcd25f883a7090", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.button.no-label"]}}, {"ruleId": "scanner-39c4981db7213e73", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 src/pages/BoardsPage.vue:252"}, "properties": {"repobilityId": "d07c0c5c41e9f4a5", "scanner": "scanner-primary", "fingerprint": "39c4981db7213e73", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-dfb540be1ca3433a", "level": "error", "message": {"text": "Runtime dotenv file present in repo: .env.development"}, "properties": {"repobilityId": "7d5eb336bd00195c", "scanner": "scanner-primary", "fingerprint": "dfb540be1ca3433a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["secrets", "config", "env-file", "runtime-env"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".env.development"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cdde2538539152d7", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in gems-fragmentada-vertical.html:260"}, "properties": {"repobilityId": "4d19618d0951f1b3", "scanner": "scanner-primary", "fingerprint": "cdde2538539152d7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "gems-fragmentada-vertical.html"}, "region": {"startLine": 260}}}]}, {"ruleId": "scanner-7c7da70cfe901e99", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in gems-mantis.html:131"}, "properties": {"repobilityId": "13082255c8df8508", "scanner": "scanner-primary", "fingerprint": "7c7da70cfe901e99", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "gems-mantis.html"}, "region": {"startLine": 131}}}]}, {"ruleId": "scanner-748b135f57fda20e", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in gems-fragmentada-demo.html:382"}, "properties": {"repobilityId": "123ad698489584ee", "scanner": "scanner-primary", "fingerprint": "748b135f57fda20e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "gems-fragmentada-demo.html"}, "region": {"startLine": 382}}}]}, {"ruleId": "scanner-59ef200108cd76ec", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in gems-costos-demo.html:256"}, "properties": {"repobilityId": "b94c3cfbb38649a5", "scanner": "scanner-primary", "fingerprint": "59ef200108cd76ec", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "gems-costos-demo.html"}, "region": {"startLine": 256}}}]}, {"ruleId": "scanner-250a55251381bc8b", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in gems-mantis-vertical.html:126"}, "properties": {"repobilityId": "28763bae99fdb459", "scanner": "scanner-primary", "fingerprint": "250a55251381bc8b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "gems-mantis-vertical.html"}, "region": {"startLine": 126}}}]}, {"ruleId": "scanner-8e4061ab153c0b76", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in gems-costos-vertical.html:222"}, "properties": {"repobilityId": "4217363ebc38040a", "scanner": "scanner-primary", "fingerprint": "8e4061ab153c0b76", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "gems-costos-vertical.html"}, "region": {"startLine": 222}}}]}, {"ruleId": "scanner-65c240e9d0414cc7", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in src/stores/auth.ts:213"}, "properties": {"repobilityId": "c20a3d808b98b345", "scanner": "scanner-primary", "fingerprint": "65c240e9d0414cc7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/stores/auth.ts"}, "region": {"startLine": 213}}}]}, {"ruleId": "scanner-258d92c23f36c641", "level": "warning", "message": {"text": "Insecure pattern 'vue_v_html' in src/components/prospects/ProspectConversation.vue:33"}, "properties": {"repobilityId": "797cc4d0b154c324", "scanner": "scanner-primary", "fingerprint": "258d92c23f36c641", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "vue_v_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/components/prospects/ProspectConversation.vue"}, "region": {"startLine": 33}}}]}, {"ruleId": "scanner-9274335bbba1dd5a", "level": "warning", "message": {"text": "Insecure pattern 'vue_v_html' in src/components/prospects/ProspectSummary.vue:18"}, "properties": {"repobilityId": "3df39175638ec740", "scanner": "scanner-primary", "fingerprint": "9274335bbba1dd5a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "vue_v_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/components/prospects/ProspectSummary.vue"}, "region": {"startLine": 18}}}]}, {"ruleId": "scanner-cd4353ea9df15d15", "level": "warning", "message": {"text": "Insecure pattern 'direct_outerhtml_assignment' in src/components/wiki/WikiEditor.vue:171"}, "properties": {"repobilityId": "679ce1056f3a8b38", "scanner": "scanner-primary", "fingerprint": "cd4353ea9df15d15", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_outerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/components/wiki/WikiEditor.vue"}, "region": {"startLine": 171}}}]}, {"ruleId": "scanner-202f867c75db2f0e", "level": "warning", "message": {"text": "Insecure pattern 'domparser_html_parse' in src/components/wiki/WikiEditor.vue:166"}, "properties": {"repobilityId": "f550593ef521d793", "scanner": "scanner-primary", "fingerprint": "202f867c75db2f0e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "domparser_html_parse"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/components/wiki/WikiEditor.vue"}, "region": {"startLine": 166}}}]}, {"ruleId": "scanner-fd2d30649b7b1c13", "level": "warning", "message": {"text": "Insecure pattern 'vue_v_html' in src/components/wiki/WikiContent.vue:2"}, "properties": {"repobilityId": "c41c38265388dbc9", "scanner": "scanner-primary", "fingerprint": "fd2d30649b7b1c13", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "vue_v_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/components/wiki/WikiContent.vue"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-a595e5e73708ede4", "level": "warning", "message": {"text": "Insecure pattern 'vue_v_html' in src/components/forms/ActivityFormModal.vue:314"}, "properties": {"repobilityId": "96ff1e20c25b6b44", "scanner": "scanner-primary", "fingerprint": "a595e5e73708ede4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "vue_v_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/components/forms/ActivityFormModal.vue"}, "region": {"startLine": 314}}}]}, {"ruleId": "scanner-b47c59c3e43fef15", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in src/services/authHeaders.ts:41"}, "properties": {"repobilityId": "23f94f52079b8d8d", "scanner": "scanner-primary", "fingerprint": "b47c59c3e43fef15", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/services/authHeaders.ts"}, "region": {"startLine": 41}}}]}, {"ruleId": "scanner-ba760a258b7dec5e", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in src/services/authService.ts:72"}, "properties": {"repobilityId": "4cca81a2a2671c2f", "scanner": "scanner-primary", "fingerprint": "ba760a258b7dec5e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/services/authService.ts"}, "region": {"startLine": 72}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-28c4a04bd807da0c", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "2aee2e2d969c7c6b", "scanner": "scanner-primary", "fingerprint": "28c4a04bd807da0c", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy.yml"}, "region": {"startLine": 18}}}]}, {"ruleId": "scanner-28c4a04bd807da0c", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "bee6b8956e03198c", "scanner": "scanner-primary", "fingerprint": "28c4a04bd807da0c", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy.yml"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-28c4a04bd807da0c", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ab7ccd611a3fc28e", "scanner": "scanner-primary", "fingerprint": "28c4a04bd807da0c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy.yml"}, "region": {"startLine": 41}}}]}, {"ruleId": "scanner-ad6701f0a8405e22", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "8384c23520d55657", "scanner": "scanner-primary", "fingerprint": "ad6701f0a8405e22", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5ecba37f7a51e364", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "9ab34cbdf90b65fb", "scanner": "scanner-primary", "fingerprint": "5ecba37f7a51e364", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/main_crmcustomertouch.yml"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-5ecba37f7a51e364", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "2f025f909d6e257b", "scanner": "scanner-primary", "fingerprint": "5ecba37f7a51e364", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/main_crmcustomertouch.yml"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-5ecba37f7a51e364", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "5ebc1ff02f2039ff", "scanner": "scanner-primary", "fingerprint": "5ecba37f7a51e364", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/main_crmcustomertouch.yml"}, "region": {"startLine": 34}}}]}, {"ruleId": "scanner-5ecba37f7a51e364", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "08555c160aecc78f", "scanner": "scanner-primary", "fingerprint": "5ecba37f7a51e364", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/main_crmcustomertouch.yml"}, "region": {"startLine": 39}}}]}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "5b6880702dc4fadf", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-11825279136b53a3", "level": "warning", "message": {"text": "CI is configured but no tests are detected"}, "properties": {"repobilityId": "9c096271c98ec782", "scanner": "scanner-primary", "fingerprint": "11825279136b53a3", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "ci", "config-theater", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "c5f69dbf87c78d97", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "5407f49a04219c45", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "fd5a7da35e076f61", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "5df85ad1523e0122", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-bea357a6497a2d5d", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: CLAUDE.md"}, "properties": {"repobilityId": "aae72df3934829ac", "scanner": "scanner-primary", "fingerprint": "bea357a6497a2d5d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "CLAUDE.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2c5f98b152cddb6d", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/launch.json"}, "properties": {"repobilityId": "0de48c0f4ab303d8", "scanner": "scanner-primary", "fingerprint": "2c5f98b152cddb6d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/launch.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7b184ff81a10298b", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/stores/theme.ts:64"}, "properties": {"repobilityId": "cfbc1d73194cdb32", "scanner": "scanner-primary", "fingerprint": "7b184ff81a10298b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ae31a912e444e9c8", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/reportsOverviewService.ts:50"}, "properties": {"repobilityId": "09946ba9af608620", "scanner": "scanner-primary", "fingerprint": "ae31a912e444e9c8", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-02ec00f5362da6fa", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/userService.ts:145"}, "properties": {"repobilityId": "dc87489f806dce71", "scanner": "scanner-primary", "fingerprint": "02ec00f5362da6fa", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-210d45fd22b94561", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/authHeaders.ts:29"}, "properties": {"repobilityId": "d7d49d18953adfce", "scanner": "scanner-primary", "fingerprint": "210d45fd22b94561", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-daca359ffeca8c3f", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/chatService.ts:187"}, "properties": {"repobilityId": "1a94afe52ac4b792", "scanner": "scanner-primary", "fingerprint": "daca359ffeca8c3f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-270d2f0e63044326", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/ticketService.ts:27"}, "properties": {"repobilityId": "2c54ebd4d6d0ead6", "scanner": "scanner-primary", "fingerprint": "270d2f0e63044326", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-de3c533e1977434b", "level": "note", "message": {"text": "Unused endpoint: GET /avatars"}, "properties": {"repobilityId": "c9ce48b037a065a5", "scanner": "scanner-primary", "fingerprint": "de3c533e1977434b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-897e09906521bec3", "level": "note", "message": {"text": "Unused endpoint: GET /avatars/user"}, "properties": {"repobilityId": "ce9043c297199750", "scanner": "scanner-primary", "fingerprint": "897e09906521bec3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5383ab72ec22f540", "level": "note", "message": {"text": "Unused endpoint: PUT /avatars/user"}, "properties": {"repobilityId": "f48a2741c3e49611", "scanner": "scanner-primary", "fingerprint": "5383ab72ec22f540", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2ac4c5a997c00390", "level": "note", "message": {"text": "Unused endpoint: DELETE /avatars/user"}, "properties": {"repobilityId": "8d26fea17ddeb79e", "scanner": "scanner-primary", "fingerprint": "2ac4c5a997c00390", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4e4ab99927ecb757", "level": "note", "message": {"text": "Unused endpoint: POST /avatars/upload-photo"}, "properties": {"repobilityId": "ea2efb4b8b195229", "scanner": "scanner-primary", "fingerprint": "4e4ab99927ecb757", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-152ad529b10a6a7c", "level": "note", "message": {"text": "Unused endpoint: DELETE /avatars/photo"}, "properties": {"repobilityId": "ee29946ee5817a06", "scanner": "scanner-primary", "fingerprint": "152ad529b10a6a7c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f83a34a970710cae", "level": "note", "message": {"text": "Unused endpoint: GET /avatars/stats"}, "properties": {"repobilityId": "f89b643544d91913", "scanner": "scanner-primary", "fingerprint": "f83a34a970710cae", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8fdbacfe9430a6ed", "level": "note", "message": {"text": "Unused endpoint: POST /auth/login"}, "properties": {"repobilityId": "a6f97bbb9f8319e5", "scanner": "scanner-primary", "fingerprint": "8fdbacfe9430a6ed", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f482a683253c5509", "level": "note", "message": {"text": "Unused endpoint: POST /auth/register-org"}, "properties": {"repobilityId": "9414459d2b90f880", "scanner": "scanner-primary", "fingerprint": "f482a683253c5509", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c25c877105f4ce5f", "level": "note", "message": {"text": "Unused endpoint: POST /auth/verify-2fa"}, "properties": {"repobilityId": "8527683c847b9937", "scanner": "scanner-primary", "fingerprint": "c25c877105f4ce5f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c059f57186114027", "level": "note", "message": {"text": "Unused endpoint: POST /auth/logout"}, "properties": {"repobilityId": "ff347131da001d12", "scanner": "scanner-primary", "fingerprint": "c059f57186114027", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-021eacddceea7c7c", "level": "note", "message": {"text": "Unused endpoint: POST /auth/verify-token"}, "properties": {"repobilityId": "58cbf7c648064136", "scanner": "scanner-primary", "fingerprint": "021eacddceea7c7c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-647ec4a4f702c47a", "level": "note", "message": {"text": "Unused endpoint: POST /auth/select-org"}, "properties": {"repobilityId": "b2f73428c8bf744d", "scanner": "scanner-primary", "fingerprint": "647ec4a4f702c47a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9c44c940210b007b", "level": "note", "message": {"text": "Unused endpoint: GET /auth/memberships"}, "properties": {"repobilityId": "1859feca6e3846b7", "scanner": "scanner-primary", "fingerprint": "9c44c940210b007b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9143464946a01de5", "level": "note", "message": {"text": "Unused endpoint: PUT /auth/profile"}, "properties": {"repobilityId": "52bb9829865fd9c0", "scanner": "scanner-primary", "fingerprint": "9143464946a01de5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-acfc2ed20c4bb703", "level": "note", "message": {"text": "Unused endpoint: PUT /auth/change-password"}, "properties": {"repobilityId": "d34889c7bff751ca", "scanner": "scanner-primary", "fingerprint": "acfc2ed20c4bb703", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e2fe5b92648ca462", "level": "note", "message": {"text": "Unused endpoint: POST /auth/forgot-password"}, "properties": {"repobilityId": "f4b471c3f6102b9d", "scanner": "scanner-primary", "fingerprint": "e2fe5b92648ca462", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-deb8df763a50c73a", "level": "note", "message": {"text": "Unused endpoint: POST /auth/reset-password"}, "properties": {"repobilityId": "b5e3a7db6177b11e", "scanner": "scanner-primary", "fingerprint": "deb8df763a50c73a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-88a29b8a5c158e5b", "level": "note", "message": {"text": "Unused endpoint: GET /roles"}, "properties": {"repobilityId": "ba3f9499fb05d4df", "scanner": "scanner-primary", "fingerprint": "88a29b8a5c158e5b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-078b3f8a9311d56a", "level": "note", "message": {"text": "Unused endpoint: POST /roles"}, "properties": {"repobilityId": "4bfdaa4d9eb7ea18", "scanner": "scanner-primary", "fingerprint": "078b3f8a9311d56a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6b95b7f414083427", "level": "note", "message": {"text": "Unused endpoint: GET /admin/organizations"}, "properties": {"repobilityId": "5c07e56adea692f9", "scanner": "scanner-primary", "fingerprint": "6b95b7f414083427", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-07ef5d265df423f3", "level": "note", "message": {"text": "Unused endpoint: POST /admin/organizations"}, "properties": {"repobilityId": "70eddcd1a55f7708", "scanner": "scanner-primary", "fingerprint": "07ef5d265df423f3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6f174755b2041b5b", "level": "note", "message": {"text": "Unused endpoint: GET /admin/super-admins"}, "properties": {"repobilityId": "e99137670a103d89", "scanner": "scanner-primary", "fingerprint": "6f174755b2041b5b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-52106b43a72b4141", "level": "note", "message": {"text": "Unused endpoint: GET /admin/audit-logs"}, "properties": {"repobilityId": "a927dc5270bc14d8", "scanner": "scanner-primary", "fingerprint": "52106b43a72b4141", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}