{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-da7d851473953e9f", "name": "Stray `console.log` in TS/JS \u2014 src/scripts/test-scheduled-items.js:128", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-scheduled-items.js:128"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5e92a4e928c1f831", "name": "Stray `console.log` in TS/JS \u2014 src/scripts/test-coupon-checkout.js:89", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-coupon-checkout.js:89"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-16de80a8365d8731", "name": "Stray `console.log` in TS/JS \u2014 src/scripts/test-type-migration.js:71", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-type-migration.js:71"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7db1f1a0dcf8161c", "name": "Stray `console.log` in TS/JS \u2014 src/scripts/test-bank-transfer.js:98", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-bank-transfer.js:98"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72dab8353a0af15c", "name": "Stray `console.log` in TS/JS \u2014 src/scripts/test-variants-admin.js:44", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-variants-admin.js:44"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-038f72379fd5d8c5", "name": "Stray `console.log` in TS/JS \u2014 src/scripts/test-myorders-filter.js:74", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-myorders-filter.js:74"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4930f6a450ba1799", "name": "Stray `console.log` in TS/JS \u2014 src/scripts/test-category-meta.js:52", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-category-meta.js:52"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-05bbedbebd1aba64", "name": "Stray `console.log` in TS/JS \u2014 src/scripts/test-product-import.js:34", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-product-import.js:34"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-80d2dff14e4e3849", "name": "Stray `console.log` in TS/JS \u2014 src/scripts/test-variants.js:139", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-variants.js:139"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d1d50a747f1737b0", "name": "Stray `console.log` in TS/JS \u2014 src/scripts/test-checkout-linepay-coupon.js:108", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-checkout-linepay-coupon.js:108"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2fd101eacf4635ed", "name": "Stray `console.log` in TS/JS \u2014 src/scripts/test-customer-auth.js:87", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-customer-auth.js:87"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-32a5681db7125801", "name": "Stray `console.log` in TS/JS \u2014 src/scripts/test-bulk-cleanup.js:66", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-bulk-cleanup.js:66"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3fbe098fc73925c8", "name": "Stray `console.log` in TS/JS \u2014 src/scripts/test-cancel-by-user.js:68", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-cancel-by-user.js:68"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-23f29da507b89819", "name": "Stray `console.log` in TS/JS \u2014 src/scripts/test-vip-upgrade.js:88", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-vip-upgrade.js:88"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-31b594680e7cbb8e", "name": "Stray `console.log` in TS/JS \u2014 src/scripts/check-pending.js:19", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/check-pending.js:19"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1a956f04fbb811ef", "name": "Stray `console.log` in TS/JS \u2014 src/scripts/test-coupon.js:84", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-coupon.js:84"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8a1f5be7b38c2c66", "name": "Stray `console.log` in TS/JS \u2014 src/scripts/manual-confirm.js:18", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/manual-confirm.js:18"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cbc34df71f241d27", "name": "Stray `console.log` in TS/JS \u2014 src/scripts/test-ecpay-logistics.js:20", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-ecpay-logistics.js:20"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8e13c99039b4ef11", "name": "Stray `console.log` in TS/JS \u2014 src/scripts/test-linepay-coupon.js:36", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-linepay-coupon.js:36"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d991126f8cde8a53", "name": "Stray `console.log` in TS/JS \u2014 src/utils/ecpay.js:163", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/utils/ecpay.js:163"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8987d6d1c30c7202", "name": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-060bbb0fedb58f72", "name": "Possible secret in src/scripts/test-customer-auth.js", "shortDescription": {"text": "Possible secret in src/scripts/test-customer-auth.js"}, "fullDescription": {"text": "Detected pattern matching password_literal. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-c20780bbf94d55da", "name": "Insecure pattern 'weak_hash' in src/utils/ecpay.js:4", "shortDescription": {"text": "Insecure pattern 'weak_hash' in src/utils/ecpay.js:4"}, "fullDescription": {"text": "Found a known-risky pattern (weak_hash). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-27924aa79fa4a517", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-64192a3c67110d01", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 174 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 36 placeholder/mock markers across 13 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8934a521ba8d9f4b", "name": "Commented-code block (7 lines) in src/utils/linepay.js:74", "shortDescription": {"text": "Commented-code block (7 lines) in src/utils/linepay.js:74"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7e5a61dd87d4badf", "name": "Commented-code block (5 lines) in src/utils/ecpay.js:133", "shortDescription": {"text": "Commented-code block (5 lines) in src/utils/ecpay.js:133"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-322d67b8ef7b2f88", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/utils/ecpay.js:111", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/utils/ecpay.js:111"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a18c586b2ebd72b1", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/oauthService.js:152", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/oauthService.js:152"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5fa5af25316da646", "name": "16 env vars used in code but missing from .env.example", "shortDescription": {"text": "16 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `BANK_ACCOUNT_HOLDER`, `BANK_ACCOUNT_NO`, `BANK_NAME`, `BANK_TRANSFER_EXPIRE_HOURS`, `ECPAY_CLIENT_REPLY_URL`, `ECPAY_DEBUG`, `ECPAY_SENDER_ADDRESS`, `ECPAY_SENDER_CELLPHONE` + 8 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-94da1aaaf36cc41f", "name": "Unused endpoint: USE /api/v1", "shortDescription": {"text": "Unused endpoint: USE /api/v1"}, "fullDescription": {"text": "`src/app.js` declares `USE /api/v1` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1d2f7fecff5fc79a", "name": "Unused endpoint: POST /foo", "shortDescription": {"text": "Unused endpoint: POST /foo"}, "fullDescription": {"text": "`src/middleware/validate.js` declares `POST /foo` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`src/routes/v1/addon.js` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6385cd0e163a390f", "name": "Unused endpoint: POST /checkout", "shortDescription": {"text": "Unused endpoint: POST /checkout"}, "fullDescription": {"text": "`src/routes/v1/payment.js` declares `POST /checkout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-29db4b5dd9147cc1", "name": "Unused endpoint: GET /linepay/confirm", "shortDescription": {"text": "Unused endpoint: GET /linepay/confirm"}, "fullDescription": {"text": "`src/routes/v1/payment.js` declares `GET /linepay/confirm` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-55c998fb9c6294d0", "name": "Unused endpoint: GET /linepay/cancel", "shortDescription": {"text": "Unused endpoint: GET /linepay/cancel"}, "fullDescription": {"text": "`src/routes/v1/payment.js` declares `GET /linepay/cancel` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-84c9c52815c3e258", "name": "Unused endpoint: GET /bank-info", "shortDescription": {"text": "Unused endpoint: GET /bank-info"}, "fullDescription": {"text": "`src/routes/v1/payment.js` declares `GET /bank-info` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ba2224a43dbb222c", "name": "Unused endpoint: POST /refund/:orderId", "shortDescription": {"text": "Unused endpoint: POST /refund/:orderId"}, "fullDescription": {"text": "`src/routes/v1/payment.js` declares `POST /refund/:orderId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-95a2f6eda8c1bb0e", "name": "Unused endpoint: GET /bundles", "shortDescription": {"text": "Unused endpoint: GET /bundles"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `GET /bundles` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5d5e8129658f7bbd", "name": "Unused endpoint: POST /bundles", "shortDescription": {"text": "Unused endpoint: POST /bundles"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `POST /bundles` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f6f2d4be23650122", "name": "Unused endpoint: PUT /bundles/:bundleId", "shortDescription": {"text": "Unused endpoint: PUT /bundles/:bundleId"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `PUT /bundles/:bundleId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e931faf6dda847e9", "name": "Unused endpoint: DELETE /bundles/:bundleId", "shortDescription": {"text": "Unused endpoint: DELETE /bundles/:bundleId"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `DELETE /bundles/:bundleId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-17db5eee07bd0ec0", "name": "Unused endpoint: GET /addons", "shortDescription": {"text": "Unused endpoint: GET /addons"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `GET /addons` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3f878bc4d6fd535e", "name": "Unused endpoint: POST /addons", "shortDescription": {"text": "Unused endpoint: POST /addons"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `POST /addons` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-18fabdc800867c82", "name": "Unused endpoint: PUT /addons/:addonId", "shortDescription": {"text": "Unused endpoint: PUT /addons/:addonId"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `PUT /addons/:addonId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4e93233c223f9d5f", "name": "Unused endpoint: DELETE /addons/:addonId", "shortDescription": {"text": "Unused endpoint: DELETE /addons/:addonId"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `DELETE /addons/:addonId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-004bc6f5f21763a4", "name": "Unused endpoint: PATCH /orders/:orderId/status", "shortDescription": {"text": "Unused endpoint: PATCH /orders/:orderId/status"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `PATCH /orders/:orderId/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-36410befa74fbfa0", "name": "Unused endpoint: PATCH /orders/:orderId/tracking", "shortDescription": {"text": "Unused endpoint: PATCH /orders/:orderId/tracking"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `PATCH /orders/:orderId/tracking` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ad911e4fcaa068c3", "name": "Unused endpoint: POST /orders/:orderId/refund", "shortDescription": {"text": "Unused endpoint: POST /orders/:orderId/refund"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `POST /orders/:orderId/refund` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-15b43cd0d73bab95", "name": "Unused endpoint: POST /orders/:orderId/mark-paid", "shortDescription": {"text": "Unused endpoint: POST /orders/:orderId/mark-paid"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `POST /orders/:orderId/mark-paid` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f1084bc3b7a4f4bb", "name": "Unused endpoint: GET /products", "shortDescription": {"text": "Unused endpoint: GET /products"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `GET /products` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0e55a03dd77a7303", "name": "Unused endpoint: POST /products/import", "shortDescription": {"text": "Unused endpoint: POST /products/import"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `POST /products/import` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6757181dc7e4b668", "name": "Unused endpoint: PATCH /products/:productId", "shortDescription": {"text": "Unused endpoint: PATCH /products/:productId"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `PATCH /products/:productId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-07bac637ad07ebaa", "name": "Unused endpoint: DELETE /products/:productId", "shortDescription": {"text": "Unused endpoint: DELETE /products/:productId"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `DELETE /products/:productId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-29cc33d9ac9bacb7", "name": "Unused endpoint: POST /products/bulk-type", "shortDescription": {"text": "Unused endpoint: POST /products/bulk-type"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `POST /products/bulk-type` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a1207f9b3a66e5dc", "name": "Unused endpoint: PATCH /products/:productId/stock", "shortDescription": {"text": "Unused endpoint: PATCH /products/:productId/stock"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `PATCH /products/:productId/stock` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5c783dff88159791", "name": "Unused endpoint: PUT /products/:productId/variants", "shortDescription": {"text": "Unused endpoint: PUT /products/:productId/variants"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `PUT /products/:productId/variants` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4468f8ca50275dbc", "name": "Unused endpoint: PATCH /products/:productId/variants/:variantIndex/stock", "shortDescription": {"text": "Unused endpoint: PATCH /products/:productId/variants/:variantIndex/stock"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `PATCH /products/:productId/variants/:variantIndex/stock` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-09da8787bc214335", "name": "Unused endpoint: POST /cleanup", "shortDescription": {"text": "Unused endpoint: POST /cleanup"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `POST /cleanup` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-00043954e5b3d4f2", "name": "Unused endpoint: PATCH /addons/:addonId/stock", "shortDescription": {"text": "Unused endpoint: PATCH /addons/:addonId/stock"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `PATCH /addons/:addonId/stock` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ed6866fa661b0be6", "name": "Unused endpoint: GET /stock/low", "shortDescription": {"text": "Unused endpoint: GET /stock/low"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `GET /stock/low` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3e8a0a7b406443bc", "name": "Unused endpoint: GET /members", "shortDescription": {"text": "Unused endpoint: GET /members"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `GET /members` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b07012f0e7661c95", "name": "Unused endpoint: POST /members/:id/reset-password", "shortDescription": {"text": "Unused endpoint: POST /members/:id/reset-password"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `POST /members/:id/reset-password` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c7ebf9a541dd2450", "name": "Unused endpoint: PATCH /categories/:key", "shortDescription": {"text": "Unused endpoint: PATCH /categories/:key"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `PATCH /categories/:key` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d04caf4423b3400a", "name": "Unused endpoint: PATCH /content", "shortDescription": {"text": "Unused endpoint: PATCH /content"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `PATCH /content` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-480294fe742e8c74", "name": "Unused endpoint: GET /coupons", "shortDescription": {"text": "Unused endpoint: GET /coupons"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `GET /coupons` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d7dd4c14babc5691", "name": "Unused endpoint: POST /coupons", "shortDescription": {"text": "Unused endpoint: POST /coupons"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `POST /coupons` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cd8dc4599ec52a08", "name": "Unused endpoint: GET /stats", "shortDescription": {"text": "Unused endpoint: GET /stats"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `GET /stats` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e7a11f17586b7592", "name": "Unused endpoint: POST /orders/:orderId/logistics/ecpay", "shortDescription": {"text": "Unused endpoint: POST /orders/:orderId/logistics/ecpay"}, "fullDescription": {"text": "`src/routes/v1/admin.js` declares `POST /orders/:orderId/logistics/ecpay` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cff43de2b698d3ea", "name": "Unused endpoint: GET /ecpay/map-form", "shortDescription": {"text": "Unused endpoint: GET /ecpay/map-form"}, "fullDescription": {"text": "`src/routes/v1/logistics.js` declares `GET /ecpay/map-form` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7c03ee25811ee6dc", "name": "Unused endpoint: POST /ecpay/map-callback", "shortDescription": {"text": "Unused endpoint: POST /ecpay/map-callback"}, "fullDescription": {"text": "`src/routes/v1/logistics.js` declares `POST /ecpay/map-callback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-25ea8ea7896b20c6", "name": "Unused endpoint: POST /ecpay/callback", "shortDescription": {"text": "Unused endpoint: POST /ecpay/callback"}, "fullDescription": {"text": "`src/routes/v1/logistics.js` declares `POST /ecpay/callback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8456eca76070a1a7", "name": "Unused endpoint: GET /mine", "shortDescription": {"text": "Unused endpoint: GET /mine"}, "fullDescription": {"text": "`src/routes/v1/coupon.js` declares `GET /mine` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-34c0472a1f1fafe5", "name": "Unused endpoint: POST /validate", "shortDescription": {"text": "Unused endpoint: POST /validate"}, "fullDescription": {"text": "`src/routes/v1/coupon.js` declares `POST /validate` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-618721b912bad1c2", "name": "Unused endpoint: POST /login", "shortDescription": {"text": "Unused endpoint: POST /login"}, "fullDescription": {"text": "`src/routes/v1/auth.js` declares `POST /login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-304b6f2b403d93f7", "name": "Unused endpoint: POST /register", "shortDescription": {"text": "Unused endpoint: POST /register"}, "fullDescription": {"text": "`src/routes/v1/auth.js` declares `POST /register` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e21cf4ee09f7c6a9", "name": "Unused endpoint: GET /providers", "shortDescription": {"text": "Unused endpoint: GET /providers"}, "fullDescription": {"text": "`src/routes/v1/auth.js` declares `GET /providers` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9771bd5bdfa4155b", "name": "Unused endpoint: POST /oauth/exchange", "shortDescription": {"text": "Unused endpoint: POST /oauth/exchange"}, "fullDescription": {"text": "`src/routes/v1/auth.js` declares `POST /oauth/exchange` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd1dc91abf32142d", "name": "Unused endpoint: GET /me", "shortDescription": {"text": "Unused endpoint: GET /me"}, "fullDescription": {"text": "`src/routes/v1/auth.js` declares `GET /me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea575b61c121b733", "name": "Unused endpoint: PATCH /me", "shortDescription": {"text": "Unused endpoint: PATCH /me"}, "fullDescription": {"text": "`src/routes/v1/auth.js` declares `PATCH /me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/23469"}, "properties": {"repository": "yuzenchen/petsnack-backend", "repoUrl": "https://github.com/yuzenchen/petsnack-backend", "branch": "main"}, "results": [{"ruleId": "scanner-da7d851473953e9f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-scheduled-items.js:128"}, "properties": {"repobilityId": "3f4215e8c176a5b1", "scanner": "scanner-primary", "fingerprint": "da7d851473953e9f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5e92a4e928c1f831", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-coupon-checkout.js:89"}, "properties": {"repobilityId": "b94c1bb8d5e2b71f", "scanner": "scanner-primary", "fingerprint": "5e92a4e928c1f831", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-16de80a8365d8731", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-type-migration.js:71"}, "properties": {"repobilityId": "3afe77814c66c281", "scanner": "scanner-primary", "fingerprint": "16de80a8365d8731", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7db1f1a0dcf8161c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-bank-transfer.js:98"}, "properties": {"repobilityId": "db84fc5310a4d965", "scanner": "scanner-primary", "fingerprint": "7db1f1a0dcf8161c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-72dab8353a0af15c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-variants-admin.js:44"}, "properties": {"repobilityId": "f96b17882b1928ed", "scanner": "scanner-primary", "fingerprint": "72dab8353a0af15c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-038f72379fd5d8c5", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-myorders-filter.js:74"}, "properties": {"repobilityId": "f028a996da5a8dd8", "scanner": "scanner-primary", "fingerprint": "038f72379fd5d8c5", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4930f6a450ba1799", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-category-meta.js:52"}, "properties": {"repobilityId": "c7acd311caee29de", "scanner": "scanner-primary", "fingerprint": "4930f6a450ba1799", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-05bbedbebd1aba64", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-product-import.js:34"}, "properties": {"repobilityId": "6ff5aa5c235aa709", "scanner": "scanner-primary", "fingerprint": "05bbedbebd1aba64", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-80d2dff14e4e3849", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-variants.js:139"}, "properties": {"repobilityId": "dd5b14c8405862da", "scanner": "scanner-primary", "fingerprint": "80d2dff14e4e3849", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d1d50a747f1737b0", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-checkout-linepay-coupon.js:108"}, "properties": {"repobilityId": "4ab7da98df160728", "scanner": "scanner-primary", "fingerprint": "d1d50a747f1737b0", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2fd101eacf4635ed", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-customer-auth.js:87"}, "properties": {"repobilityId": "9784e77041e8a1fa", "scanner": "scanner-primary", "fingerprint": "2fd101eacf4635ed", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-32a5681db7125801", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-bulk-cleanup.js:66"}, "properties": {"repobilityId": "1dab91c043dfaa3e", "scanner": "scanner-primary", "fingerprint": "32a5681db7125801", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3fbe098fc73925c8", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-cancel-by-user.js:68"}, "properties": {"repobilityId": "e949a0e9b6d57d2f", "scanner": "scanner-primary", "fingerprint": "3fbe098fc73925c8", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-23f29da507b89819", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-vip-upgrade.js:88"}, "properties": {"repobilityId": "0d7484697374fd5d", "scanner": "scanner-primary", "fingerprint": "23f29da507b89819", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-31b594680e7cbb8e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/check-pending.js:19"}, "properties": {"repobilityId": "6f886b13e1d4ba7f", "scanner": "scanner-primary", "fingerprint": "31b594680e7cbb8e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-1a956f04fbb811ef", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-coupon.js:84"}, "properties": {"repobilityId": "e97917df34db14b1", "scanner": "scanner-primary", "fingerprint": "1a956f04fbb811ef", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8a1f5be7b38c2c66", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/manual-confirm.js:18"}, "properties": {"repobilityId": "1a757ea1af9a64c3", "scanner": "scanner-primary", "fingerprint": "8a1f5be7b38c2c66", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-cbc34df71f241d27", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-ecpay-logistics.js:20"}, "properties": {"repobilityId": "80d812e9a9d5b826", "scanner": "scanner-primary", "fingerprint": "cbc34df71f241d27", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8e13c99039b4ef11", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scripts/test-linepay-coupon.js:36"}, "properties": {"repobilityId": "3e76ce4d49f851f5", "scanner": "scanner-primary", "fingerprint": "8e13c99039b4ef11", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d991126f8cde8a53", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/utils/ecpay.js:163"}, "properties": {"repobilityId": "76fe94e4a336d09d", "scanner": "scanner-primary", "fingerprint": "d991126f8cde8a53", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8987d6d1c30c7202", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine"}, "properties": {"repobilityId": "0a9b1585173bd3c0", "scanner": "scanner-primary", "fingerprint": "8987d6d1c30c7202", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 16}}}]}, {"ruleId": "scanner-8987d6d1c30c7202", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine"}, "properties": {"repobilityId": "0cb120e5a9b83bec", "scanner": "scanner-primary", "fingerprint": "8987d6d1c30c7202", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-8987d6d1c30c7202", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine"}, "properties": {"repobilityId": "d6fb7b37c45047b4", "scanner": "scanner-primary", "fingerprint": "8987d6d1c30c7202", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 44}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-060bbb0fedb58f72", "level": "error", "message": {"text": "Possible secret in src/scripts/test-customer-auth.js"}, "properties": {"repobilityId": "cd7e7a997bfdd4cd", "scanner": "scanner-primary", "fingerprint": "060bbb0fedb58f72", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/scripts/test-customer-auth.js"}, "region": {"startLine": 92}}}]}, {"ruleId": "scanner-060bbb0fedb58f72", "level": "error", "message": {"text": "Possible secret in src/scripts/test-customer-auth.js"}, "properties": {"repobilityId": "cd7e7a997bfdd4cd", "scanner": "scanner-primary", "fingerprint": "060bbb0fedb58f72", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/scripts/test-customer-auth.js"}, "region": {"startLine": 107}}}]}, {"ruleId": "scanner-060bbb0fedb58f72", "level": "error", "message": {"text": "Possible secret in src/scripts/test-customer-auth.js"}, "properties": {"repobilityId": "cd7e7a997bfdd4cd", "scanner": "scanner-primary", "fingerprint": "060bbb0fedb58f72", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/scripts/test-customer-auth.js"}, "region": {"startLine": 114}}}]}, {"ruleId": "scanner-c20780bbf94d55da", "level": "warning", "message": {"text": "Insecure pattern 'weak_hash' in src/utils/ecpay.js:4"}, "properties": {"repobilityId": "64e5da6cf4754257", "scanner": "scanner-primary", "fingerprint": "c20780bbf94d55da", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "weak_hash"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/utils/ecpay.js"}, "region": {"startLine": 4}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ae16880318b99912", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 31}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "989a74409a402368", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 34}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ae16880318b99912", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 69}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "70c386bf3a50e33b", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 72}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "d1b973fc5722bf04", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 75}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "c3fda9e893c533ec", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 78}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "c4b845a5807c42de", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 86}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "86f821b931a15b71", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 98}}}]}, {"ruleId": "scanner-64192a3c67110d01", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "87338a8bfcb6f435", "scanner": "scanner-primary", "fingerprint": "64192a3c67110d01", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "5b9c7dfe36119bf3", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "0cc9b5a1311a7812", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "b9a97a89a538f75f", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "64c4de4020282246", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "9b71c832cdedfaf5", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "ce190b6a6e1dfb88", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8934a521ba8d9f4b", "level": "none", "message": {"text": "Commented-code block (7 lines) in src/utils/linepay.js:74"}, "properties": {"repobilityId": "e5bb208216f318b0", "scanner": "scanner-primary", "fingerprint": "8934a521ba8d9f4b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7e5a61dd87d4badf", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/utils/ecpay.js:133"}, "properties": {"repobilityId": "9000fc091a90cb5c", "scanner": "scanner-primary", "fingerprint": "7e5a61dd87d4badf", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-322d67b8ef7b2f88", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/utils/ecpay.js:111"}, "properties": {"repobilityId": "d357390cb9ca7e51", "scanner": "scanner-primary", "fingerprint": "322d67b8ef7b2f88", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-a18c586b2ebd72b1", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/oauthService.js:152"}, "properties": {"repobilityId": "5db4189171a05cc1", "scanner": "scanner-primary", "fingerprint": "a18c586b2ebd72b1", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-5fa5af25316da646", "level": "note", "message": {"text": "16 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "e0919a3f6a45e8c2", "scanner": "scanner-primary", "fingerprint": "5fa5af25316da646", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-94da1aaaf36cc41f", "level": "note", "message": {"text": "Unused endpoint: USE /api/v1"}, "properties": {"repobilityId": "08ada707f767765d", "scanner": "scanner-primary", "fingerprint": "94da1aaaf36cc41f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1d2f7fecff5fc79a", "level": "note", "message": {"text": "Unused endpoint: POST /foo"}, "properties": {"repobilityId": "92fcdf2fc911dee1", "scanner": "scanner-primary", "fingerprint": "1d2f7fecff5fc79a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "023eab260ff2e14b", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6385cd0e163a390f", "level": "note", "message": {"text": "Unused endpoint: POST /checkout"}, "properties": {"repobilityId": "627e40150445f672", "scanner": "scanner-primary", "fingerprint": "6385cd0e163a390f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-29db4b5dd9147cc1", "level": "note", "message": {"text": "Unused endpoint: GET /linepay/confirm"}, "properties": {"repobilityId": "e429d10d4904608a", "scanner": "scanner-primary", "fingerprint": "29db4b5dd9147cc1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-55c998fb9c6294d0", "level": "note", "message": {"text": "Unused endpoint: GET /linepay/cancel"}, "properties": {"repobilityId": "e817a2f4e764ef29", "scanner": "scanner-primary", "fingerprint": "55c998fb9c6294d0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-84c9c52815c3e258", "level": "note", "message": {"text": "Unused endpoint: GET /bank-info"}, "properties": {"repobilityId": "bbfdeae534e23381", "scanner": "scanner-primary", "fingerprint": "84c9c52815c3e258", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ba2224a43dbb222c", "level": "note", "message": {"text": "Unused endpoint: POST /refund/:orderId"}, "properties": {"repobilityId": "1d18a0239a5d6466", "scanner": "scanner-primary", "fingerprint": "ba2224a43dbb222c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-95a2f6eda8c1bb0e", "level": "note", "message": {"text": "Unused endpoint: GET /bundles"}, "properties": {"repobilityId": "5755f0f17c73864d", "scanner": "scanner-primary", "fingerprint": "95a2f6eda8c1bb0e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5d5e8129658f7bbd", "level": "note", "message": {"text": "Unused endpoint: POST /bundles"}, "properties": {"repobilityId": "90f4ebb4e142926a", "scanner": "scanner-primary", "fingerprint": "5d5e8129658f7bbd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f6f2d4be23650122", "level": "note", "message": {"text": "Unused endpoint: PUT /bundles/:bundleId"}, "properties": {"repobilityId": "a1714944b1c9954e", "scanner": "scanner-primary", "fingerprint": "f6f2d4be23650122", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e931faf6dda847e9", "level": "note", "message": {"text": "Unused endpoint: DELETE /bundles/:bundleId"}, "properties": {"repobilityId": "ce66cc4959a8e6ca", "scanner": "scanner-primary", "fingerprint": "e931faf6dda847e9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-17db5eee07bd0ec0", "level": "note", "message": {"text": "Unused endpoint: GET /addons"}, "properties": {"repobilityId": "86ff4dfbe4a0aadc", "scanner": "scanner-primary", "fingerprint": "17db5eee07bd0ec0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3f878bc4d6fd535e", "level": "note", "message": {"text": "Unused endpoint: POST /addons"}, "properties": {"repobilityId": "51b42ff39089e57d", "scanner": "scanner-primary", "fingerprint": "3f878bc4d6fd535e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-18fabdc800867c82", "level": "note", "message": {"text": "Unused endpoint: PUT /addons/:addonId"}, "properties": {"repobilityId": "b9c82028d68becf2", "scanner": "scanner-primary", "fingerprint": "18fabdc800867c82", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4e93233c223f9d5f", "level": "note", "message": {"text": "Unused endpoint: DELETE /addons/:addonId"}, "properties": {"repobilityId": "c451ea2828bc3691", "scanner": "scanner-primary", "fingerprint": "4e93233c223f9d5f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-004bc6f5f21763a4", "level": "note", "message": {"text": "Unused endpoint: PATCH /orders/:orderId/status"}, "properties": {"repobilityId": "45fdb1969192fdb1", "scanner": "scanner-primary", "fingerprint": "004bc6f5f21763a4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-36410befa74fbfa0", "level": "note", "message": {"text": "Unused endpoint: PATCH /orders/:orderId/tracking"}, "properties": {"repobilityId": "1180198301f46012", "scanner": "scanner-primary", "fingerprint": "36410befa74fbfa0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ad911e4fcaa068c3", "level": "note", "message": {"text": "Unused endpoint: POST /orders/:orderId/refund"}, "properties": {"repobilityId": "cc20c8f0831f6202", "scanner": "scanner-primary", "fingerprint": "ad911e4fcaa068c3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-15b43cd0d73bab95", "level": "note", "message": {"text": "Unused endpoint: POST /orders/:orderId/mark-paid"}, "properties": {"repobilityId": "99447206fa2e21da", "scanner": "scanner-primary", "fingerprint": "15b43cd0d73bab95", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f1084bc3b7a4f4bb", "level": "note", "message": {"text": "Unused endpoint: GET /products"}, "properties": {"repobilityId": "45bcd52a65674b82", "scanner": "scanner-primary", "fingerprint": "f1084bc3b7a4f4bb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0e55a03dd77a7303", "level": "note", "message": {"text": "Unused endpoint: POST /products/import"}, "properties": {"repobilityId": "0edea51dda54dbbe", "scanner": "scanner-primary", "fingerprint": "0e55a03dd77a7303", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6757181dc7e4b668", "level": "note", "message": {"text": "Unused endpoint: PATCH /products/:productId"}, "properties": {"repobilityId": "df9ecfa25d3370ea", "scanner": "scanner-primary", "fingerprint": "6757181dc7e4b668", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-07bac637ad07ebaa", "level": "note", "message": {"text": "Unused endpoint: DELETE /products/:productId"}, "properties": {"repobilityId": "aa5e47bfc6cb526a", "scanner": "scanner-primary", "fingerprint": "07bac637ad07ebaa", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-29cc33d9ac9bacb7", "level": "note", "message": {"text": "Unused endpoint: POST /products/bulk-type"}, "properties": {"repobilityId": "447532ea3270ac64", "scanner": "scanner-primary", "fingerprint": "29cc33d9ac9bacb7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a1207f9b3a66e5dc", "level": "note", "message": {"text": "Unused endpoint: PATCH /products/:productId/stock"}, "properties": {"repobilityId": "d34f698077198dac", "scanner": "scanner-primary", "fingerprint": "a1207f9b3a66e5dc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5c783dff88159791", "level": "note", "message": {"text": "Unused endpoint: PUT /products/:productId/variants"}, "properties": {"repobilityId": "3900d8d04134e946", "scanner": "scanner-primary", "fingerprint": "5c783dff88159791", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4468f8ca50275dbc", "level": "note", "message": {"text": "Unused endpoint: PATCH /products/:productId/variants/:variantIndex/stock"}, "properties": {"repobilityId": "5021f29e52e45ae6", "scanner": "scanner-primary", "fingerprint": "4468f8ca50275dbc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-09da8787bc214335", "level": "note", "message": {"text": "Unused endpoint: POST /cleanup"}, "properties": {"repobilityId": "50b482e370573f33", "scanner": "scanner-primary", "fingerprint": "09da8787bc214335", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-00043954e5b3d4f2", "level": "note", "message": {"text": "Unused endpoint: PATCH /addons/:addonId/stock"}, "properties": {"repobilityId": "99a550b51487a120", "scanner": "scanner-primary", "fingerprint": "00043954e5b3d4f2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ed6866fa661b0be6", "level": "note", "message": {"text": "Unused endpoint: GET /stock/low"}, "properties": {"repobilityId": "aa464786b420baa7", "scanner": "scanner-primary", "fingerprint": "ed6866fa661b0be6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3e8a0a7b406443bc", "level": "note", "message": {"text": "Unused endpoint: GET /members"}, "properties": {"repobilityId": "487164624cba2d17", "scanner": "scanner-primary", "fingerprint": "3e8a0a7b406443bc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b07012f0e7661c95", "level": "note", "message": {"text": "Unused endpoint: POST /members/:id/reset-password"}, "properties": {"repobilityId": "32dd5a959dc47c7c", "scanner": "scanner-primary", "fingerprint": "b07012f0e7661c95", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c7ebf9a541dd2450", "level": "note", "message": {"text": "Unused endpoint: PATCH /categories/:key"}, "properties": {"repobilityId": "1db7cc9d55ae1a13", "scanner": "scanner-primary", "fingerprint": "c7ebf9a541dd2450", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d04caf4423b3400a", "level": "note", "message": {"text": "Unused endpoint: PATCH /content"}, "properties": {"repobilityId": "2a5292c1e91317d4", "scanner": "scanner-primary", "fingerprint": "d04caf4423b3400a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-480294fe742e8c74", "level": "note", "message": {"text": "Unused endpoint: GET /coupons"}, "properties": {"repobilityId": "71876da1b78f9aea", "scanner": "scanner-primary", "fingerprint": "480294fe742e8c74", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d7dd4c14babc5691", "level": "note", "message": {"text": "Unused endpoint: POST /coupons"}, "properties": {"repobilityId": "12683c6d343cd403", "scanner": "scanner-primary", "fingerprint": "d7dd4c14babc5691", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cd8dc4599ec52a08", "level": "note", "message": {"text": "Unused endpoint: GET /stats"}, "properties": {"repobilityId": "0c3d29a4398e15d0", "scanner": "scanner-primary", "fingerprint": "cd8dc4599ec52a08", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e7a11f17586b7592", "level": "note", "message": {"text": "Unused endpoint: POST /orders/:orderId/logistics/ecpay"}, "properties": {"repobilityId": "d4dde78bb04ddafa", "scanner": "scanner-primary", "fingerprint": "e7a11f17586b7592", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cff43de2b698d3ea", "level": "note", "message": {"text": "Unused endpoint: GET /ecpay/map-form"}, "properties": {"repobilityId": "81ad16a327fb25a8", "scanner": "scanner-primary", "fingerprint": "cff43de2b698d3ea", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7c03ee25811ee6dc", "level": "note", "message": {"text": "Unused endpoint: POST /ecpay/map-callback"}, "properties": {"repobilityId": "03b7870402098ff6", "scanner": "scanner-primary", "fingerprint": "7c03ee25811ee6dc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-25ea8ea7896b20c6", "level": "note", "message": {"text": "Unused endpoint: POST /ecpay/callback"}, "properties": {"repobilityId": "6faa575ea3ff0924", "scanner": "scanner-primary", "fingerprint": "25ea8ea7896b20c6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8456eca76070a1a7", "level": "note", "message": {"text": "Unused endpoint: GET /mine"}, "properties": {"repobilityId": "eb8b0fb81011e885", "scanner": "scanner-primary", "fingerprint": "8456eca76070a1a7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-34c0472a1f1fafe5", "level": "note", "message": {"text": "Unused endpoint: POST /validate"}, "properties": {"repobilityId": "844392b19da89320", "scanner": "scanner-primary", "fingerprint": "34c0472a1f1fafe5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-618721b912bad1c2", "level": "note", "message": {"text": "Unused endpoint: POST /login"}, "properties": {"repobilityId": "bed664d3c66c4f74", "scanner": "scanner-primary", "fingerprint": "618721b912bad1c2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-304b6f2b403d93f7", "level": "note", "message": {"text": "Unused endpoint: POST /register"}, "properties": {"repobilityId": "ba915f15f3cdabcd", "scanner": "scanner-primary", "fingerprint": "304b6f2b403d93f7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e21cf4ee09f7c6a9", "level": "note", "message": {"text": "Unused endpoint: GET /providers"}, "properties": {"repobilityId": "883e1ee5e2e57a4b", "scanner": "scanner-primary", "fingerprint": "e21cf4ee09f7c6a9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9771bd5bdfa4155b", "level": "note", "message": {"text": "Unused endpoint: POST /oauth/exchange"}, "properties": {"repobilityId": "af3cc593d27b1a7b", "scanner": "scanner-primary", "fingerprint": "9771bd5bdfa4155b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd1dc91abf32142d", "level": "note", "message": {"text": "Unused endpoint: GET /me"}, "properties": {"repobilityId": "be098ac01270f631", "scanner": "scanner-primary", "fingerprint": "fd1dc91abf32142d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ea575b61c121b733", "level": "note", "message": {"text": "Unused endpoint: PATCH /me"}, "properties": {"repobilityId": "a578dd89008fb57b", "scanner": "scanner-primary", "fingerprint": "ea575b61c121b733", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}