{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-d73026fde563f3a4", "name": "Possibly dead Python function: actor_of", "shortDescription": {"text": "Possibly dead Python function: actor_of"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-130876f5d624b8f1", "name": "Possibly dead Python function: is_cited", "shortDescription": {"text": "Possibly dead Python function: is_cited"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e47af23d8ebcc71e", "name": "Possibly dead Python function: runner", "shortDescription": {"text": "Possibly dead Python function: runner"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-48a0fa49411b80bf", "name": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/components/Layout.tsx:93", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/components/Layout.tsx:93"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cc003898718711e3", "name": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/pages/Admin.tsx:402", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/pages/Admin.tsx:402"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c9d5873ab069d045", "name": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/pages/Worklist.tsx:453", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/pages/Worklist.tsx:453"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b9088ff3ad1679c9", "name": "`truncate` class without `title=` for hover reveal \u2014 p2r/frontend/src/components/Layout.tsx:71", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 p2r/frontend/src/components/Layout.tsx:71"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3dbe2ba5ea581c29", "name": "`truncate` class without `title=` for hover reveal \u2014 p2r/frontend/src/pages/Sources.tsx:99", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 p2r/frontend/src/pages/Sources.tsx:99"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-85d9a7fb5daef869", "name": "`truncate` class without `title=` for hover reveal \u2014 p2r/frontend/src/pages/Workbench.tsx:194", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 p2r/frontend/src/pages/Workbench.tsx:194"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-77ef6cfaaaa8a9a3", "name": "`truncate` class without `title=` for hover reveal \u2014 p2r/frontend/src/pages/ReviewQueue.tsx:123", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 p2r/frontend/src/pages/ReviewQueue.tsx:123"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3c4c568ca818004b", "name": "`truncate` class without `title=` for hover reveal \u2014 p2r/frontend/src/pages/EvalHarness.tsx:166", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 p2r/frontend/src/pages/EvalHarness.tsx:166"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2ad5f22b5b93dc6e", "name": "Stray `console.log` in TS/JS \u2014 deck/build_deck.js:600", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 deck/build_deck.js:600"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7e9bdbdf599614c1", "name": "Stray `console.log` in TS/JS \u2014 e2e/convert.js:17", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 e2e/convert.js:17"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-60427b03771411b6", "name": "Dockerfile runs as root: frontend/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: frontend/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-faa134129e5545ff", "name": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e9c1e66a27308f49", "name": "Docker base image is tag-pinned but not digest-pinned: nginx:1.27-alpine", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: nginx:1.27-alpine"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-51ea26a6207fd922", "name": "Dockerfile runs as root: p2r/frontend/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: p2r/frontend/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-34417406ff5bfd8a", "name": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7026e75345e6d7d9", "name": "Docker base image is tag-pinned but not digest-pinned: nginx:1.27-alpine", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: nginx:1.27-alpine"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a1362a01f55b9b2f", "name": "Dockerfile runs as root: p2r/backend/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: p2r/backend/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0ce0d203abd662ce", "name": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1f66ad88286ca30a", "name": "Dockerfile runs as root: backend/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: backend/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-714c31ca9f474ae6", "name": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5fbef85554c6b67e", "name": "Insecure pattern 'cors_wildcard' in p2r/backend/app/main.py:30", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in p2r/backend/app/main.py:30"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b22053e64eef8d98", "name": "Insecure pattern 'cors_wildcard' in backend/app/main.py:34", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in backend/app/main.py:34"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3ec1b21216958f0a", "name": "Insecure pattern 'node_child_process' in e2e/convert.js:2", "shortDescription": {"text": "Insecure pattern 'node_child_process' in e2e/convert.js:2"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c12284917a0e6772", "name": "Very large file: generate-demo-doc.mjs (1051 lines)", "shortDescription": {"text": "Very large file: generate-demo-doc.mjs (1051 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-99383b8f77f6deb7", "name": "Very large file: frontend/src/pages/EncounterDetail.tsx (1078 lines)", "shortDescription": {"text": "Very large file: frontend/src/pages/EncounterDetail.tsx (1078 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-53976a11c4887b46", "name": "Very large file: backend/app/pipeline/orchestrator.py (1286 lines)", "shortDescription": {"text": "Very large file: backend/app/pipeline/orchestrator.py (1286 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fed7de98592aa661", "name": "Very large file: backend/app/seed/reference_data.py (3418 lines)", "shortDescription": {"text": "Very large file: backend/app/seed/reference_data.py (3418 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5743b0b840c82222", "name": "Very large file: backend/app/seed/charts.py (1373 lines)", "shortDescription": {"text": "Very large file: backend/app/seed/charts.py (1373 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "2 test file(s) for 110 source file(s) (ratio 0.02). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 65 placeholder/mock markers across 16 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-460ee60b07e453d6", "name": "Commented-code block (6 lines) in p2r/backend/app/sample.py:39", "shortDescription": {"text": "Commented-code block (6 lines) in p2r/backend/app/sample.py:39"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-70cdd2a3c471d59a", "name": "Commented-code block (7 lines) in backend/app/pipeline/orchestrator.py:828", "shortDescription": {"text": "Commented-code block (7 lines) in backend/app/pipeline/orchestrator.py:828"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5528126cb9d06ddb", "name": "Commented-code block (7 lines) in backend/app/seed/reference_data.py:2755", "shortDescription": {"text": "Commented-code block (7 lines) in backend/app/seed/reference_data.py:2755"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ba9522d3d518a173", "name": "Commented-code block (5 lines) in e2e/tests/demo.spec.js:1", "shortDescription": {"text": "Commented-code block (5 lines) in e2e/tests/demo.spec.js:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b334d875f2339fa1", "name": "5 env vars used in code but missing from .env.example", "shortDescription": {"text": "5 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `ACE_BASE_URL`, `LLM_BASE_URL`, `MODEL_DEFAULT`, `MODEL_HARD`, `P2R_BASE_URL`. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\np2r/backend/app/config_store.py:put, backend/app/config_store.py:set_key\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be46ea126aa5d8dc", "name": "Near-duplicate function bodies in 3 places", "shortDescription": {"text": "Near-duplicate function bodies in 3 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nbackend/app/routes/cdi.py:work, backend/app/routes/coding.py:work, backend/app/routes/coding.py:work\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eb5045e090538358", "name": "Frontend route `/encounter/:id` has no Link/navigate to it \u2014 frontend/src/App.tsx", "shortDescription": {"text": "Frontend route `/encounter/:id` has no Link/navigate to it \u2014 frontend/src/App.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6eec788f870f288a", "name": "FastAPI POST `ingest_policy` without auth dependency \u2014 p2r/backend/app/main.py:106", "shortDescription": {"text": "FastAPI POST `ingest_policy` without auth dependency \u2014 p2r/backend/app/main.py:106"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8900a28d8231c0a6", "name": "FastAPI POST `ingest_sample` without auth dependency \u2014 p2r/backend/app/main.py:115", "shortDescription": {"text": "FastAPI POST `ingest_sample` without auth dependency \u2014 p2r/backend/app/main.py:115"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3768c0d11d82b4ab", "name": "FastAPI POST `ingest_document` without auth dependency \u2014 p2r/backend/app/main.py:122", "shortDescription": {"text": "FastAPI POST `ingest_document` without auth dependency \u2014 p2r/backend/app/main.py:122"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-78075d4fe53dbdce", "name": "FastAPI POST `recommend_from_document` without auth dependency \u2014 p2r/backend/app/main.py:178", "shortDescription": {"text": "FastAPI POST `recommend_from_document` without auth dependency \u2014 p2r/backend/app/main.py:178"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7d3698b0566e7042", "name": "FastAPI PATCH `edit_recommendation` without auth dependency \u2014 p2r/backend/app/main.py:216", "shortDescription": {"text": "FastAPI PATCH `edit_recommendation` without auth dependency \u2014 p2r/backend/app/main.py:216"}, "fullDescription": {"text": "`@router.patch` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eca78ede8ba75393", "name": "FastAPI POST `approve_recommendation` without auth dependency \u2014 p2r/backend/app/main.py:243", "shortDescription": {"text": "FastAPI POST `approve_recommendation` without auth dependency \u2014 p2r/backend/app/main.py:243"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f020b43438a2a7d8", "name": "FastAPI POST `recommendation_replay` without auth dependency \u2014 p2r/backend/app/main.py:276", "shortDescription": {"text": "FastAPI POST `recommendation_replay` without auth dependency \u2014 p2r/backend/app/main.py:276"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-abf0e5bdca69a208", "name": "FastAPI POST `recommendation_rollback` without auth dependency \u2014 p2r/backend/app/main.py:285", "shortDescription": {"text": "FastAPI POST `recommendation_rollback` without auth dependency \u2014 p2r/backend/app/main.py:285"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cc357653010ca144", "name": "FastAPI POST `publish_to_ace` without auth dependency \u2014 p2r/backend/app/main.py:297", "shortDescription": {"text": "FastAPI POST `publish_to_ace` without auth dependency \u2014 p2r/backend/app/main.py:297"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-816cdccaf755d277", "name": "FastAPI POST `acquire_source` without auth dependency \u2014 p2r/backend/app/main.py:316", "shortDescription": {"text": "FastAPI POST `acquire_source` without auth dependency \u2014 p2r/backend/app/main.py:316"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1d31537060c0fa69", "name": "FastAPI POST `denials_load_sample` without auth dependency \u2014 p2r/backend/app/main.py:348", "shortDescription": {"text": "FastAPI POST `denials_load_sample` without auth dependency \u2014 p2r/backend/app/main.py:348"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c4b15395661be23c", "name": "FastAPI POST `denials_detect` without auth dependency \u2014 p2r/backend/app/main.py:354", "shortDescription": {"text": "FastAPI POST `denials_detect` without auth dependency \u2014 p2r/backend/app/main.py:354"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f12cdad53d9e82b4", "name": "FastAPI POST `denials_promote` without auth dependency \u2014 p2r/backend/app/main.py:386", "shortDescription": {"text": "FastAPI POST `denials_promote` without auth dependency \u2014 p2r/backend/app/main.py:386"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9b8c47e56a8eb71f", "name": "FastAPI PUT `admin_put_config` without auth dependency \u2014 p2r/backend/app/main.py:416", "shortDescription": {"text": "FastAPI PUT `admin_put_config` without auth dependency \u2014 p2r/backend/app/main.py:416"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-26f975eb8ac7eb11", "name": "FastAPI POST `admin_reset_config` without auth dependency \u2014 p2r/backend/app/main.py:427", "shortDescription": {"text": "FastAPI POST `admin_reset_config` without auth dependency \u2014 p2r/backend/app/main.py:427"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d2069101c9a3a32f", "name": "FastAPI POST `admin_llm_test` without auth dependency \u2014 p2r/backend/app/main.py:442", "shortDescription": {"text": "FastAPI POST `admin_llm_test` without auth dependency \u2014 p2r/backend/app/main.py:442"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3e24bac6d4a15bd6", "name": "FastAPI POST `create_rule` without auth dependency \u2014 p2r/backend/app/main.py:464", "shortDescription": {"text": "FastAPI POST `create_rule` without auth dependency \u2014 p2r/backend/app/main.py:464"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e1de06c96397cac2", "name": "FastAPI PUT `update_rule` without auth dependency \u2014 p2r/backend/app/main.py:477", "shortDescription": {"text": "FastAPI PUT `update_rule` without auth dependency \u2014 p2r/backend/app/main.py:477"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ea3e1b66d9850dbc", "name": "FastAPI DELETE `delete_rule` without auth dependency \u2014 p2r/backend/app/main.py:492", "shortDescription": {"text": "FastAPI DELETE `delete_rule` without auth dependency \u2014 p2r/backend/app/main.py:492"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9a5b8f518e9841fd", "name": "FastAPI POST `create_source` without auth dependency \u2014 p2r/backend/app/main.py:514", "shortDescription": {"text": "FastAPI POST `create_source` without auth dependency \u2014 p2r/backend/app/main.py:514"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-028b80caabf20901", "name": "FastAPI PUT `update_source` without auth dependency \u2014 p2r/backend/app/main.py:525", "shortDescription": {"text": "FastAPI PUT `update_source` without auth dependency \u2014 p2r/backend/app/main.py:525"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a9ad61a47a5fb4c9", "name": "FastAPI POST `eval_golden_create` without auth dependency \u2014 p2r/backend/app/main.py:571", "shortDescription": {"text": "FastAPI POST `eval_golden_create` without auth dependency \u2014 p2r/backend/app/main.py:571"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9fcc2bf9f5766031", "name": "FastAPI DELETE `eval_golden_delete` without auth dependency \u2014 p2r/backend/app/main.py:581", "shortDescription": {"text": "FastAPI DELETE `eval_golden_delete` without auth dependency \u2014 p2r/backend/app/main.py:581"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-547b4a4f643382dc", "name": "FastAPI POST `eval_run` without auth dependency \u2014 p2r/backend/app/main.py:593", "shortDescription": {"text": "FastAPI POST `eval_run` without auth dependency \u2014 p2r/backend/app/main.py:593"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f5cd591d4db5f34c", "name": "FastAPI POST `cdi_scan` without auth dependency \u2014 backend/app/routes/cdi.py:35", "shortDescription": {"text": "FastAPI POST `cdi_scan` without auth dependency \u2014 backend/app/routes/cdi.py:35"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7eae5cbbbcd5c7c0", "name": "FastAPI POST `cdi_respond` without auth dependency \u2014 backend/app/routes/cdi.py:84", "shortDescription": {"text": "FastAPI POST `cdi_respond` without auth dependency \u2014 backend/app/routes/cdi.py:84"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c58e209912e66f5a", "name": "FastAPI POST `assign` without auth dependency \u2014 backend/app/routes/ops.py:109", "shortDescription": {"text": "FastAPI POST `assign` without auth dependency \u2014 backend/app/routes/ops.py:109"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fce7274344003add", "name": "FastAPI POST `create_policy` without auth dependency \u2014 backend/app/routes/ops.py:151", "shortDescription": {"text": "FastAPI POST `create_policy` without auth dependency \u2014 backend/app/routes/ops.py:151"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-41e3d4a2966a2cc1", "name": "FastAPI PUT `update_policy` without auth dependency \u2014 backend/app/routes/ops.py:162", "shortDescription": {"text": "FastAPI PUT `update_policy` without auth dependency \u2014 backend/app/routes/ops.py:162"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bbc1bdc8eda54576", "name": "FastAPI DELETE `delete_policy` without auth dependency \u2014 backend/app/routes/ops.py:176", "shortDescription": {"text": "FastAPI DELETE `delete_policy` without auth dependency \u2014 backend/app/routes/ops.py:176"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6896c974675aa9bd", "name": "FastAPI POST `create_concept` without auth dependency \u2014 backend/app/routes/ops.py:249", "shortDescription": {"text": "FastAPI POST `create_concept` without auth dependency \u2014 backend/app/routes/ops.py:249"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4b4bf91e10e5b6f3", "name": "FastAPI PUT `update_concept` without auth dependency \u2014 backend/app/routes/ops.py:269", "shortDescription": {"text": "FastAPI PUT `update_concept` without auth dependency \u2014 backend/app/routes/ops.py:269"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-13249ea59b235fc4", "name": "FastAPI DELETE `delete_concept` without auth dependency \u2014 backend/app/routes/ops.py:285", "shortDescription": {"text": "FastAPI DELETE `delete_concept` without auth dependency \u2014 backend/app/routes/ops.py:285"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d64ebfa286a663c0", "name": "FastAPI POST `create_edge` without auth dependency \u2014 backend/app/routes/ops.py:308", "shortDescription": {"text": "FastAPI POST `create_edge` without auth dependency \u2014 backend/app/routes/ops.py:308"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-153bb1f87f5abab2", "name": "FastAPI DELETE `delete_edge` without auth dependency \u2014 backend/app/routes/ops.py:332", "shortDescription": {"text": "FastAPI DELETE `delete_edge` without auth dependency \u2014 backend/app/routes/ops.py:332"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7ca1f265e15ab858", "name": "FastAPI POST `create_guideline` without auth dependency \u2014 backend/app/routes/ops.py:363", "shortDescription": {"text": "FastAPI POST `create_guideline` without auth dependency \u2014 backend/app/routes/ops.py:363"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-78a35bf3e3cc59c2", "name": "FastAPI PUT `update_guideline` without auth dependency \u2014 backend/app/routes/ops.py:378", "shortDescription": {"text": "FastAPI PUT `update_guideline` without auth dependency \u2014 backend/app/routes/ops.py:378"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-067940edd13c7d5e", "name": "FastAPI DELETE `delete_guideline` without auth dependency \u2014 backend/app/routes/ops.py:394", "shortDescription": {"text": "FastAPI DELETE `delete_guideline` without auth dependency \u2014 backend/app/routes/ops.py:394"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a71a063d79de81a6", "name": "FastAPI POST `create_refcode` without auth dependency \u2014 backend/app/routes/ops.py:443", "shortDescription": {"text": "FastAPI POST `create_refcode` without auth dependency \u2014 backend/app/routes/ops.py:443"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7bbb8d7543b55eef", "name": "FastAPI PUT `update_refcode` without auth dependency \u2014 backend/app/routes/ops.py:458", "shortDescription": {"text": "FastAPI PUT `update_refcode` without auth dependency \u2014 backend/app/routes/ops.py:458"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-268767ad311b7d1b", "name": "FastAPI DELETE `delete_refcode` without auth dependency \u2014 backend/app/routes/ops.py:472", "shortDescription": {"text": "FastAPI DELETE `delete_refcode` without auth dependency \u2014 backend/app/routes/ops.py:472"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7877928f2cdbc722", "name": "FastAPI POST `create_ncci` without auth dependency \u2014 backend/app/routes/ops.py:503", "shortDescription": {"text": "FastAPI POST `create_ncci` without auth dependency \u2014 backend/app/routes/ops.py:503"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fea186b1e2d546b7", "name": "FastAPI DELETE `delete_ncci` without auth dependency \u2014 backend/app/routes/ops.py:515", "shortDescription": {"text": "FastAPI DELETE `delete_ncci` without auth dependency \u2014 backend/app/routes/ops.py:515"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8a1d604f2cd563af", "name": "FastAPI POST `create_mue` without auth dependency \u2014 backend/app/routes/ops.py:544", "shortDescription": {"text": "FastAPI POST `create_mue` without auth dependency \u2014 backend/app/routes/ops.py:544"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3207afebfe3dde6d", "name": "FastAPI PUT `update_mue` without auth dependency \u2014 backend/app/routes/ops.py:557", "shortDescription": {"text": "FastAPI PUT `update_mue` without auth dependency \u2014 backend/app/routes/ops.py:557"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-968f9957ab433e11", "name": "FastAPI DELETE `delete_mue` without auth dependency \u2014 backend/app/routes/ops.py:571", "shortDescription": {"text": "FastAPI DELETE `delete_mue` without auth dependency \u2014 backend/app/routes/ops.py:571"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4a64f5f05e033781", "name": "FastAPI POST `create_modifier` without auth dependency \u2014 backend/app/routes/ops.py:601", "shortDescription": {"text": "FastAPI POST `create_modifier` without auth dependency \u2014 backend/app/routes/ops.py:601"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d7e15f1d984ba04c", "name": "FastAPI DELETE `delete_modifier` without auth dependency \u2014 backend/app/routes/ops.py:614", "shortDescription": {"text": "FastAPI DELETE `delete_modifier` without auth dependency \u2014 backend/app/routes/ops.py:614"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e6d5d35ac1655b42", "name": "FastAPI POST `ingest` without auth dependency \u2014 backend/app/routes/ops.py:682", "shortDescription": {"text": "FastAPI POST `ingest` without auth dependency \u2014 backend/app/routes/ops.py:682"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-500759752b15c609", "name": "FastAPI POST `ingest_document` without auth dependency \u2014 backend/app/routes/ops.py:704", "shortDescription": {"text": "FastAPI POST `ingest_document` without auth dependency \u2014 backend/app/routes/ops.py:704"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-00effd51ccb9362f", "name": "FastAPI PUT `put_config` without auth dependency \u2014 backend/app/routes/admin.py:35", "shortDescription": {"text": "FastAPI PUT `put_config` without auth dependency \u2014 backend/app/routes/admin.py:35"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-006a6ad0a1e201c2", "name": "FastAPI POST `reset_config` without auth dependency \u2014 backend/app/routes/admin.py:46", "shortDescription": {"text": "FastAPI POST `reset_config` without auth dependency \u2014 backend/app/routes/admin.py:46"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3322f0fc535eddcb", "name": "FastAPI POST `llm_test` without auth dependency \u2014 backend/app/routes/admin.py:73", "shortDescription": {"text": "FastAPI POST `llm_test` without auth dependency \u2014 backend/app/routes/admin.py:73"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f93254c2abf88bcb", "name": "FastAPI POST `trigger_seed` without auth dependency \u2014 backend/app/routes/admin.py:102", "shortDescription": {"text": "FastAPI POST `trigger_seed` without auth dependency \u2014 backend/app/routes/admin.py:102"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f0e4c5912e47ca3a", "name": "FastAPI PATCH `patch_learning` without auth dependency \u2014 backend/app/routes/insights.py:259", "shortDescription": {"text": "FastAPI PATCH `patch_learning` without auth dependency \u2014 backend/app/routes/insights.py:259"}, "fullDescription": {"text": "`@router.patch` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-85586ffe800ddbec", "name": "FastAPI DELETE `delete_learning` without auth dependency \u2014 backend/app/routes/insights.py:269", "shortDescription": {"text": "FastAPI DELETE `delete_learning` without auth dependency \u2014 backend/app/routes/insights.py:269"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-814d0601210c37b8", "name": "FastAPI POST `create_golden` without auth dependency \u2014 backend/app/routes/insights.py:314", "shortDescription": {"text": "FastAPI POST `create_golden` without auth dependency \u2014 backend/app/routes/insights.py:314"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-38f08d2d709c6315", "name": "FastAPI PUT `update_golden` without auth dependency \u2014 backend/app/routes/insights.py:328", "shortDescription": {"text": "FastAPI PUT `update_golden` without auth dependency \u2014 backend/app/routes/insights.py:328"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-574a7761876c4cc6", "name": "FastAPI DELETE `delete_golden` without auth dependency \u2014 backend/app/routes/insights.py:345", "shortDescription": {"text": "FastAPI DELETE `delete_golden` without auth dependency \u2014 backend/app/routes/insights.py:345"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7d28ff3795d5e9c9", "name": "FastAPI POST `eval_run` without auth dependency \u2014 backend/app/routes/insights.py:530", "shortDescription": {"text": "FastAPI POST `eval_run` without auth dependency \u2014 backend/app/routes/insights.py:530"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4a2fe61b99641190", "name": "FastAPI POST `reassign_run` without auth dependency \u2014 backend/app/routes/coding.py:38", "shortDescription": {"text": "FastAPI POST `reassign_run` without auth dependency \u2014 backend/app/routes/coding.py:38"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7b0bc20e6161bafe", "name": "FastAPI POST `rollback_run` without auth dependency \u2014 backend/app/routes/coding.py:58", "shortDescription": {"text": "FastAPI POST `rollback_run` without auth dependency \u2014 backend/app/routes/coding.py:58"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f01162b99c30dc55", "name": "FastAPI POST `escalate_run` without auth dependency \u2014 backend/app/routes/coding.py:97", "shortDescription": {"text": "FastAPI POST `escalate_run` without auth dependency \u2014 backend/app/routes/coding.py:97"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ceac2aeb5bc2a73b", "name": "FastAPI POST `code_encounter` without auth dependency \u2014 backend/app/routes/coding.py:113", "shortDescription": {"text": "FastAPI POST `code_encounter` without auth dependency \u2014 backend/app/routes/coding.py:113"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-432267ff47d5ad0f", "name": "FastAPI POST `run_all` without auth dependency \u2014 backend/app/routes/coding.py:173", "shortDescription": {"text": "FastAPI POST `run_all` without auth dependency \u2014 backend/app/routes/coding.py:173"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dd3c87de1fda2427", "name": "FastAPI POST `add_addendum` without auth dependency \u2014 backend/app/routes/coding.py:203", "shortDescription": {"text": "FastAPI POST `add_addendum` without auth dependency \u2014 backend/app/routes/coding.py:203"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-40447f8f663f37b4", "name": "FastAPI POST `accept_code` without auth dependency \u2014 backend/app/routes/coding.py:251", "shortDescription": {"text": "FastAPI POST `accept_code` without auth dependency \u2014 backend/app/routes/coding.py:251"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-285a6a57a9b0b7d3", "name": "FastAPI POST `override_code` without auth dependency \u2014 backend/app/routes/coding.py:265", "shortDescription": {"text": "FastAPI POST `override_code` without auth dependency \u2014 backend/app/routes/coding.py:265"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-833edacd3634c902", "name": "Unused endpoint: GET /meta", "shortDescription": {"text": "Unused endpoint: GET /meta"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `GET /meta` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c96a14905be67a3c", "name": "Unused endpoint: POST /ingest/policy", "shortDescription": {"text": "Unused endpoint: POST /ingest/policy"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `POST /ingest/policy` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7337beeb73e4750f", "name": "Unused endpoint: POST /ingest/policy/sample", "shortDescription": {"text": "Unused endpoint: POST /ingest/policy/sample"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `POST /ingest/policy/sample` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9921d02ec5b05e8d", "name": "Unused endpoint: POST /ingest/policy/document", "shortDescription": {"text": "Unused endpoint: POST /ingest/policy/document"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `POST /ingest/policy/document` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ffc9ad08ed6cdd74", "name": "Unused endpoint: GET /documents", "shortDescription": {"text": "Unused endpoint: GET /documents"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `GET /documents` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ff65bfc3949844c4", "name": "Unused endpoint: GET /documents/{doc_id}/provisions", "shortDescription": {"text": "Unused endpoint: GET /documents/{doc_id}/provisions"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `GET /documents/{doc_id}/provisions` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a8b338285e916bb7", "name": "Unused endpoint: GET /provisions", "shortDescription": {"text": "Unused endpoint: GET /provisions"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `GET /provisions` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-693c6e86dced9070", "name": "Unused endpoint: GET /rule-library", "shortDescription": {"text": "Unused endpoint: GET /rule-library"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `GET /rule-library` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1c9f3fc47b3ab9a2", "name": "Unused endpoint: POST /recommendations/from-document/{doc_id}", "shortDescription": {"text": "Unused endpoint: POST /recommendations/from-document/{doc_id}"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `POST /recommendations/from-document/{doc_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-96893e003e8de1eb", "name": "Unused endpoint: GET /recommendations/from-document/{doc_id}/stream", "shortDescription": {"text": "Unused endpoint: GET /recommendations/from-document/{doc_id}/stream"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `GET /recommendations/from-document/{doc_id}/stream` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1f77f6f75187981c", "name": "Unused endpoint: GET /recommendations", "shortDescription": {"text": "Unused endpoint: GET /recommendations"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `GET /recommendations` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0a1eb0e541688151", "name": "Unused endpoint: PATCH /recommendations/{rec_id}", "shortDescription": {"text": "Unused endpoint: PATCH /recommendations/{rec_id}"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `PATCH /recommendations/{rec_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3e27c235f7070593", "name": "Unused endpoint: POST /recommendations/{rec_id}/approve", "shortDescription": {"text": "Unused endpoint: POST /recommendations/{rec_id}/approve"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `POST /recommendations/{rec_id}/approve` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3afd61ca78904655", "name": "Unused endpoint: GET /integration/ace/status", "shortDescription": {"text": "Unused endpoint: GET /integration/ace/status"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `GET /integration/ace/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cece27e015a00556", "name": "Unused endpoint: GET /recommendations/{rec_id}/rule-ir", "shortDescription": {"text": "Unused endpoint: GET /recommendations/{rec_id}/rule-ir"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `GET /recommendations/{rec_id}/rule-ir` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-620a97895f308a9a", "name": "Unused endpoint: POST /recommendations/{rec_id}/replay", "shortDescription": {"text": "Unused endpoint: POST /recommendations/{rec_id}/replay"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `POST /recommendations/{rec_id}/replay` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ca7632571d841972", "name": "Unused endpoint: POST /recommendations/{rec_id}/rollback", "shortDescription": {"text": "Unused endpoint: POST /recommendations/{rec_id}/rollback"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `POST /recommendations/{rec_id}/rollback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6d7812d4b8d87e99", "name": "Unused endpoint: POST /recommendations/{rec_id}/publish-to-ace", "shortDescription": {"text": "Unused endpoint: POST /recommendations/{rec_id}/publish-to-ace"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `POST /recommendations/{rec_id}/publish-to-ace` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9617aa24fd377881", "name": "Unused endpoint: GET /sources", "shortDescription": {"text": "Unused endpoint: GET /sources"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `GET /sources` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-374943260c8faa42", "name": "Unused endpoint: POST /sources/{source_id}/acquire", "shortDescription": {"text": "Unused endpoint: POST /sources/{source_id}/acquire"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `POST /sources/{source_id}/acquire` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5a1e198eb18f1953", "name": "Unused endpoint: GET /sources/{source_id}/acquire/stream", "shortDescription": {"text": "Unused endpoint: GET /sources/{source_id}/acquire/stream"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `GET /sources/{source_id}/acquire/stream` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c30e15c74bdb7970", "name": "Unused endpoint: GET /deltas", "shortDescription": {"text": "Unused endpoint: GET /deltas"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `GET /deltas` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d9def61ad733bec3", "name": "Unused endpoint: GET /payer-master", "shortDescription": {"text": "Unused endpoint: GET /payer-master"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `GET /payer-master` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9c5c90b86a8b1ad6", "name": "Unused endpoint: POST /denials/load-sample", "shortDescription": {"text": "Unused endpoint: POST /denials/load-sample"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `POST /denials/load-sample` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d36851936ca82c10", "name": "Unused endpoint: POST /denials/detect", "shortDescription": {"text": "Unused endpoint: POST /denials/detect"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `POST /denials/detect` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7438169b8eaafbed", "name": "Unused endpoint: GET /denials/signals", "shortDescription": {"text": "Unused endpoint: GET /denials/signals"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `GET /denials/signals` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f0c81d48a2cff0d8", "name": "Unused endpoint: GET /denials/remittances", "shortDescription": {"text": "Unused endpoint: GET /denials/remittances"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `GET /denials/remittances` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c3cdb4e93b9aa45", "name": "Unused endpoint: POST /denials/signals/{signal_id}/promote", "shortDescription": {"text": "Unused endpoint: POST /denials/signals/{signal_id}/promote"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `POST /denials/signals/{signal_id}/promote` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7c7e6b66c64ac953", "name": "Unused endpoint: GET /denials/signals/{signal_id}/promote/stream", "shortDescription": {"text": "Unused endpoint: GET /denials/signals/{signal_id}/promote/stream"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `GET /denials/signals/{signal_id}/promote/stream` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c7914268ea70bbb0", "name": "Unused endpoint: GET /admin/config", "shortDescription": {"text": "Unused endpoint: GET /admin/config"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `GET /admin/config` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-419f41a8829b4758", "name": "Unused endpoint: PUT /admin/config/{key}", "shortDescription": {"text": "Unused endpoint: PUT /admin/config/{key}"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `PUT /admin/config/{key}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6004e94965207e20", "name": "Unused endpoint: POST /admin/config/reset", "shortDescription": {"text": "Unused endpoint: POST /admin/config/reset"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `POST /admin/config/reset` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-37916a796965e2bd", "name": "Unused endpoint: GET /admin/llm/status", "shortDescription": {"text": "Unused endpoint: GET /admin/llm/status"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `GET /admin/llm/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d9a238fc5520344b", "name": "Unused endpoint: POST /admin/llm/test", "shortDescription": {"text": "Unused endpoint: POST /admin/llm/test"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `POST /admin/llm/test` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aadc34cdd73778b8", "name": "Unused endpoint: POST /rule-library", "shortDescription": {"text": "Unused endpoint: POST /rule-library"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `POST /rule-library` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3f3031eb50975f88", "name": "Unused endpoint: PUT /rule-library/{rule_id}", "shortDescription": {"text": "Unused endpoint: PUT /rule-library/{rule_id}"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `PUT /rule-library/{rule_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ec4b033b3e6f9720", "name": "Unused endpoint: DELETE /rule-library/{rule_id}", "shortDescription": {"text": "Unused endpoint: DELETE /rule-library/{rule_id}"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `DELETE /rule-library/{rule_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5467e682054ad3ed", "name": "Unused endpoint: POST /sources", "shortDescription": {"text": "Unused endpoint: POST /sources"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `POST /sources` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9b4354893001b6bb", "name": "Unused endpoint: PUT /sources/{source_id}", "shortDescription": {"text": "Unused endpoint: PUT /sources/{source_id}"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `PUT /sources/{source_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-00d297d86aa253fe", "name": "Unused endpoint: GET /audit", "shortDescription": {"text": "Unused endpoint: GET /audit"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `GET /audit` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ac8cea070ef66a8e", "name": "Unused endpoint: GET /recommendations/{rec_id}/lineage", "shortDescription": {"text": "Unused endpoint: GET /recommendations/{rec_id}/lineage"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `GET /recommendations/{rec_id}/lineage` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a72f985756188e7a", "name": "Unused endpoint: GET /eval/golden", "shortDescription": {"text": "Unused endpoint: GET /eval/golden"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `GET /eval/golden` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5fcc93e17bdd4795", "name": "Unused endpoint: POST /eval/golden", "shortDescription": {"text": "Unused endpoint: POST /eval/golden"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `POST /eval/golden` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-691561e09d311d2e", "name": "Unused endpoint: DELETE /eval/golden/{case_id}", "shortDescription": {"text": "Unused endpoint: DELETE /eval/golden/{case_id}"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `DELETE /eval/golden/{case_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f84e91408ec499c6", "name": "Unused endpoint: POST /eval/run", "shortDescription": {"text": "Unused endpoint: POST /eval/run"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `POST /eval/run` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7dca636b75fdc439", "name": "Unused endpoint: GET /eval/golden/denials", "shortDescription": {"text": "Unused endpoint: GET /eval/golden/denials"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `GET /eval/golden/denials` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e23ff94fb6fc96ab", "name": "Unused endpoint: GET /eval/history", "shortDescription": {"text": "Unused endpoint: GET /eval/history"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `GET /eval/history` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6ed45ba9e4841214", "name": "Unused endpoint: GET /eval/run/stream", "shortDescription": {"text": "Unused endpoint: GET /eval/run/stream"}, "fullDescription": {"text": "`p2r/backend/app/main.py` declares `GET /eval/run/stream` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3bfd327cf713b0a7", "name": "Unused endpoint: POST /encounters/{enc_id}/cdi-scan", "shortDescription": {"text": "Unused endpoint: POST /encounters/{enc_id}/cdi-scan"}, "fullDescription": {"text": "`backend/app/routes/cdi.py` declares `POST /encounters/{enc_id}/cdi-scan` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ab455fc07b0dabe2", "name": "Unused endpoint: GET /encounters/{enc_id}/cdi-scan/stream", "shortDescription": {"text": "Unused endpoint: GET /encounters/{enc_id}/cdi-scan/stream"}, "fullDescription": {"text": "`backend/app/routes/cdi.py` declares `GET /encounters/{enc_id}/cdi-scan/stream` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/20609"}, "properties": {"repository": "swarupd227/ACE", "repoUrl": "https://github.com/swarupd227/ACE", "branch": "main"}, "results": [{"ruleId": "scanner-d73026fde563f3a4", "level": "note", "message": {"text": "Possibly dead Python function: actor_of"}, "properties": {"repobilityId": "e81a12112432ac45", "scanner": "scanner-primary", "fingerprint": "d73026fde563f3a4", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py:35"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-130876f5d624b8f1", "level": "note", "message": {"text": "Possibly dead Python function: is_cited"}, "properties": {"repobilityId": "c35d3db166a83026", "scanner": "scanner-primary", "fingerprint": "130876f5d624b8f1", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "core/ir.py:59"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e47af23d8ebcc71e", "level": "note", "message": {"text": "Possibly dead Python function: runner"}, "properties": {"repobilityId": "b45a8bd7c8362977", "scanner": "scanner-primary", "fingerprint": "e47af23d8ebcc71e", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/_sse.py:19"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-48a0fa49411b80bf", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/components/Layout.tsx:93"}, "properties": {"repobilityId": "4d0ca9e37bee02cd", "scanner": "scanner-primary", "fingerprint": "48a0fa49411b80bf", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-cc003898718711e3", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/pages/Admin.tsx:402"}, "properties": {"repobilityId": "679d4c88f4756af2", "scanner": "scanner-primary", "fingerprint": "cc003898718711e3", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-c9d5873ab069d045", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/pages/Worklist.tsx:453"}, "properties": {"repobilityId": "40c9376444c8a946", "scanner": "scanner-primary", "fingerprint": "c9d5873ab069d045", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-b9088ff3ad1679c9", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 p2r/frontend/src/components/Layout.tsx:71"}, "properties": {"repobilityId": "7fdd00a79a87393e", "scanner": "scanner-primary", "fingerprint": "b9088ff3ad1679c9", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-3dbe2ba5ea581c29", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 p2r/frontend/src/pages/Sources.tsx:99"}, "properties": {"repobilityId": "e8c130774eeebb4f", "scanner": "scanner-primary", "fingerprint": "3dbe2ba5ea581c29", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-85d9a7fb5daef869", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 p2r/frontend/src/pages/Workbench.tsx:194"}, "properties": {"repobilityId": "a1fd3b4fc8690069", "scanner": "scanner-primary", "fingerprint": "85d9a7fb5daef869", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-77ef6cfaaaa8a9a3", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 p2r/frontend/src/pages/ReviewQueue.tsx:123"}, "properties": {"repobilityId": "b5f5bb97e1e7f07d", "scanner": "scanner-primary", "fingerprint": "77ef6cfaaaa8a9a3", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-3c4c568ca818004b", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 p2r/frontend/src/pages/EvalHarness.tsx:166"}, "properties": {"repobilityId": "ade1f06fd51e1990", "scanner": "scanner-primary", "fingerprint": "3c4c568ca818004b", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-2ad5f22b5b93dc6e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 deck/build_deck.js:600"}, "properties": {"repobilityId": "14682ec689203868", "scanner": "scanner-primary", "fingerprint": "2ad5f22b5b93dc6e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7e9bdbdf599614c1", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 e2e/convert.js:17"}, "properties": {"repobilityId": "8e6dca67ef78e7ef", "scanner": "scanner-primary", "fingerprint": "7e9bdbdf599614c1", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-60427b03771411b6", "level": "warning", "message": {"text": "Dockerfile runs as root: frontend/Dockerfile"}, "properties": {"repobilityId": "735c01d8531dfd2c", "scanner": "scanner-primary", "fingerprint": "60427b03771411b6", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-faa134129e5545ff", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine"}, "properties": {"repobilityId": "0f6e83a510b94936", "scanner": "scanner-primary", "fingerprint": "faa134129e5545ff", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/Dockerfile"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-e9c1e66a27308f49", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: nginx:1.27-alpine"}, "properties": {"repobilityId": "48fbbb576b5b7044", "scanner": "scanner-primary", "fingerprint": "e9c1e66a27308f49", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/Dockerfile"}, "region": {"startLine": 12}}}]}, {"ruleId": "scanner-51ea26a6207fd922", "level": "warning", "message": {"text": "Dockerfile runs as root: p2r/frontend/Dockerfile"}, "properties": {"repobilityId": "10127baf8d1cd3b4", "scanner": "scanner-primary", "fingerprint": "51ea26a6207fd922", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-34417406ff5bfd8a", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine"}, "properties": {"repobilityId": "5ea84f5edbe10bca", "scanner": "scanner-primary", "fingerprint": "34417406ff5bfd8a", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/frontend/Dockerfile"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-7026e75345e6d7d9", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: nginx:1.27-alpine"}, "properties": {"repobilityId": "548360f34fbaff97", "scanner": "scanner-primary", "fingerprint": "7026e75345e6d7d9", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/frontend/Dockerfile"}, "region": {"startLine": 12}}}]}, {"ruleId": "scanner-a1362a01f55b9b2f", "level": "warning", "message": {"text": "Dockerfile runs as root: p2r/backend/Dockerfile"}, "properties": {"repobilityId": "8a16565b21be1ff3", "scanner": "scanner-primary", "fingerprint": "a1362a01f55b9b2f", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-0ce0d203abd662ce", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "properties": {"repobilityId": "590b85c453c4cd08", "scanner": "scanner-primary", "fingerprint": "0ce0d203abd662ce", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/Dockerfile"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-1f66ad88286ca30a", "level": "warning", "message": {"text": "Dockerfile runs as root: backend/Dockerfile"}, "properties": {"repobilityId": "7afd2b0e8a8c9eeb", "scanner": "scanner-primary", "fingerprint": "1f66ad88286ca30a", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-714c31ca9f474ae6", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "properties": {"repobilityId": "f614a1e41f331b37", "scanner": "scanner-primary", "fingerprint": "714c31ca9f474ae6", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-5fbef85554c6b67e", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in p2r/backend/app/main.py:30"}, "properties": {"repobilityId": "9fbeda44922f17b3", "scanner": "scanner-primary", "fingerprint": "5fbef85554c6b67e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 30}}}]}, {"ruleId": "scanner-b22053e64eef8d98", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in backend/app/main.py:34"}, "properties": {"repobilityId": "1a4affa5fa498eb7", "scanner": "scanner-primary", "fingerprint": "b22053e64eef8d98", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/main.py"}, "region": {"startLine": 34}}}]}, {"ruleId": "scanner-3ec1b21216958f0a", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in e2e/convert.js:2"}, "properties": {"repobilityId": "e53661d1b314029a", "scanner": "scanner-primary", "fingerprint": "3ec1b21216958f0a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "e2e/convert.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-c12284917a0e6772", "level": "note", "message": {"text": "Very large file: generate-demo-doc.mjs (1051 lines)"}, "properties": {"repobilityId": "2e05dd0bcef4d30e", "scanner": "scanner-primary", "fingerprint": "c12284917a0e6772", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-99383b8f77f6deb7", "level": "note", "message": {"text": "Very large file: frontend/src/pages/EncounterDetail.tsx (1078 lines)"}, "properties": {"repobilityId": "9d912cf2ff5a19ca", "scanner": "scanner-primary", "fingerprint": "99383b8f77f6deb7", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-53976a11c4887b46", "level": "note", "message": {"text": "Very large file: backend/app/pipeline/orchestrator.py (1286 lines)"}, "properties": {"repobilityId": "3f0d2a5a9ff94f00", "scanner": "scanner-primary", "fingerprint": "53976a11c4887b46", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-fed7de98592aa661", "level": "note", "message": {"text": "Very large file: backend/app/seed/reference_data.py (3418 lines)"}, "properties": {"repobilityId": "e900b9929bb955b3", "scanner": "scanner-primary", "fingerprint": "fed7de98592aa661", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-5743b0b840c82222", "level": "note", "message": {"text": "Very large file: backend/app/seed/charts.py (1373 lines)"}, "properties": {"repobilityId": "032344c31bec779b", "scanner": "scanner-primary", "fingerprint": "5743b0b840c82222", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "9571652a71f7657f", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "6d80319a23607f8a", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "7e1b8090239e300d", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "0fafa43772b6ea96", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-460ee60b07e453d6", "level": "none", "message": {"text": "Commented-code block (6 lines) in p2r/backend/app/sample.py:39"}, "properties": {"repobilityId": "0c549ec77ecd6b76", "scanner": "scanner-primary", "fingerprint": "460ee60b07e453d6", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-70cdd2a3c471d59a", "level": "none", "message": {"text": "Commented-code block (7 lines) in backend/app/pipeline/orchestrator.py:828"}, "properties": {"repobilityId": "912b0b0c7624cd0e", "scanner": "scanner-primary", "fingerprint": "70cdd2a3c471d59a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5528126cb9d06ddb", "level": "none", "message": {"text": "Commented-code block (7 lines) in backend/app/seed/reference_data.py:2755"}, "properties": {"repobilityId": "82f3b75f6ca43db0", "scanner": "scanner-primary", "fingerprint": "5528126cb9d06ddb", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ba9522d3d518a173", "level": "none", "message": {"text": "Commented-code block (5 lines) in e2e/tests/demo.spec.js:1"}, "properties": {"repobilityId": "c65f4be5ea7883c8", "scanner": "scanner-primary", "fingerprint": "ba9522d3d518a173", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b334d875f2339fa1", "level": "note", "message": {"text": "5 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "faa38682016f5d53", "scanner": "scanner-primary", "fingerprint": "b334d875f2339fa1", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "d419b90fa14ad4a3", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "8e3c9c77332219aa", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "51fb744e3ec69d69", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "bbbb6df4a0e2806f", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "6540a13e91e3622f", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "ee44f7bbe9f5367e", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "4bd15c1342426bc4", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "a727f79d59404aa6", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "8cefeedf061f1c0d", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-eb5045e090538358", "level": "warning", "message": {"text": "Frontend route `/encounter/:id` has no Link/navigate to it \u2014 frontend/src/App.tsx"}, "properties": {"repobilityId": "9bc47b3744ccd44a", "scanner": "scanner-primary", "fingerprint": "eb5045e090538358", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-6eec788f870f288a", "level": "error", "message": {"text": "FastAPI POST `ingest_policy` without auth dependency \u2014 p2r/backend/app/main.py:106"}, "properties": {"repobilityId": "9510bc6da3c22452", "scanner": "scanner-primary", "fingerprint": "6eec788f870f288a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 106}}}]}, {"ruleId": "scanner-8900a28d8231c0a6", "level": "error", "message": {"text": "FastAPI POST `ingest_sample` without auth dependency \u2014 p2r/backend/app/main.py:115"}, "properties": {"repobilityId": "afeed35ebdcc29a8", "scanner": "scanner-primary", "fingerprint": "8900a28d8231c0a6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 115}}}]}, {"ruleId": "scanner-3768c0d11d82b4ab", "level": "error", "message": {"text": "FastAPI POST `ingest_document` without auth dependency \u2014 p2r/backend/app/main.py:122"}, "properties": {"repobilityId": "95f123004bdd5a11", "scanner": "scanner-primary", "fingerprint": "3768c0d11d82b4ab", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 122}}}]}, {"ruleId": "scanner-78075d4fe53dbdce", "level": "error", "message": {"text": "FastAPI POST `recommend_from_document` without auth dependency \u2014 p2r/backend/app/main.py:178"}, "properties": {"repobilityId": "8eb3ae002f91afa9", "scanner": "scanner-primary", "fingerprint": "78075d4fe53dbdce", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 178}}}]}, {"ruleId": "scanner-7d3698b0566e7042", "level": "error", "message": {"text": "FastAPI PATCH `edit_recommendation` without auth dependency \u2014 p2r/backend/app/main.py:216"}, "properties": {"repobilityId": "fd52b3536a04b1c9", "scanner": "scanner-primary", "fingerprint": "7d3698b0566e7042", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 216}}}]}, {"ruleId": "scanner-eca78ede8ba75393", "level": "error", "message": {"text": "FastAPI POST `approve_recommendation` without auth dependency \u2014 p2r/backend/app/main.py:243"}, "properties": {"repobilityId": "1106ea8090687de8", "scanner": "scanner-primary", "fingerprint": "eca78ede8ba75393", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 243}}}]}, {"ruleId": "scanner-f020b43438a2a7d8", "level": "error", "message": {"text": "FastAPI POST `recommendation_replay` without auth dependency \u2014 p2r/backend/app/main.py:276"}, "properties": {"repobilityId": "1232be8710927d55", "scanner": "scanner-primary", "fingerprint": "f020b43438a2a7d8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 276}}}]}, {"ruleId": "scanner-abf0e5bdca69a208", "level": "error", "message": {"text": "FastAPI POST `recommendation_rollback` without auth dependency \u2014 p2r/backend/app/main.py:285"}, "properties": {"repobilityId": "bcbbb9ecb1d92958", "scanner": "scanner-primary", "fingerprint": "abf0e5bdca69a208", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 285}}}]}, {"ruleId": "scanner-cc357653010ca144", "level": "error", "message": {"text": "FastAPI POST `publish_to_ace` without auth dependency \u2014 p2r/backend/app/main.py:297"}, "properties": {"repobilityId": "20c552a02aa7843c", "scanner": "scanner-primary", "fingerprint": "cc357653010ca144", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 297}}}]}, {"ruleId": "scanner-816cdccaf755d277", "level": "error", "message": {"text": "FastAPI POST `acquire_source` without auth dependency \u2014 p2r/backend/app/main.py:316"}, "properties": {"repobilityId": "8984f5568607747c", "scanner": "scanner-primary", "fingerprint": "816cdccaf755d277", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 316}}}]}, {"ruleId": "scanner-1d31537060c0fa69", "level": "error", "message": {"text": "FastAPI POST `denials_load_sample` without auth dependency \u2014 p2r/backend/app/main.py:348"}, "properties": {"repobilityId": "935d1908a9ab124f", "scanner": "scanner-primary", "fingerprint": "1d31537060c0fa69", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 348}}}]}, {"ruleId": "scanner-c4b15395661be23c", "level": "error", "message": {"text": "FastAPI POST `denials_detect` without auth dependency \u2014 p2r/backend/app/main.py:354"}, "properties": {"repobilityId": "a7d086e04fad5ad1", "scanner": "scanner-primary", "fingerprint": "c4b15395661be23c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 354}}}]}, {"ruleId": "scanner-f12cdad53d9e82b4", "level": "error", "message": {"text": "FastAPI POST `denials_promote` without auth dependency \u2014 p2r/backend/app/main.py:386"}, "properties": {"repobilityId": "75452e28935dee1d", "scanner": "scanner-primary", "fingerprint": "f12cdad53d9e82b4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 386}}}]}, {"ruleId": "scanner-9b8c47e56a8eb71f", "level": "error", "message": {"text": "FastAPI PUT `admin_put_config` without auth dependency \u2014 p2r/backend/app/main.py:416"}, "properties": {"repobilityId": "1f8b95e3b8012d1d", "scanner": "scanner-primary", "fingerprint": "9b8c47e56a8eb71f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 416}}}]}, {"ruleId": "scanner-26f975eb8ac7eb11", "level": "error", "message": {"text": "FastAPI POST `admin_reset_config` without auth dependency \u2014 p2r/backend/app/main.py:427"}, "properties": {"repobilityId": "db6afcb4d6da9834", "scanner": "scanner-primary", "fingerprint": "26f975eb8ac7eb11", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 427}}}]}, {"ruleId": "scanner-d2069101c9a3a32f", "level": "error", "message": {"text": "FastAPI POST `admin_llm_test` without auth dependency \u2014 p2r/backend/app/main.py:442"}, "properties": {"repobilityId": "7a56b927f62c9097", "scanner": "scanner-primary", "fingerprint": "d2069101c9a3a32f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 442}}}]}, {"ruleId": "scanner-3e24bac6d4a15bd6", "level": "error", "message": {"text": "FastAPI POST `create_rule` without auth dependency \u2014 p2r/backend/app/main.py:464"}, "properties": {"repobilityId": "1d207d432a342831", "scanner": "scanner-primary", "fingerprint": "3e24bac6d4a15bd6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 464}}}]}, {"ruleId": "scanner-e1de06c96397cac2", "level": "error", "message": {"text": "FastAPI PUT `update_rule` without auth dependency \u2014 p2r/backend/app/main.py:477"}, "properties": {"repobilityId": "defc83268159341d", "scanner": "scanner-primary", "fingerprint": "e1de06c96397cac2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 477}}}]}, {"ruleId": "scanner-ea3e1b66d9850dbc", "level": "error", "message": {"text": "FastAPI DELETE `delete_rule` without auth dependency \u2014 p2r/backend/app/main.py:492"}, "properties": {"repobilityId": "e6f692d060d57601", "scanner": "scanner-primary", "fingerprint": "ea3e1b66d9850dbc", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 492}}}]}, {"ruleId": "scanner-9a5b8f518e9841fd", "level": "error", "message": {"text": "FastAPI POST `create_source` without auth dependency \u2014 p2r/backend/app/main.py:514"}, "properties": {"repobilityId": "38a5bbcae6a8971f", "scanner": "scanner-primary", "fingerprint": "9a5b8f518e9841fd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 514}}}]}, {"ruleId": "scanner-028b80caabf20901", "level": "error", "message": {"text": "FastAPI PUT `update_source` without auth dependency \u2014 p2r/backend/app/main.py:525"}, "properties": {"repobilityId": "3ff4466205ccb582", "scanner": "scanner-primary", "fingerprint": "028b80caabf20901", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 525}}}]}, {"ruleId": "scanner-a9ad61a47a5fb4c9", "level": "error", "message": {"text": "FastAPI POST `eval_golden_create` without auth dependency \u2014 p2r/backend/app/main.py:571"}, "properties": {"repobilityId": "9bab1e8964f8d2c1", "scanner": "scanner-primary", "fingerprint": "a9ad61a47a5fb4c9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 571}}}]}, {"ruleId": "scanner-9fcc2bf9f5766031", "level": "error", "message": {"text": "FastAPI DELETE `eval_golden_delete` without auth dependency \u2014 p2r/backend/app/main.py:581"}, "properties": {"repobilityId": "f3b8325e23dcd547", "scanner": "scanner-primary", "fingerprint": "9fcc2bf9f5766031", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 581}}}]}, {"ruleId": "scanner-547b4a4f643382dc", "level": "error", "message": {"text": "FastAPI POST `eval_run` without auth dependency \u2014 p2r/backend/app/main.py:593"}, "properties": {"repobilityId": "670c6cb40a177ee9", "scanner": "scanner-primary", "fingerprint": "547b4a4f643382dc", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "p2r/backend/app/main.py"}, "region": {"startLine": 593}}}]}, {"ruleId": "scanner-f5cd591d4db5f34c", "level": "error", "message": {"text": "FastAPI POST `cdi_scan` without auth dependency \u2014 backend/app/routes/cdi.py:35"}, "properties": {"repobilityId": "ba6bd55168c4e709", "scanner": "scanner-primary", "fingerprint": "f5cd591d4db5f34c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/cdi.py"}, "region": {"startLine": 35}}}]}, {"ruleId": "scanner-7eae5cbbbcd5c7c0", "level": "error", "message": {"text": "FastAPI POST `cdi_respond` without auth dependency \u2014 backend/app/routes/cdi.py:84"}, "properties": {"repobilityId": "65754f0f0c2ffc90", "scanner": "scanner-primary", "fingerprint": "7eae5cbbbcd5c7c0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/cdi.py"}, "region": {"startLine": 84}}}]}, {"ruleId": "scanner-c58e209912e66f5a", "level": "error", "message": {"text": "FastAPI POST `assign` without auth dependency \u2014 backend/app/routes/ops.py:109"}, "properties": {"repobilityId": "7e27228978a7fa80", "scanner": "scanner-primary", "fingerprint": "c58e209912e66f5a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/ops.py"}, "region": {"startLine": 109}}}]}, {"ruleId": "scanner-fce7274344003add", "level": "error", "message": {"text": "FastAPI POST `create_policy` without auth dependency \u2014 backend/app/routes/ops.py:151"}, "properties": {"repobilityId": "bccccc5f6e551e9b", "scanner": "scanner-primary", "fingerprint": "fce7274344003add", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/ops.py"}, "region": {"startLine": 151}}}]}, {"ruleId": "scanner-41e3d4a2966a2cc1", "level": "error", "message": {"text": "FastAPI PUT `update_policy` without auth dependency \u2014 backend/app/routes/ops.py:162"}, "properties": {"repobilityId": "0fc733be8ff3610a", "scanner": "scanner-primary", "fingerprint": "41e3d4a2966a2cc1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/ops.py"}, "region": {"startLine": 162}}}]}, {"ruleId": "scanner-bbc1bdc8eda54576", "level": "error", "message": {"text": "FastAPI DELETE `delete_policy` without auth dependency \u2014 backend/app/routes/ops.py:176"}, "properties": {"repobilityId": "82b8241796f34ab3", "scanner": "scanner-primary", "fingerprint": "bbc1bdc8eda54576", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/ops.py"}, "region": {"startLine": 176}}}]}, {"ruleId": "scanner-6896c974675aa9bd", "level": "error", "message": {"text": "FastAPI POST `create_concept` without auth dependency \u2014 backend/app/routes/ops.py:249"}, "properties": {"repobilityId": "833457f7271d35d5", "scanner": "scanner-primary", "fingerprint": "6896c974675aa9bd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/ops.py"}, "region": {"startLine": 249}}}]}, {"ruleId": "scanner-4b4bf91e10e5b6f3", "level": "error", "message": {"text": "FastAPI PUT `update_concept` without auth dependency \u2014 backend/app/routes/ops.py:269"}, "properties": {"repobilityId": "1528b8fb59037baf", "scanner": "scanner-primary", "fingerprint": "4b4bf91e10e5b6f3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/ops.py"}, "region": {"startLine": 269}}}]}, {"ruleId": "scanner-13249ea59b235fc4", "level": "error", "message": {"text": "FastAPI DELETE `delete_concept` without auth dependency \u2014 backend/app/routes/ops.py:285"}, "properties": {"repobilityId": "f8bd4fb4d4e95967", "scanner": "scanner-primary", "fingerprint": "13249ea59b235fc4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/ops.py"}, "region": {"startLine": 285}}}]}, {"ruleId": "scanner-d64ebfa286a663c0", "level": "error", "message": {"text": "FastAPI POST `create_edge` without auth dependency \u2014 backend/app/routes/ops.py:308"}, "properties": {"repobilityId": "129d83f373ab36c2", "scanner": "scanner-primary", "fingerprint": "d64ebfa286a663c0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/ops.py"}, "region": {"startLine": 308}}}]}, {"ruleId": "scanner-153bb1f87f5abab2", "level": "error", "message": {"text": "FastAPI DELETE `delete_edge` without auth dependency \u2014 backend/app/routes/ops.py:332"}, "properties": {"repobilityId": "f2fc0f70992c6b57", "scanner": "scanner-primary", "fingerprint": "153bb1f87f5abab2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/ops.py"}, "region": {"startLine": 332}}}]}, {"ruleId": "scanner-7ca1f265e15ab858", "level": "error", "message": {"text": "FastAPI POST `create_guideline` without auth dependency \u2014 backend/app/routes/ops.py:363"}, "properties": {"repobilityId": "034b1495682ea7b6", "scanner": "scanner-primary", "fingerprint": "7ca1f265e15ab858", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/ops.py"}, "region": {"startLine": 363}}}]}, {"ruleId": "scanner-78a35bf3e3cc59c2", "level": "error", "message": {"text": "FastAPI PUT `update_guideline` without auth dependency \u2014 backend/app/routes/ops.py:378"}, "properties": {"repobilityId": "e8be070f89a67318", "scanner": "scanner-primary", "fingerprint": "78a35bf3e3cc59c2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/ops.py"}, "region": {"startLine": 378}}}]}, {"ruleId": "scanner-067940edd13c7d5e", "level": "error", "message": {"text": "FastAPI DELETE `delete_guideline` without auth dependency \u2014 backend/app/routes/ops.py:394"}, "properties": {"repobilityId": "a44eaa754fe52f39", "scanner": "scanner-primary", "fingerprint": "067940edd13c7d5e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/ops.py"}, "region": {"startLine": 394}}}]}, {"ruleId": "scanner-a71a063d79de81a6", "level": "error", "message": {"text": "FastAPI POST `create_refcode` without auth dependency \u2014 backend/app/routes/ops.py:443"}, "properties": {"repobilityId": "d0704923021d829b", "scanner": "scanner-primary", "fingerprint": "a71a063d79de81a6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/ops.py"}, "region": {"startLine": 443}}}]}, {"ruleId": "scanner-7bbb8d7543b55eef", "level": "error", "message": {"text": "FastAPI PUT `update_refcode` without auth dependency \u2014 backend/app/routes/ops.py:458"}, "properties": {"repobilityId": "1778836811473f1e", "scanner": "scanner-primary", "fingerprint": "7bbb8d7543b55eef", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/ops.py"}, "region": {"startLine": 458}}}]}, {"ruleId": "scanner-268767ad311b7d1b", "level": "error", "message": {"text": "FastAPI DELETE `delete_refcode` without auth dependency \u2014 backend/app/routes/ops.py:472"}, "properties": {"repobilityId": "06d3e25556b600f6", "scanner": "scanner-primary", "fingerprint": "268767ad311b7d1b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/ops.py"}, "region": {"startLine": 472}}}]}, {"ruleId": "scanner-7877928f2cdbc722", "level": "error", "message": {"text": "FastAPI POST `create_ncci` without auth dependency \u2014 backend/app/routes/ops.py:503"}, "properties": {"repobilityId": "fe0b1ec060bd7bd2", "scanner": "scanner-primary", "fingerprint": "7877928f2cdbc722", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/ops.py"}, "region": {"startLine": 503}}}]}, {"ruleId": "scanner-fea186b1e2d546b7", "level": "error", "message": {"text": "FastAPI DELETE `delete_ncci` without auth dependency \u2014 backend/app/routes/ops.py:515"}, "properties": {"repobilityId": "878df2740d1c1902", "scanner": "scanner-primary", "fingerprint": "fea186b1e2d546b7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/ops.py"}, "region": {"startLine": 515}}}]}, {"ruleId": "scanner-8a1d604f2cd563af", "level": "error", "message": {"text": "FastAPI POST `create_mue` without auth dependency \u2014 backend/app/routes/ops.py:544"}, "properties": {"repobilityId": "69e9ff47b8dd2c2d", "scanner": "scanner-primary", "fingerprint": "8a1d604f2cd563af", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/ops.py"}, "region": {"startLine": 544}}}]}, {"ruleId": "scanner-3207afebfe3dde6d", "level": "error", "message": {"text": "FastAPI PUT `update_mue` without auth dependency \u2014 backend/app/routes/ops.py:557"}, "properties": {"repobilityId": "798177f9227fda45", "scanner": "scanner-primary", "fingerprint": "3207afebfe3dde6d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/ops.py"}, "region": {"startLine": 557}}}]}, {"ruleId": "scanner-968f9957ab433e11", "level": "error", "message": {"text": "FastAPI DELETE `delete_mue` without auth dependency \u2014 backend/app/routes/ops.py:571"}, "properties": {"repobilityId": "13fad08e7ef0eea0", "scanner": "scanner-primary", "fingerprint": "968f9957ab433e11", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/ops.py"}, "region": {"startLine": 571}}}]}, {"ruleId": "scanner-4a64f5f05e033781", "level": "error", "message": {"text": "FastAPI POST `create_modifier` without auth dependency \u2014 backend/app/routes/ops.py:601"}, "properties": {"repobilityId": "01852c0a1f08addd", "scanner": "scanner-primary", "fingerprint": "4a64f5f05e033781", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/ops.py"}, "region": {"startLine": 601}}}]}, {"ruleId": "scanner-d7e15f1d984ba04c", "level": "error", "message": {"text": "FastAPI DELETE `delete_modifier` without auth dependency \u2014 backend/app/routes/ops.py:614"}, "properties": {"repobilityId": "4e437fd7c12a2a94", "scanner": "scanner-primary", "fingerprint": "d7e15f1d984ba04c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/ops.py"}, "region": {"startLine": 614}}}]}, {"ruleId": "scanner-e6d5d35ac1655b42", "level": "error", "message": {"text": "FastAPI POST `ingest` without auth dependency \u2014 backend/app/routes/ops.py:682"}, "properties": {"repobilityId": "683c14e2da2e1349", "scanner": "scanner-primary", "fingerprint": "e6d5d35ac1655b42", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/ops.py"}, "region": {"startLine": 682}}}]}, {"ruleId": "scanner-500759752b15c609", "level": "error", "message": {"text": "FastAPI POST `ingest_document` without auth dependency \u2014 backend/app/routes/ops.py:704"}, "properties": {"repobilityId": "2ba13be7c3af1a20", "scanner": "scanner-primary", "fingerprint": "500759752b15c609", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/ops.py"}, "region": {"startLine": 704}}}]}, {"ruleId": "scanner-00effd51ccb9362f", "level": "error", "message": {"text": "FastAPI PUT `put_config` without auth dependency \u2014 backend/app/routes/admin.py:35"}, "properties": {"repobilityId": "7784f9fe492d702f", "scanner": "scanner-primary", "fingerprint": "00effd51ccb9362f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/admin.py"}, "region": {"startLine": 35}}}]}, {"ruleId": "scanner-006a6ad0a1e201c2", "level": "error", "message": {"text": "FastAPI POST `reset_config` without auth dependency \u2014 backend/app/routes/admin.py:46"}, "properties": {"repobilityId": "429a1d55a010e476", "scanner": "scanner-primary", "fingerprint": "006a6ad0a1e201c2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/admin.py"}, "region": {"startLine": 46}}}]}, {"ruleId": "scanner-3322f0fc535eddcb", "level": "error", "message": {"text": "FastAPI POST `llm_test` without auth dependency \u2014 backend/app/routes/admin.py:73"}, "properties": {"repobilityId": "c7b4db4bb6c7be0b", "scanner": "scanner-primary", "fingerprint": "3322f0fc535eddcb", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/admin.py"}, "region": {"startLine": 73}}}]}, {"ruleId": "scanner-f93254c2abf88bcb", "level": "error", "message": {"text": "FastAPI POST `trigger_seed` without auth dependency \u2014 backend/app/routes/admin.py:102"}, "properties": {"repobilityId": "039611f6e487a6fb", "scanner": "scanner-primary", "fingerprint": "f93254c2abf88bcb", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/admin.py"}, "region": {"startLine": 102}}}]}, {"ruleId": "scanner-f0e4c5912e47ca3a", "level": "error", "message": {"text": "FastAPI PATCH `patch_learning` without auth dependency \u2014 backend/app/routes/insights.py:259"}, "properties": {"repobilityId": "46ec93b3339a9492", "scanner": "scanner-primary", "fingerprint": "f0e4c5912e47ca3a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/insights.py"}, "region": {"startLine": 259}}}]}, {"ruleId": "scanner-85586ffe800ddbec", "level": "error", "message": {"text": "FastAPI DELETE `delete_learning` without auth dependency \u2014 backend/app/routes/insights.py:269"}, "properties": {"repobilityId": "32fa02b4db2b52d0", "scanner": "scanner-primary", "fingerprint": "85586ffe800ddbec", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/insights.py"}, "region": {"startLine": 269}}}]}, {"ruleId": "scanner-814d0601210c37b8", "level": "error", "message": {"text": "FastAPI POST `create_golden` without auth dependency \u2014 backend/app/routes/insights.py:314"}, "properties": {"repobilityId": "d3d2959d2b70d54e", "scanner": "scanner-primary", "fingerprint": "814d0601210c37b8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/insights.py"}, "region": {"startLine": 314}}}]}, {"ruleId": "scanner-38f08d2d709c6315", "level": "error", "message": {"text": "FastAPI PUT `update_golden` without auth dependency \u2014 backend/app/routes/insights.py:328"}, "properties": {"repobilityId": "1691949b96426995", "scanner": "scanner-primary", "fingerprint": "38f08d2d709c6315", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/insights.py"}, "region": {"startLine": 328}}}]}, {"ruleId": "scanner-574a7761876c4cc6", "level": "error", "message": {"text": "FastAPI DELETE `delete_golden` without auth dependency \u2014 backend/app/routes/insights.py:345"}, "properties": {"repobilityId": "1636f4b214107a9d", "scanner": "scanner-primary", "fingerprint": "574a7761876c4cc6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/insights.py"}, "region": {"startLine": 345}}}]}, {"ruleId": "scanner-7d28ff3795d5e9c9", "level": "error", "message": {"text": "FastAPI POST `eval_run` without auth dependency \u2014 backend/app/routes/insights.py:530"}, "properties": {"repobilityId": "3786e2a59e5fe78f", "scanner": "scanner-primary", "fingerprint": "7d28ff3795d5e9c9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/insights.py"}, "region": {"startLine": 530}}}]}, {"ruleId": "scanner-4a2fe61b99641190", "level": "error", "message": {"text": "FastAPI POST `reassign_run` without auth dependency \u2014 backend/app/routes/coding.py:38"}, "properties": {"repobilityId": "97bcfd57787ecb43", "scanner": "scanner-primary", "fingerprint": "4a2fe61b99641190", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/coding.py"}, "region": {"startLine": 38}}}]}, {"ruleId": "scanner-7b0bc20e6161bafe", "level": "error", "message": {"text": "FastAPI POST `rollback_run` without auth dependency \u2014 backend/app/routes/coding.py:58"}, "properties": {"repobilityId": "c324f6df3ace13ed", "scanner": "scanner-primary", "fingerprint": "7b0bc20e6161bafe", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/coding.py"}, "region": {"startLine": 58}}}]}, {"ruleId": "scanner-f01162b99c30dc55", "level": "error", "message": {"text": "FastAPI POST `escalate_run` without auth dependency \u2014 backend/app/routes/coding.py:97"}, "properties": {"repobilityId": "9306e1bcc1b0f96a", "scanner": "scanner-primary", "fingerprint": "f01162b99c30dc55", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/coding.py"}, "region": {"startLine": 97}}}]}, {"ruleId": "scanner-ceac2aeb5bc2a73b", "level": "error", "message": {"text": "FastAPI POST `code_encounter` without auth dependency \u2014 backend/app/routes/coding.py:113"}, "properties": {"repobilityId": "d5f6291b155ca597", "scanner": "scanner-primary", "fingerprint": "ceac2aeb5bc2a73b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/coding.py"}, "region": {"startLine": 113}}}]}, {"ruleId": "scanner-432267ff47d5ad0f", "level": "error", "message": {"text": "FastAPI POST `run_all` without auth dependency \u2014 backend/app/routes/coding.py:173"}, "properties": {"repobilityId": "032957d90cb7d943", "scanner": "scanner-primary", "fingerprint": "432267ff47d5ad0f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/coding.py"}, "region": {"startLine": 173}}}]}, {"ruleId": "scanner-dd3c87de1fda2427", "level": "error", "message": {"text": "FastAPI POST `add_addendum` without auth dependency \u2014 backend/app/routes/coding.py:203"}, "properties": {"repobilityId": "1498c9d0bc492b39", "scanner": "scanner-primary", "fingerprint": "dd3c87de1fda2427", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/coding.py"}, "region": {"startLine": 203}}}]}, {"ruleId": "scanner-40447f8f663f37b4", "level": "error", "message": {"text": "FastAPI POST `accept_code` without auth dependency \u2014 backend/app/routes/coding.py:251"}, "properties": {"repobilityId": "94df08f15fbefad7", "scanner": "scanner-primary", "fingerprint": "40447f8f663f37b4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/coding.py"}, "region": {"startLine": 251}}}]}, {"ruleId": "scanner-285a6a57a9b0b7d3", "level": "error", "message": {"text": "FastAPI POST `override_code` without auth dependency \u2014 backend/app/routes/coding.py:265"}, "properties": {"repobilityId": "890c10dd2657bd30", "scanner": "scanner-primary", "fingerprint": "285a6a57a9b0b7d3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/routes/coding.py"}, "region": {"startLine": 265}}}]}, {"ruleId": "scanner-833edacd3634c902", "level": "note", "message": {"text": "Unused endpoint: GET /meta"}, "properties": {"repobilityId": "4756bdbdae174190", "scanner": "scanner-primary", "fingerprint": "833edacd3634c902", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c96a14905be67a3c", "level": "note", "message": {"text": "Unused endpoint: POST /ingest/policy"}, "properties": {"repobilityId": "42d851eb8c60abb2", "scanner": "scanner-primary", "fingerprint": "c96a14905be67a3c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7337beeb73e4750f", "level": "note", "message": {"text": "Unused endpoint: POST /ingest/policy/sample"}, "properties": {"repobilityId": "13e030d2582466d0", "scanner": "scanner-primary", "fingerprint": "7337beeb73e4750f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9921d02ec5b05e8d", "level": "note", "message": {"text": "Unused endpoint: POST /ingest/policy/document"}, "properties": {"repobilityId": "5a52e8bc348ac12a", "scanner": "scanner-primary", "fingerprint": "9921d02ec5b05e8d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ffc9ad08ed6cdd74", "level": "note", "message": {"text": "Unused endpoint: GET /documents"}, "properties": {"repobilityId": "436d9dd41171a8bf", "scanner": "scanner-primary", "fingerprint": "ffc9ad08ed6cdd74", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ff65bfc3949844c4", "level": "note", "message": {"text": "Unused endpoint: GET /documents/{doc_id}/provisions"}, "properties": {"repobilityId": "a79c40380102a846", "scanner": "scanner-primary", "fingerprint": "ff65bfc3949844c4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a8b338285e916bb7", "level": "note", "message": {"text": "Unused endpoint: GET /provisions"}, "properties": {"repobilityId": "7fbfdf919f28b716", "scanner": "scanner-primary", "fingerprint": "a8b338285e916bb7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-693c6e86dced9070", "level": "note", "message": {"text": "Unused endpoint: GET /rule-library"}, "properties": {"repobilityId": "7791f5578f4a8207", "scanner": "scanner-primary", "fingerprint": "693c6e86dced9070", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1c9f3fc47b3ab9a2", "level": "note", "message": {"text": "Unused endpoint: POST /recommendations/from-document/{doc_id}"}, "properties": {"repobilityId": "e4613a01f57d5a4e", "scanner": "scanner-primary", "fingerprint": "1c9f3fc47b3ab9a2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-96893e003e8de1eb", "level": "note", "message": {"text": "Unused endpoint: GET /recommendations/from-document/{doc_id}/stream"}, "properties": {"repobilityId": "3602f905b9d4b161", "scanner": "scanner-primary", "fingerprint": "96893e003e8de1eb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1f77f6f75187981c", "level": "note", "message": {"text": "Unused endpoint: GET /recommendations"}, "properties": {"repobilityId": "4de087fe3ee6034f", "scanner": "scanner-primary", "fingerprint": "1f77f6f75187981c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0a1eb0e541688151", "level": "note", "message": {"text": "Unused endpoint: PATCH /recommendations/{rec_id}"}, "properties": {"repobilityId": "df1bbafea6f2ee44", "scanner": "scanner-primary", "fingerprint": "0a1eb0e541688151", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3e27c235f7070593", "level": "note", "message": {"text": "Unused endpoint: POST /recommendations/{rec_id}/approve"}, "properties": {"repobilityId": "52544e6ec00e2816", "scanner": "scanner-primary", "fingerprint": "3e27c235f7070593", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3afd61ca78904655", "level": "note", "message": {"text": "Unused endpoint: GET /integration/ace/status"}, "properties": {"repobilityId": "a2b84d73df267779", "scanner": "scanner-primary", "fingerprint": "3afd61ca78904655", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cece27e015a00556", "level": "note", "message": {"text": "Unused endpoint: GET /recommendations/{rec_id}/rule-ir"}, "properties": {"repobilityId": "f3cc5c245bd355b8", "scanner": "scanner-primary", "fingerprint": "cece27e015a00556", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-620a97895f308a9a", "level": "note", "message": {"text": "Unused endpoint: POST /recommendations/{rec_id}/replay"}, "properties": {"repobilityId": "e5132cf4c3206d23", "scanner": "scanner-primary", "fingerprint": "620a97895f308a9a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ca7632571d841972", "level": "note", "message": {"text": "Unused endpoint: POST /recommendations/{rec_id}/rollback"}, "properties": {"repobilityId": "7da897309918beb2", "scanner": "scanner-primary", "fingerprint": "ca7632571d841972", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6d7812d4b8d87e99", "level": "note", "message": {"text": "Unused endpoint: POST /recommendations/{rec_id}/publish-to-ace"}, "properties": {"repobilityId": "9df2bc1b5c614210", "scanner": "scanner-primary", "fingerprint": "6d7812d4b8d87e99", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9617aa24fd377881", "level": "note", "message": {"text": "Unused endpoint: GET /sources"}, "properties": {"repobilityId": "472be9ec724892bf", "scanner": "scanner-primary", "fingerprint": "9617aa24fd377881", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-374943260c8faa42", "level": "note", "message": {"text": "Unused endpoint: POST /sources/{source_id}/acquire"}, "properties": {"repobilityId": "b98c48f29875237c", "scanner": "scanner-primary", "fingerprint": "374943260c8faa42", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5a1e198eb18f1953", "level": "note", "message": {"text": "Unused endpoint: GET /sources/{source_id}/acquire/stream"}, "properties": {"repobilityId": "0e0cf10ebc1561e4", "scanner": "scanner-primary", "fingerprint": "5a1e198eb18f1953", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c30e15c74bdb7970", "level": "note", "message": {"text": "Unused endpoint: GET /deltas"}, "properties": {"repobilityId": "e568402fbfc8da1f", "scanner": "scanner-primary", "fingerprint": "c30e15c74bdb7970", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d9def61ad733bec3", "level": "note", "message": {"text": "Unused endpoint: GET /payer-master"}, "properties": {"repobilityId": "10ffb1c82af8e69a", "scanner": "scanner-primary", "fingerprint": "d9def61ad733bec3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9c5c90b86a8b1ad6", "level": "note", "message": {"text": "Unused endpoint: POST /denials/load-sample"}, "properties": {"repobilityId": "2a289b78918cdba0", "scanner": "scanner-primary", "fingerprint": "9c5c90b86a8b1ad6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d36851936ca82c10", "level": "note", "message": {"text": "Unused endpoint: POST /denials/detect"}, "properties": {"repobilityId": "aed438b01398ddf5", "scanner": "scanner-primary", "fingerprint": "d36851936ca82c10", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7438169b8eaafbed", "level": "note", "message": {"text": "Unused endpoint: GET /denials/signals"}, "properties": {"repobilityId": "a2aefd1434d1ed7c", "scanner": "scanner-primary", "fingerprint": "7438169b8eaafbed", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f0c81d48a2cff0d8", "level": "note", "message": {"text": "Unused endpoint: GET /denials/remittances"}, "properties": {"repobilityId": "22a90c66d393fa18", "scanner": "scanner-primary", "fingerprint": "f0c81d48a2cff0d8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2c3cdb4e93b9aa45", "level": "note", "message": {"text": "Unused endpoint: POST /denials/signals/{signal_id}/promote"}, "properties": {"repobilityId": "1f18d3076faf8f8b", "scanner": "scanner-primary", "fingerprint": "2c3cdb4e93b9aa45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7c7e6b66c64ac953", "level": "note", "message": {"text": "Unused endpoint: GET /denials/signals/{signal_id}/promote/stream"}, "properties": {"repobilityId": "7030b472c6480e7e", "scanner": "scanner-primary", "fingerprint": "7c7e6b66c64ac953", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c7914268ea70bbb0", "level": "note", "message": {"text": "Unused endpoint: GET /admin/config"}, "properties": {"repobilityId": "4cdbcb52c9b8bd2b", "scanner": "scanner-primary", "fingerprint": "c7914268ea70bbb0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-419f41a8829b4758", "level": "note", "message": {"text": "Unused endpoint: PUT /admin/config/{key}"}, "properties": {"repobilityId": "253c66e2943691ca", "scanner": "scanner-primary", "fingerprint": "419f41a8829b4758", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6004e94965207e20", "level": "note", "message": {"text": "Unused endpoint: POST /admin/config/reset"}, "properties": {"repobilityId": "017af076b863d8e9", "scanner": "scanner-primary", "fingerprint": "6004e94965207e20", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-37916a796965e2bd", "level": "note", "message": {"text": "Unused endpoint: GET /admin/llm/status"}, "properties": {"repobilityId": "882e68fc8239b150", "scanner": "scanner-primary", "fingerprint": "37916a796965e2bd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d9a238fc5520344b", "level": "note", "message": {"text": "Unused endpoint: POST /admin/llm/test"}, "properties": {"repobilityId": "5e7285eadfc41aef", "scanner": "scanner-primary", "fingerprint": "d9a238fc5520344b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-aadc34cdd73778b8", "level": "note", "message": {"text": "Unused endpoint: POST /rule-library"}, "properties": {"repobilityId": "ccf130256385903a", "scanner": "scanner-primary", "fingerprint": "aadc34cdd73778b8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3f3031eb50975f88", "level": "note", "message": {"text": "Unused endpoint: PUT /rule-library/{rule_id}"}, "properties": {"repobilityId": "d2a83b8c3fea37d1", "scanner": "scanner-primary", "fingerprint": "3f3031eb50975f88", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ec4b033b3e6f9720", "level": "note", "message": {"text": "Unused endpoint: DELETE /rule-library/{rule_id}"}, "properties": {"repobilityId": "870e01d29a4d1793", "scanner": "scanner-primary", "fingerprint": "ec4b033b3e6f9720", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5467e682054ad3ed", "level": "note", "message": {"text": "Unused endpoint: POST /sources"}, "properties": {"repobilityId": "249cfd5c30d1ea83", "scanner": "scanner-primary", "fingerprint": "5467e682054ad3ed", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9b4354893001b6bb", "level": "note", "message": {"text": "Unused endpoint: PUT /sources/{source_id}"}, "properties": {"repobilityId": "912b436133edcb2f", "scanner": "scanner-primary", "fingerprint": "9b4354893001b6bb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-00d297d86aa253fe", "level": "note", "message": {"text": "Unused endpoint: GET /audit"}, "properties": {"repobilityId": "7b78dc035ee09e10", "scanner": "scanner-primary", "fingerprint": "00d297d86aa253fe", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ac8cea070ef66a8e", "level": "note", "message": {"text": "Unused endpoint: GET /recommendations/{rec_id}/lineage"}, "properties": {"repobilityId": "b1cfdc0dce09a0fb", "scanner": "scanner-primary", "fingerprint": "ac8cea070ef66a8e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a72f985756188e7a", "level": "note", "message": {"text": "Unused endpoint: GET /eval/golden"}, "properties": {"repobilityId": "2bf146021708afb7", "scanner": "scanner-primary", "fingerprint": "a72f985756188e7a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5fcc93e17bdd4795", "level": "note", "message": {"text": "Unused endpoint: POST /eval/golden"}, "properties": {"repobilityId": "0161eee2b1c074da", "scanner": "scanner-primary", "fingerprint": "5fcc93e17bdd4795", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-691561e09d311d2e", "level": "note", "message": {"text": "Unused endpoint: DELETE /eval/golden/{case_id}"}, "properties": {"repobilityId": "c9ec42d83aa6c0dd", "scanner": "scanner-primary", "fingerprint": "691561e09d311d2e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f84e91408ec499c6", "level": "note", "message": {"text": "Unused endpoint: POST /eval/run"}, "properties": {"repobilityId": "9f2c9201392b755f", "scanner": "scanner-primary", "fingerprint": "f84e91408ec499c6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7dca636b75fdc439", "level": "note", "message": {"text": "Unused endpoint: GET /eval/golden/denials"}, "properties": {"repobilityId": "3bbffa5c0a845205", "scanner": "scanner-primary", "fingerprint": "7dca636b75fdc439", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e23ff94fb6fc96ab", "level": "note", "message": {"text": "Unused endpoint: GET /eval/history"}, "properties": {"repobilityId": "0af2973d6ffb1bcd", "scanner": "scanner-primary", "fingerprint": "e23ff94fb6fc96ab", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6ed45ba9e4841214", "level": "note", "message": {"text": "Unused endpoint: GET /eval/run/stream"}, "properties": {"repobilityId": "1caa02ef2c5244cd", "scanner": "scanner-primary", "fingerprint": "6ed45ba9e4841214", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3bfd327cf713b0a7", "level": "note", "message": {"text": "Unused endpoint: POST /encounters/{enc_id}/cdi-scan"}, "properties": {"repobilityId": "ae1b8e0fa62b2030", "scanner": "scanner-primary", "fingerprint": "3bfd327cf713b0a7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ab455fc07b0dabe2", "level": "note", "message": {"text": "Unused endpoint: GET /encounters/{enc_id}/cdi-scan/stream"}, "properties": {"repobilityId": "755e47f669c47d48", "scanner": "scanner-primary", "fingerprint": "ab455fc07b0dabe2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}