{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-901679837c50fd78", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 electron-app/src/renderer/src/ui/components/AiAgentChat.tsx:511", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 electron-app/src/renderer/src/ui/components/AiAgentChat.tsx:511"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-55ce3ca82bc7f273", "name": "React Flow edge with `label=` but no project-wide edge-label CSS override \u2014 electron-app/src/renderer/src/ui/pages/ToolD", "shortDescription": {"text": "React Flow edge with `label=` but no project-wide edge-label CSS override \u2014 electron-app/src/renderer/src/ui/pages/ToolDetailsPage.tsx:282"}, "fullDescription": {"text": "React Flow edge labels render with a white rectangle behind the text by default, which scatters bright boxes across a dark canvas. Either drop the label, or override `.react-flow__edge-textbg` and `.react-flow__edge-text` in your stylesheet.\n\nWhy: P-H in CHECKLIST.md \u2014 vendor edge labels bleed white through a dark canvas.\nRule id: fq.edge-label.no-bg"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b9105ce8ccb5eca2", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 electron-app/src/renderer/src/ui/pages/ReportPresetPage.tsx:1053", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 electron-app/src/renderer/src/ui/pages/ReportPresetPage.tsx:1053"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8593ce78fe938e9c", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 electron-app/src/renderer/src/ui/pages/ReportsPage.tsx:525", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 electron-app/src/renderer/src/ui/pages/ReportsPage.tsx:525"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5d36c8528cffca33", "name": "Stray `console.log` in TS/JS \u2014 electron-app/src/main/services/blockmapDelta.measure.test.ts:45", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 electron-app/src/main/services/blockmapDelta.measure.test.ts:45"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cbe38d001d66f513", "name": "Stray `console.log` in TS/JS \u2014 electron-app/src/main/services/partsService.ts:120", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 electron-app/src/main/services/partsService.ts:120"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6bf8ae6c266d6bce", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/migrateChecklistToEngineInventory.ts:97", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/migrateChecklistToEngineInventory.ts:97"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-063e365eec606e4a", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/fixChatPermissions.ts:41", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/fixChatPermissions.ts:41"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9e3dafed29f973bc", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/unifyPartIdConvention.ts:136", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/unifyPartIdConvention.ts:136"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9df502a57c82cb30", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/cleanupBulkEntityTypes.ts:71", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/cleanupBulkEntityTypes.ts:71"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d9c2e3e9a2daba83", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/importBasePartsList.ts:184", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/importBasePartsList.ts:184"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ccbf9b366748d422", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/warehouseThreeLevelDryRun.ts:267", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/warehouseThreeLevelDryRun.ts:267"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5c73882a08594753", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/cleanupChatMessages.ts:43", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/cleanupChatMessages.ts:43"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b618a761ff93a777", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/rebuildLedgerTxIndex.ts:13", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/rebuildLedgerTxIndex.ts:13"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eb46078d29fa6342", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/touchMasterdataForSync.ts:141", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/touchMasterdataForSync.ts:141"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-88950fc5b500c692", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/seedNomenclatureVerifyFixture.ts:239", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/seedNomenclatureVerifyFixture.ts:239"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-14c19e1f26315b9e", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillMovementEngineId.ts:39", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillMovementEngineId.ts:39"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b88e2f97e61c2820", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/cleanupEmptyEntities.ts:145", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/cleanupEmptyEntities.ts:145"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-749e7824e72e5d3a", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillMasterdataToLedger.ts:206", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillMasterdataToLedger.ts:206"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-48673b56cbb0eed3", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/seedVariantBomVerifyFixture.ts:125", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/seedVariantBomVerifyFixture.ts:125"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5a11b642c6931029", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/erpLegacyCleanup.ts:32", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/erpLegacyCleanup.ts:32"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dbe4fc7fe4af4026", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/importEngineBrandPartMatrix.ts:300", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/importEngineBrandPartMatrix.ts:300"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1d39303df9eb08fa", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/seedPermissions.ts:16", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/seedPermissions.ts:16"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-96f400e3400c59b5", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/checkSyncContract.ts:27", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/checkSyncContract.ts:27"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b3d96a2702beebcc", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillDirectoryBrandLinksFromEav.ts:210", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillDirectoryBrandLinksFromEav.ts:210"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-09b18207a354e751", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/migrateUsersToEmployees.ts:84", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/migrateUsersToEmployees.ts:84"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7f25639c3e4b8c75", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillNomenclatureGovernance.ts:170", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillNomenclatureGovernance.ts:170"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-09e681969e52f659", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/auditPartsMirror.ts:61", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/auditPartsMirror.ts:61"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-97db15b696000a7a", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/migrateExistingWorkshopOrders.ts:77", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/migrateExistingWorkshopOrders.ts:77"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9f5ff6e12763649e", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/dedupeEngines.ts:22", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/dedupeEngines.ts:22"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2a0726e1b8299415", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillDirectoryEngineBrands.ts:75", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillDirectoryEngineBrands.ts:75"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d531d2def0591a80", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/fixPartsMirror.ts:178", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/fixPartsMirror.ts:178"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-454e0433d93e2a0b", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillStockBalanceNomenclature.ts:16", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillStockBalanceNomenclature.ts:16"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-84cf67bafeda39de", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/ledgerReplayToDb.ts:10", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/ledgerReplayToDb.ts:10"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c364c21e85412faa", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillOrphanPartNomenclature.ts:23", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillOrphanPartNomenclature.ts:23"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-78ee8349fee3f309", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/rotateLedgerDataKey.ts:91", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/rotateLedgerDataKey.ts:91"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-96f80a2908cd6b92", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/canonicalizeLedgerTypes.ts:252", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/canonicalizeLedgerTypes.ts:252"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dd1ee37a6da6bc9e", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/softDeleteLegacyRepairOperations.ts:63", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/softDeleteLegacyRepairOperations.ts:63"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9a089fd157cea168", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillDirectoryPartsMetadata.ts:152", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillDirectoryPartsMetadata.ts:152"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4b22cd210cde4acc", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/dryRunDirectoriesToNomenclature.ts:150", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/dryRunDirectoriesToNomenclature.ts:150"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0d0e5908525f7c20", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/cleanupChatFiles.ts:74", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/cleanupChatFiles.ts:74"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5f529e8c5bb25472", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/bootstrapDevEntityTypes.ts:76", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/bootstrapDevEntityTypes.ts:76"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fc7671ea078dd691", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/fixLedgerEntitiesMissingType.ts:69", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/fixLedgerEntitiesMissingType.ts:69"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d585b82c83ffa361", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/migrateEavToErp.ts:237", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/migrateEavToErp.ts:237"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-87bb1092aae1d617", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/dedupeMasterdata.ts:120", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/dedupeMasterdata.ts:120"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fe6e76c988e7a515", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/enableClientLogging.ts:13", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/enableClientLogging.ts:13"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d69227e0ff94b294", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/migrateWorkshopTemplatesToWorkOrderTemplates.ts:99", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/migrateWorkshopTemplatesToWorkOrderTemplates.ts:99"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fbf1efaa875c1fbf", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/nightlyBackup.ts:343", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/nightlyBackup.ts:343"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2e68c1754daf7f1d", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/seedDevFixtures.ts:245", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/seedDevFixtures.ts:245"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3479c34e49868c29", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/mergeCounterparties.ts:531", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/mergeCounterparties.ts:531"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-38c5d8daf8cd508b", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillDirectoryParts.ts:144", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillDirectoryParts.ts:144"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c1dabbe2df790196", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/seedBaseCategories.ts:89", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/seedBaseCategories.ts:89"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8b0ab0ccf2173739", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/tightenGlobalUiDensity.ts:56", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/tightenGlobalUiDensity.ts:56"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9a049bf6e206b542", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillWarehouseLocations.ts:75", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillWarehouseLocations.ts:75"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ed713f7e788f40de", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/emitSyncSnapshot.ts:64", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/emitSyncSnapshot.ts:64"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fa78960dffca19d9", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/createUser.ts:72", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/createUser.ts:72"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-86b6354d974f3b12", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/migrateDirectoriesToNomenclature.ts:334", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/migrateDirectoriesToNomenclature.ts:334"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f0d8e691102b9a27", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/importContractsGoz.ts:571", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/importContractsGoz.ts:571"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1363ce00c9467c10", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/seedNomenclatureGroups.ts:123", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/seedNomenclatureGroups.ts:123"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c6663289453e4325", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillChangeLog.ts:314", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillChangeLog.ts:314"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a6338fd1ec2a815", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/migrateComponentTypeFromSpecJson.ts:80", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/migrateComponentTypeFromSpecJson.ts:80"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e94d6e806870371c", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/importEnginesFromCompletenessCsv.ts:71", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/importEnginesFromCompletenessCsv.ts:71"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-878833b956d0649f", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/mergeWarehouseLocations.ts:69", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/mergeWarehouseLocations.ts:69"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f0567d11ad80345a", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/emitMasterdataLedgerSnapshot.ts:5", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/emitMasterdataLedgerSnapshot.ts:5"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c539e18673909d9d", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/utils/logger.ts:32", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/utils/logger.ts:32"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7657f6ca56012c69", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/database/migrate.ts:7", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/database/migrate.ts:7"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0cae51fff496bf2d", "name": "Stray `console.log` in TS/JS \u2014 backend-api/src/services/ai/aiChatHistoryService.ts:222", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/services/ai/aiChatHistoryService.ts:222"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f42d7635723f70f2", "name": "React Flow edge with `label=` but no project-wide edge-label CSS override \u2014 web-admin/src/ui/components/RepairChecklistP", "shortDescription": {"text": "React Flow edge with `label=` but no project-wide edge-label CSS override \u2014 web-admin/src/ui/components/RepairChecklistPanel.tsx:749"}, "fullDescription": {"text": "React Flow edge labels render with a white rectangle behind the text by default, which scatters bright boxes across a dark canvas. Either drop the label, or override `.react-flow__edge-textbg` and `.react-flow__edge-text` in your stylesheet.\n\nWhy: P-H in CHECKLIST.md \u2014 vendor edge labels bleed white through a dark canvas.\nRule id: fq.edge-label.no-bg"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b05fcfeac3258fa5", "name": "Privileged port 17 in use", "shortDescription": {"text": "Privileged port 17 in use"}, "fullDescription": {"text": "Port 17 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7ced02fe8565a19c", "name": "Privileged port 23 in use", "shortDescription": {"text": "Privileged port 23 in use"}, "fullDescription": {"text": "Port 23 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3326eefbf9056d70", "name": "Insecure pattern 'direct_innerhtml_assignment' in electron-app/src/renderer/public/update.html:128", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in electron-app/src/renderer/public/update.html:128"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b879d0dcaef2f6a5", "name": "Insecure pattern 'direct_innerhtml_assignment' in electron-app/src/renderer/src/main.tsx:42", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in electron-app/src/renderer/src/main.tsx:42"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4fe84bb071ec5f9a", "name": "Insecure pattern 'document_write' in electron-app/src/renderer/src/ui/utils/printPreview.ts:108", "shortDescription": {"text": "Insecure pattern 'document_write' in electron-app/src/renderer/src/ui/utils/printPreview.ts:108"}, "fullDescription": {"text": "Found a known-risky pattern (document_write). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-87925ecdf7efa838", "name": "Insecure pattern 'document_write' in electron-app/src/renderer/src/ui/utils/engineInventoryPrintHtml.ts:367", "shortDescription": {"text": "Insecure pattern 'document_write' in electron-app/src/renderer/src/ui/utils/engineInventoryPrintHtml.ts:367"}, "fullDescription": {"text": "Found a known-risky pattern (document_write). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-64bc4404505a8fcf", "name": "Insecure pattern 'document_write' in electron-app/src/renderer/src/ui/components/RepairChecklistPanel.tsx:1369", "shortDescription": {"text": "Insecure pattern 'document_write' in electron-app/src/renderer/src/ui/components/RepairChecklistPanel.tsx:1369"}, "fullDescription": {"text": "Found a known-risky pattern (document_write). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dbb89a394a164ede", "name": "Insecure pattern 'dangerous_innerhtml' in electron-app/src/renderer/src/ui/components/AiAgentChat.tsx:511", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in electron-app/src/renderer/src/ui/components/AiAgentChat.tsx:511"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a0d6b3f321e77f2b", "name": "Insecure pattern 'dangerous_innerhtml' in electron-app/src/renderer/src/ui/pages/ReportPresetPage.tsx:1053", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in electron-app/src/renderer/src/ui/pages/ReportPresetPage.tsx:1053"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-02d29e80eaac34e2", "name": "Insecure pattern 'dangerous_innerhtml' in electron-app/src/renderer/src/ui/pages/ReportsPage.tsx:525", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in electron-app/src/renderer/src/ui/pages/ReportsPage.tsx:525"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e2686b42dd099664", "name": "Insecure pattern 'node_child_process' in electron-app/src/main/services/updateService.ts:3", "shortDescription": {"text": "Insecure pattern 'node_child_process' in electron-app/src/main/services/updateService.ts:3"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7e65710c33437fed", "name": "Insecure pattern 'node_child_process' in electron-app/src/main/services/emergencyUpdate.ts:10", "shortDescription": {"text": "Insecure pattern 'node_child_process' in electron-app/src/main/services/emergencyUpdate.ts:10"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9e66a8b7f431ac59", "name": "Insecure pattern 'private_key_in_repo' in backend-api/ledger/server-key.json:3", "shortDescription": {"text": "Insecure pattern 'private_key_in_repo' in backend-api/ledger/server-key.json:3"}, "fullDescription": {"text": "Found a known-risky pattern (private_key_in_repo). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-61a4515a733bb896", "name": "Insecure pattern 'cors_wildcard' in backend-api/src/app.ts:55", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in backend-api/src/app.ts:55"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fe254666dfec8183", "name": "Insecure pattern 'node_child_process' in backend-api/src/scripts/nightlyBackup.ts:2", "shortDescription": {"text": "Insecure pattern 'node_child_process' in backend-api/src/scripts/nightlyBackup.ts:2"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b331578528b45e1a", "name": "Insecure pattern 'node_child_process' in backend-api/src/routes/backups.ts:3", "shortDescription": {"text": "Insecure pattern 'node_child_process' in backend-api/src/routes/backups.ts:3"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aa21d2973bd6dbe1", "name": "Insecure pattern 'document_write' in web-admin/src/ui/EngineDetailsPage.tsx:114", "shortDescription": {"text": "Insecure pattern 'document_write' in web-admin/src/ui/EngineDetailsPage.tsx:114"}, "fullDescription": {"text": "Found a known-risky pattern (document_write). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d288a9769c62d8d2", "name": "Insecure pattern 'document_write' in web-admin/src/ui/components/RepairChecklistPanel.tsx:642", "shortDescription": {"text": "Insecure pattern 'document_write' in web-admin/src/ui/components/RepairChecklistPanel.tsx:642"}, "fullDescription": {"text": "Found a known-risky pattern (document_write). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f03eccd2234cb56f", "name": "Insecure pattern 'node_child_process' in scripts/bump-backend-version.mjs:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/bump-backend-version.mjs:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3ce9e47a75f30422", "name": "Insecure pattern 'node_child_process' in scripts/run-with-backend-env.mjs:4", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/run-with-backend-env.mjs:4"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fe5824b3872b6d70", "name": "Insecure pattern 'node_child_process' in scripts/publish-ledger-release.mjs:15", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/publish-ledger-release.mjs:15"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ad8ba3ddd200089f", "name": "Insecure pattern 'node_child_process' in scripts/release-auto.mjs:2", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/release-auto.mjs:2"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8f4c232b4aa78fc9", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v5 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-47019809066cf7f6", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v5 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-266162aa2c525a31", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v5 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a9b6dd5d37f3e59d", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v5 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-12522bf27bea173c", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v5 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9f4aee53bdfaab38", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v5 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0b128f7d6f786b46", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f12cfa59ab2159bc", "name": "package.json defines install-time lifecycle scripts", "shortDescription": {"text": "package.json defines install-time lifecycle scripts"}, "fullDescription": {"text": "preinstall/install/postinstall/prepare scripts execute during dependency installation. Review them carefully for network calls, obfuscation, shell execution, or credential access."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c2632ea9a191a687", "name": "package.json defines install-time lifecycle scripts", "shortDescription": {"text": "package.json defines install-time lifecycle scripts"}, "fullDescription": {"text": "preinstall/install/postinstall/prepare scripts execute during dependency installation. Review them carefully for network calls, obfuscation, shell execution, or credential access."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-37cbb120632af5e6", "name": "Very large file: electron-app/src/renderer/src/ui/App.tsx (4200 lines)", "shortDescription": {"text": "Very large file: electron-app/src/renderer/src/ui/App.tsx (4200 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-47ee1d4663d7cf81", "name": "Very large file: electron-app/src/renderer/src/ui/components/RepairChecklistPanel.tsx (2753 lines)", "shortDescription": {"text": "Very large file: electron-app/src/renderer/src/ui/components/RepairChecklistPanel.tsx (2753 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6e80dba5ca459e0f", "name": "Very large file: electron-app/src/renderer/src/ui/pages/EngineDetailsPage.tsx (1180 lines)", "shortDescription": {"text": "Very large file: electron-app/src/renderer/src/ui/pages/EngineDetailsPage.tsx (1180 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-23b39356d3429e9c", "name": "Very large file: electron-app/src/renderer/src/ui/pages/EngineAssemblyBomDetailsPage.tsx (2204 lines)", "shortDescription": {"text": "Very large file: electron-app/src/renderer/src/ui/pages/EngineAssemblyBomDetailsPage.tsx (2204 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f1d0b849768ad225", "name": "Very large file: electron-app/src/renderer/src/ui/pages/WorkOrderDetailsPage.tsx (1989 lines)", "shortDescription": {"text": "Very large file: electron-app/src/renderer/src/ui/pages/WorkOrderDetailsPage.tsx (1989 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eca8347e82131368", "name": "Very large file: electron-app/src/renderer/src/ui/pages/SupplyRequestDetailsPage.tsx (1496 lines)", "shortDescription": {"text": "Very large file: electron-app/src/renderer/src/ui/pages/SupplyRequestDetailsPage.tsx (1496 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-565824c8dd79f7e1", "name": "Very large file: electron-app/src/renderer/src/ui/pages/ContractDetailsPage.tsx (1768 lines)", "shortDescription": {"text": "Very large file: electron-app/src/renderer/src/ui/pages/ContractDetailsPage.tsx (1768 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b85a4a29f232bf46", "name": "Very large file: electron-app/src/renderer/src/ui/pages/AdminPage.tsx (1986 lines)", "shortDescription": {"text": "Very large file: electron-app/src/renderer/src/ui/pages/AdminPage.tsx (1986 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-099b6c220dca032c", "name": "Very large file: electron-app/src/renderer/src/ui/pages/PartDetailsPage.tsx (2819 lines)", "shortDescription": {"text": "Very large file: electron-app/src/renderer/src/ui/pages/PartDetailsPage.tsx (2819 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e375a84a768a78dd", "name": "Very large file: electron-app/src/renderer/src/ui/pages/ReportPresetPage.tsx (1124 lines)", "shortDescription": {"text": "Very large file: electron-app/src/renderer/src/ui/pages/ReportPresetPage.tsx (1124 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0602f95ae95a9a92", "name": "Very large file: electron-app/src/renderer/src/ui/pages/NomenclatureDetailsPage.tsx (1280 lines)", "shortDescription": {"text": "Very large file: electron-app/src/renderer/src/ui/pages/NomenclatureDetailsPage.tsx (1280 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9bc0e4d0483576ec", "name": "Very large file: electron-app/src/renderer/src/ui/pages/EmployeeDetailsPage.tsx (1873 lines)", "shortDescription": {"text": "Very large file: electron-app/src/renderer/src/ui/pages/EmployeeDetailsPage.tsx (1873 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-501c8f39c1944332", "name": "Very large file: electron-app/src/main/services/toolsService.ts (1290 lines)", "shortDescription": {"text": "Very large file: electron-app/src/main/services/toolsService.ts (1290 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-207b40a985639836", "name": "Very large file: electron-app/src/main/services/updateService.ts (3173 lines)", "shortDescription": {"text": "Very large file: electron-app/src/main/services/updateService.ts (3173 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4f108bff18807a76", "name": "Very large file: electron-app/src/main/services/reportPresetService.ts (4560 lines)", "shortDescription": {"text": "Very large file: electron-app/src/main/services/reportPresetService.ts (4560 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4f7da332e5b6a78b", "name": "Very large file: electron-app/src/main/services/syncService.ts (3220 lines)", "shortDescription": {"text": "Very large file: electron-app/src/main/services/syncService.ts (3220 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4e9d88862f13abce", "name": "Very large file: electron-app/src/main/services/erpService.ts (1586 lines)", "shortDescription": {"text": "Very large file: electron-app/src/main/services/erpService.ts (1586 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-160da9bd3d6c6f57", "name": "Very large file: backend-api/src/scripts/importEnginesFromCompletenessCsv.ts (1312 lines)", "shortDescription": {"text": "Very large file: backend-api/src/scripts/importEnginesFromCompletenessCsv.ts (1312 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4d2e0e80ae79116e", "name": "Very large file: backend-api/src/database/schema.ts (1389 lines)", "shortDescription": {"text": "Very large file: backend-api/src/database/schema.ts (1389 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-feb2d52c332e6a69", "name": "Very large file: backend-api/src/routes/warehouse.ts (1122 lines)", "shortDescription": {"text": "Very large file: backend-api/src/routes/warehouse.ts (1122 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-01ca4246d4c94acd", "name": "Very large file: backend-api/src/services/warehouseBomService.ts (1318 lines)", "shortDescription": {"text": "Very large file: backend-api/src/services/warehouseBomService.ts (1318 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-19ec9bde90c07cdd", "name": "Very large file: backend-api/src/services/warehouseService.ts (3602 lines)", "shortDescription": {"text": "Very large file: backend-api/src/services/warehouseService.ts (3602 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-06795c86b88b8065", "name": "Very large file: backend-api/src/services/sync/applyPushBatch.ts (1667 lines)", "shortDescription": {"text": "Very large file: backend-api/src/services/sync/applyPushBatch.ts (1667 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-58e5bb34faeb6a0a", "name": "Very large file: web-admin/src/ui/AdminUsersPage.tsx (1064 lines)", "shortDescription": {"text": "Very large file: web-admin/src/ui/AdminUsersPage.tsx (1064 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5dbee85799eef32b", "name": "Very large file: web-admin/src/ui/AdminPage.tsx (1886 lines)", "shortDescription": {"text": "Very large file: web-admin/src/ui/AdminPage.tsx (1886 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d0ec23c0904687b8", "name": "Very large file: shared/src/ipc/types.ts (1747 lines)", "shortDescription": {"text": "Very large file: shared/src/ipc/types.ts (1747 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aaa2dad3e5f49058", "name": "Very large file: shared/src/domain/assemblyForecast.ts (1236 lines)", "shortDescription": {"text": "Very large file: shared/src/domain/assemblyForecast.ts (1236 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-58517a60886cf90b", "name": "Very large file: shared/src/domain/releaseWelcome.ts (2202 lines)", "shortDescription": {"text": "Very large file: shared/src/domain/releaseWelcome.ts (2202 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea3b5e389d8c9c0f", "name": "Low test-to-source ratio", "shortDescription": {"text": "Low test-to-source ratio"}, "fullDescription": {"text": "87 tests / 530 src (ratio 0.16)."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f004592ea670ecd8", "name": "Node manifest has dependencies but no lockfile: electron-app/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: electron-app/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4ba7bf03eee0f05b", "name": "Node manifest has dependencies but no lockfile: backend-api/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: backend-api/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-feb3f31ed6425312", "name": "Node manifest has dependencies but no lockfile: web-admin/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: web-admin/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2b3b4131c0cb2eaa", "name": "Node manifest has dependencies but no lockfile: shared/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: shared/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa902b1772572e86", "name": "Node manifest has dependencies but no lockfile: ledger/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: ledger/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 382 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 330 placeholder/mock markers across 84 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9d79c4077342a7d0", "name": "Runtime service client appears to use placeholder configuration", "shortDescription": {"text": "Runtime service client appears to use placeholder configuration"}, "fullDescription": {"text": "A runtime source file appears to wire Supabase/Firebase/AI/payment-style clients to placeholder URLs, keys, or fallback values. In the Fable corpus this often means the UI/API shape is present while the backend service is not actually configured."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, lockfile. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license, lockfile. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-122f91b7f2906dc4", "name": "Agent authority lacks a verifier contract: .claude/settings.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/settings.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b1c5c6472f566842", "name": "Legacy-named symbol `matrica_client_input_assist_history_v1` in electron-app/src/renderer/src/ui/App.tsx:4194", "shortDescription": {"text": "Legacy-named symbol `matrica_client_input_assist_history_v1` in electron-app/src/renderer/src/ui/App.tsx:4194"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-12f5f99d057b38ec", "name": "Commented-code block (6 lines) in electron-app/src/renderer/src/ui/utils/partsPagination.ts:13", "shortDescription": {"text": "Commented-code block (6 lines) in electron-app/src/renderer/src/ui/utils/partsPagination.ts:13"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-43b495520c75fe6c", "name": "Commented-code block (5 lines) in electron-app/src/renderer/src/ui/components/RepairChecklistPanel.tsx:2262", "shortDescription": {"text": "Commented-code block (5 lines) in electron-app/src/renderer/src/ui/components/RepairChecklistPanel.tsx:2262"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-34147fa005ad75e2", "name": "Legacy-named symbol `parts_movement_v1` in electron-app/src/renderer/src/ui/components/EngineDismantlePreviewDialog.tsx:", "shortDescription": {"text": "Legacy-named symbol `parts_movement_v1` in electron-app/src/renderer/src/ui/components/EngineDismantlePreviewDialog.tsx:196"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b0b42d1beb5eec14", "name": "Commented-code block (5 lines) in electron-app/src/renderer/src/ui/pages/EngineDetailsPage.tsx:24", "shortDescription": {"text": "Commented-code block (5 lines) in electron-app/src/renderer/src/ui/pages/EngineDetailsPage.tsx:24"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-72733448902bc96b", "name": "Legacy-named symbol `bom_relation_schema_v1` in electron-app/src/renderer/src/ui/pages/EngineAssemblyBomDetailsPage.tsx:", "shortDescription": {"text": "Legacy-named symbol `bom_relation_schema_v1` in electron-app/src/renderer/src/ui/pages/EngineAssemblyBomDetailsPage.tsx:480"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-87300f0d404c39f3", "name": "Commented-code block (6 lines) in electron-app/src/renderer/src/ui/pages/EngineAssemblyBomDetailsPage.tsx:719", "shortDescription": {"text": "Commented-code block (6 lines) in electron-app/src/renderer/src/ui/pages/EngineAssemblyBomDetailsPage.tsx:719"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7cc1c50e57863002", "name": "Commented-code block (6 lines) in electron-app/src/renderer/src/ui/pages/WorkOrderDetailsPage.tsx:1529", "shortDescription": {"text": "Commented-code block (6 lines) in electron-app/src/renderer/src/ui/pages/WorkOrderDetailsPage.tsx:1529"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4985cac3ba625406", "name": "Legacy-named symbol `contractSectionsToLegacy` in electron-app/src/renderer/src/ui/pages/ContractDetailsPage.tsx:22", "shortDescription": {"text": "Legacy-named symbol `contractSectionsToLegacy` in electron-app/src/renderer/src/ui/pages/ContractDetailsPage.tsx:22"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ba3a4c1a5ca23925", "name": "Commented-code block (6 lines) in electron-app/src/renderer/src/ui/pages/ContractsPage.tsx:193", "shortDescription": {"text": "Commented-code block (6 lines) in electron-app/src/renderer/src/ui/pages/ContractsPage.tsx:193"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b62e83cb2070ccb0", "name": "Legacy-named symbol `supplierLegacy` in electron-app/src/renderer/src/ui/pages/PartDetailsPage.tsx:112", "shortDescription": {"text": "Legacy-named symbol `supplierLegacy` in electron-app/src/renderer/src/ui/pages/PartDetailsPage.tsx:112"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4bf13c63caf3d615", "name": "Commented-code block (5 lines) in electron-app/src/renderer/src/ui/pages/PartDetailsPage.tsx:226", "shortDescription": {"text": "Commented-code block (5 lines) in electron-app/src/renderer/src/ui/pages/PartDetailsPage.tsx:226"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-09b671c39e215b93", "name": "Commented-code block (6 lines) in electron-app/src/renderer/src/ui/pages/NomenclatureDetailsPage.tsx:525", "shortDescription": {"text": "Commented-code block (6 lines) in electron-app/src/renderer/src/ui/pages/NomenclatureDetailsPage.tsx:525"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-86a993bf24b5fefd", "name": "Commented-code block (8 lines) in electron-app/src/renderer/src/ui/pages/StockDocumentDetailsPage.tsx:362", "shortDescription": {"text": "Commented-code block (8 lines) in electron-app/src/renderer/src/ui/pages/StockDocumentDetailsPage.tsx:362"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-eaed041eaa10c306", "name": "Commented-code block (6 lines) in electron-app/src/main/index.ts:48", "shortDescription": {"text": "Commented-code block (6 lines) in electron-app/src/main/index.ts:48"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-14b44c7e5b024102", "name": "Commented-code block (5 lines) in electron-app/src/main/utils/logger.ts:7", "shortDescription": {"text": "Commented-code block (5 lines) in electron-app/src/main/utils/logger.ts:7"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e42989f505671965", "name": "Commented-code block (7 lines) in electron-app/src/main/database/migrate.ts:17", "shortDescription": {"text": "Commented-code block (7 lines) in electron-app/src/main/database/migrate.ts:17"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8ca9b1a6b8695b15", "name": "Legacy-named symbol `force_full_pull_v2` in electron-app/src/main/services/clientAdminService.ts:62", "shortDescription": {"text": "Legacy-named symbol `force_full_pull_v2` in electron-app/src/main/services/clientAdminService.ts:62"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9b754730dffefd42", "name": "`fetch()` without try/.catch or AbortSignal \u2014 electron-app/src/main/services/clientAdminService.ts:97", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 electron-app/src/main/services/clientAdminService.ts:97"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c7ed445ec47a9ca1", "name": "Commented-code block (7 lines) in electron-app/src/main/services/blockmapDelta.measure.test.ts:1", "shortDescription": {"text": "Commented-code block (7 lines) in electron-app/src/main/services/blockmapDelta.measure.test.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c1875c965e3b0491", "name": "Commented-code block (7 lines) in electron-app/src/main/services/yandexResourceMeta.ts:4", "shortDescription": {"text": "Commented-code block (7 lines) in electron-app/src/main/services/yandexResourceMeta.ts:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0c256590a309d95a", "name": "Commented-code block (5 lines) in electron-app/src/main/services/updateService.ts:805", "shortDescription": {"text": "Commented-code block (5 lines) in electron-app/src/main/services/updateService.ts:805"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-34b127adcb69abc3", "name": "Commented-code block (7 lines) in electron-app/src/main/services/installerIntegrityRecovery.ts:4", "shortDescription": {"text": "Commented-code block (7 lines) in electron-app/src/main/services/installerIntegrityRecovery.ts:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-078b5c5505221ab6", "name": "`fetch()` without try/.catch or AbortSignal \u2014 electron-app/src/main/services/fileService.ts:445", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 electron-app/src/main/services/fileService.ts:445"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-82e5e6007b18e994", "name": "Commented-code block (7 lines) in electron-app/src/main/services/emergencyUpdate.ts:1", "shortDescription": {"text": "Commented-code block (7 lines) in electron-app/src/main/services/emergencyUpdate.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a3537a79eec22ac1", "name": "Commented-code block (7 lines) in electron-app/src/main/services/syncService.ts:1358", "shortDescription": {"text": "Commented-code block (7 lines) in electron-app/src/main/services/syncService.ts:1358"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3db8e6a531d8c450", "name": "`fetch()` without try/.catch or AbortSignal \u2014 electron-app/src/main/services/backupService.ts:77", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 electron-app/src/main/services/backupService.ts:77"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dce5e4faf41d2ead", "name": "Commented-code block (5 lines) in backend-api/src/tests/warehouseBomUpsert.integration.test.ts:8", "shortDescription": {"text": "Commented-code block (5 lines) in backend-api/src/tests/warehouseBomUpsert.integration.test.ts:8"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ac40c7f3e99a9a1f", "name": "Legacy-named symbol `bom_line_meta_v1` in backend-api/src/tests/assemblyForecastKitBuilder.test.ts:121", "shortDescription": {"text": "Legacy-named symbol `bom_line_meta_v1` in backend-api/src/tests/assemblyForecastKitBuilder.test.ts:121"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c9d104b9c17e9d63", "name": "Commented-code block (7 lines) in backend-api/src/tests/assemblyForecastKitBuilder.test.ts:5", "shortDescription": {"text": "Commented-code block (7 lines) in backend-api/src/tests/assemblyForecastKitBuilder.test.ts:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4796f3be6d996150", "name": "Commented-code block (5 lines) in backend-api/src/tests/warehouse.partSpec.roundtrip.test.ts:3", "shortDescription": {"text": "Commented-code block (5 lines) in backend-api/src/tests/warehouse.partSpec.roundtrip.test.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b02e625218a3dd2b", "name": "Legacy-named symbol `supplierLegacy` in backend-api/src/tests/partFieldMirror.test.ts:65", "shortDescription": {"text": "Legacy-named symbol `supplierLegacy` in backend-api/src/tests/partFieldMirror.test.ts:65"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-54a56c8054f02fed", "name": "Legacy-named symbol `parts_movement_v1` in backend-api/src/tests/warehouse.assemblyReserve.test.ts:64", "shortDescription": {"text": "Legacy-named symbol `parts_movement_v1` in backend-api/src/tests/warehouse.assemblyReserve.test.ts:64"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d615deccbedeb58d", "name": "Legacy-named symbol `hasLegacy` in backend-api/src/scripts/migrateChecklistToEngineInventory.ts:162", "shortDescription": {"text": "Legacy-named symbol `hasLegacy` in backend-api/src/scripts/migrateChecklistToEngineInventory.ts:162"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9de70d9d2496863d", "name": "Commented-code block (6 lines) in backend-api/src/scripts/migrateChecklistToEngineInventory.ts:26", "shortDescription": {"text": "Commented-code block (6 lines) in backend-api/src/scripts/migrateChecklistToEngineInventory.ts:26"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-555d3836197a9ee5", "name": "Commented-code block (8 lines) in backend-api/src/scripts/importBasePartsList.ts:4", "shortDescription": {"text": "Commented-code block (8 lines) in backend-api/src/scripts/importBasePartsList.ts:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8dae9c737b685d7a", "name": "Commented-code block (6 lines) in backend-api/src/scripts/seedNomenclatureVerifyFixture.ts:20", "shortDescription": {"text": "Commented-code block (6 lines) in backend-api/src/scripts/seedNomenclatureVerifyFixture.ts:20"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-681f0d0fd38c433e", "name": "Commented-code block (5 lines) in backend-api/src/scripts/auditPartsMirror.ts:7", "shortDescription": {"text": "Commented-code block (5 lines) in backend-api/src/scripts/auditPartsMirror.ts:7"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5cc5e8a5284d9f56", "name": "Commented-code block (5 lines) in backend-api/src/scripts/migrateExistingWorkshopOrders.ts:10", "shortDescription": {"text": "Commented-code block (5 lines) in backend-api/src/scripts/migrateExistingWorkshopOrders.ts:10"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0a83d86f14fdacd5", "name": "Commented-code block (8 lines) in backend-api/src/scripts/fixPartsMirror.ts:7", "shortDescription": {"text": "Commented-code block (8 lines) in backend-api/src/scripts/fixPartsMirror.ts:7"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bc957f86fd00e78f", "name": "Commented-code block (5 lines) in backend-api/src/scripts/backfillOrphanPartNomenclature.ts:6", "shortDescription": {"text": "Commented-code block (5 lines) in backend-api/src/scripts/backfillOrphanPartNomenclature.ts:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3923541c7fa46b0d", "name": "Commented-code block (5 lines) in backend-api/src/scripts/softDeleteLegacyRepairOperations.ts:7", "shortDescription": {"text": "Commented-code block (5 lines) in backend-api/src/scripts/softDeleteLegacyRepairOperations.ts:7"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b8fc9b8726422564", "name": "Legacy-named symbol `supplierLegacy` in backend-api/src/scripts/backfillDirectoryPartsMetadata.ts:130", "shortDescription": {"text": "Legacy-named symbol `supplierLegacy` in backend-api/src/scripts/backfillDirectoryPartsMetadata.ts:130"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aed84ae9cd82d8ee", "name": "Commented-code block (10 lines) in backend-api/src/scripts/migrateWorkshopTemplatesToWorkOrderTemplates.ts:8", "shortDescription": {"text": "Commented-code block (10 lines) in backend-api/src/scripts/migrateWorkshopTemplatesToWorkOrderTemplates.ts:8"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ac73969f8b8d5746", "name": "Commented-code block (5 lines) in backend-api/src/scripts/seedDevFixtures.ts:135", "shortDescription": {"text": "Commented-code block (5 lines) in backend-api/src/scripts/seedDevFixtures.ts:135"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9a4b54234d3d1658", "name": "Commented-code block (6 lines) in backend-api/src/scripts/migrateComponentTypeFromSpecJson.ts:8", "shortDescription": {"text": "Commented-code block (6 lines) in backend-api/src/scripts/migrateComponentTypeFromSpecJson.ts:8"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-73b56c3a4ec9ea07", "name": "`fetch()` without try/.catch or AbortSignal \u2014 backend-api/src/routes/files.ts:429", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend-api/src/routes/files.ts:429"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-37679f2dc2d241fc", "name": "Legacy-named symbol `supplierLegacy` in backend-api/src/routes/warehouse.ts:394", "shortDescription": {"text": "Legacy-named symbol `supplierLegacy` in backend-api/src/routes/warehouse.ts:394"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8a16b2e6ce10e4a5", "name": "Legacy-named symbol `force_full_pull_v2` in backend-api/src/routes/adminClients.ts:103", "shortDescription": {"text": "Legacy-named symbol `force_full_pull_v2` in backend-api/src/routes/adminClients.ts:103"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b4fa0528a4a45ee2", "name": "Legacy-named symbol `markDeprecated` in backend-api/src/routes/workshops.ts:74", "shortDescription": {"text": "Legacy-named symbol `markDeprecated` in backend-api/src/routes/workshops.ts:74"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-136d8f4e931dcabc", "name": "Commented-code block (6 lines) in backend-api/src/services/directoryPartsDedupeService.ts:1", "shortDescription": {"text": "Commented-code block (6 lines) in backend-api/src/services/directoryPartsDedupeService.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b4d9f4fb12c1a269", "name": "Legacy-named symbol `supplierLegacy` in backend-api/src/services/partFieldMirror.ts:130", "shortDescription": {"text": "Legacy-named symbol `supplierLegacy` in backend-api/src/services/partFieldMirror.ts:130"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-db3354e8c6423b04", "name": "Commented-code block (8 lines) in backend-api/src/services/warehouseBomService.ts:459", "shortDescription": {"text": "Commented-code block (8 lines) in backend-api/src/services/warehouseBomService.ts:459"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bdb279474a23ff61", "name": "Legacy-named symbol `parts_movement_v1` in backend-api/src/services/warehouseService.ts:86", "shortDescription": {"text": "Legacy-named symbol `parts_movement_v1` in backend-api/src/services/warehouseService.ts:86"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9c491aeb4de6c03b", "name": "Commented-code block (7 lines) in backend-api/src/services/warehouseService.ts:796", "shortDescription": {"text": "Commented-code block (7 lines) in backend-api/src/services/warehouseService.ts:796"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a5f958dab29a174d", "name": "Legacy-named symbol `bom_line_meta_v1` in backend-api/src/services/warehouseBomLineMeta.ts:2", "shortDescription": {"text": "Legacy-named symbol `bom_line_meta_v1` in backend-api/src/services/warehouseBomLineMeta.ts:2"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-10c4db9732b507f4", "name": "Commented-code block (8 lines) in backend-api/src/services/engineDedupeService.ts:3", "shortDescription": {"text": "Commented-code block (8 lines) in backend-api/src/services/engineDedupeService.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5de81af3029437f1", "name": "Commented-code block (5 lines) in backend-api/src/services/engineNumberGuard.ts:1", "shortDescription": {"text": "Commented-code block (5 lines) in backend-api/src/services/engineNumberGuard.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3f424ff8efb6a430", "name": "Legacy-named symbol `force_full_pull_v2` in backend-api/src/services/diagnosticsAutohealService.ts:10", "shortDescription": {"text": "Legacy-named symbol `force_full_pull_v2` in backend-api/src/services/diagnosticsAutohealService.ts:10"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7cb36c29702caf4b", "name": "Commented-code block (8 lines) in backend-api/src/services/workshopRepairTemplateService.ts:111", "shortDescription": {"text": "Commented-code block (8 lines) in backend-api/src/services/workshopRepairTemplateService.ts:111"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a05d82e75cfdaed5", "name": "Commented-code block (5 lines) in backend-api/src/services/warehouseForecastService.ts:63", "shortDescription": {"text": "Commented-code block (5 lines) in backend-api/src/services/warehouseForecastService.ts:63"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f179c4a5e3ce98a3", "name": "Legacy-named symbol `parts_movement_v1` in backend-api/src/services/workOrderClosingService.ts:517", "shortDescription": {"text": "Legacy-named symbol `parts_movement_v1` in backend-api/src/services/workOrderClosingService.ts:517"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-03cfe17e84f4dbf9", "name": "Commented-code block (5 lines) in backend-api/src/services/workOrderClosingService.ts:420", "shortDescription": {"text": "Commented-code block (5 lines) in backend-api/src/services/workOrderClosingService.ts:420"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cfe037a902f6f46a", "name": "Commented-code block (5 lines) in backend-api/src/services/sync/applyPushBatch.ts:523", "shortDescription": {"text": "Commented-code block (5 lines) in backend-api/src/services/sync/applyPushBatch.ts:523"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1de6c540b0e7fe4a", "name": "Commented-code block (6 lines) in web-admin/src/api/parts.ts:3", "shortDescription": {"text": "Commented-code block (6 lines) in web-admin/src/api/parts.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f1a0804976012adf", "name": "Legacy-named symbol `matrica_webadmin_input_assist_history_v1` in web-admin/src/ui/App.tsx:633", "shortDescription": {"text": "Legacy-named symbol `matrica_webadmin_input_assist_history_v1` in web-admin/src/ui/App.tsx:633"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a177a5f7a189b57c", "name": "`fetch()` without try/.catch or AbortSignal \u2014 web-admin/src/ui/ChatPanel.tsx:378", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 web-admin/src/ui/ChatPanel.tsx:378"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e00b45a32d4a1b71", "name": "`fetch()` without try/.catch or AbortSignal \u2014 web-admin/src/ui/components/AttachmentsPanel.tsx:76", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 web-admin/src/ui/components/AttachmentsPanel.tsx:76"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6ae6e14d8579ceab", "name": "Commented-code block (5 lines) in shared/src/domain/partsDedup.ts:7", "shortDescription": {"text": "Commented-code block (5 lines) in shared/src/domain/partsDedup.ts:7"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9c0d2c41ce624ebd", "name": "Legacy-named symbol `bom_relation_schema_v1` in shared/src/domain/buildEngineBomSkeletonBlockLines.test.ts:11", "shortDescription": {"text": "Legacy-named symbol `bom_relation_schema_v1` in shared/src/domain/buildEngineBomSkeletonBlockLines.test.ts:11"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-21934ccd88c096ee", "name": "Commented-code block (8 lines) in shared/src/domain/tieredSearch.ts:4", "shortDescription": {"text": "Commented-code block (8 lines) in shared/src/domain/tieredSearch.ts:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-98e39187aae1e5f7", "name": "Commented-code block (6 lines) in shared/src/domain/calver.ts:1", "shortDescription": {"text": "Commented-code block (6 lines) in shared/src/domain/calver.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-390774e397bdce22", "name": "Legacy-named symbol `bom_relation_schema_v1` in shared/src/domain/groupedNomenclatureOptions.test.ts:51", "shortDescription": {"text": "Legacy-named symbol `bom_relation_schema_v1` in shared/src/domain/groupedNomenclatureOptions.test.ts:51"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1816800c71499a1f", "name": "Legacy-named symbol `bom_relation_schema_v1` in shared/src/domain/warehouse.ts:819", "shortDescription": {"text": "Legacy-named symbol `bom_relation_schema_v1` in shared/src/domain/warehouse.ts:819"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9299f980ecd95524", "name": "Legacy-named symbol `parts_movement_v1` in shared/src/domain/releaseWelcome.ts:1276", "shortDescription": {"text": "Legacy-named symbol `parts_movement_v1` in shared/src/domain/releaseWelcome.ts:1276"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-29034aafdb57dee4", "name": "Legacy-named symbol `contractSectionsToLegacy` in shared/src/domain/contract.ts:478", "shortDescription": {"text": "Legacy-named symbol `contractSectionsToLegacy` in shared/src/domain/contract.ts:478"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5e1b59485d3ca808", "name": "Legacy-named symbol `supplierLegacy` in shared/src/domain/part.ts:93", "shortDescription": {"text": "Legacy-named symbol `supplierLegacy` in shared/src/domain/part.ts:93"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6dba8c0e4e319c63", "name": "Commented-code block (6 lines) in shared/src/domain/part.ts:55", "shortDescription": {"text": "Commented-code block (6 lines) in shared/src/domain/part.ts:55"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5ccec860ab42b60c", "name": "Legacy-named symbol `hasLegacy` in scripts/release-auto.mjs:219", "shortDescription": {"text": "Legacy-named symbol `hasLegacy` in scripts/release-auto.mjs:219"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e7330ddc3338c11a", "name": "Commented-code block (5 lines) in .claude/skills/verifier-electron/scripts/cdp-drive.mjs:535", "shortDescription": {"text": "Commented-code block (5 lines) in .claude/skills/verifier-electron/scripts/cdp-drive.mjs:535"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a0b23e01683e0b09", "name": "99 env vars used in code but missing from .env.example", "shortDescription": {"text": "99 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `AI_ANALYTICS_ENABLED`, `AI_ANALYTICS_MAX_TOKENS`, `AI_CHAT_FAST_PATH_ENABLED`, `AI_CHAT_HISTORY_CLEANUP_INTERVAL_MS`, `AI_CHAT_LEARNING_ENABLED`, `AI_CHAT_LEARNING_INTERVAL_MS`, `AI_CHAT_LEARNING_LIMIT`, `AI_CHAT_LEARNING_WINDOW_HOURS` + 91 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9aed0ad53a8d9fb5", "name": "Dangling fetch: GET https://api.telegram.org/bot${token}/getUpdates?${qs.toString()} (backend-api/src/services/telegramB", "shortDescription": {"text": "Dangling fetch: GET https://api.telegram.org/bot${token}/getUpdates?${qs.toString()} (backend-api/src/services/telegramBotService.ts:67)"}, "fullDescription": {"text": "`backend-api/src/services/telegramBotService.ts:67` calls `GET https://api.telegram.org/bot${token}/getUpdates?${qs.toString()}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.telegram.org/bot/<p>/getupdates`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-604c514fdb0744c0", "name": "Dangling fetch: POST https://api.telegram.org/bot${token}/sendMessage (backend-api/src/services/telegramBotService.ts:12", "shortDescription": {"text": "Dangling fetch: POST https://api.telegram.org/bot${token}/sendMessage (backend-api/src/services/telegramBotService.ts:127)"}, "fullDescription": {"text": "`backend-api/src/services/telegramBotService.ts:127` calls `POST https://api.telegram.org/bot${token}/sendMessage` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.telegram.org/bot/<p>/sendmessage`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a3878f30db3e653f", "name": "Dangling fetch: POST https://api.telegram.org/bot${token}/sendMessage (backend-api/src/services/telegramBotService.ts:14", "shortDescription": {"text": "Dangling fetch: POST https://api.telegram.org/bot${token}/sendMessage (backend-api/src/services/telegramBotService.ts:141)"}, "fullDescription": {"text": "`backend-api/src/services/telegramBotService.ts:141` calls `POST https://api.telegram.org/bot${token}/sendMessage` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.telegram.org/bot/<p>/sendmessage`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-65d96c8d9b6a82fb", "name": "Dangling fetch: POST https://api.telegram.org/bot${token}/sendMessage (backend-api/src/services/telegramBotService.ts:17", "shortDescription": {"text": "Dangling fetch: POST https://api.telegram.org/bot${token}/sendMessage (backend-api/src/services/telegramBotService.ts:176)"}, "fullDescription": {"text": "`backend-api/src/services/telegramBotService.ts:176` calls `POST https://api.telegram.org/bot${token}/sendMessage` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.telegram.org/bot/<p>/sendmessage`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c20b017acb9100b1", "name": "Dangling fetch: POST https://api.telegram.org/bot${token}/answerCallbackQuery (backend-api/src/services/telegramBotServi", "shortDescription": {"text": "Dangling fetch: POST https://api.telegram.org/bot${token}/answerCallbackQuery (backend-api/src/services/telegramBotService.ts:206)"}, "fullDescription": {"text": "`backend-api/src/services/telegramBotService.ts:206` calls `POST https://api.telegram.org/bot${token}/answerCallbackQuery` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.telegram.org/bot/<p>/answercallbackquery`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b28d92215a503990", "name": "Unused endpoint: USE /auth", "shortDescription": {"text": "Unused endpoint: USE /auth"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /auth` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d1e264ad403454f2", "name": "Unused endpoint: USE /sync", "shortDescription": {"text": "Unused endpoint: USE /sync"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /sync` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b17f829e3d159660", "name": "Unused endpoint: USE /ledger", "shortDescription": {"text": "Unused endpoint: USE /ledger"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /ledger` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ed523761442e1550", "name": "Unused endpoint: USE /chat", "shortDescription": {"text": "Unused endpoint: USE /chat"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /chat` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ac6a148d5ebfd22d", "name": "Unused endpoint: USE /notes", "shortDescription": {"text": "Unused endpoint: USE /notes"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /notes` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3631280e38df0f48", "name": "Unused endpoint: USE /presence", "shortDescription": {"text": "Unused endpoint: USE /presence"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /presence` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b2d8849fb6b1ac47", "name": "Unused endpoint: USE /admin", "shortDescription": {"text": "Unused endpoint: USE /admin"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /admin` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8b7d781b752795b6", "name": "Unused endpoint: USE /admin/audit", "shortDescription": {"text": "Unused endpoint: USE /admin/audit"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /admin/audit` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-062c46d5b843a144", "name": "Unused endpoint: USE /admin/masterdata", "shortDescription": {"text": "Unused endpoint: USE /admin/masterdata"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /admin/masterdata` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-435018eab0195ac5", "name": "Unused endpoint: USE /changes", "shortDescription": {"text": "Unused endpoint: USE /changes"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /changes` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a0665830dbcd2d75", "name": "Unused endpoint: USE /files", "shortDescription": {"text": "Unused endpoint: USE /files"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /files` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-02a6953bf3de2811", "name": "Unused endpoint: USE /parts", "shortDescription": {"text": "Unused endpoint: USE /parts"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /parts` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f71af222bae50fc3", "name": "Unused endpoint: USE /logs", "shortDescription": {"text": "Unused endpoint: USE /logs"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /logs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-54a2bc88d734e604", "name": "Unused endpoint: USE /backups", "shortDescription": {"text": "Unused endpoint: USE /backups"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /backups` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-04c73ad45855ed5c", "name": "Unused endpoint: USE /updates", "shortDescription": {"text": "Unused endpoint: USE /updates"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /updates` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-520546e90f7fd2b2", "name": "Unused endpoint: USE /client", "shortDescription": {"text": "Unused endpoint: USE /client"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /client` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f97bd0fa8037a2d5", "name": "Unused endpoint: USE /employees", "shortDescription": {"text": "Unused endpoint: USE /employees"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /employees` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b7fb24880fe6e9b0", "name": "Unused endpoint: USE /checklists", "shortDescription": {"text": "Unused endpoint: USE /checklists"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /checklists` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a773f635fec979c9", "name": "Unused endpoint: USE /diagnostics", "shortDescription": {"text": "Unused endpoint: USE /diagnostics"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /diagnostics` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6bdcbf2073dfa768", "name": "Unused endpoint: USE /ai", "shortDescription": {"text": "Unused endpoint: USE /ai"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /ai` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a8f40a426fdfb45", "name": "Unused endpoint: USE /reports", "shortDescription": {"text": "Unused endpoint: USE /reports"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /reports` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-13eff24bd33b83d1", "name": "Unused endpoint: USE /erp", "shortDescription": {"text": "Unused endpoint: USE /erp"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /erp` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-459977599dd00f73", "name": "Unused endpoint: USE /warehouse", "shortDescription": {"text": "Unused endpoint: USE /warehouse"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /warehouse` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4ce40f9d5c4d6e99", "name": "Unused endpoint: USE /work-orders", "shortDescription": {"text": "Unused endpoint: USE /work-orders"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /work-orders` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-24cb02ddec517007", "name": "Unused endpoint: USE /work-order-templates", "shortDescription": {"text": "Unused endpoint: USE /work-order-templates"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /work-order-templates` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b804dfef0189b34a", "name": "Unused endpoint: USE /workshops", "shortDescription": {"text": "Unused endpoint: USE /workshops"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /workshops` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9d576b555a46f4ba", "name": "Unused endpoint: USE /warehouse-locations", "shortDescription": {"text": "Unused endpoint: USE /warehouse-locations"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /warehouse-locations` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c204d5a6447f5b37", "name": "Unused endpoint: USE /service-pricing", "shortDescription": {"text": "Unused endpoint: USE /service-pricing"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /service-pricing` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-166f8ca84e7c11a2", "name": "Unused endpoint: USE /admin-ui", "shortDescription": {"text": "Unused endpoint: USE /admin-ui"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `USE /admin-ui` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d5677aacc06eb64c", "name": "Unused endpoint: GET /admin-ui/*", "shortDescription": {"text": "Unused endpoint: GET /admin-ui/*"}, "fullDescription": {"text": "`backend-api/src/app.ts` declares `GET /admin-ui/*` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-618721b912bad1c2", "name": "Unused endpoint: POST /login", "shortDescription": {"text": "Unused endpoint: POST /login"}, "fullDescription": {"text": "`backend-api/src/routes/auth.ts` declares `POST /login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-304b6f2b403d93f7", "name": "Unused endpoint: POST /register", "shortDescription": {"text": "Unused endpoint: POST /register"}, "fullDescription": {"text": "`backend-api/src/routes/auth.ts` declares `POST /register` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cabf0be91b0aec0b", "name": "Unused endpoint: GET /login-options", "shortDescription": {"text": "Unused endpoint: GET /login-options"}, "fullDescription": {"text": "`backend-api/src/routes/auth.ts` declares `GET /login-options` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd1dc91abf32142d", "name": "Unused endpoint: GET /me", "shortDescription": {"text": "Unused endpoint: GET /me"}, "fullDescription": {"text": "`backend-api/src/routes/auth.ts` declares `GET /me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f28f51e38b33ffc8", "name": "Unused endpoint: POST /release-token", "shortDescription": {"text": "Unused endpoint: POST /release-token"}, "fullDescription": {"text": "`backend-api/src/routes/auth.ts` declares `POST /release-token` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8c1bfd0a66740639", "name": "Unused endpoint: GET /users/:id/permissions-view", "shortDescription": {"text": "Unused endpoint: GET /users/:id/permissions-view"}, "fullDescription": {"text": "`backend-api/src/routes/auth.ts` declares `GET /users/:id/permissions-view` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2595b39638e5c045", "name": "Unused endpoint: GET /profile", "shortDescription": {"text": "Unused endpoint: GET /profile"}, "fullDescription": {"text": "`backend-api/src/routes/auth.ts` declares `GET /profile` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-512ccb0fd0b230ba", "name": "Unused endpoint: GET /settings", "shortDescription": {"text": "Unused endpoint: GET /settings"}, "fullDescription": {"text": "`backend-api/src/routes/auth.ts` declares `GET /settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-689e4ffd880f570d", "name": "Unused endpoint: PATCH /settings", "shortDescription": {"text": "Unused endpoint: PATCH /settings"}, "fullDescription": {"text": "`backend-api/src/routes/auth.ts` declares `PATCH /settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-73c3b023fb81d73a", "name": "Unused endpoint: GET /ui-settings", "shortDescription": {"text": "Unused endpoint: GET /ui-settings"}, "fullDescription": {"text": "`backend-api/src/routes/auth.ts` declares `GET /ui-settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7c1ea719911c281b", "name": "Unused endpoint: PATCH /ui-settings", "shortDescription": {"text": "Unused endpoint: PATCH /ui-settings"}, "fullDescription": {"text": "`backend-api/src/routes/auth.ts` declares `PATCH /ui-settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-70d575c3569a5404", "name": "Unused endpoint: GET /ui-profile", "shortDescription": {"text": "Unused endpoint: GET /ui-profile"}, "fullDescription": {"text": "`backend-api/src/routes/auth.ts` declares `GET /ui-profile` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fb68a196d9cac55e", "name": "Unused endpoint: PATCH /ui-profile", "shortDescription": {"text": "Unused endpoint: PATCH /ui-profile"}, "fullDescription": {"text": "`backend-api/src/routes/auth.ts` declares `PATCH /ui-profile` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2a45f4e5dfe7a73c", "name": "Unused endpoint: GET /ui-settings/global", "shortDescription": {"text": "Unused endpoint: GET /ui-settings/global"}, "fullDescription": {"text": "`backend-api/src/routes/auth.ts` declares `GET /ui-settings/global` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-347c717f6eb2c190", "name": "Unused endpoint: PATCH /ui-settings/global", "shortDescription": {"text": "Unused endpoint: PATCH /ui-settings/global"}, "fullDescription": {"text": "`backend-api/src/routes/auth.ts` declares `PATCH /ui-settings/global` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-59a1cc885f47e39f", "name": "Unused endpoint: PATCH /profile", "shortDescription": {"text": "Unused endpoint: PATCH /profile"}, "fullDescription": {"text": "`backend-api/src/routes/auth.ts` declares `PATCH /profile` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7ce17d6b092a81ca", "name": "Unused endpoint: POST /refresh", "shortDescription": {"text": "Unused endpoint: POST /refresh"}, "fullDescription": {"text": "`backend-api/src/routes/auth.ts` declares `POST /refresh` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-99fc36db98c134ce", "name": "Unused endpoint: POST /logout", "shortDescription": {"text": "Unused endpoint: POST /logout"}, "fullDescription": {"text": "`backend-api/src/routes/auth.ts` declares `POST /logout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4fe9bb486644f008", "name": "Unused endpoint: POST /change-password", "shortDescription": {"text": "Unused endpoint: POST /change-password"}, "fullDescription": {"text": "`backend-api/src/routes/auth.ts` declares `POST /change-password` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`backend-api/src/routes/health.ts` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/22054"}, "properties": {"repository": "Valstan/MatricaRMZ", "repoUrl": "https://github.com/Valstan/MatricaRMZ", "branch": "main"}, "results": [{"ruleId": "scanner-901679837c50fd78", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 electron-app/src/renderer/src/ui/components/AiAgentChat.tsx:511"}, "properties": {"repobilityId": "b1386d2985a6f514", "scanner": "scanner-primary", "fingerprint": "901679837c50fd78", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-55ce3ca82bc7f273", "level": "note", "message": {"text": "React Flow edge with `label=` but no project-wide edge-label CSS override \u2014 electron-app/src/renderer/src/ui/pages/ToolDetailsPage.tsx:282"}, "properties": {"repobilityId": "21c8953895e4609a", "scanner": "scanner-primary", "fingerprint": "55ce3ca82bc7f273", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.edge-label.no-bg"]}}, {"ruleId": "scanner-b9105ce8ccb5eca2", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 electron-app/src/renderer/src/ui/pages/ReportPresetPage.tsx:1053"}, "properties": {"repobilityId": "e6c8b4692940d57d", "scanner": "scanner-primary", "fingerprint": "b9105ce8ccb5eca2", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-8593ce78fe938e9c", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 electron-app/src/renderer/src/ui/pages/ReportsPage.tsx:525"}, "properties": {"repobilityId": "38b99dd10c44da3e", "scanner": "scanner-primary", "fingerprint": "8593ce78fe938e9c", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-5d36c8528cffca33", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 electron-app/src/main/services/blockmapDelta.measure.test.ts:45"}, "properties": {"repobilityId": "c430f4cdf0751d19", "scanner": "scanner-primary", "fingerprint": "5d36c8528cffca33", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-cbe38d001d66f513", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 electron-app/src/main/services/partsService.ts:120"}, "properties": {"repobilityId": "cd352c008896c817", "scanner": "scanner-primary", "fingerprint": "cbe38d001d66f513", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-6bf8ae6c266d6bce", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/migrateChecklistToEngineInventory.ts:97"}, "properties": {"repobilityId": "0480a4fa18ab54d7", "scanner": "scanner-primary", "fingerprint": "6bf8ae6c266d6bce", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-063e365eec606e4a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/fixChatPermissions.ts:41"}, "properties": {"repobilityId": "e24a799b170d9609", "scanner": "scanner-primary", "fingerprint": "063e365eec606e4a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9e3dafed29f973bc", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/unifyPartIdConvention.ts:136"}, "properties": {"repobilityId": "3ebe3ffe8383b341", "scanner": "scanner-primary", "fingerprint": "9e3dafed29f973bc", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9df502a57c82cb30", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/cleanupBulkEntityTypes.ts:71"}, "properties": {"repobilityId": "8bc4e5286dd747b2", "scanner": "scanner-primary", "fingerprint": "9df502a57c82cb30", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d9c2e3e9a2daba83", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/importBasePartsList.ts:184"}, "properties": {"repobilityId": "097b732e25495b05", "scanner": "scanner-primary", "fingerprint": "d9c2e3e9a2daba83", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ccbf9b366748d422", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/warehouseThreeLevelDryRun.ts:267"}, "properties": {"repobilityId": "71c23866c962521a", "scanner": "scanner-primary", "fingerprint": "ccbf9b366748d422", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5c73882a08594753", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/cleanupChatMessages.ts:43"}, "properties": {"repobilityId": "0714ba0283ca212c", "scanner": "scanner-primary", "fingerprint": "5c73882a08594753", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b618a761ff93a777", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/rebuildLedgerTxIndex.ts:13"}, "properties": {"repobilityId": "462c138d7f0daab9", "scanner": "scanner-primary", "fingerprint": "b618a761ff93a777", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-eb46078d29fa6342", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/touchMasterdataForSync.ts:141"}, "properties": {"repobilityId": "e446c9a20d6251d6", "scanner": "scanner-primary", "fingerprint": "eb46078d29fa6342", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-88950fc5b500c692", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/seedNomenclatureVerifyFixture.ts:239"}, "properties": {"repobilityId": "8166066f5a65a706", "scanner": "scanner-primary", "fingerprint": "88950fc5b500c692", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-14c19e1f26315b9e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillMovementEngineId.ts:39"}, "properties": {"repobilityId": "953d09e2a69c6a44", "scanner": "scanner-primary", "fingerprint": "14c19e1f26315b9e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b88e2f97e61c2820", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/cleanupEmptyEntities.ts:145"}, "properties": {"repobilityId": "e6171e734c2cfc24", "scanner": "scanner-primary", "fingerprint": "b88e2f97e61c2820", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-749e7824e72e5d3a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillMasterdataToLedger.ts:206"}, "properties": {"repobilityId": "d1bcb5c38e608fb2", "scanner": "scanner-primary", "fingerprint": "749e7824e72e5d3a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-48673b56cbb0eed3", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/seedVariantBomVerifyFixture.ts:125"}, "properties": {"repobilityId": "fdc6c5cd5b8d2c88", "scanner": "scanner-primary", "fingerprint": "48673b56cbb0eed3", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5a11b642c6931029", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/erpLegacyCleanup.ts:32"}, "properties": {"repobilityId": "1ceb83e86a31ac3c", "scanner": "scanner-primary", "fingerprint": "5a11b642c6931029", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-dbe4fc7fe4af4026", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/importEngineBrandPartMatrix.ts:300"}, "properties": {"repobilityId": "108feca7f78ec319", "scanner": "scanner-primary", "fingerprint": "dbe4fc7fe4af4026", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-1d39303df9eb08fa", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/seedPermissions.ts:16"}, "properties": {"repobilityId": "38dcd664a7e63127", "scanner": "scanner-primary", "fingerprint": "1d39303df9eb08fa", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-96f400e3400c59b5", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/checkSyncContract.ts:27"}, "properties": {"repobilityId": "6d15834e34214f8e", "scanner": "scanner-primary", "fingerprint": "96f400e3400c59b5", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b3d96a2702beebcc", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillDirectoryBrandLinksFromEav.ts:210"}, "properties": {"repobilityId": "c7756dedf4a7019a", "scanner": "scanner-primary", "fingerprint": "b3d96a2702beebcc", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-09b18207a354e751", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/migrateUsersToEmployees.ts:84"}, "properties": {"repobilityId": "bf412d6465131bd9", "scanner": "scanner-primary", "fingerprint": "09b18207a354e751", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7f25639c3e4b8c75", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillNomenclatureGovernance.ts:170"}, "properties": {"repobilityId": "49f42344dc57c2fc", "scanner": "scanner-primary", "fingerprint": "7f25639c3e4b8c75", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-09e681969e52f659", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/auditPartsMirror.ts:61"}, "properties": {"repobilityId": "5cb730f6973c2c9b", "scanner": "scanner-primary", "fingerprint": "09e681969e52f659", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-97db15b696000a7a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/migrateExistingWorkshopOrders.ts:77"}, "properties": {"repobilityId": "4d2420ff7e80cd1d", "scanner": "scanner-primary", "fingerprint": "97db15b696000a7a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9f5ff6e12763649e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/dedupeEngines.ts:22"}, "properties": {"repobilityId": "95d151e92271f8d4", "scanner": "scanner-primary", "fingerprint": "9f5ff6e12763649e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2a0726e1b8299415", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillDirectoryEngineBrands.ts:75"}, "properties": {"repobilityId": "98f0e87ba715c06c", "scanner": "scanner-primary", "fingerprint": "2a0726e1b8299415", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d531d2def0591a80", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/fixPartsMirror.ts:178"}, "properties": {"repobilityId": "57fc72349b78414a", "scanner": "scanner-primary", "fingerprint": "d531d2def0591a80", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-454e0433d93e2a0b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillStockBalanceNomenclature.ts:16"}, "properties": {"repobilityId": "3d37c2ad49a3506b", "scanner": "scanner-primary", "fingerprint": "454e0433d93e2a0b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-84cf67bafeda39de", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/ledgerReplayToDb.ts:10"}, "properties": {"repobilityId": "70feb794d6b424a5", "scanner": "scanner-primary", "fingerprint": "84cf67bafeda39de", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c364c21e85412faa", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillOrphanPartNomenclature.ts:23"}, "properties": {"repobilityId": "b2d96b76d19c73ab", "scanner": "scanner-primary", "fingerprint": "c364c21e85412faa", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-78ee8349fee3f309", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/rotateLedgerDataKey.ts:91"}, "properties": {"repobilityId": "8daf8b9082fa0c84", "scanner": "scanner-primary", "fingerprint": "78ee8349fee3f309", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-96f80a2908cd6b92", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/canonicalizeLedgerTypes.ts:252"}, "properties": {"repobilityId": "b11b2bbb9d88a418", "scanner": "scanner-primary", "fingerprint": "96f80a2908cd6b92", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-dd1ee37a6da6bc9e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/softDeleteLegacyRepairOperations.ts:63"}, "properties": {"repobilityId": "55301bf06a546118", "scanner": "scanner-primary", "fingerprint": "dd1ee37a6da6bc9e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9a089fd157cea168", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillDirectoryPartsMetadata.ts:152"}, "properties": {"repobilityId": "1da5119b54aabbed", "scanner": "scanner-primary", "fingerprint": "9a089fd157cea168", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4b22cd210cde4acc", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/dryRunDirectoriesToNomenclature.ts:150"}, "properties": {"repobilityId": "87493992b88cab91", "scanner": "scanner-primary", "fingerprint": "4b22cd210cde4acc", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0d0e5908525f7c20", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/cleanupChatFiles.ts:74"}, "properties": {"repobilityId": "b425572dbb26c8f5", "scanner": "scanner-primary", "fingerprint": "0d0e5908525f7c20", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5f529e8c5bb25472", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/bootstrapDevEntityTypes.ts:76"}, "properties": {"repobilityId": "0c097c862979176d", "scanner": "scanner-primary", "fingerprint": "5f529e8c5bb25472", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-fc7671ea078dd691", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/fixLedgerEntitiesMissingType.ts:69"}, "properties": {"repobilityId": "7a72e3a4d2d80f26", "scanner": "scanner-primary", "fingerprint": "fc7671ea078dd691", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d585b82c83ffa361", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/migrateEavToErp.ts:237"}, "properties": {"repobilityId": "f5fd26eda0cb187c", "scanner": "scanner-primary", "fingerprint": "d585b82c83ffa361", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-87bb1092aae1d617", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/dedupeMasterdata.ts:120"}, "properties": {"repobilityId": "8dd6fabb44a5b012", "scanner": "scanner-primary", "fingerprint": "87bb1092aae1d617", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-fe6e76c988e7a515", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/enableClientLogging.ts:13"}, "properties": {"repobilityId": "2f444a87225ac93a", "scanner": "scanner-primary", "fingerprint": "fe6e76c988e7a515", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d69227e0ff94b294", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/migrateWorkshopTemplatesToWorkOrderTemplates.ts:99"}, "properties": {"repobilityId": "7534a8cc9997d7d8", "scanner": "scanner-primary", "fingerprint": "d69227e0ff94b294", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-fbf1efaa875c1fbf", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/nightlyBackup.ts:343"}, "properties": {"repobilityId": "46aed630934139d1", "scanner": "scanner-primary", "fingerprint": "fbf1efaa875c1fbf", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2e68c1754daf7f1d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/seedDevFixtures.ts:245"}, "properties": {"repobilityId": "be3cc8a53cd6e6e0", "scanner": "scanner-primary", "fingerprint": "2e68c1754daf7f1d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3479c34e49868c29", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/mergeCounterparties.ts:531"}, "properties": {"repobilityId": "95e0f31983747215", "scanner": "scanner-primary", "fingerprint": "3479c34e49868c29", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-38c5d8daf8cd508b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillDirectoryParts.ts:144"}, "properties": {"repobilityId": "e73bc4091260ee18", "scanner": "scanner-primary", "fingerprint": "38c5d8daf8cd508b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c1dabbe2df790196", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/seedBaseCategories.ts:89"}, "properties": {"repobilityId": "1be49de895cf5241", "scanner": "scanner-primary", "fingerprint": "c1dabbe2df790196", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8b0ab0ccf2173739", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/tightenGlobalUiDensity.ts:56"}, "properties": {"repobilityId": "a9847d387f660261", "scanner": "scanner-primary", "fingerprint": "8b0ab0ccf2173739", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9a049bf6e206b542", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillWarehouseLocations.ts:75"}, "properties": {"repobilityId": "c352bc613088d0de", "scanner": "scanner-primary", "fingerprint": "9a049bf6e206b542", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ed713f7e788f40de", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/emitSyncSnapshot.ts:64"}, "properties": {"repobilityId": "a2ed8c0455e248e2", "scanner": "scanner-primary", "fingerprint": "ed713f7e788f40de", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-fa78960dffca19d9", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/createUser.ts:72"}, "properties": {"repobilityId": "5aade9b7610f0e49", "scanner": "scanner-primary", "fingerprint": "fa78960dffca19d9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-86b6354d974f3b12", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/migrateDirectoriesToNomenclature.ts:334"}, "properties": {"repobilityId": "6e21221bbfd090e3", "scanner": "scanner-primary", "fingerprint": "86b6354d974f3b12", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f0d8e691102b9a27", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/importContractsGoz.ts:571"}, "properties": {"repobilityId": "c9f5bbf29405af2e", "scanner": "scanner-primary", "fingerprint": "f0d8e691102b9a27", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-1363ce00c9467c10", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/seedNomenclatureGroups.ts:123"}, "properties": {"repobilityId": "de7d0cf01757a6f7", "scanner": "scanner-primary", "fingerprint": "1363ce00c9467c10", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c6663289453e4325", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/backfillChangeLog.ts:314"}, "properties": {"repobilityId": "3d251aece887786d", "scanner": "scanner-primary", "fingerprint": "c6663289453e4325", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7a6338fd1ec2a815", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/migrateComponentTypeFromSpecJson.ts:80"}, "properties": {"repobilityId": "1a70c1757cf4fd03", "scanner": "scanner-primary", "fingerprint": "7a6338fd1ec2a815", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e94d6e806870371c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/importEnginesFromCompletenessCsv.ts:71"}, "properties": {"repobilityId": "43f4e0d8e60fd7f4", "scanner": "scanner-primary", "fingerprint": "e94d6e806870371c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-878833b956d0649f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/mergeWarehouseLocations.ts:69"}, "properties": {"repobilityId": "333472240ad7fcf4", "scanner": "scanner-primary", "fingerprint": "878833b956d0649f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f0567d11ad80345a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/scripts/emitMasterdataLedgerSnapshot.ts:5"}, "properties": {"repobilityId": "09e2b612f38ad970", "scanner": "scanner-primary", "fingerprint": "f0567d11ad80345a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c539e18673909d9d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/utils/logger.ts:32"}, "properties": {"repobilityId": "a870673a2d107b25", "scanner": "scanner-primary", "fingerprint": "c539e18673909d9d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7657f6ca56012c69", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/database/migrate.ts:7"}, "properties": {"repobilityId": "c84af1655a5d3984", "scanner": "scanner-primary", "fingerprint": "7657f6ca56012c69", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0cae51fff496bf2d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend-api/src/services/ai/aiChatHistoryService.ts:222"}, "properties": {"repobilityId": "023e1318622d57f0", "scanner": "scanner-primary", "fingerprint": "0cae51fff496bf2d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f42d7635723f70f2", "level": "note", "message": {"text": "React Flow edge with `label=` but no project-wide edge-label CSS override \u2014 web-admin/src/ui/components/RepairChecklistPanel.tsx:749"}, "properties": {"repobilityId": "0c71cc0aedff8284", "scanner": "scanner-primary", "fingerprint": "f42d7635723f70f2", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.edge-label.no-bg"]}}, {"ruleId": "scanner-b05fcfeac3258fa5", "level": "warning", "message": {"text": "Privileged port 17 in use"}, "properties": {"repobilityId": "0bf38fb8f89ec589", "scanner": "scanner-primary", "fingerprint": "b05fcfeac3258fa5", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/prod-ops/install-prod-ops.sh"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7ced02fe8565a19c", "level": "warning", "message": {"text": "Privileged port 23 in use"}, "properties": {"repobilityId": "a1230e3dfc4becfa", "scanner": "scanner-primary", "fingerprint": "7ced02fe8565a19c", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/prod-ops/install-prod-ops.sh"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3326eefbf9056d70", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in electron-app/src/renderer/public/update.html:128"}, "properties": {"repobilityId": "1b75b48b07e7a45e", "scanner": "scanner-primary", "fingerprint": "3326eefbf9056d70", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "electron-app/src/renderer/public/update.html"}, "region": {"startLine": 128}}}]}, {"ruleId": "scanner-b879d0dcaef2f6a5", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in electron-app/src/renderer/src/main.tsx:42"}, "properties": {"repobilityId": "8fcff56995a69540", "scanner": "scanner-primary", "fingerprint": "b879d0dcaef2f6a5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "electron-app/src/renderer/src/main.tsx"}, "region": {"startLine": 42}}}]}, {"ruleId": "scanner-4fe84bb071ec5f9a", "level": "note", "message": {"text": "Insecure pattern 'document_write' in electron-app/src/renderer/src/ui/utils/printPreview.ts:108"}, "properties": {"repobilityId": "988a22d6d64f7435", "scanner": "scanner-primary", "fingerprint": "4fe84bb071ec5f9a", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["owasp", "document_write"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "electron-app/src/renderer/src/ui/utils/printPreview.ts"}, "region": {"startLine": 108}}}]}, {"ruleId": "scanner-87925ecdf7efa838", "level": "note", "message": {"text": "Insecure pattern 'document_write' in electron-app/src/renderer/src/ui/utils/engineInventoryPrintHtml.ts:367"}, "properties": {"repobilityId": "13084e57d889f27b", "scanner": "scanner-primary", "fingerprint": "87925ecdf7efa838", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["owasp", "document_write"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "electron-app/src/renderer/src/ui/utils/engineInventoryPrintHtml.ts"}, "region": {"startLine": 367}}}]}, {"ruleId": "scanner-64bc4404505a8fcf", "level": "note", "message": {"text": "Insecure pattern 'document_write' in electron-app/src/renderer/src/ui/components/RepairChecklistPanel.tsx:1369"}, "properties": {"repobilityId": "9512e05c06216e72", "scanner": "scanner-primary", "fingerprint": "64bc4404505a8fcf", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["owasp", "document_write"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "electron-app/src/renderer/src/ui/components/RepairChecklistPanel.tsx"}, "region": {"startLine": 1369}}}]}, {"ruleId": "scanner-dbb89a394a164ede", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in electron-app/src/renderer/src/ui/components/AiAgentChat.tsx:511"}, "properties": {"repobilityId": "78b0a326f1a31a59", "scanner": "scanner-primary", "fingerprint": "dbb89a394a164ede", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "electron-app/src/renderer/src/ui/components/AiAgentChat.tsx"}, "region": {"startLine": 511}}}]}, {"ruleId": "scanner-a0d6b3f321e77f2b", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in electron-app/src/renderer/src/ui/pages/ReportPresetPage.tsx:1053"}, "properties": {"repobilityId": "e013d1513505db79", "scanner": "scanner-primary", "fingerprint": "a0d6b3f321e77f2b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "electron-app/src/renderer/src/ui/pages/ReportPresetPage.tsx"}, "region": {"startLine": 1053}}}]}, {"ruleId": "scanner-02d29e80eaac34e2", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in electron-app/src/renderer/src/ui/pages/ReportsPage.tsx:525"}, "properties": {"repobilityId": "e7bd3bedd1c08457", "scanner": "scanner-primary", "fingerprint": "02d29e80eaac34e2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "electron-app/src/renderer/src/ui/pages/ReportsPage.tsx"}, "region": {"startLine": 525}}}]}, {"ruleId": "scanner-e2686b42dd099664", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in electron-app/src/main/services/updateService.ts:3"}, "properties": {"repobilityId": "e6593ef3a8c53c98", "scanner": "scanner-primary", "fingerprint": "e2686b42dd099664", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "electron-app/src/main/services/updateService.ts"}, "region": {"startLine": 3}}}]}, {"ruleId": "scanner-7e65710c33437fed", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in electron-app/src/main/services/emergencyUpdate.ts:10"}, "properties": {"repobilityId": "614ddbac7de0e1df", "scanner": "scanner-primary", "fingerprint": "7e65710c33437fed", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "electron-app/src/main/services/emergencyUpdate.ts"}, "region": {"startLine": 10}}}]}, {"ruleId": "scanner-9e66a8b7f431ac59", "level": "error", "message": {"text": "Insecure pattern 'private_key_in_repo' in backend-api/ledger/server-key.json:3"}, "properties": {"repobilityId": "c04587927a91af2b", "scanner": "scanner-primary", "fingerprint": "9e66a8b7f431ac59", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["owasp", "private_key_in_repo"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend-api/ledger/server-key.json"}, "region": {"startLine": 3}}}]}, {"ruleId": "scanner-61a4515a733bb896", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in backend-api/src/app.ts:55"}, "properties": {"repobilityId": "6e7d120fb84d75f9", "scanner": "scanner-primary", "fingerprint": "61a4515a733bb896", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend-api/src/app.ts"}, "region": {"startLine": 55}}}]}, {"ruleId": "scanner-fe254666dfec8183", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in backend-api/src/scripts/nightlyBackup.ts:2"}, "properties": {"repobilityId": "897392805ab52308", "scanner": "scanner-primary", "fingerprint": "fe254666dfec8183", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend-api/src/scripts/nightlyBackup.ts"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-b331578528b45e1a", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in backend-api/src/routes/backups.ts:3"}, "properties": {"repobilityId": "8af3d8a119aa94fc", "scanner": "scanner-primary", "fingerprint": "b331578528b45e1a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend-api/src/routes/backups.ts"}, "region": {"startLine": 3}}}]}, {"ruleId": "scanner-aa21d2973bd6dbe1", "level": "note", "message": {"text": "Insecure pattern 'document_write' in web-admin/src/ui/EngineDetailsPage.tsx:114"}, "properties": {"repobilityId": "e0d0c32d365f8ec4", "scanner": "scanner-primary", "fingerprint": "aa21d2973bd6dbe1", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["owasp", "document_write"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web-admin/src/ui/EngineDetailsPage.tsx"}, "region": {"startLine": 114}}}]}, {"ruleId": "scanner-d288a9769c62d8d2", "level": "note", "message": {"text": "Insecure pattern 'document_write' in web-admin/src/ui/components/RepairChecklistPanel.tsx:642"}, "properties": {"repobilityId": "e8d5712e4d880501", "scanner": "scanner-primary", "fingerprint": "d288a9769c62d8d2", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["owasp", "document_write"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web-admin/src/ui/components/RepairChecklistPanel.tsx"}, "region": {"startLine": 642}}}]}, {"ruleId": "scanner-f03eccd2234cb56f", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/bump-backend-version.mjs:1"}, "properties": {"repobilityId": "1d091198e16e4089", "scanner": "scanner-primary", "fingerprint": "f03eccd2234cb56f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/bump-backend-version.mjs"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ce9e47a75f30422", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/run-with-backend-env.mjs:4"}, "properties": {"repobilityId": "3a02a84f9e289f60", "scanner": "scanner-primary", "fingerprint": "3ce9e47a75f30422", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/run-with-backend-env.mjs"}, "region": {"startLine": 4}}}]}, {"ruleId": "scanner-fe5824b3872b6d70", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/publish-ledger-release.mjs:15"}, "properties": {"repobilityId": "67ba9332a2337aae", "scanner": "scanner-primary", "fingerprint": "fe5824b3872b6d70", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/publish-ledger-release.mjs"}, "region": {"startLine": 15}}}]}, {"ruleId": "scanner-ad8ba3ddd200089f", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/release-auto.mjs:2"}, "properties": {"repobilityId": "7a6b5dacc36943bd", "scanner": "scanner-primary", "fingerprint": "ad8ba3ddd200089f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/release-auto.mjs"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-8f4c232b4aa78fc9", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "c12bee5eb58a5ecf", "scanner": "scanner-primary", "fingerprint": "8f4c232b4aa78fc9", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/claude-code-review.yml"}, "region": {"startLine": 34}}}]}, {"ruleId": "scanner-8f4c232b4aa78fc9", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "7572d8d133564421", "scanner": "scanner-primary", "fingerprint": "8f4c232b4aa78fc9", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/claude-code-review.yml"}, "region": {"startLine": 39}}}]}, {"ruleId": "scanner-47019809066cf7f6", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "a5e8a8d3a82a6f35", "scanner": "scanner-primary", "fingerprint": "47019809066cf7f6", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/typecheck.yml"}, "region": {"startLine": 14}}}]}, {"ruleId": "scanner-47019809066cf7f6", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "380893527c8ec28b", "scanner": "scanner-primary", "fingerprint": "47019809066cf7f6", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/typecheck.yml"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-47019809066cf7f6", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "846abab106613348", "scanner": "scanner-primary", "fingerprint": "47019809066cf7f6", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/typecheck.yml"}, "region": {"startLine": 22}}}]}, {"ruleId": "scanner-266162aa2c525a31", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "d3510036b5495e29", "scanner": "scanner-primary", "fingerprint": "266162aa2c525a31", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/lint.yml"}, "region": {"startLine": 14}}}]}, {"ruleId": "scanner-266162aa2c525a31", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "d6f011547df7ee21", "scanner": "scanner-primary", "fingerprint": "266162aa2c525a31", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/lint.yml"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-266162aa2c525a31", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "d690c48cacbaa6bf", "scanner": "scanner-primary", "fingerprint": "266162aa2c525a31", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/lint.yml"}, "region": {"startLine": 22}}}]}, {"ruleId": "scanner-a9b6dd5d37f3e59d", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "cb4d9345dccc12b0", "scanner": "scanner-primary", "fingerprint": "a9b6dd5d37f3e59d", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/check-sync-contract.yml"}, "region": {"startLine": 14}}}]}, {"ruleId": "scanner-a9b6dd5d37f3e59d", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "3848a263a667e16d", "scanner": "scanner-primary", "fingerprint": "a9b6dd5d37f3e59d", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/check-sync-contract.yml"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-a9b6dd5d37f3e59d", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "798e33d981815e12", "scanner": "scanner-primary", "fingerprint": "a9b6dd5d37f3e59d", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/check-sync-contract.yml"}, "region": {"startLine": 22}}}]}, {"ruleId": "scanner-12522bf27bea173c", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "2b969a8d0206488d", "scanner": "scanner-primary", "fingerprint": "12522bf27bea173c", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/secret-scan.yml"}, "region": {"startLine": 18}}}]}, {"ruleId": "scanner-12522bf27bea173c", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "b5a63b98c363d324", "scanner": "scanner-primary", "fingerprint": "12522bf27bea173c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/secret-scan.yml"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-9f4aee53bdfaab38", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "bad0e0e59dcf3661", "scanner": "scanner-primary", "fingerprint": "9f4aee53bdfaab38", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release-electron-windows.yml"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-9f4aee53bdfaab38", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "f21a5c29fd66bfc0", "scanner": "scanner-primary", "fingerprint": "9f4aee53bdfaab38", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release-electron-windows.yml"}, "region": {"startLine": 20}}}]}, {"ruleId": "scanner-9f4aee53bdfaab38", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "3f96fd2cacd6bf58", "scanner": "scanner-primary", "fingerprint": "9f4aee53bdfaab38", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release-electron-windows.yml"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-0b128f7d6f786b46", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "a72fb634a783d8e3", "scanner": "scanner-primary", "fingerprint": "0b128f7d6f786b46", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release-electron-windows.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f12cfa59ab2159bc", "level": "note", "message": {"text": "package.json defines install-time lifecycle scripts"}, "properties": {"repobilityId": "8886105707356b86", "scanner": "scanner-primary", "fingerprint": "f12cfa59ab2159bc", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "npm", "install-scripts"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "shared/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c2632ea9a191a687", "level": "note", "message": {"text": "package.json defines install-time lifecycle scripts"}, "properties": {"repobilityId": "825ea88f70579cab", "scanner": "scanner-primary", "fingerprint": "c2632ea9a191a687", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "npm", "install-scripts"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "ledger/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-37cbb120632af5e6", "level": "note", "message": {"text": "Very large file: electron-app/src/renderer/src/ui/App.tsx (4200 lines)"}, "properties": {"repobilityId": "2957a6c5ae0221fa", "scanner": "scanner-primary", "fingerprint": "37cbb120632af5e6", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-47ee1d4663d7cf81", "level": "note", "message": {"text": "Very large file: electron-app/src/renderer/src/ui/components/RepairChecklistPanel.tsx (2753 lines)"}, "properties": {"repobilityId": "69229282cc196e9c", "scanner": "scanner-primary", "fingerprint": "47ee1d4663d7cf81", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6e80dba5ca459e0f", "level": "note", "message": {"text": "Very large file: electron-app/src/renderer/src/ui/pages/EngineDetailsPage.tsx (1180 lines)"}, "properties": {"repobilityId": "786c410944428a37", "scanner": "scanner-primary", "fingerprint": "6e80dba5ca459e0f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-23b39356d3429e9c", "level": "note", "message": {"text": "Very large file: electron-app/src/renderer/src/ui/pages/EngineAssemblyBomDetailsPage.tsx (2204 lines)"}, "properties": {"repobilityId": "e8fb5b66228ba2c6", "scanner": "scanner-primary", "fingerprint": "23b39356d3429e9c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-f1d0b849768ad225", "level": "note", "message": {"text": "Very large file: electron-app/src/renderer/src/ui/pages/WorkOrderDetailsPage.tsx (1989 lines)"}, "properties": {"repobilityId": "b6811ccfd6549c58", "scanner": "scanner-primary", "fingerprint": "f1d0b849768ad225", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-eca8347e82131368", "level": "note", "message": {"text": "Very large file: electron-app/src/renderer/src/ui/pages/SupplyRequestDetailsPage.tsx (1496 lines)"}, "properties": {"repobilityId": "c367e4b46f6dc27f", "scanner": "scanner-primary", "fingerprint": "eca8347e82131368", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-565824c8dd79f7e1", "level": "note", "message": {"text": "Very large file: electron-app/src/renderer/src/ui/pages/ContractDetailsPage.tsx (1768 lines)"}, "properties": {"repobilityId": "d531fe287999f3d2", "scanner": "scanner-primary", "fingerprint": "565824c8dd79f7e1", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-b85a4a29f232bf46", "level": "note", "message": {"text": "Very large file: electron-app/src/renderer/src/ui/pages/AdminPage.tsx (1986 lines)"}, "properties": {"repobilityId": "50dbfc643992c4a2", "scanner": "scanner-primary", "fingerprint": "b85a4a29f232bf46", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-099b6c220dca032c", "level": "note", "message": {"text": "Very large file: electron-app/src/renderer/src/ui/pages/PartDetailsPage.tsx (2819 lines)"}, "properties": {"repobilityId": "2e47a6eaf17a56eb", "scanner": "scanner-primary", "fingerprint": "099b6c220dca032c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-e375a84a768a78dd", "level": "note", "message": {"text": "Very large file: electron-app/src/renderer/src/ui/pages/ReportPresetPage.tsx (1124 lines)"}, "properties": {"repobilityId": "d87634c1d888452d", "scanner": "scanner-primary", "fingerprint": "e375a84a768a78dd", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-0602f95ae95a9a92", "level": "note", "message": {"text": "Very large file: electron-app/src/renderer/src/ui/pages/NomenclatureDetailsPage.tsx (1280 lines)"}, "properties": {"repobilityId": "be258b3cc610718a", "scanner": "scanner-primary", "fingerprint": "0602f95ae95a9a92", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-9bc0e4d0483576ec", "level": "note", "message": {"text": "Very large file: electron-app/src/renderer/src/ui/pages/EmployeeDetailsPage.tsx (1873 lines)"}, "properties": {"repobilityId": "e34a57aa81d682a1", "scanner": "scanner-primary", "fingerprint": "9bc0e4d0483576ec", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-501c8f39c1944332", "level": "note", "message": {"text": "Very large file: electron-app/src/main/services/toolsService.ts (1290 lines)"}, "properties": {"repobilityId": "3bc38e3da5ed1488", "scanner": "scanner-primary", "fingerprint": "501c8f39c1944332", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-207b40a985639836", "level": "note", "message": {"text": "Very large file: electron-app/src/main/services/updateService.ts (3173 lines)"}, "properties": {"repobilityId": "24dd351fd0ce439c", "scanner": "scanner-primary", "fingerprint": "207b40a985639836", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-4f108bff18807a76", "level": "note", "message": {"text": "Very large file: electron-app/src/main/services/reportPresetService.ts (4560 lines)"}, "properties": {"repobilityId": "47e8343b74e14c77", "scanner": "scanner-primary", "fingerprint": "4f108bff18807a76", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-4f7da332e5b6a78b", "level": "note", "message": {"text": "Very large file: electron-app/src/main/services/syncService.ts (3220 lines)"}, "properties": {"repobilityId": "0f0fbc4850395d07", "scanner": "scanner-primary", "fingerprint": "4f7da332e5b6a78b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-4e9d88862f13abce", "level": "note", "message": {"text": "Very large file: electron-app/src/main/services/erpService.ts (1586 lines)"}, "properties": {"repobilityId": "d12d7bc68395b05b", "scanner": "scanner-primary", "fingerprint": "4e9d88862f13abce", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-160da9bd3d6c6f57", "level": "note", "message": {"text": "Very large file: backend-api/src/scripts/importEnginesFromCompletenessCsv.ts (1312 lines)"}, "properties": {"repobilityId": "d3dbec5c7ad89a4f", "scanner": "scanner-primary", "fingerprint": "160da9bd3d6c6f57", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-4d2e0e80ae79116e", "level": "note", "message": {"text": "Very large file: backend-api/src/database/schema.ts (1389 lines)"}, "properties": {"repobilityId": "d935d279370faa6b", "scanner": "scanner-primary", "fingerprint": "4d2e0e80ae79116e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-feb2d52c332e6a69", "level": "note", "message": {"text": "Very large file: backend-api/src/routes/warehouse.ts (1122 lines)"}, "properties": {"repobilityId": "1008ee3bebd29814", "scanner": "scanner-primary", "fingerprint": "feb2d52c332e6a69", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-01ca4246d4c94acd", "level": "note", "message": {"text": "Very large file: backend-api/src/services/warehouseBomService.ts (1318 lines)"}, "properties": {"repobilityId": "7078f02bc8025fba", "scanner": "scanner-primary", "fingerprint": "01ca4246d4c94acd", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-19ec9bde90c07cdd", "level": "note", "message": {"text": "Very large file: backend-api/src/services/warehouseService.ts (3602 lines)"}, "properties": {"repobilityId": "89a9fea84356a024", "scanner": "scanner-primary", "fingerprint": "19ec9bde90c07cdd", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-06795c86b88b8065", "level": "note", "message": {"text": "Very large file: backend-api/src/services/sync/applyPushBatch.ts (1667 lines)"}, "properties": {"repobilityId": "8c3d2fcce5d4b756", "scanner": "scanner-primary", "fingerprint": "06795c86b88b8065", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-58e5bb34faeb6a0a", "level": "note", "message": {"text": "Very large file: web-admin/src/ui/AdminUsersPage.tsx (1064 lines)"}, "properties": {"repobilityId": "2669b3cd2156cc30", "scanner": "scanner-primary", "fingerprint": "58e5bb34faeb6a0a", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-5dbee85799eef32b", "level": "note", "message": {"text": "Very large file: web-admin/src/ui/AdminPage.tsx (1886 lines)"}, "properties": {"repobilityId": "91613ff0ae578739", "scanner": "scanner-primary", "fingerprint": "5dbee85799eef32b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-d0ec23c0904687b8", "level": "note", "message": {"text": "Very large file: shared/src/ipc/types.ts (1747 lines)"}, "properties": {"repobilityId": "fcf620f457f9cf43", "scanner": "scanner-primary", "fingerprint": "d0ec23c0904687b8", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-aaa2dad3e5f49058", "level": "note", "message": {"text": "Very large file: shared/src/domain/assemblyForecast.ts (1236 lines)"}, "properties": {"repobilityId": "c6f3648b6f47cbe1", "scanner": "scanner-primary", "fingerprint": "aaa2dad3e5f49058", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-58517a60886cf90b", "level": "note", "message": {"text": "Very large file: shared/src/domain/releaseWelcome.ts (2202 lines)"}, "properties": {"repobilityId": "b8dc1d55fa09f9eb", "scanner": "scanner-primary", "fingerprint": "58517a60886cf90b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ea3b5e389d8c9c0f", "level": "note", "message": {"text": "Low test-to-source ratio"}, "properties": {"repobilityId": "ef7b2552cc00a375", "scanner": "scanner-primary", "fingerprint": "ea3b5e389d8c9c0f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["tests"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "30c97f94acb460f6", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-f004592ea670ecd8", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: electron-app/package.json"}, "properties": {"repobilityId": "5715b2e5741b5582", "scanner": "scanner-primary", "fingerprint": "f004592ea670ecd8", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "electron-app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4ba7bf03eee0f05b", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: backend-api/package.json"}, "properties": {"repobilityId": "5a4905f0d3e4df7c", "scanner": "scanner-primary", "fingerprint": "4ba7bf03eee0f05b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend-api/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-feb3f31ed6425312", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: web-admin/package.json"}, "properties": {"repobilityId": "0d7bca9a69f03e7b", "scanner": "scanner-primary", "fingerprint": "feb3f31ed6425312", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web-admin/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2b3b4131c0cb2eaa", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: shared/package.json"}, "properties": {"repobilityId": "310fa61d19fba401", "scanner": "scanner-primary", "fingerprint": "2b3b4131c0cb2eaa", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "shared/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa902b1772572e86", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: ledger/package.json"}, "properties": {"repobilityId": "c966f1dc1ee604e0", "scanner": "scanner-primary", "fingerprint": "aa902b1772572e86", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "ledger/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "de76abca28967790", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "bf0417bb1066b545", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-9d79c4077342a7d0", "level": "warning", "message": {"text": "Runtime service client appears to use placeholder configuration"}, "properties": {"repobilityId": "37954dd388e9a2dd", "scanner": "scanner-primary", "fingerprint": "9d79c4077342a7d0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "runtime-config", "service-client", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "a13127f9f960389d", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "4013f0ab989eca4e", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "fa0255268f4d6979", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "f62900f8025ffb09", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "23ed30651063b293", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-122f91b7f2906dc4", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/settings.json"}, "properties": {"repobilityId": "a2967269048b6a9d", "scanner": "scanner-primary", "fingerprint": "122f91b7f2906dc4", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/settings.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b1c5c6472f566842", "level": "note", "message": {"text": "Legacy-named symbol `matrica_client_input_assist_history_v1` in electron-app/src/renderer/src/ui/App.tsx:4194"}, "properties": {"repobilityId": "11da4960dc5e7d1a", "scanner": "scanner-primary", "fingerprint": "b1c5c6472f566842", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-12f5f99d057b38ec", "level": "none", "message": {"text": "Commented-code block (6 lines) in electron-app/src/renderer/src/ui/utils/partsPagination.ts:13"}, "properties": {"repobilityId": "c3fc9911b7da558b", "scanner": "scanner-primary", "fingerprint": "12f5f99d057b38ec", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-43b495520c75fe6c", "level": "none", "message": {"text": "Commented-code block (5 lines) in electron-app/src/renderer/src/ui/components/RepairChecklistPanel.tsx:2262"}, "properties": {"repobilityId": "581a3c63db6ddc5c", "scanner": "scanner-primary", "fingerprint": "43b495520c75fe6c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-34147fa005ad75e2", "level": "note", "message": {"text": "Legacy-named symbol `parts_movement_v1` in electron-app/src/renderer/src/ui/components/EngineDismantlePreviewDialog.tsx:196"}, "properties": {"repobilityId": "25ec442eb4b9a9f5", "scanner": "scanner-primary", "fingerprint": "34147fa005ad75e2", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-b0b42d1beb5eec14", "level": "none", "message": {"text": "Commented-code block (5 lines) in electron-app/src/renderer/src/ui/pages/EngineDetailsPage.tsx:24"}, "properties": {"repobilityId": "2cd030c86c4c8367", "scanner": "scanner-primary", "fingerprint": "b0b42d1beb5eec14", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-72733448902bc96b", "level": "note", "message": {"text": "Legacy-named symbol `bom_relation_schema_v1` in electron-app/src/renderer/src/ui/pages/EngineAssemblyBomDetailsPage.tsx:480"}, "properties": {"repobilityId": "f68937a645813624", "scanner": "scanner-primary", "fingerprint": "72733448902bc96b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-87300f0d404c39f3", "level": "none", "message": {"text": "Commented-code block (6 lines) in electron-app/src/renderer/src/ui/pages/EngineAssemblyBomDetailsPage.tsx:719"}, "properties": {"repobilityId": "5fd5f1e163bddbdd", "scanner": "scanner-primary", "fingerprint": "87300f0d404c39f3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7cc1c50e57863002", "level": "none", "message": {"text": "Commented-code block (6 lines) in electron-app/src/renderer/src/ui/pages/WorkOrderDetailsPage.tsx:1529"}, "properties": {"repobilityId": "1664b160b08358db", "scanner": "scanner-primary", "fingerprint": "7cc1c50e57863002", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4985cac3ba625406", "level": "note", "message": {"text": "Legacy-named symbol `contractSectionsToLegacy` in electron-app/src/renderer/src/ui/pages/ContractDetailsPage.tsx:22"}, "properties": {"repobilityId": "0c9bebfa0a9de07d", "scanner": "scanner-primary", "fingerprint": "4985cac3ba625406", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-ba3a4c1a5ca23925", "level": "none", "message": {"text": "Commented-code block (6 lines) in electron-app/src/renderer/src/ui/pages/ContractsPage.tsx:193"}, "properties": {"repobilityId": "ddee3bb92017ee83", "scanner": "scanner-primary", "fingerprint": "ba3a4c1a5ca23925", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b62e83cb2070ccb0", "level": "note", "message": {"text": "Legacy-named symbol `supplierLegacy` in electron-app/src/renderer/src/ui/pages/PartDetailsPage.tsx:112"}, "properties": {"repobilityId": "28927709665b8d74", "scanner": "scanner-primary", "fingerprint": "b62e83cb2070ccb0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-4bf13c63caf3d615", "level": "none", "message": {"text": "Commented-code block (5 lines) in electron-app/src/renderer/src/ui/pages/PartDetailsPage.tsx:226"}, "properties": {"repobilityId": "a3736c45ffd8d45f", "scanner": "scanner-primary", "fingerprint": "4bf13c63caf3d615", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-09b671c39e215b93", "level": "none", "message": {"text": "Commented-code block (6 lines) in electron-app/src/renderer/src/ui/pages/NomenclatureDetailsPage.tsx:525"}, "properties": {"repobilityId": "c4328dc7b1b9ef58", "scanner": "scanner-primary", "fingerprint": "09b671c39e215b93", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-86a993bf24b5fefd", "level": "none", "message": {"text": "Commented-code block (8 lines) in electron-app/src/renderer/src/ui/pages/StockDocumentDetailsPage.tsx:362"}, "properties": {"repobilityId": "f2150aea4a026b45", "scanner": "scanner-primary", "fingerprint": "86a993bf24b5fefd", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-eaed041eaa10c306", "level": "none", "message": {"text": "Commented-code block (6 lines) in electron-app/src/main/index.ts:48"}, "properties": {"repobilityId": "89a206cd48a0a0e2", "scanner": "scanner-primary", "fingerprint": "eaed041eaa10c306", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-14b44c7e5b024102", "level": "none", "message": {"text": "Commented-code block (5 lines) in electron-app/src/main/utils/logger.ts:7"}, "properties": {"repobilityId": "f1846c23087937ce", "scanner": "scanner-primary", "fingerprint": "14b44c7e5b024102", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e42989f505671965", "level": "none", "message": {"text": "Commented-code block (7 lines) in electron-app/src/main/database/migrate.ts:17"}, "properties": {"repobilityId": "74f8e9b76fa38815", "scanner": "scanner-primary", "fingerprint": "e42989f505671965", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8ca9b1a6b8695b15", "level": "note", "message": {"text": "Legacy-named symbol `force_full_pull_v2` in electron-app/src/main/services/clientAdminService.ts:62"}, "properties": {"repobilityId": "2aa902e874f13f10", "scanner": "scanner-primary", "fingerprint": "8ca9b1a6b8695b15", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-9b754730dffefd42", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 electron-app/src/main/services/clientAdminService.ts:97"}, "properties": {"repobilityId": "07392f31e22aa30c", "scanner": "scanner-primary", "fingerprint": "9b754730dffefd42", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-c7ed445ec47a9ca1", "level": "none", "message": {"text": "Commented-code block (7 lines) in electron-app/src/main/services/blockmapDelta.measure.test.ts:1"}, "properties": {"repobilityId": "f621e70304101606", "scanner": "scanner-primary", "fingerprint": "c7ed445ec47a9ca1", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c1875c965e3b0491", "level": "none", "message": {"text": "Commented-code block (7 lines) in electron-app/src/main/services/yandexResourceMeta.ts:4"}, "properties": {"repobilityId": "9b290d70e0245f1a", "scanner": "scanner-primary", "fingerprint": "c1875c965e3b0491", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0c256590a309d95a", "level": "none", "message": {"text": "Commented-code block (5 lines) in electron-app/src/main/services/updateService.ts:805"}, "properties": {"repobilityId": "cb0dfde6ffb0bad2", "scanner": "scanner-primary", "fingerprint": "0c256590a309d95a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-34b127adcb69abc3", "level": "none", "message": {"text": "Commented-code block (7 lines) in electron-app/src/main/services/installerIntegrityRecovery.ts:4"}, "properties": {"repobilityId": "97cb44efe795ab61", "scanner": "scanner-primary", "fingerprint": "34b127adcb69abc3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-078b5c5505221ab6", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 electron-app/src/main/services/fileService.ts:445"}, "properties": {"repobilityId": "12cc2ae481d757f8", "scanner": "scanner-primary", "fingerprint": "078b5c5505221ab6", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-82e5e6007b18e994", "level": "none", "message": {"text": "Commented-code block (7 lines) in electron-app/src/main/services/emergencyUpdate.ts:1"}, "properties": {"repobilityId": "77503d9b30d21f61", "scanner": "scanner-primary", "fingerprint": "82e5e6007b18e994", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a3537a79eec22ac1", "level": "none", "message": {"text": "Commented-code block (7 lines) in electron-app/src/main/services/syncService.ts:1358"}, "properties": {"repobilityId": "866da03efd825b0f", "scanner": "scanner-primary", "fingerprint": "a3537a79eec22ac1", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3db8e6a531d8c450", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 electron-app/src/main/services/backupService.ts:77"}, "properties": {"repobilityId": "47338692df6cef7e", "scanner": "scanner-primary", "fingerprint": "3db8e6a531d8c450", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-dce5e4faf41d2ead", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend-api/src/tests/warehouseBomUpsert.integration.test.ts:8"}, "properties": {"repobilityId": "c23c9bed4cbe1e31", "scanner": "scanner-primary", "fingerprint": "dce5e4faf41d2ead", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ac40c7f3e99a9a1f", "level": "note", "message": {"text": "Legacy-named symbol `bom_line_meta_v1` in backend-api/src/tests/assemblyForecastKitBuilder.test.ts:121"}, "properties": {"repobilityId": "d833cba68f25c91d", "scanner": "scanner-primary", "fingerprint": "ac40c7f3e99a9a1f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-c9d104b9c17e9d63", "level": "none", "message": {"text": "Commented-code block (7 lines) in backend-api/src/tests/assemblyForecastKitBuilder.test.ts:5"}, "properties": {"repobilityId": "bca5737bbbaa461e", "scanner": "scanner-primary", "fingerprint": "c9d104b9c17e9d63", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4796f3be6d996150", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend-api/src/tests/warehouse.partSpec.roundtrip.test.ts:3"}, "properties": {"repobilityId": "af473cace4697e2b", "scanner": "scanner-primary", "fingerprint": "4796f3be6d996150", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b02e625218a3dd2b", "level": "note", "message": {"text": "Legacy-named symbol `supplierLegacy` in backend-api/src/tests/partFieldMirror.test.ts:65"}, "properties": {"repobilityId": "7ba2943f205001a8", "scanner": "scanner-primary", "fingerprint": "b02e625218a3dd2b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-54a56c8054f02fed", "level": "note", "message": {"text": "Legacy-named symbol `parts_movement_v1` in backend-api/src/tests/warehouse.assemblyReserve.test.ts:64"}, "properties": {"repobilityId": "32ef82628b7a62b9", "scanner": "scanner-primary", "fingerprint": "54a56c8054f02fed", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-d615deccbedeb58d", "level": "note", "message": {"text": "Legacy-named symbol `hasLegacy` in backend-api/src/scripts/migrateChecklistToEngineInventory.ts:162"}, "properties": {"repobilityId": "0f902367ccc791ed", "scanner": "scanner-primary", "fingerprint": "d615deccbedeb58d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-9de70d9d2496863d", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend-api/src/scripts/migrateChecklistToEngineInventory.ts:26"}, "properties": {"repobilityId": "d602f8a2608a91bb", "scanner": "scanner-primary", "fingerprint": "9de70d9d2496863d", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-555d3836197a9ee5", "level": "none", "message": {"text": "Commented-code block (8 lines) in backend-api/src/scripts/importBasePartsList.ts:4"}, "properties": {"repobilityId": "bc172d55232545c6", "scanner": "scanner-primary", "fingerprint": "555d3836197a9ee5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8dae9c737b685d7a", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend-api/src/scripts/seedNomenclatureVerifyFixture.ts:20"}, "properties": {"repobilityId": "1789ea0fcc210ffb", "scanner": "scanner-primary", "fingerprint": "8dae9c737b685d7a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-681f0d0fd38c433e", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend-api/src/scripts/auditPartsMirror.ts:7"}, "properties": {"repobilityId": "caca0d833e203557", "scanner": "scanner-primary", "fingerprint": "681f0d0fd38c433e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5cc5e8a5284d9f56", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend-api/src/scripts/migrateExistingWorkshopOrders.ts:10"}, "properties": {"repobilityId": "2db4eb08dd086bd9", "scanner": "scanner-primary", "fingerprint": "5cc5e8a5284d9f56", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0a83d86f14fdacd5", "level": "none", "message": {"text": "Commented-code block (8 lines) in backend-api/src/scripts/fixPartsMirror.ts:7"}, "properties": {"repobilityId": "aed24f6b4cab7b36", "scanner": "scanner-primary", "fingerprint": "0a83d86f14fdacd5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-bc957f86fd00e78f", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend-api/src/scripts/backfillOrphanPartNomenclature.ts:6"}, "properties": {"repobilityId": "22e31e1995664ef0", "scanner": "scanner-primary", "fingerprint": "bc957f86fd00e78f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3923541c7fa46b0d", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend-api/src/scripts/softDeleteLegacyRepairOperations.ts:7"}, "properties": {"repobilityId": "5985434ac06fdc99", "scanner": "scanner-primary", "fingerprint": "3923541c7fa46b0d", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b8fc9b8726422564", "level": "note", "message": {"text": "Legacy-named symbol `supplierLegacy` in backend-api/src/scripts/backfillDirectoryPartsMetadata.ts:130"}, "properties": {"repobilityId": "3705ef4ec783c84d", "scanner": "scanner-primary", "fingerprint": "b8fc9b8726422564", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-aed84ae9cd82d8ee", "level": "none", "message": {"text": "Commented-code block (10 lines) in backend-api/src/scripts/migrateWorkshopTemplatesToWorkOrderTemplates.ts:8"}, "properties": {"repobilityId": "2f8e35131acca391", "scanner": "scanner-primary", "fingerprint": "aed84ae9cd82d8ee", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ac73969f8b8d5746", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend-api/src/scripts/seedDevFixtures.ts:135"}, "properties": {"repobilityId": "6e68936abf0bb34e", "scanner": "scanner-primary", "fingerprint": "ac73969f8b8d5746", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-9a4b54234d3d1658", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend-api/src/scripts/migrateComponentTypeFromSpecJson.ts:8"}, "properties": {"repobilityId": "6ea8514a95f0ce70", "scanner": "scanner-primary", "fingerprint": "9a4b54234d3d1658", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-73b56c3a4ec9ea07", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend-api/src/routes/files.ts:429"}, "properties": {"repobilityId": "24e76375784b8029", "scanner": "scanner-primary", "fingerprint": "73b56c3a4ec9ea07", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-37679f2dc2d241fc", "level": "note", "message": {"text": "Legacy-named symbol `supplierLegacy` in backend-api/src/routes/warehouse.ts:394"}, "properties": {"repobilityId": "d506535b1b10b101", "scanner": "scanner-primary", "fingerprint": "37679f2dc2d241fc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-8a16b2e6ce10e4a5", "level": "note", "message": {"text": "Legacy-named symbol `force_full_pull_v2` in backend-api/src/routes/adminClients.ts:103"}, "properties": {"repobilityId": "a95cc468386e2656", "scanner": "scanner-primary", "fingerprint": "8a16b2e6ce10e4a5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-b4fa0528a4a45ee2", "level": "note", "message": {"text": "Legacy-named symbol `markDeprecated` in backend-api/src/routes/workshops.ts:74"}, "properties": {"repobilityId": "096c83e97e6c4906", "scanner": "scanner-primary", "fingerprint": "b4fa0528a4a45ee2", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-136d8f4e931dcabc", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend-api/src/services/directoryPartsDedupeService.ts:1"}, "properties": {"repobilityId": "bfcdfe7af7a2fa2a", "scanner": "scanner-primary", "fingerprint": "136d8f4e931dcabc", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b4d9f4fb12c1a269", "level": "note", "message": {"text": "Legacy-named symbol `supplierLegacy` in backend-api/src/services/partFieldMirror.ts:130"}, "properties": {"repobilityId": "af931a435b6bbb53", "scanner": "scanner-primary", "fingerprint": "b4d9f4fb12c1a269", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-db3354e8c6423b04", "level": "none", "message": {"text": "Commented-code block (8 lines) in backend-api/src/services/warehouseBomService.ts:459"}, "properties": {"repobilityId": "52f14e5992550546", "scanner": "scanner-primary", "fingerprint": "db3354e8c6423b04", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-bdb279474a23ff61", "level": "note", "message": {"text": "Legacy-named symbol `parts_movement_v1` in backend-api/src/services/warehouseService.ts:86"}, "properties": {"repobilityId": "38bdb89a8daf64ba", "scanner": "scanner-primary", "fingerprint": "bdb279474a23ff61", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-9c491aeb4de6c03b", "level": "none", "message": {"text": "Commented-code block (7 lines) in backend-api/src/services/warehouseService.ts:796"}, "properties": {"repobilityId": "d3ac71c211b10d9b", "scanner": "scanner-primary", "fingerprint": "9c491aeb4de6c03b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a5f958dab29a174d", "level": "note", "message": {"text": "Legacy-named symbol `bom_line_meta_v1` in backend-api/src/services/warehouseBomLineMeta.ts:2"}, "properties": {"repobilityId": "0bd9a2b5ffb8ef2d", "scanner": "scanner-primary", "fingerprint": "a5f958dab29a174d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-10c4db9732b507f4", "level": "none", "message": {"text": "Commented-code block (8 lines) in backend-api/src/services/engineDedupeService.ts:3"}, "properties": {"repobilityId": "882afea4aca43d7f", "scanner": "scanner-primary", "fingerprint": "10c4db9732b507f4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5de81af3029437f1", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend-api/src/services/engineNumberGuard.ts:1"}, "properties": {"repobilityId": "ab4eccb9dfbeb531", "scanner": "scanner-primary", "fingerprint": "5de81af3029437f1", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3f424ff8efb6a430", "level": "note", "message": {"text": "Legacy-named symbol `force_full_pull_v2` in backend-api/src/services/diagnosticsAutohealService.ts:10"}, "properties": {"repobilityId": "6977abfc7b27f90f", "scanner": "scanner-primary", "fingerprint": "3f424ff8efb6a430", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-7cb36c29702caf4b", "level": "none", "message": {"text": "Commented-code block (8 lines) in backend-api/src/services/workshopRepairTemplateService.ts:111"}, "properties": {"repobilityId": "c2a6b5781a7d383f", "scanner": "scanner-primary", "fingerprint": "7cb36c29702caf4b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a05d82e75cfdaed5", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend-api/src/services/warehouseForecastService.ts:63"}, "properties": {"repobilityId": "afa8bfb3ab138552", "scanner": "scanner-primary", "fingerprint": "a05d82e75cfdaed5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f179c4a5e3ce98a3", "level": "note", "message": {"text": "Legacy-named symbol `parts_movement_v1` in backend-api/src/services/workOrderClosingService.ts:517"}, "properties": {"repobilityId": "fd6efc496f73bbb5", "scanner": "scanner-primary", "fingerprint": "f179c4a5e3ce98a3", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-03cfe17e84f4dbf9", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend-api/src/services/workOrderClosingService.ts:420"}, "properties": {"repobilityId": "4266508f0739e48b", "scanner": "scanner-primary", "fingerprint": "03cfe17e84f4dbf9", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-cfe037a902f6f46a", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend-api/src/services/sync/applyPushBatch.ts:523"}, "properties": {"repobilityId": "2ad0ac22ad5202f9", "scanner": "scanner-primary", "fingerprint": "cfe037a902f6f46a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1de6c540b0e7fe4a", "level": "none", "message": {"text": "Commented-code block (6 lines) in web-admin/src/api/parts.ts:3"}, "properties": {"repobilityId": "9d3b4e2dff9352a6", "scanner": "scanner-primary", "fingerprint": "1de6c540b0e7fe4a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f1a0804976012adf", "level": "note", "message": {"text": "Legacy-named symbol `matrica_webadmin_input_assist_history_v1` in web-admin/src/ui/App.tsx:633"}, "properties": {"repobilityId": "071a32438262ca61", "scanner": "scanner-primary", "fingerprint": "f1a0804976012adf", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-a177a5f7a189b57c", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 web-admin/src/ui/ChatPanel.tsx:378"}, "properties": {"repobilityId": "b4fa59682f7c1c71", "scanner": "scanner-primary", "fingerprint": "a177a5f7a189b57c", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-e00b45a32d4a1b71", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 web-admin/src/ui/components/AttachmentsPanel.tsx:76"}, "properties": {"repobilityId": "b971ade3cc8cf6f8", "scanner": "scanner-primary", "fingerprint": "e00b45a32d4a1b71", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-6ae6e14d8579ceab", "level": "none", "message": {"text": "Commented-code block (5 lines) in shared/src/domain/partsDedup.ts:7"}, "properties": {"repobilityId": "c0529ec537f33d56", "scanner": "scanner-primary", "fingerprint": "6ae6e14d8579ceab", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-9c0d2c41ce624ebd", "level": "note", "message": {"text": "Legacy-named symbol `bom_relation_schema_v1` in shared/src/domain/buildEngineBomSkeletonBlockLines.test.ts:11"}, "properties": {"repobilityId": "a2b35043caa663d5", "scanner": "scanner-primary", "fingerprint": "9c0d2c41ce624ebd", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-21934ccd88c096ee", "level": "none", "message": {"text": "Commented-code block (8 lines) in shared/src/domain/tieredSearch.ts:4"}, "properties": {"repobilityId": "3fde348f1cbb40c4", "scanner": "scanner-primary", "fingerprint": "21934ccd88c096ee", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-98e39187aae1e5f7", "level": "none", "message": {"text": "Commented-code block (6 lines) in shared/src/domain/calver.ts:1"}, "properties": {"repobilityId": "6b3783fe723487f9", "scanner": "scanner-primary", "fingerprint": "98e39187aae1e5f7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-390774e397bdce22", "level": "note", "message": {"text": "Legacy-named symbol `bom_relation_schema_v1` in shared/src/domain/groupedNomenclatureOptions.test.ts:51"}, "properties": {"repobilityId": "28869798ce83b644", "scanner": "scanner-primary", "fingerprint": "390774e397bdce22", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-1816800c71499a1f", "level": "note", "message": {"text": "Legacy-named symbol `bom_relation_schema_v1` in shared/src/domain/warehouse.ts:819"}, "properties": {"repobilityId": "e10455fdfa645f1c", "scanner": "scanner-primary", "fingerprint": "1816800c71499a1f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-9299f980ecd95524", "level": "note", "message": {"text": "Legacy-named symbol `parts_movement_v1` in shared/src/domain/releaseWelcome.ts:1276"}, "properties": {"repobilityId": "746f03f6b92f6171", "scanner": "scanner-primary", "fingerprint": "9299f980ecd95524", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-29034aafdb57dee4", "level": "note", "message": {"text": "Legacy-named symbol `contractSectionsToLegacy` in shared/src/domain/contract.ts:478"}, "properties": {"repobilityId": "d9d5d32d4704f504", "scanner": "scanner-primary", "fingerprint": "29034aafdb57dee4", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-5e1b59485d3ca808", "level": "note", "message": {"text": "Legacy-named symbol `supplierLegacy` in shared/src/domain/part.ts:93"}, "properties": {"repobilityId": "f9e8188a2b190853", "scanner": "scanner-primary", "fingerprint": "5e1b59485d3ca808", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-6dba8c0e4e319c63", "level": "none", "message": {"text": "Commented-code block (6 lines) in shared/src/domain/part.ts:55"}, "properties": {"repobilityId": "e800f7412c435fb8", "scanner": "scanner-primary", "fingerprint": "6dba8c0e4e319c63", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5ccec860ab42b60c", "level": "note", "message": {"text": "Legacy-named symbol `hasLegacy` in scripts/release-auto.mjs:219"}, "properties": {"repobilityId": "af61bfa8c65538f3", "scanner": "scanner-primary", "fingerprint": "5ccec860ab42b60c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-e7330ddc3338c11a", "level": "none", "message": {"text": "Commented-code block (5 lines) in .claude/skills/verifier-electron/scripts/cdp-drive.mjs:535"}, "properties": {"repobilityId": "aaa36871612a182a", "scanner": "scanner-primary", "fingerprint": "e7330ddc3338c11a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a0b23e01683e0b09", "level": "note", "message": {"text": "99 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "0232a8319d7ea77c", "scanner": "scanner-primary", "fingerprint": "a0b23e01683e0b09", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-9aed0ad53a8d9fb5", "level": "error", "message": {"text": "Dangling fetch: GET https://api.telegram.org/bot${token}/getUpdates?${qs.toString()} (backend-api/src/services/telegramBotService.ts:67)"}, "properties": {"repobilityId": "c8133f0b92c2320f", "scanner": "scanner-primary", "fingerprint": "9aed0ad53a8d9fb5", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-604c514fdb0744c0", "level": "error", "message": {"text": "Dangling fetch: POST https://api.telegram.org/bot${token}/sendMessage (backend-api/src/services/telegramBotService.ts:127)"}, "properties": {"repobilityId": "d24bb9cc098d6f63", "scanner": "scanner-primary", "fingerprint": "604c514fdb0744c0", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-a3878f30db3e653f", "level": "error", "message": {"text": "Dangling fetch: POST https://api.telegram.org/bot${token}/sendMessage (backend-api/src/services/telegramBotService.ts:141)"}, "properties": {"repobilityId": "6152eba0383f2c3b", "scanner": "scanner-primary", "fingerprint": "a3878f30db3e653f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-65d96c8d9b6a82fb", "level": "error", "message": {"text": "Dangling fetch: POST https://api.telegram.org/bot${token}/sendMessage (backend-api/src/services/telegramBotService.ts:176)"}, "properties": {"repobilityId": "810af361f1355a2a", "scanner": "scanner-primary", "fingerprint": "65d96c8d9b6a82fb", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-c20b017acb9100b1", "level": "error", "message": {"text": "Dangling fetch: POST https://api.telegram.org/bot${token}/answerCallbackQuery (backend-api/src/services/telegramBotService.ts:206)"}, "properties": {"repobilityId": "3195b5460ef8585b", "scanner": "scanner-primary", "fingerprint": "c20b017acb9100b1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-b28d92215a503990", "level": "note", "message": {"text": "Unused endpoint: USE /auth"}, "properties": {"repobilityId": "d098fffbcc842443", "scanner": "scanner-primary", "fingerprint": "b28d92215a503990", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d1e264ad403454f2", "level": "note", "message": {"text": "Unused endpoint: USE /sync"}, "properties": {"repobilityId": "e2ee8e7420215b51", "scanner": "scanner-primary", "fingerprint": "d1e264ad403454f2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b17f829e3d159660", "level": "note", "message": {"text": "Unused endpoint: USE /ledger"}, "properties": {"repobilityId": "17b4be8ae1bc9426", "scanner": "scanner-primary", "fingerprint": "b17f829e3d159660", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ed523761442e1550", "level": "note", "message": {"text": "Unused endpoint: USE /chat"}, "properties": {"repobilityId": "3ffd6d55ce384703", "scanner": "scanner-primary", "fingerprint": "ed523761442e1550", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ac6a148d5ebfd22d", "level": "note", "message": {"text": "Unused endpoint: USE /notes"}, "properties": {"repobilityId": "df428c7559e9b703", "scanner": "scanner-primary", "fingerprint": "ac6a148d5ebfd22d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3631280e38df0f48", "level": "note", "message": {"text": "Unused endpoint: USE /presence"}, "properties": {"repobilityId": "2a3d3fb15e953c62", "scanner": "scanner-primary", "fingerprint": "3631280e38df0f48", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b2d8849fb6b1ac47", "level": "note", "message": {"text": "Unused endpoint: USE /admin"}, "properties": {"repobilityId": "97a5eab07caa975b", "scanner": "scanner-primary", "fingerprint": "b2d8849fb6b1ac47", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8b7d781b752795b6", "level": "note", "message": {"text": "Unused endpoint: USE /admin/audit"}, "properties": {"repobilityId": "01fced38be121b86", "scanner": "scanner-primary", "fingerprint": "8b7d781b752795b6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-062c46d5b843a144", "level": "note", "message": {"text": "Unused endpoint: USE /admin/masterdata"}, "properties": {"repobilityId": "a3bb0e39b3a65c3e", "scanner": "scanner-primary", "fingerprint": "062c46d5b843a144", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-435018eab0195ac5", "level": "note", "message": {"text": "Unused endpoint: USE /changes"}, "properties": {"repobilityId": "a747702c8336297b", "scanner": "scanner-primary", "fingerprint": "435018eab0195ac5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a0665830dbcd2d75", "level": "note", "message": {"text": "Unused endpoint: USE /files"}, "properties": {"repobilityId": "d4390f7107a40dff", "scanner": "scanner-primary", "fingerprint": "a0665830dbcd2d75", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-02a6953bf3de2811", "level": "note", "message": {"text": "Unused endpoint: USE /parts"}, "properties": {"repobilityId": "0e542fa580446626", "scanner": "scanner-primary", "fingerprint": "02a6953bf3de2811", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f71af222bae50fc3", "level": "note", "message": {"text": "Unused endpoint: USE /logs"}, "properties": {"repobilityId": "e557d075be30af41", "scanner": "scanner-primary", "fingerprint": "f71af222bae50fc3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-54a2bc88d734e604", "level": "note", "message": {"text": "Unused endpoint: USE /backups"}, "properties": {"repobilityId": "a3718264e9ad9e95", "scanner": "scanner-primary", "fingerprint": "54a2bc88d734e604", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-04c73ad45855ed5c", "level": "note", "message": {"text": "Unused endpoint: USE /updates"}, "properties": {"repobilityId": "fbafd8be4a18a223", "scanner": "scanner-primary", "fingerprint": "04c73ad45855ed5c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-520546e90f7fd2b2", "level": "note", "message": {"text": "Unused endpoint: USE /client"}, "properties": {"repobilityId": "91b3810ebda0d8fb", "scanner": "scanner-primary", "fingerprint": "520546e90f7fd2b2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f97bd0fa8037a2d5", "level": "note", "message": {"text": "Unused endpoint: USE /employees"}, "properties": {"repobilityId": "9a82ebf2da1e6e1c", "scanner": "scanner-primary", "fingerprint": "f97bd0fa8037a2d5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b7fb24880fe6e9b0", "level": "note", "message": {"text": "Unused endpoint: USE /checklists"}, "properties": {"repobilityId": "7b1ccfbd011a1011", "scanner": "scanner-primary", "fingerprint": "b7fb24880fe6e9b0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a773f635fec979c9", "level": "note", "message": {"text": "Unused endpoint: USE /diagnostics"}, "properties": {"repobilityId": "079cf0158cf920a1", "scanner": "scanner-primary", "fingerprint": "a773f635fec979c9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6bdcbf2073dfa768", "level": "note", "message": {"text": "Unused endpoint: USE /ai"}, "properties": {"repobilityId": "ea3beabb41d0c298", "scanner": "scanner-primary", "fingerprint": "6bdcbf2073dfa768", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a8f40a426fdfb45", "level": "note", "message": {"text": "Unused endpoint: USE /reports"}, "properties": {"repobilityId": "ea2b0ffec98b2581", "scanner": "scanner-primary", "fingerprint": "7a8f40a426fdfb45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-13eff24bd33b83d1", "level": "note", "message": {"text": "Unused endpoint: USE /erp"}, "properties": {"repobilityId": "54e6e374827380d7", "scanner": "scanner-primary", "fingerprint": "13eff24bd33b83d1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-459977599dd00f73", "level": "note", "message": {"text": "Unused endpoint: USE /warehouse"}, "properties": {"repobilityId": "5aa51d8cc945ccd4", "scanner": "scanner-primary", "fingerprint": "459977599dd00f73", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4ce40f9d5c4d6e99", "level": "note", "message": {"text": "Unused endpoint: USE /work-orders"}, "properties": {"repobilityId": "a99bfceef9444fbf", "scanner": "scanner-primary", "fingerprint": "4ce40f9d5c4d6e99", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-24cb02ddec517007", "level": "note", "message": {"text": "Unused endpoint: USE /work-order-templates"}, "properties": {"repobilityId": "549a7c18f4917290", "scanner": "scanner-primary", "fingerprint": "24cb02ddec517007", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b804dfef0189b34a", "level": "note", "message": {"text": "Unused endpoint: USE /workshops"}, "properties": {"repobilityId": "e88829b6ba88a056", "scanner": "scanner-primary", "fingerprint": "b804dfef0189b34a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9d576b555a46f4ba", "level": "note", "message": {"text": "Unused endpoint: USE /warehouse-locations"}, "properties": {"repobilityId": "d4abfa8028ba5a44", "scanner": "scanner-primary", "fingerprint": "9d576b555a46f4ba", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c204d5a6447f5b37", "level": "note", "message": {"text": "Unused endpoint: USE /service-pricing"}, "properties": {"repobilityId": "d9a18892d3b0166a", "scanner": "scanner-primary", "fingerprint": "c204d5a6447f5b37", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-166f8ca84e7c11a2", "level": "note", "message": {"text": "Unused endpoint: USE /admin-ui"}, "properties": {"repobilityId": "102a0a0fae024f05", "scanner": "scanner-primary", "fingerprint": "166f8ca84e7c11a2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d5677aacc06eb64c", "level": "note", "message": {"text": "Unused endpoint: GET /admin-ui/*"}, "properties": {"repobilityId": "6592889dc72fd5ab", "scanner": "scanner-primary", "fingerprint": "d5677aacc06eb64c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-618721b912bad1c2", "level": "note", "message": {"text": "Unused endpoint: POST /login"}, "properties": {"repobilityId": "cb1ad8a3dd0660ac", "scanner": "scanner-primary", "fingerprint": "618721b912bad1c2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-304b6f2b403d93f7", "level": "note", "message": {"text": "Unused endpoint: POST /register"}, "properties": {"repobilityId": "ff951b4fa05e5d09", "scanner": "scanner-primary", "fingerprint": "304b6f2b403d93f7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cabf0be91b0aec0b", "level": "note", "message": {"text": "Unused endpoint: GET /login-options"}, "properties": {"repobilityId": "d2371c0a1ad8c613", "scanner": "scanner-primary", "fingerprint": "cabf0be91b0aec0b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd1dc91abf32142d", "level": "note", "message": {"text": "Unused endpoint: GET /me"}, "properties": {"repobilityId": "d79fcbc91a4b17ff", "scanner": "scanner-primary", "fingerprint": "fd1dc91abf32142d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f28f51e38b33ffc8", "level": "note", "message": {"text": "Unused endpoint: POST /release-token"}, "properties": {"repobilityId": "079ffc9fe4c2a003", "scanner": "scanner-primary", "fingerprint": "f28f51e38b33ffc8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8c1bfd0a66740639", "level": "note", "message": {"text": "Unused endpoint: GET /users/:id/permissions-view"}, "properties": {"repobilityId": "044118475fd9cda4", "scanner": "scanner-primary", "fingerprint": "8c1bfd0a66740639", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2595b39638e5c045", "level": "note", "message": {"text": "Unused endpoint: GET /profile"}, "properties": {"repobilityId": "1847839fcbf1277a", "scanner": "scanner-primary", "fingerprint": "2595b39638e5c045", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-512ccb0fd0b230ba", "level": "note", "message": {"text": "Unused endpoint: GET /settings"}, "properties": {"repobilityId": "00747bfb4737ab89", "scanner": "scanner-primary", "fingerprint": "512ccb0fd0b230ba", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-689e4ffd880f570d", "level": "note", "message": {"text": "Unused endpoint: PATCH /settings"}, "properties": {"repobilityId": "2ba75c98a6955f93", "scanner": "scanner-primary", "fingerprint": "689e4ffd880f570d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-73c3b023fb81d73a", "level": "note", "message": {"text": "Unused endpoint: GET /ui-settings"}, "properties": {"repobilityId": "dec6e5223dc5d085", "scanner": "scanner-primary", "fingerprint": "73c3b023fb81d73a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7c1ea719911c281b", "level": "note", "message": {"text": "Unused endpoint: PATCH /ui-settings"}, "properties": {"repobilityId": "1e11061fb3c024b1", "scanner": "scanner-primary", "fingerprint": "7c1ea719911c281b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-70d575c3569a5404", "level": "note", "message": {"text": "Unused endpoint: GET /ui-profile"}, "properties": {"repobilityId": "c2bf4903f11ca21f", "scanner": "scanner-primary", "fingerprint": "70d575c3569a5404", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fb68a196d9cac55e", "level": "note", "message": {"text": "Unused endpoint: PATCH /ui-profile"}, "properties": {"repobilityId": "87a6d34a2c9b6f07", "scanner": "scanner-primary", "fingerprint": "fb68a196d9cac55e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2a45f4e5dfe7a73c", "level": "note", "message": {"text": "Unused endpoint: GET /ui-settings/global"}, "properties": {"repobilityId": "8e05965e338a6b7f", "scanner": "scanner-primary", "fingerprint": "2a45f4e5dfe7a73c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-347c717f6eb2c190", "level": "note", "message": {"text": "Unused endpoint: PATCH /ui-settings/global"}, "properties": {"repobilityId": "bb422bdfe8d2520e", "scanner": "scanner-primary", "fingerprint": "347c717f6eb2c190", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-59a1cc885f47e39f", "level": "note", "message": {"text": "Unused endpoint: PATCH /profile"}, "properties": {"repobilityId": "279b4b671e5a5e86", "scanner": "scanner-primary", "fingerprint": "59a1cc885f47e39f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7ce17d6b092a81ca", "level": "note", "message": {"text": "Unused endpoint: POST /refresh"}, "properties": {"repobilityId": "9a52964a9ec08b76", "scanner": "scanner-primary", "fingerprint": "7ce17d6b092a81ca", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-99fc36db98c134ce", "level": "note", "message": {"text": "Unused endpoint: POST /logout"}, "properties": {"repobilityId": "2a298d8adaf5b169", "scanner": "scanner-primary", "fingerprint": "99fc36db98c134ce", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4fe9bb486644f008", "level": "note", "message": {"text": "Unused endpoint: POST /change-password"}, "properties": {"repobilityId": "dc250abe8f383dc5", "scanner": "scanner-primary", "fingerprint": "4fe9bb486644f008", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "a0a86e805364eed1", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}