{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-8b6b7e6a2ca79364", "name": "Stray `console.log` in TS/JS \u2014 test-endpoints.js:79", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 test-endpoints.js:79"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0b364b137ab9b1b0", "name": "Stray `console.log` in TS/JS \u2014 test-swagger-endpoint.js:5", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 test-swagger-endpoint.js:5"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa372a40d58f685d", "name": "Stray `console.log` in TS/JS \u2014 healthcheck.js:11", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 healthcheck.js:11"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-09114618a3dc38c4", "name": "Stray `console.log` in TS/JS \u2014 test-all-endpoints.js:77", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 test-all-endpoints.js:77"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-552def99ab26e334", "name": "Stray `console.log` in TS/JS \u2014 tests/run-ml-tests.js:29", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/run-ml-tests.js:29"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d03506d2fb852d6b", "name": "Stray `console.log` in TS/JS \u2014 tests/generateApiDocs.js:16", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/generateApiDocs.js:16"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b15363dd9547e36b", "name": "Stray `console.log` in TS/JS \u2014 tests/ml-service-coverage.test.js:18", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/ml-service-coverage.test.js:18"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-136ca7725aa2d40c", "name": "Stray `console.log` in TS/JS \u2014 tests/start-ml-service.js:22", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/start-ml-service.js:22"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-02c77983ec3d73ea", "name": "Stray `console.log` in TS/JS \u2014 tests/ml-service-simple.test.js:18", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/ml-service-simple.test.js:18"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-359b30ac86b8b552", "name": "Stray `console.log` in TS/JS \u2014 tests/runAllTests.js:31", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/runAllTests.js:31"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-441b7a765cea73ef", "name": "Stray `console.log` in TS/JS \u2014 tests/ml-service.test.js:24", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/ml-service.test.js:24"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-54c9ae26e0b78fe1", "name": "Stray `console.log` in TS/JS \u2014 tests/ml-service-integration.test.js:24", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/ml-service-integration.test.js:24"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b8a58d9ef4afa2ee", "name": "Stray `console.log` in TS/JS \u2014 tests/performanceBenchmark.js:21", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/performanceBenchmark.js:21"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d3921d714cc21a57", "name": "Stray `console.log` in TS/JS \u2014 tests/runTests.js:23", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/runTests.js:23"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3e354e764b31d864", "name": "Stray `console.log` in TS/JS \u2014 tests/helpers/mockMLService.js:190", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/helpers/mockMLService.js:190"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-624cbad840e4792b", "name": "Stray `console.log` in TS/JS \u2014 tests/helpers/mlServiceHelper.js:41", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/helpers/mlServiceHelper.js:41"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e040dd9eaba902b0", "name": "Stray `console.log` in TS/JS \u2014 scripts/create-demo-users.js:70", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/create-demo-users.js:70"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2fc5f3a6646669e2", "name": "Stray `console.log` in TS/JS \u2014 scripts/verify-endpoints.js:19", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/verify-endpoints.js:19"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-61628df9b950ca3c", "name": "Stray `console.log` in TS/JS \u2014 scripts/create-demo-data.js:213", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/create-demo-data.js:213"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-17e6c1f5143dad72", "name": "Stray `console.log` in TS/JS \u2014 scripts/verify-bulk-voucher-sync.js:21", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/verify-bulk-voucher-sync.js:21"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-41a3d0cd3a49a023", "name": "Stray `console.log` in TS/JS \u2014 scripts/create-single-admin.js:11", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/create-single-admin.js:11"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-41a1c89969e7b190", "name": "Stray `console.log` in TS/JS \u2014 scripts/voucher-detail-cleanup.js:19", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/voucher-detail-cleanup.js:19"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ac0bc88d520b4838", "name": "Stray `console.log` in TS/JS \u2014 scripts/test-swagger.js:3", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-swagger.js:3"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-da6ee9fb2da421fe", "name": "Stray `console.log` in TS/JS \u2014 scripts/verifyTallyIntegration.js:18", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/verifyTallyIntegration.js:18"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-75696cc2c92dcb29", "name": "Stray `console.log` in TS/JS \u2014 scripts/demo-disable-licensing.js:35", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/demo-disable-licensing.js:35"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bc529cd608607312", "name": "Stray `console.log` in TS/JS \u2014 scripts/verify-licensing-bypass.js:36", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/verify-licensing-bypass.js:36"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0d1c9e1ace17115c", "name": "Stray `console.log` in TS/JS \u2014 scripts/create-admin-users.js:12", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/create-admin-users.js:12"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cf7cf0309496dac2", "name": "Stray `console.log` in TS/JS \u2014 scripts/clear-tally-data.js:9", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/clear-tally-data.js:9"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3115b73acdd2eb16", "name": "Stray `console.log` in TS/JS \u2014 scripts/create-demo-user.js:15", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/create-demo-user.js:15"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7c14c6634a8851b6", "name": "TODO/FIXME marker in shipping code \u2014 src/controllers/paymentController.js:112", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 src/controllers/paymentController.js:112"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-52819ee63aed81f5", "name": "TODO/FIXME marker in shipping code \u2014 src/services/paymentService.js:281", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 src/services/paymentService.js:281"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b0a79fba1e13fb60", "name": "TODO/FIXME marker in shipping code \u2014 src/services/tallyCommunicationService.js:467", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 src/services/tallyCommunicationService.js:467"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-91434f4ca7fb998c", "name": "TODO/FIXME marker in shipping code \u2014 src/services/tallySyncService.js:518", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 src/services/tallySyncService.js:518"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2dd0454eae927d4c", "name": "TODO/FIXME marker in shipping code \u2014 src/services/tallyWebSocketService.js:3369", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 src/services/tallyWebSocketService.js:3369"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-fddc1267b35d0c7b", "name": "Docker base image is tag-pinned but not digest-pinned: node:18-alpine", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:18-alpine"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d9af6fa8b065efd9", "name": "Possible secret in test-all-endpoints.js", "shortDescription": {"text": "Possible secret in test-all-endpoints.js"}, "fullDescription": {"text": "Detected pattern matching password_literal. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-33b2f8da807fa106", "name": "Possible secret in scripts/create-demo-users.js", "shortDescription": {"text": "Possible secret in scripts/create-demo-users.js"}, "fullDescription": {"text": "Detected pattern matching password_literal. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-60ee194167fc5501", "name": "Possible secret in scripts/create-single-admin.js", "shortDescription": {"text": "Possible secret in scripts/create-single-admin.js"}, "fullDescription": {"text": "Detected pattern matching password_literal. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-9f98d81fbacdf84c", "name": "Possible secret in scripts/create-admin-users.js", "shortDescription": {"text": "Possible secret in scripts/create-admin-users.js"}, "fullDescription": {"text": "Detected pattern matching password_literal. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-90e7cf6f65364a93", "name": "Very large file: src/controllers/reportController.mjs (2491 lines)", "shortDescription": {"text": "Very large file: src/controllers/reportController.mjs (2491 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-05754a2d7def8d18", "name": "Very large file: src/services/tallyWebSocketService.js (3566 lines)", "shortDescription": {"text": "Very large file: src/services/tallyWebSocketService.js (3566 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b3ed68815bca2f8c", "name": "Node manifest has dependencies but no lockfile: package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 217 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 15 placeholder/mock markers across 6 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: ci, lockfile. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-89900dd149bd935f", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/subscriptionBillingService.js:618", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/subscriptionBillingService.js:618"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-64bc033a45ab26f1", "name": "34 env vars used in code but missing from .env.example", "shortDescription": {"text": "34 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `AGENT_API_KEY`, `AI_INTENT_MODEL`, `AI_MAX_OUTPUT_TOKENS`, `AI_MODEL`, `BILLING_CALLBACK_URL`, `BILLING_MAX_SEATS`, `BILLING_MONTHLY_PRICE_PAISE`, `BILLING_YEARLY_PRICE_PAISE` + 26 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-76889df7c8e240c5", "name": "Unused endpoint: USE /api/", "shortDescription": {"text": "Unused endpoint: USE /api/"}, "fullDescription": {"text": "`src/server.js` declares `USE /api/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ed01f1141cc01775", "name": "Unused endpoint: USE /api/ml", "shortDescription": {"text": "Unused endpoint: USE /api/ml"}, "fullDescription": {"text": "`src/server.js` declares `USE /api/ml` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9a9e32807fd54937", "name": "Unused endpoint: USE /ml", "shortDescription": {"text": "Unused endpoint: USE /ml"}, "fullDescription": {"text": "`src/server.js` declares `USE /ml` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-931c868392c7d192", "name": "Unused endpoint: GET /api-docs.json", "shortDescription": {"text": "Unused endpoint: GET /api-docs.json"}, "fullDescription": {"text": "`src/server.js` declares `GET /api-docs.json` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6ad67c39ae34cae3", "name": "Unused endpoint: USE /api-docs", "shortDescription": {"text": "Unused endpoint: USE /api-docs"}, "fullDescription": {"text": "`src/server.js` declares `USE /api-docs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6dfb8881543293df", "name": "Unused endpoint: GET /api-docs", "shortDescription": {"text": "Unused endpoint: GET /api-docs"}, "fullDescription": {"text": "`src/server.js` declares `GET /api-docs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6eb452fbfb454d20", "name": "Unused endpoint: USE /api/auth", "shortDescription": {"text": "Unused endpoint: USE /api/auth"}, "fullDescription": {"text": "`src/server.js` declares `USE /api/auth` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4ff40cb10f7c8519", "name": "Unused endpoint: USE /api/users", "shortDescription": {"text": "Unused endpoint: USE /api/users"}, "fullDescription": {"text": "`src/server.js` declares `USE /api/users` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bb789cf847f59e24", "name": "Unused endpoint: USE /api/companies", "shortDescription": {"text": "Unused endpoint: USE /api/companies"}, "fullDescription": {"text": "`src/server.js` declares `USE /api/companies` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-04f16683a1468a25", "name": "Unused endpoint: USE /api/vouchers", "shortDescription": {"text": "Unused endpoint: USE /api/vouchers"}, "fullDescription": {"text": "`src/server.js` declares `USE /api/vouchers` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bab42d9ce9b7b7d4", "name": "Unused endpoint: USE /api/transactions", "shortDescription": {"text": "Unused endpoint: USE /api/transactions"}, "fullDescription": {"text": "`src/server.js` declares `USE /api/transactions` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-99725bd06fb56b62", "name": "Unused endpoint: USE /api/inventory", "shortDescription": {"text": "Unused endpoint: USE /api/inventory"}, "fullDescription": {"text": "`src/server.js` declares `USE /api/inventory` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-147d47af117855a7", "name": "Unused endpoint: USE /api/parties", "shortDescription": {"text": "Unused endpoint: USE /api/parties"}, "fullDescription": {"text": "`src/server.js` declares `USE /api/parties` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-571fc2ffa014e08c", "name": "Unused endpoint: USE /api/masters", "shortDescription": {"text": "Unused endpoint: USE /api/masters"}, "fullDescription": {"text": "`src/server.js` declares `USE /api/masters` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f8242ba07247d2f8", "name": "Unused endpoint: USE /api/payments", "shortDescription": {"text": "Unused endpoint: USE /api/payments"}, "fullDescription": {"text": "`src/server.js` declares `USE /api/payments` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aea1536787095782", "name": "Unused endpoint: USE /api/tally", "shortDescription": {"text": "Unused endpoint: USE /api/tally"}, "fullDescription": {"text": "`src/server.js` declares `USE /api/tally` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-009afc3e72d0787f", "name": "Unused endpoint: USE /api/devices", "shortDescription": {"text": "Unused endpoint: USE /api/devices"}, "fullDescription": {"text": "`src/server.js` declares `USE /api/devices` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-946dc627de4f272d", "name": "Unused endpoint: USE /api/billing", "shortDescription": {"text": "Unused endpoint: USE /api/billing"}, "fullDescription": {"text": "`src/server.js` declares `USE /api/billing` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-17e730ac6e56d070", "name": "Unused endpoint: USE /api/tally-serial", "shortDescription": {"text": "Unused endpoint: USE /api/tally-serial"}, "fullDescription": {"text": "`src/server.js` declares `USE /api/tally-serial` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-316c43db307befc3", "name": "Unused endpoint: USE /api/ai", "shortDescription": {"text": "Unused endpoint: USE /api/ai"}, "fullDescription": {"text": "`src/server.js` declares `USE /api/ai` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d93a530ce10d47d9", "name": "Unused endpoint: USE /api/admin", "shortDescription": {"text": "Unused endpoint: USE /api/admin"}, "fullDescription": {"text": "`src/server.js` declares `USE /api/admin` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1bc898b3b7565990", "name": "Unused endpoint: USE /uploads", "shortDescription": {"text": "Unused endpoint: USE /uploads"}, "fullDescription": {"text": "`src/server.js` declares `USE /uploads` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-69c9ac39e42dc830", "name": "Unused endpoint: GET /outstanding", "shortDescription": {"text": "Unused endpoint: GET /outstanding"}, "fullDescription": {"text": "`src/routes/parties.js` declares `GET /outstanding` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`src/routes/parties.js` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a009b1a56794f45", "name": "Unused endpoint: POST /", "shortDescription": {"text": "Unused endpoint: POST /"}, "fullDescription": {"text": "`src/routes/parties.js` declares `POST /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ca5756175765b49d", "name": "Unused endpoint: GET /:id", "shortDescription": {"text": "Unused endpoint: GET /:id"}, "fullDescription": {"text": "`src/routes/parties.js` declares `GET /:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8d5b2b188d08ca82", "name": "Unused endpoint: PUT /:id", "shortDescription": {"text": "Unused endpoint: PUT /:id"}, "fullDescription": {"text": "`src/routes/parties.js` declares `PUT /:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a61c112b611f4bb", "name": "Unused endpoint: DELETE /:id", "shortDescription": {"text": "Unused endpoint: DELETE /:id"}, "fullDescription": {"text": "`src/routes/parties.js` declares `DELETE /:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-63d4475f58176f51", "name": "Unused endpoint: GET /:id/balance", "shortDescription": {"text": "Unused endpoint: GET /:id/balance"}, "fullDescription": {"text": "`src/routes/parties.js` declares `GET /:id/balance` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ac2f552bf9d967ce", "name": "Unused endpoint: GET /overview", "shortDescription": {"text": "Unused endpoint: GET /overview"}, "fullDescription": {"text": "`src/routes/admin.js` declares `GET /overview` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a12d652045da70a", "name": "Unused endpoint: GET /organizations", "shortDescription": {"text": "Unused endpoint: GET /organizations"}, "fullDescription": {"text": "`src/routes/admin.js` declares `GET /organizations` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b82146d6b4056725", "name": "Unused endpoint: GET /organizations/:id", "shortDescription": {"text": "Unused endpoint: GET /organizations/:id"}, "fullDescription": {"text": "`src/routes/admin.js` declares `GET /organizations/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-86feb5c9b909e40e", "name": "Unused endpoint: PATCH /organizations/:id/subscription", "shortDescription": {"text": "Unused endpoint: PATCH /organizations/:id/subscription"}, "fullDescription": {"text": "`src/routes/admin.js` declares `PATCH /organizations/:id/subscription` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e8ebe817d16c5e42", "name": "Unused endpoint: GET /devices", "shortDescription": {"text": "Unused endpoint: GET /devices"}, "fullDescription": {"text": "`src/routes/admin.js` declares `GET /devices` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-522f79807f09023f", "name": "Unused endpoint: POST /devices/:agentId/transfer", "shortDescription": {"text": "Unused endpoint: POST /devices/:agentId/transfer"}, "fullDescription": {"text": "`src/routes/admin.js` declares `POST /devices/:agentId/transfer` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dd48b2c75f220753", "name": "Unused endpoint: DELETE /devices/:agentId", "shortDescription": {"text": "Unused endpoint: DELETE /devices/:agentId"}, "fullDescription": {"text": "`src/routes/admin.js` declares `DELETE /devices/:agentId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e1b7bee247ffc801", "name": "Unused endpoint: GET /summary", "shortDescription": {"text": "Unused endpoint: GET /summary"}, "fullDescription": {"text": "`src/routes/budgets.mjs` declares `GET /summary` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-256335142068eeef", "name": "Unused endpoint: POST /:id/spending", "shortDescription": {"text": "Unused endpoint: POST /:id/spending"}, "fullDescription": {"text": "`src/routes/budgets.mjs` declares `POST /:id/spending` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cff8da5fbc19c76d", "name": "Unused endpoint: POST /chat", "shortDescription": {"text": "Unused endpoint: POST /chat"}, "fullDescription": {"text": "`src/routes/ai.js` declares `POST /chat` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4991af097027200f", "name": "Unused endpoint: GET /voucher-types", "shortDescription": {"text": "Unused endpoint: GET /voucher-types"}, "fullDescription": {"text": "`src/routes/masters.js` declares `GET /voucher-types` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8b68a9ee9e2d9557", "name": "Unused endpoint: GET /godowns", "shortDescription": {"text": "Unused endpoint: GET /godowns"}, "fullDescription": {"text": "`src/routes/masters.js` declares `GET /godowns` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c502418535ee4f4f", "name": "Unused endpoint: GET /units", "shortDescription": {"text": "Unused endpoint: GET /units"}, "fullDescription": {"text": "`src/routes/masters.js` declares `GET /units` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-09e922276d2f74a6", "name": "Unused endpoint: GET /account-ledgers", "shortDescription": {"text": "Unused endpoint: GET /account-ledgers"}, "fullDescription": {"text": "`src/routes/masters.js` declares `GET /account-ledgers` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c73e300438921537", "name": "Unused endpoint: GET /ledgers", "shortDescription": {"text": "Unused endpoint: GET /ledgers"}, "fullDescription": {"text": "`src/routes/masters.js` declares `GET /ledgers` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c6e73567f160646e", "name": "Unused endpoint: GET /gst-registrations", "shortDescription": {"text": "Unused endpoint: GET /gst-registrations"}, "fullDescription": {"text": "`src/routes/masters.js` declares `GET /gst-registrations` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2f222a275ed687b3", "name": "Unused endpoint: POST /send", "shortDescription": {"text": "Unused endpoint: POST /send"}, "fullDescription": {"text": "`src/routes/emails.js` declares `POST /send` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9e19849ce888ceda", "name": "Unused endpoint: POST /invoice-notification", "shortDescription": {"text": "Unused endpoint: POST /invoice-notification"}, "fullDescription": {"text": "`src/routes/emails.js` declares `POST /invoice-notification` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ba865afdcc7ee0f4", "name": "Unused endpoint: POST /payment-reminder", "shortDescription": {"text": "Unused endpoint: POST /payment-reminder"}, "fullDescription": {"text": "`src/routes/emails.js` declares `POST /payment-reminder` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f754589d199d0560", "name": "Unused endpoint: POST /bulk-payment-reminders", "shortDescription": {"text": "Unused endpoint: POST /bulk-payment-reminders"}, "fullDescription": {"text": "`src/routes/emails.js` declares `POST /bulk-payment-reminders` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5dcca22cf53507de", "name": "Unused endpoint: GET /preview/:template", "shortDescription": {"text": "Unused endpoint: GET /preview/:template"}, "fullDescription": {"text": "`src/routes/emails.js` declares `GET /preview/:template` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/18218"}, "properties": {"repository": "RizwanKharadi/Backend", "repoUrl": "https://github.com/RizwanKharadi/Backend", "branch": "main"}, "results": [{"ruleId": "scanner-8b6b7e6a2ca79364", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 test-endpoints.js:79"}, "properties": {"repobilityId": "4b2570718a10a4c7", "scanner": "scanner-primary", "fingerprint": "8b6b7e6a2ca79364", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0b364b137ab9b1b0", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 test-swagger-endpoint.js:5"}, "properties": {"repobilityId": "18948bbb722f2088", "scanner": "scanner-primary", "fingerprint": "0b364b137ab9b1b0", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-aa372a40d58f685d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 healthcheck.js:11"}, "properties": {"repobilityId": "291a6d2823dcd8c7", "scanner": "scanner-primary", "fingerprint": "aa372a40d58f685d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-09114618a3dc38c4", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 test-all-endpoints.js:77"}, "properties": {"repobilityId": "0d5ef705544fc648", "scanner": "scanner-primary", "fingerprint": "09114618a3dc38c4", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-552def99ab26e334", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/run-ml-tests.js:29"}, "properties": {"repobilityId": "c77e086d6607136f", "scanner": "scanner-primary", "fingerprint": "552def99ab26e334", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d03506d2fb852d6b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/generateApiDocs.js:16"}, "properties": {"repobilityId": "0f9492bc24150bf9", "scanner": "scanner-primary", "fingerprint": "d03506d2fb852d6b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b15363dd9547e36b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/ml-service-coverage.test.js:18"}, "properties": {"repobilityId": "97799c10cab9ccaf", "scanner": "scanner-primary", "fingerprint": "b15363dd9547e36b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-136ca7725aa2d40c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/start-ml-service.js:22"}, "properties": {"repobilityId": "18df04e92ecd8a2a", "scanner": "scanner-primary", "fingerprint": "136ca7725aa2d40c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-02c77983ec3d73ea", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/ml-service-simple.test.js:18"}, "properties": {"repobilityId": "5a9f1bd2b5a1a59c", "scanner": "scanner-primary", "fingerprint": "02c77983ec3d73ea", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-359b30ac86b8b552", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/runAllTests.js:31"}, "properties": {"repobilityId": "fa9476316d79c543", "scanner": "scanner-primary", "fingerprint": "359b30ac86b8b552", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-441b7a765cea73ef", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/ml-service.test.js:24"}, "properties": {"repobilityId": "af87c3359ae03c58", "scanner": "scanner-primary", "fingerprint": "441b7a765cea73ef", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-54c9ae26e0b78fe1", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/ml-service-integration.test.js:24"}, "properties": {"repobilityId": "728a9b3741b4d0e4", "scanner": "scanner-primary", "fingerprint": "54c9ae26e0b78fe1", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b8a58d9ef4afa2ee", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/performanceBenchmark.js:21"}, "properties": {"repobilityId": "55c34f5bcba561d1", "scanner": "scanner-primary", "fingerprint": "b8a58d9ef4afa2ee", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d3921d714cc21a57", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/runTests.js:23"}, "properties": {"repobilityId": "9a163a9030ef865b", "scanner": "scanner-primary", "fingerprint": "d3921d714cc21a57", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3e354e764b31d864", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/helpers/mockMLService.js:190"}, "properties": {"repobilityId": "bf00e465a5c26a59", "scanner": "scanner-primary", "fingerprint": "3e354e764b31d864", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-624cbad840e4792b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/helpers/mlServiceHelper.js:41"}, "properties": {"repobilityId": "9337afd48bd9bd3e", "scanner": "scanner-primary", "fingerprint": "624cbad840e4792b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e040dd9eaba902b0", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/create-demo-users.js:70"}, "properties": {"repobilityId": "ebc83cdd78a82bd1", "scanner": "scanner-primary", "fingerprint": "e040dd9eaba902b0", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2fc5f3a6646669e2", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/verify-endpoints.js:19"}, "properties": {"repobilityId": "0f0fedad2a4e6f9e", "scanner": "scanner-primary", "fingerprint": "2fc5f3a6646669e2", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-61628df9b950ca3c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/create-demo-data.js:213"}, "properties": {"repobilityId": "65db389dc0cb4e17", "scanner": "scanner-primary", "fingerprint": "61628df9b950ca3c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-17e6c1f5143dad72", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/verify-bulk-voucher-sync.js:21"}, "properties": {"repobilityId": "564506c25d923ed7", "scanner": "scanner-primary", "fingerprint": "17e6c1f5143dad72", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-41a3d0cd3a49a023", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/create-single-admin.js:11"}, "properties": {"repobilityId": "e9c96b82b7c7bb5f", "scanner": "scanner-primary", "fingerprint": "41a3d0cd3a49a023", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-41a1c89969e7b190", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/voucher-detail-cleanup.js:19"}, "properties": {"repobilityId": "8a8a86f9f3c976b6", "scanner": "scanner-primary", "fingerprint": "41a1c89969e7b190", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ac0bc88d520b4838", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-swagger.js:3"}, "properties": {"repobilityId": "71f34b841663a3d8", "scanner": "scanner-primary", "fingerprint": "ac0bc88d520b4838", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-da6ee9fb2da421fe", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/verifyTallyIntegration.js:18"}, "properties": {"repobilityId": "37cff0b4bb4d4223", "scanner": "scanner-primary", "fingerprint": "da6ee9fb2da421fe", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-75696cc2c92dcb29", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/demo-disable-licensing.js:35"}, "properties": {"repobilityId": "4d9f4665c6bf7ea5", "scanner": "scanner-primary", "fingerprint": "75696cc2c92dcb29", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-bc529cd608607312", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/verify-licensing-bypass.js:36"}, "properties": {"repobilityId": "89c3cd364fe6a97b", "scanner": "scanner-primary", "fingerprint": "bc529cd608607312", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0d1c9e1ace17115c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/create-admin-users.js:12"}, "properties": {"repobilityId": "60846b01d01253de", "scanner": "scanner-primary", "fingerprint": "0d1c9e1ace17115c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-cf7cf0309496dac2", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/clear-tally-data.js:9"}, "properties": {"repobilityId": "8a63dfa058714c98", "scanner": "scanner-primary", "fingerprint": "cf7cf0309496dac2", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3115b73acdd2eb16", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/create-demo-user.js:15"}, "properties": {"repobilityId": "eb3a8b55e68293c5", "scanner": "scanner-primary", "fingerprint": "3115b73acdd2eb16", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7c14c6634a8851b6", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 src/controllers/paymentController.js:112"}, "properties": {"repobilityId": "5098c1880f5de4e4", "scanner": "scanner-primary", "fingerprint": "7c14c6634a8851b6", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-52819ee63aed81f5", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 src/services/paymentService.js:281"}, "properties": {"repobilityId": "db0ab65e8fba05d1", "scanner": "scanner-primary", "fingerprint": "52819ee63aed81f5", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-b0a79fba1e13fb60", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 src/services/tallyCommunicationService.js:467"}, "properties": {"repobilityId": "8316ba49603cfb54", "scanner": "scanner-primary", "fingerprint": "b0a79fba1e13fb60", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-91434f4ca7fb998c", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 src/services/tallySyncService.js:518"}, "properties": {"repobilityId": "a8bae43288c12226", "scanner": "scanner-primary", "fingerprint": "91434f4ca7fb998c", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-2dd0454eae927d4c", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 src/services/tallyWebSocketService.js:3369"}, "properties": {"repobilityId": "5a537c069b16314a", "scanner": "scanner-primary", "fingerprint": "2dd0454eae927d4c", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-fddc1267b35d0c7b", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:18-alpine"}, "properties": {"repobilityId": "b99821d798b46f3b", "scanner": "scanner-primary", "fingerprint": "fddc1267b35d0c7b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-d9af6fa8b065efd9", "level": "error", "message": {"text": "Possible secret in test-all-endpoints.js"}, "properties": {"repobilityId": "2c82471339566817", "scanner": "scanner-primary", "fingerprint": "d9af6fa8b065efd9", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "test-all-endpoints.js"}, "region": {"startLine": 127}}}]}, {"ruleId": "scanner-33b2f8da807fa106", "level": "error", "message": {"text": "Possible secret in scripts/create-demo-users.js"}, "properties": {"repobilityId": "f17d50bb21557cbe", "scanner": "scanner-primary", "fingerprint": "33b2f8da807fa106", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/create-demo-users.js"}, "region": {"startLine": 11}}}]}, {"ruleId": "scanner-33b2f8da807fa106", "level": "error", "message": {"text": "Possible secret in scripts/create-demo-users.js"}, "properties": {"repobilityId": "f17d50bb21557cbe", "scanner": "scanner-primary", "fingerprint": "33b2f8da807fa106", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/create-demo-users.js"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-33b2f8da807fa106", "level": "error", "message": {"text": "Possible secret in scripts/create-demo-users.js"}, "properties": {"repobilityId": "f17d50bb21557cbe", "scanner": "scanner-primary", "fingerprint": "33b2f8da807fa106", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/create-demo-users.js"}, "region": {"startLine": 37}}}]}, {"ruleId": "scanner-33b2f8da807fa106", "level": "error", "message": {"text": "Possible secret in scripts/create-demo-users.js"}, "properties": {"repobilityId": "f17d50bb21557cbe", "scanner": "scanner-primary", "fingerprint": "33b2f8da807fa106", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/create-demo-users.js"}, "region": {"startLine": 50}}}]}, {"ruleId": "scanner-60ee194167fc5501", "level": "error", "message": {"text": "Possible secret in scripts/create-single-admin.js"}, "properties": {"repobilityId": "b491871ed713f496", "scanner": "scanner-primary", "fingerprint": "60ee194167fc5501", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/create-single-admin.js"}, "region": {"startLine": 39}}}]}, {"ruleId": "scanner-60ee194167fc5501", "level": "error", "message": {"text": "Possible secret in scripts/create-single-admin.js"}, "properties": {"repobilityId": "b491871ed713f496", "scanner": "scanner-primary", "fingerprint": "60ee194167fc5501", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/create-single-admin.js"}, "region": {"startLine": 52}}}]}, {"ruleId": "scanner-9f98d81fbacdf84c", "level": "error", "message": {"text": "Possible secret in scripts/create-admin-users.js"}, "properties": {"repobilityId": "ff205ae078f415a9", "scanner": "scanner-primary", "fingerprint": "9f98d81fbacdf84c", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/create-admin-users.js"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-9f98d81fbacdf84c", "level": "error", "message": {"text": "Possible secret in scripts/create-admin-users.js"}, "properties": {"repobilityId": "ff205ae078f415a9", "scanner": "scanner-primary", "fingerprint": "9f98d81fbacdf84c", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/create-admin-users.js"}, "region": {"startLine": 40}}}]}, {"ruleId": "scanner-9f98d81fbacdf84c", "level": "error", "message": {"text": "Possible secret in scripts/create-admin-users.js"}, "properties": {"repobilityId": "ff205ae078f415a9", "scanner": "scanner-primary", "fingerprint": "9f98d81fbacdf84c", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/create-admin-users.js"}, "region": {"startLine": 55}}}]}, {"ruleId": "scanner-9f98d81fbacdf84c", "level": "error", "message": {"text": "Possible secret in scripts/create-admin-users.js"}, "properties": {"repobilityId": "ff205ae078f415a9", "scanner": "scanner-primary", "fingerprint": "9f98d81fbacdf84c", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/create-admin-users.js"}, "region": {"startLine": 73}}}]}, {"ruleId": "scanner-9f98d81fbacdf84c", "level": "error", "message": {"text": "Possible secret in scripts/create-admin-users.js"}, "properties": {"repobilityId": "ff205ae078f415a9", "scanner": "scanner-primary", "fingerprint": "9f98d81fbacdf84c", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/create-admin-users.js"}, "region": {"startLine": 88}}}]}, {"ruleId": "scanner-9f98d81fbacdf84c", "level": "error", "message": {"text": "Possible secret in scripts/create-admin-users.js"}, "properties": {"repobilityId": "ff205ae078f415a9", "scanner": "scanner-primary", "fingerprint": "9f98d81fbacdf84c", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/create-admin-users.js"}, "region": {"startLine": 103}}}]}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-90e7cf6f65364a93", "level": "note", "message": {"text": "Very large file: src/controllers/reportController.mjs (2491 lines)"}, "properties": {"repobilityId": "c24ca72517d51ec0", "scanner": "scanner-primary", "fingerprint": "90e7cf6f65364a93", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-05754a2d7def8d18", "level": "note", "message": {"text": "Very large file: src/services/tallyWebSocketService.js (3566 lines)"}, "properties": {"repobilityId": "e22250512faa9846", "scanner": "scanner-primary", "fingerprint": "05754a2d7def8d18", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-b3ed68815bca2f8c", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: package.json"}, "properties": {"repobilityId": "7edae0550c126386", "scanner": "scanner-primary", "fingerprint": "b3ed68815bca2f8c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "506e5cb59857908a", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "c38ecdb5438d4227", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "b751d747971559f4", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "32397e48b0b5775d", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "1d13e4a1b2bbf0b0", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "a3a85aac3c055b21", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-89900dd149bd935f", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/subscriptionBillingService.js:618"}, "properties": {"repobilityId": "8e6c21edeb347ab7", "scanner": "scanner-primary", "fingerprint": "89900dd149bd935f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-64bc033a45ab26f1", "level": "note", "message": {"text": "34 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "dab9f6f977f9c414", "scanner": "scanner-primary", "fingerprint": "64bc033a45ab26f1", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-76889df7c8e240c5", "level": "note", "message": {"text": "Unused endpoint: USE /api/"}, "properties": {"repobilityId": "2d1ceb837732a2da", "scanner": "scanner-primary", "fingerprint": "76889df7c8e240c5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ed01f1141cc01775", "level": "note", "message": {"text": "Unused endpoint: USE /api/ml"}, "properties": {"repobilityId": "6295211fa19febfa", "scanner": "scanner-primary", "fingerprint": "ed01f1141cc01775", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9a9e32807fd54937", "level": "note", "message": {"text": "Unused endpoint: USE /ml"}, "properties": {"repobilityId": "40ae3dc41142f554", "scanner": "scanner-primary", "fingerprint": "9a9e32807fd54937", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-931c868392c7d192", "level": "note", "message": {"text": "Unused endpoint: GET /api-docs.json"}, "properties": {"repobilityId": "c190f81ac2d6b784", "scanner": "scanner-primary", "fingerprint": "931c868392c7d192", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6ad67c39ae34cae3", "level": "note", "message": {"text": "Unused endpoint: USE /api-docs"}, "properties": {"repobilityId": "b8efc53d191420e2", "scanner": "scanner-primary", "fingerprint": "6ad67c39ae34cae3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6dfb8881543293df", "level": "note", "message": {"text": "Unused endpoint: GET /api-docs"}, "properties": {"repobilityId": "844595978e08d257", "scanner": "scanner-primary", "fingerprint": "6dfb8881543293df", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6eb452fbfb454d20", "level": "note", "message": {"text": "Unused endpoint: USE /api/auth"}, "properties": {"repobilityId": "0ecb946d42c7b0e6", "scanner": "scanner-primary", "fingerprint": "6eb452fbfb454d20", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4ff40cb10f7c8519", "level": "note", "message": {"text": "Unused endpoint: USE /api/users"}, "properties": {"repobilityId": "f0cb4c77e70295ab", "scanner": "scanner-primary", "fingerprint": "4ff40cb10f7c8519", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bb789cf847f59e24", "level": "note", "message": {"text": "Unused endpoint: USE /api/companies"}, "properties": {"repobilityId": "e525b0fadd18689e", "scanner": "scanner-primary", "fingerprint": "bb789cf847f59e24", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-04f16683a1468a25", "level": "note", "message": {"text": "Unused endpoint: USE /api/vouchers"}, "properties": {"repobilityId": "a8de73c99b720161", "scanner": "scanner-primary", "fingerprint": "04f16683a1468a25", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bab42d9ce9b7b7d4", "level": "note", "message": {"text": "Unused endpoint: USE /api/transactions"}, "properties": {"repobilityId": "c7460169a8bbf569", "scanner": "scanner-primary", "fingerprint": "bab42d9ce9b7b7d4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-99725bd06fb56b62", "level": "note", "message": {"text": "Unused endpoint: USE /api/inventory"}, "properties": {"repobilityId": "4376636c21ce0456", "scanner": "scanner-primary", "fingerprint": "99725bd06fb56b62", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-147d47af117855a7", "level": "note", "message": {"text": "Unused endpoint: USE /api/parties"}, "properties": {"repobilityId": "a89996cc2ded2349", "scanner": "scanner-primary", "fingerprint": "147d47af117855a7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-571fc2ffa014e08c", "level": "note", "message": {"text": "Unused endpoint: USE /api/masters"}, "properties": {"repobilityId": "74eef7126653b7d6", "scanner": "scanner-primary", "fingerprint": "571fc2ffa014e08c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f8242ba07247d2f8", "level": "note", "message": {"text": "Unused endpoint: USE /api/payments"}, "properties": {"repobilityId": "f9dcb5a0cfebee38", "scanner": "scanner-primary", "fingerprint": "f8242ba07247d2f8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-aea1536787095782", "level": "note", "message": {"text": "Unused endpoint: USE /api/tally"}, "properties": {"repobilityId": "3ebb998e87dba34f", "scanner": "scanner-primary", "fingerprint": "aea1536787095782", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-009afc3e72d0787f", "level": "note", "message": {"text": "Unused endpoint: USE /api/devices"}, "properties": {"repobilityId": "a1b5eb1f4ffa3ddd", "scanner": "scanner-primary", "fingerprint": "009afc3e72d0787f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-946dc627de4f272d", "level": "note", "message": {"text": "Unused endpoint: USE /api/billing"}, "properties": {"repobilityId": "3671c795692786c7", "scanner": "scanner-primary", "fingerprint": "946dc627de4f272d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-17e730ac6e56d070", "level": "note", "message": {"text": "Unused endpoint: USE /api/tally-serial"}, "properties": {"repobilityId": "0ae3f4459fa07714", "scanner": "scanner-primary", "fingerprint": "17e730ac6e56d070", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-316c43db307befc3", "level": "note", "message": {"text": "Unused endpoint: USE /api/ai"}, "properties": {"repobilityId": "7489fbd81765c035", "scanner": "scanner-primary", "fingerprint": "316c43db307befc3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d93a530ce10d47d9", "level": "note", "message": {"text": "Unused endpoint: USE /api/admin"}, "properties": {"repobilityId": "889dc22765f92212", "scanner": "scanner-primary", "fingerprint": "d93a530ce10d47d9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1bc898b3b7565990", "level": "note", "message": {"text": "Unused endpoint: USE /uploads"}, "properties": {"repobilityId": "5b284dad46e8a872", "scanner": "scanner-primary", "fingerprint": "1bc898b3b7565990", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-69c9ac39e42dc830", "level": "note", "message": {"text": "Unused endpoint: GET /outstanding"}, "properties": {"repobilityId": "648640fbb285d580", "scanner": "scanner-primary", "fingerprint": "69c9ac39e42dc830", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "95f85a287a286f1e", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a009b1a56794f45", "level": "note", "message": {"text": "Unused endpoint: POST /"}, "properties": {"repobilityId": "f0721d19a7e952ba", "scanner": "scanner-primary", "fingerprint": "7a009b1a56794f45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ca5756175765b49d", "level": "note", "message": {"text": "Unused endpoint: GET /:id"}, "properties": {"repobilityId": "f9deb2cc17998170", "scanner": "scanner-primary", "fingerprint": "ca5756175765b49d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8d5b2b188d08ca82", "level": "note", "message": {"text": "Unused endpoint: PUT /:id"}, "properties": {"repobilityId": "a429f8748b7214ea", "scanner": "scanner-primary", "fingerprint": "8d5b2b188d08ca82", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a61c112b611f4bb", "level": "note", "message": {"text": "Unused endpoint: DELETE /:id"}, "properties": {"repobilityId": "d616346e766aa17d", "scanner": "scanner-primary", "fingerprint": "7a61c112b611f4bb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-63d4475f58176f51", "level": "note", "message": {"text": "Unused endpoint: GET /:id/balance"}, "properties": {"repobilityId": "ba4cd8ddb5daeb20", "scanner": "scanner-primary", "fingerprint": "63d4475f58176f51", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ac2f552bf9d967ce", "level": "note", "message": {"text": "Unused endpoint: GET /overview"}, "properties": {"repobilityId": "b54fc06b3297f176", "scanner": "scanner-primary", "fingerprint": "ac2f552bf9d967ce", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a12d652045da70a", "level": "note", "message": {"text": "Unused endpoint: GET /organizations"}, "properties": {"repobilityId": "93447d42e475491a", "scanner": "scanner-primary", "fingerprint": "7a12d652045da70a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b82146d6b4056725", "level": "note", "message": {"text": "Unused endpoint: GET /organizations/:id"}, "properties": {"repobilityId": "89946f0b58d14a86", "scanner": "scanner-primary", "fingerprint": "b82146d6b4056725", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-86feb5c9b909e40e", "level": "note", "message": {"text": "Unused endpoint: PATCH /organizations/:id/subscription"}, "properties": {"repobilityId": "fcd0ce3e40b3d3ef", "scanner": "scanner-primary", "fingerprint": "86feb5c9b909e40e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e8ebe817d16c5e42", "level": "note", "message": {"text": "Unused endpoint: GET /devices"}, "properties": {"repobilityId": "de5f1af29da7c524", "scanner": "scanner-primary", "fingerprint": "e8ebe817d16c5e42", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-522f79807f09023f", "level": "note", "message": {"text": "Unused endpoint: POST /devices/:agentId/transfer"}, "properties": {"repobilityId": "c5fdbfc74c38974d", "scanner": "scanner-primary", "fingerprint": "522f79807f09023f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dd48b2c75f220753", "level": "note", "message": {"text": "Unused endpoint: DELETE /devices/:agentId"}, "properties": {"repobilityId": "4a5a5c4002bff76b", "scanner": "scanner-primary", "fingerprint": "dd48b2c75f220753", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e1b7bee247ffc801", "level": "note", "message": {"text": "Unused endpoint: GET /summary"}, "properties": {"repobilityId": "1fd3a570d4567502", "scanner": "scanner-primary", "fingerprint": "e1b7bee247ffc801", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-256335142068eeef", "level": "note", "message": {"text": "Unused endpoint: POST /:id/spending"}, "properties": {"repobilityId": "9b1b0a7ed50e707e", "scanner": "scanner-primary", "fingerprint": "256335142068eeef", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cff8da5fbc19c76d", "level": "note", "message": {"text": "Unused endpoint: POST /chat"}, "properties": {"repobilityId": "471edfee50fa7794", "scanner": "scanner-primary", "fingerprint": "cff8da5fbc19c76d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4991af097027200f", "level": "note", "message": {"text": "Unused endpoint: GET /voucher-types"}, "properties": {"repobilityId": "97faf4498126d2a5", "scanner": "scanner-primary", "fingerprint": "4991af097027200f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8b68a9ee9e2d9557", "level": "note", "message": {"text": "Unused endpoint: GET /godowns"}, "properties": {"repobilityId": "b94c133954643aa6", "scanner": "scanner-primary", "fingerprint": "8b68a9ee9e2d9557", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c502418535ee4f4f", "level": "note", "message": {"text": "Unused endpoint: GET /units"}, "properties": {"repobilityId": "507098d46b88ab38", "scanner": "scanner-primary", "fingerprint": "c502418535ee4f4f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-09e922276d2f74a6", "level": "note", "message": {"text": "Unused endpoint: GET /account-ledgers"}, "properties": {"repobilityId": "eab515ecb64a2975", "scanner": "scanner-primary", "fingerprint": "09e922276d2f74a6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c73e300438921537", "level": "note", "message": {"text": "Unused endpoint: GET /ledgers"}, "properties": {"repobilityId": "11622e8284b04d07", "scanner": "scanner-primary", "fingerprint": "c73e300438921537", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c6e73567f160646e", "level": "note", "message": {"text": "Unused endpoint: GET /gst-registrations"}, "properties": {"repobilityId": "23e4548a0871c6aa", "scanner": "scanner-primary", "fingerprint": "c6e73567f160646e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2f222a275ed687b3", "level": "note", "message": {"text": "Unused endpoint: POST /send"}, "properties": {"repobilityId": "e61e74496ad01235", "scanner": "scanner-primary", "fingerprint": "2f222a275ed687b3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9e19849ce888ceda", "level": "note", "message": {"text": "Unused endpoint: POST /invoice-notification"}, "properties": {"repobilityId": "b88c2f506228136a", "scanner": "scanner-primary", "fingerprint": "9e19849ce888ceda", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ba865afdcc7ee0f4", "level": "note", "message": {"text": "Unused endpoint: POST /payment-reminder"}, "properties": {"repobilityId": "219b12561d11251a", "scanner": "scanner-primary", "fingerprint": "ba865afdcc7ee0f4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f754589d199d0560", "level": "note", "message": {"text": "Unused endpoint: POST /bulk-payment-reminders"}, "properties": {"repobilityId": "5f5d136f5e515fd7", "scanner": "scanner-primary", "fingerprint": "f754589d199d0560", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5dcca22cf53507de", "level": "note", "message": {"text": "Unused endpoint: GET /preview/:template"}, "properties": {"repobilityId": "4bca48a38baa3f01", "scanner": "scanner-primary", "fingerprint": "5dcca22cf53507de", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}