{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-6f1229f1e63f4fb8", "name": "Stray `console.log` in TS/JS \u2014 server.js:209", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 server.js:209"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d951ed3a4cb6aa3", "name": "Stray `console.log` in TS/JS \u2014 scripts/generate-all-files.js:47", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/generate-all-files.js:47"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-339a890101ec2b45", "name": "Stray `console.log` in TS/JS \u2014 public/js/app.js:36", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 public/js/app.js:36"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-74a12a2bf62eb799", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/js/simulator-three.js:101", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/js/simulator-three.js:101"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8f3221bde38030ab", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/js/ui-controls.js:157", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/js/ui-controls.js:157"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6d264afd1f9c24f0", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/js/tools-dock.js:18", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/js/tools-dock.js:18"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c7ecbeaeb0872eb7", "name": "Insecure pattern 'document_write' in public/js/app.js:404", "shortDescription": {"text": "Insecure pattern 'document_write' in public/js/app.js:404"}, "fullDescription": {"text": "Found a known-risky pattern (document_write). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-759089c95dbf4626", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/js/app.js:479", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/js/app.js:479"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9675f4f83ffec9db", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/js/machine-control.js:228", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/js/machine-control.js:228"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-19993f83a5ef4364", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/js/gcode-preview.js:23", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/js/gcode-preview.js:23"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0cdb9e1aea22b2b3", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/js/tools-rail-flyout.js:23", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/js/tools-rail-flyout.js:23"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1c197bcdce342cd2", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/js/supabase-auth.js:79", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/js/supabase-auth.js:79"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3ce68fda6a535a71", "name": "Very large file: public/js/tools-extra.js (1023 lines)", "shortDescription": {"text": "Very large file: public/js/tools-extra.js (1023 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "5 test file(s) for 78 source file(s) (ratio 0.06). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 25 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9d79c4077342a7d0", "name": "Runtime service client appears to use placeholder configuration", "shortDescription": {"text": "Runtime service client appears to use placeholder configuration"}, "fullDescription": {"text": "A runtime source file appears to wire Supabase/Firebase/AI/payment-style clients to placeholder URLs, keys, or fallback values. In the Fable corpus this often means the UI/API shape is present while the backend service is not actually configured."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-fa5f832e6ba669c1", "name": "`fetch()` without try/.catch or AbortSignal \u2014 public/sw.js:104", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/sw.js:104"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ba28d0093c5170ff", "name": "`fetch()` without try/.catch or AbortSignal \u2014 public/js/file-importer.js:75", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/js/file-importer.js:75"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d4f7e6968894bf24", "name": "`fetch()` without try/.catch or AbortSignal \u2014 public/js/app.js:504", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/js/app.js:504"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a05112e8911c8b61", "name": "`fetch()` without try/.catch or AbortSignal \u2014 public/js/machine-control.js:166", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/js/machine-control.js:166"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-965c4a608e63d175", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/payments/providers.js:105", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/payments/providers.js:105"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cffe7e300e9cb20a", "name": "Legacy-named symbol `clearOld` in src/core/Analytics.js:97", "shortDescription": {"text": "Legacy-named symbol `clearOld` in src/core/Analytics.js:97"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3482f7e5dd70cd1a", "name": "6 env vars used in code but missing from .env.example", "shortDescription": {"text": "6 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `CI`, `RAILWAY_ENVIRONMENT`, `SITE_URL`, `SUPABASE_SERVICE_KEY`, `SUPABASE_SERVICE_ROLE_KEY`, `VERCEL`. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a673804131ddd27d", "name": "Unused endpoint: USE /shared", "shortDescription": {"text": "Unused endpoint: USE /shared"}, "fullDescription": {"text": "`server.js` declares `USE /shared` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dde3adb27bf7eebe", "name": "Unused endpoint: USE /api", "shortDescription": {"text": "Unused endpoint: USE /api"}, "fullDescription": {"text": "`server.js` declares `USE /api` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`server.js` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b9d4602aa46abe88", "name": "Unused endpoint: GET /auth", "shortDescription": {"text": "Unused endpoint: GET /auth"}, "fullDescription": {"text": "`server.js` declares `GET /auth` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-769398a8a95bd693", "name": "Unused endpoint: GET /app", "shortDescription": {"text": "Unused endpoint: GET /app"}, "fullDescription": {"text": "`server.js` declares `GET /app` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6fade9d72cd7b1df", "name": "Unused endpoint: POST /api/export", "shortDescription": {"text": "Unused endpoint: POST /api/export"}, "fullDescription": {"text": "`server.js` declares `POST /api/export` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aee2aa7b8ec56e42", "name": "Unused endpoint: POST /api/postprocess", "shortDescription": {"text": "Unused endpoint: POST /api/postprocess"}, "fullDescription": {"text": "`server.js` declares `POST /api/postprocess` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ddcb2124cc97aa90", "name": "Unused endpoint: GET /api/tools/:id/speeds/:material", "shortDescription": {"text": "Unused endpoint: GET /api/tools/:id/speeds/:material"}, "fullDescription": {"text": "`server.js` declares `GET /api/tools/:id/speeds/:material` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c93fe63321eefc5d", "name": "Unused endpoint: POST /api/queue/enqueue", "shortDescription": {"text": "Unused endpoint: POST /api/queue/enqueue"}, "fullDescription": {"text": "`server.js` declares `POST /api/queue/enqueue` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ef75da8c58c853e0", "name": "Unused endpoint: DELETE /api/queue/:id", "shortDescription": {"text": "Unused endpoint: DELETE /api/queue/:id"}, "fullDescription": {"text": "`server.js` declares `DELETE /api/queue/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3c5750dfa4b3af21", "name": "Unused endpoint: POST /api/queue/start", "shortDescription": {"text": "Unused endpoint: POST /api/queue/start"}, "fullDescription": {"text": "`server.js` declares `POST /api/queue/start` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-952bab24240402ce", "name": "Unused endpoint: POST /api/queue/stop", "shortDescription": {"text": "Unused endpoint: POST /api/queue/stop"}, "fullDescription": {"text": "`server.js` declares `POST /api/queue/stop` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8ae717e3316dc522", "name": "Unused endpoint: POST /api/queue/clear", "shortDescription": {"text": "Unused endpoint: POST /api/queue/clear"}, "fullDescription": {"text": "`server.js` declares `POST /api/queue/clear` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b5461c3c4afda997", "name": "Unused endpoint: GET /api/queue/status", "shortDescription": {"text": "Unused endpoint: GET /api/queue/status"}, "fullDescription": {"text": "`server.js` declares `GET /api/queue/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aee9d82ab3ed4634", "name": "Unused endpoint: POST /api/cost/estimate", "shortDescription": {"text": "Unused endpoint: POST /api/cost/estimate"}, "fullDescription": {"text": "`server.js` declares `POST /api/cost/estimate` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-43097970bc86e477", "name": "Unused endpoint: POST /api/cost/quote", "shortDescription": {"text": "Unused endpoint: POST /api/cost/quote"}, "fullDescription": {"text": "`server.js` declares `POST /api/cost/quote` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9038f398d3a7b0af", "name": "Unused endpoint: PUT /api/cost/rates", "shortDescription": {"text": "Unused endpoint: PUT /api/cost/rates"}, "fullDescription": {"text": "`server.js` declares `PUT /api/cost/rates` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-885de0fa0133f6c0", "name": "Unused endpoint: GET /api/plans", "shortDescription": {"text": "Unused endpoint: GET /api/plans"}, "fullDescription": {"text": "`server.js` declares `GET /api/plans` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-92440a113179a7ef", "name": "Unused endpoint: POST /api/payments/callback/fib", "shortDescription": {"text": "Unused endpoint: POST /api/payments/callback/fib"}, "fullDescription": {"text": "`server.js` declares `POST /api/payments/callback/fib` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-73fbb78b2c236626", "name": "Unused endpoint: ALL /api/payments/callback/card", "shortDescription": {"text": "Unused endpoint: ALL /api/payments/callback/card"}, "fullDescription": {"text": "`server.js` declares `ALL /api/payments/callback/card` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d0332882540c8b83", "name": "Unused endpoint: GET /api/subscription/:userId", "shortDescription": {"text": "Unused endpoint: GET /api/subscription/:userId"}, "fullDescription": {"text": "`server.js` declares `GET /api/subscription/:userId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-22d5d00d58a706ac", "name": "Unused endpoint: POST /api/subscription/:userId", "shortDescription": {"text": "Unused endpoint: POST /api/subscription/:userId"}, "fullDescription": {"text": "`server.js` declares `POST /api/subscription/:userId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd6b553aa765ddc0", "name": "Unused endpoint: POST /api/batch/process", "shortDescription": {"text": "Unused endpoint: POST /api/batch/process"}, "fullDescription": {"text": "`server.js` declares `POST /api/batch/process` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b9afe02da6381b95", "name": "Unused endpoint: GET /api/monitor/health", "shortDescription": {"text": "Unused endpoint: GET /api/monitor/health"}, "fullDescription": {"text": "`server.js` declares `GET /api/monitor/health` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3e06bfbfe68f6021", "name": "Unused endpoint: POST /api/monitor/reset", "shortDescription": {"text": "Unused endpoint: POST /api/monitor/reset"}, "fullDescription": {"text": "`server.js` declares `POST /api/monitor/reset` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b499aa0db7c751dd", "name": "Unused endpoint: GET /api/templates", "shortDescription": {"text": "Unused endpoint: GET /api/templates"}, "fullDescription": {"text": "`server.js` declares `GET /api/templates` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d907f175af50ca72", "name": "Unused endpoint: POST /api/templates", "shortDescription": {"text": "Unused endpoint: POST /api/templates"}, "fullDescription": {"text": "`server.js` declares `POST /api/templates` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-43143ae143c6f532", "name": "Unused endpoint: GET /api/templates/:id", "shortDescription": {"text": "Unused endpoint: GET /api/templates/:id"}, "fullDescription": {"text": "`server.js` declares `GET /api/templates/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8719090bb1dedf21", "name": "Unused endpoint: DELETE /api/templates/:id", "shortDescription": {"text": "Unused endpoint: DELETE /api/templates/:id"}, "fullDescription": {"text": "`server.js` declares `DELETE /api/templates/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1547031ed11dab8e", "name": "Unused endpoint: GET /api/analytics/report", "shortDescription": {"text": "Unused endpoint: GET /api/analytics/report"}, "fullDescription": {"text": "`server.js` declares `GET /api/analytics/report` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bbdf1daeb8ea0b47", "name": "Unused endpoint: POST /api/analytics/payment", "shortDescription": {"text": "Unused endpoint: POST /api/analytics/payment"}, "fullDescription": {"text": "`server.js` declares `POST /api/analytics/payment` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-181740bcdce2601b", "name": "Unused endpoint: GET /api/backup/list", "shortDescription": {"text": "Unused endpoint: GET /api/backup/list"}, "fullDescription": {"text": "`server.js` declares `GET /api/backup/list` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eea33de891560665", "name": "Unused endpoint: POST /api/backup/now", "shortDescription": {"text": "Unused endpoint: POST /api/backup/now"}, "fullDescription": {"text": "`server.js` declares `POST /api/backup/now` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f59aa1f038ba84be", "name": "Unused endpoint: POST /api/backup/restore/:id", "shortDescription": {"text": "Unused endpoint: POST /api/backup/restore/:id"}, "fullDescription": {"text": "`server.js` declares `POST /api/backup/restore/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d8d299959ad992eb", "name": "Unused endpoint: GET /api/webhooks", "shortDescription": {"text": "Unused endpoint: GET /api/webhooks"}, "fullDescription": {"text": "`server.js` declares `GET /api/webhooks` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d644b3146644e7cf", "name": "Unused endpoint: POST /api/webhooks", "shortDescription": {"text": "Unused endpoint: POST /api/webhooks"}, "fullDescription": {"text": "`server.js` declares `POST /api/webhooks` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0abdb6c00f579d58", "name": "Unused endpoint: PUT /api/webhooks/:id", "shortDescription": {"text": "Unused endpoint: PUT /api/webhooks/:id"}, "fullDescription": {"text": "`server.js` declares `PUT /api/webhooks/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-14d10a6e46af4eb5", "name": "Unused endpoint: DELETE /api/webhooks/:id", "shortDescription": {"text": "Unused endpoint: DELETE /api/webhooks/:id"}, "fullDescription": {"text": "`server.js` declares `DELETE /api/webhooks/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fbf68207ca9636d5", "name": "Unused endpoint: POST /api/webhooks/:id/test", "shortDescription": {"text": "Unused endpoint: POST /api/webhooks/:id/test"}, "fullDescription": {"text": "`server.js` declares `POST /api/webhooks/:id/test` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2e9bd766e9b914c4", "name": "Unused endpoint: GET /api/materials", "shortDescription": {"text": "Unused endpoint: GET /api/materials"}, "fullDescription": {"text": "`server.js` declares `GET /api/materials` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b37ce3d0c609313e", "name": "Unused endpoint: POST /api/materials/cost", "shortDescription": {"text": "Unused endpoint: POST /api/materials/cost"}, "fullDescription": {"text": "`server.js` declares `POST /api/materials/cost` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e0b51011aedb6df9", "name": "Unused endpoint: POST /api/materials/nesting", "shortDescription": {"text": "Unused endpoint: POST /api/materials/nesting"}, "fullDescription": {"text": "`server.js` declares `POST /api/materials/nesting` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3eabd22416000be7", "name": "Unused endpoint: POST /api/cnc/jog", "shortDescription": {"text": "Unused endpoint: POST /api/cnc/jog"}, "fullDescription": {"text": "`server.js` declares `POST /api/cnc/jog` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/22881"}, "properties": {"repository": "wrya77/Diqqat-Qalam", "repoUrl": "https://github.com/wrya77/Diqqat-Qalam", "branch": "main"}, "results": [{"ruleId": "scanner-6f1229f1e63f4fb8", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 server.js:209"}, "properties": {"repobilityId": "a9deebb5fdc93edc", "scanner": "scanner-primary", "fingerprint": "6f1229f1e63f4fb8", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2d951ed3a4cb6aa3", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/generate-all-files.js:47"}, "properties": {"repobilityId": "ab191a20fa0ddcb2", "scanner": "scanner-primary", "fingerprint": "2d951ed3a4cb6aa3", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-339a890101ec2b45", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 public/js/app.js:36"}, "properties": {"repobilityId": "5bf343aa4978169a", "scanner": "scanner-primary", "fingerprint": "339a890101ec2b45", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-74a12a2bf62eb799", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/js/simulator-three.js:101"}, "properties": {"repobilityId": "131d4fa17f2c5707", "scanner": "scanner-primary", "fingerprint": "74a12a2bf62eb799", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/js/simulator-three.js"}, "region": {"startLine": 101}}}]}, {"ruleId": "scanner-8f3221bde38030ab", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/js/ui-controls.js:157"}, "properties": {"repobilityId": "66993ab2b6cf9c59", "scanner": "scanner-primary", "fingerprint": "8f3221bde38030ab", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/js/ui-controls.js"}, "region": {"startLine": 157}}}]}, {"ruleId": "scanner-6d264afd1f9c24f0", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/js/tools-dock.js:18"}, "properties": {"repobilityId": "d4981a27cfd5e648", "scanner": "scanner-primary", "fingerprint": "6d264afd1f9c24f0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/js/tools-dock.js"}, "region": {"startLine": 18}}}]}, {"ruleId": "scanner-c7ecbeaeb0872eb7", "level": "note", "message": {"text": "Insecure pattern 'document_write' in public/js/app.js:404"}, "properties": {"repobilityId": "cc754300f2d6c57d", "scanner": "scanner-primary", "fingerprint": "c7ecbeaeb0872eb7", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["owasp", "document_write"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/js/app.js"}, "region": {"startLine": 404}}}]}, {"ruleId": "scanner-759089c95dbf4626", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/js/app.js:479"}, "properties": {"repobilityId": "20ef8ff0d2135a46", "scanner": "scanner-primary", "fingerprint": "759089c95dbf4626", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/js/app.js"}, "region": {"startLine": 479}}}]}, {"ruleId": "scanner-9675f4f83ffec9db", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/js/machine-control.js:228"}, "properties": {"repobilityId": "be0c44a69853820f", "scanner": "scanner-primary", "fingerprint": "9675f4f83ffec9db", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/js/machine-control.js"}, "region": {"startLine": 228}}}]}, {"ruleId": "scanner-19993f83a5ef4364", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/js/gcode-preview.js:23"}, "properties": {"repobilityId": "346d9f594fb736c4", "scanner": "scanner-primary", "fingerprint": "19993f83a5ef4364", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/js/gcode-preview.js"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-0cdb9e1aea22b2b3", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/js/tools-rail-flyout.js:23"}, "properties": {"repobilityId": "48d777725b73dd4c", "scanner": "scanner-primary", "fingerprint": "0cdb9e1aea22b2b3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/js/tools-rail-flyout.js"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-1c197bcdce342cd2", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/js/supabase-auth.js:79"}, "properties": {"repobilityId": "0125ed2fadb3b067", "scanner": "scanner-primary", "fingerprint": "1c197bcdce342cd2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/js/supabase-auth.js"}, "region": {"startLine": 79}}}]}, {"ruleId": "scanner-3ce68fda6a535a71", "level": "note", "message": {"text": "Very large file: public/js/tools-extra.js (1023 lines)"}, "properties": {"repobilityId": "7fcbf6f163c26373", "scanner": "scanner-primary", "fingerprint": "3ce68fda6a535a71", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "74a9b7ed27740f4a", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "1cf1c2f19ca27b5e", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-9d79c4077342a7d0", "level": "warning", "message": {"text": "Runtime service client appears to use placeholder configuration"}, "properties": {"repobilityId": "c5243969dbbcfb49", "scanner": "scanner-primary", "fingerprint": "9d79c4077342a7d0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "runtime-config", "service-client", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "88349e28596881bb", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "b6fc053e9a3149f9", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "df7a95a9aa61ad49", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "8844c17646335d82", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-fa5f832e6ba669c1", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/sw.js:104"}, "properties": {"repobilityId": "50a012674d09a99d", "scanner": "scanner-primary", "fingerprint": "fa5f832e6ba669c1", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-ba28d0093c5170ff", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/js/file-importer.js:75"}, "properties": {"repobilityId": "c3ef028efd2ff90d", "scanner": "scanner-primary", "fingerprint": "ba28d0093c5170ff", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-d4f7e6968894bf24", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/js/app.js:504"}, "properties": {"repobilityId": "9a536b2348c9324e", "scanner": "scanner-primary", "fingerprint": "d4f7e6968894bf24", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-a05112e8911c8b61", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/js/machine-control.js:166"}, "properties": {"repobilityId": "e497d471862f0058", "scanner": "scanner-primary", "fingerprint": "a05112e8911c8b61", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-965c4a608e63d175", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/payments/providers.js:105"}, "properties": {"repobilityId": "e424016409cbf4d9", "scanner": "scanner-primary", "fingerprint": "965c4a608e63d175", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-cffe7e300e9cb20a", "level": "note", "message": {"text": "Legacy-named symbol `clearOld` in src/core/Analytics.js:97"}, "properties": {"repobilityId": "2daeb09c08f9011d", "scanner": "scanner-primary", "fingerprint": "cffe7e300e9cb20a", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-3482f7e5dd70cd1a", "level": "note", "message": {"text": "6 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "1da70f25aa46f6e9", "scanner": "scanner-primary", "fingerprint": "3482f7e5dd70cd1a", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-a673804131ddd27d", "level": "note", "message": {"text": "Unused endpoint: USE /shared"}, "properties": {"repobilityId": "be6f6838916963a5", "scanner": "scanner-primary", "fingerprint": "a673804131ddd27d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dde3adb27bf7eebe", "level": "note", "message": {"text": "Unused endpoint: USE /api"}, "properties": {"repobilityId": "a3eddf5065ffbf6c", "scanner": "scanner-primary", "fingerprint": "dde3adb27bf7eebe", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "9b883326e67da4e4", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b9d4602aa46abe88", "level": "note", "message": {"text": "Unused endpoint: GET /auth"}, "properties": {"repobilityId": "221c24f2a4c30daa", "scanner": "scanner-primary", "fingerprint": "b9d4602aa46abe88", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-769398a8a95bd693", "level": "note", "message": {"text": "Unused endpoint: GET /app"}, "properties": {"repobilityId": "53899da4bddebaed", "scanner": "scanner-primary", "fingerprint": "769398a8a95bd693", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6fade9d72cd7b1df", "level": "note", "message": {"text": "Unused endpoint: POST /api/export"}, "properties": {"repobilityId": "80f2d8ed6e3ea6e2", "scanner": "scanner-primary", "fingerprint": "6fade9d72cd7b1df", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-aee2aa7b8ec56e42", "level": "note", "message": {"text": "Unused endpoint: POST /api/postprocess"}, "properties": {"repobilityId": "fdc978b1e00cdc35", "scanner": "scanner-primary", "fingerprint": "aee2aa7b8ec56e42", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ddcb2124cc97aa90", "level": "note", "message": {"text": "Unused endpoint: GET /api/tools/:id/speeds/:material"}, "properties": {"repobilityId": "e366e25e04e250ba", "scanner": "scanner-primary", "fingerprint": "ddcb2124cc97aa90", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c93fe63321eefc5d", "level": "note", "message": {"text": "Unused endpoint: POST /api/queue/enqueue"}, "properties": {"repobilityId": "f550af1d5f898835", "scanner": "scanner-primary", "fingerprint": "c93fe63321eefc5d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ef75da8c58c853e0", "level": "note", "message": {"text": "Unused endpoint: DELETE /api/queue/:id"}, "properties": {"repobilityId": "2d947d9f00f76b2f", "scanner": "scanner-primary", "fingerprint": "ef75da8c58c853e0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3c5750dfa4b3af21", "level": "note", "message": {"text": "Unused endpoint: POST /api/queue/start"}, "properties": {"repobilityId": "0ded626536d683a7", "scanner": "scanner-primary", "fingerprint": "3c5750dfa4b3af21", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-952bab24240402ce", "level": "note", "message": {"text": "Unused endpoint: POST /api/queue/stop"}, "properties": {"repobilityId": "13e6e98e63ddb37e", "scanner": "scanner-primary", "fingerprint": "952bab24240402ce", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8ae717e3316dc522", "level": "note", "message": {"text": "Unused endpoint: POST /api/queue/clear"}, "properties": {"repobilityId": "0e20beeb638fe298", "scanner": "scanner-primary", "fingerprint": "8ae717e3316dc522", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b5461c3c4afda997", "level": "note", "message": {"text": "Unused endpoint: GET /api/queue/status"}, "properties": {"repobilityId": "9a31f32a256e8eba", "scanner": "scanner-primary", "fingerprint": "b5461c3c4afda997", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-aee9d82ab3ed4634", "level": "note", "message": {"text": "Unused endpoint: POST /api/cost/estimate"}, "properties": {"repobilityId": "1a661dd16ae79dc4", "scanner": "scanner-primary", "fingerprint": "aee9d82ab3ed4634", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-43097970bc86e477", "level": "note", "message": {"text": "Unused endpoint: POST /api/cost/quote"}, "properties": {"repobilityId": "25252548599b011e", "scanner": "scanner-primary", "fingerprint": "43097970bc86e477", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9038f398d3a7b0af", "level": "note", "message": {"text": "Unused endpoint: PUT /api/cost/rates"}, "properties": {"repobilityId": "ffae0f933d9b884e", "scanner": "scanner-primary", "fingerprint": "9038f398d3a7b0af", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-885de0fa0133f6c0", "level": "note", "message": {"text": "Unused endpoint: GET /api/plans"}, "properties": {"repobilityId": "ab970895e7e6f384", "scanner": "scanner-primary", "fingerprint": "885de0fa0133f6c0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-92440a113179a7ef", "level": "note", "message": {"text": "Unused endpoint: POST /api/payments/callback/fib"}, "properties": {"repobilityId": "f0a59712e629a403", "scanner": "scanner-primary", "fingerprint": "92440a113179a7ef", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-73fbb78b2c236626", "level": "note", "message": {"text": "Unused endpoint: ALL /api/payments/callback/card"}, "properties": {"repobilityId": "76e0cbae2cd7e91c", "scanner": "scanner-primary", "fingerprint": "73fbb78b2c236626", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d0332882540c8b83", "level": "note", "message": {"text": "Unused endpoint: GET /api/subscription/:userId"}, "properties": {"repobilityId": "322f0d6e5f10d4ef", "scanner": "scanner-primary", "fingerprint": "d0332882540c8b83", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-22d5d00d58a706ac", "level": "note", "message": {"text": "Unused endpoint: POST /api/subscription/:userId"}, "properties": {"repobilityId": "330b09cf75550849", "scanner": "scanner-primary", "fingerprint": "22d5d00d58a706ac", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd6b553aa765ddc0", "level": "note", "message": {"text": "Unused endpoint: POST /api/batch/process"}, "properties": {"repobilityId": "137ba69e32706dd4", "scanner": "scanner-primary", "fingerprint": "fd6b553aa765ddc0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b9afe02da6381b95", "level": "note", "message": {"text": "Unused endpoint: GET /api/monitor/health"}, "properties": {"repobilityId": "e8c9f3ecd933bbe8", "scanner": "scanner-primary", "fingerprint": "b9afe02da6381b95", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3e06bfbfe68f6021", "level": "note", "message": {"text": "Unused endpoint: POST /api/monitor/reset"}, "properties": {"repobilityId": "2a845bd814f3c3c2", "scanner": "scanner-primary", "fingerprint": "3e06bfbfe68f6021", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b499aa0db7c751dd", "level": "note", "message": {"text": "Unused endpoint: GET /api/templates"}, "properties": {"repobilityId": "c6238ffa9506b577", "scanner": "scanner-primary", "fingerprint": "b499aa0db7c751dd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d907f175af50ca72", "level": "note", "message": {"text": "Unused endpoint: POST /api/templates"}, "properties": {"repobilityId": "6f18c7feca556c31", "scanner": "scanner-primary", "fingerprint": "d907f175af50ca72", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-43143ae143c6f532", "level": "note", "message": {"text": "Unused endpoint: GET /api/templates/:id"}, "properties": {"repobilityId": "96a92f859cdee386", "scanner": "scanner-primary", "fingerprint": "43143ae143c6f532", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8719090bb1dedf21", "level": "note", "message": {"text": "Unused endpoint: DELETE /api/templates/:id"}, "properties": {"repobilityId": "d51cb50c5c2e2a46", "scanner": "scanner-primary", "fingerprint": "8719090bb1dedf21", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1547031ed11dab8e", "level": "note", "message": {"text": "Unused endpoint: GET /api/analytics/report"}, "properties": {"repobilityId": "54b7e5849a97f322", "scanner": "scanner-primary", "fingerprint": "1547031ed11dab8e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bbdf1daeb8ea0b47", "level": "note", "message": {"text": "Unused endpoint: POST /api/analytics/payment"}, "properties": {"repobilityId": "68d1ec3da2ce0548", "scanner": "scanner-primary", "fingerprint": "bbdf1daeb8ea0b47", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-181740bcdce2601b", "level": "note", "message": {"text": "Unused endpoint: GET /api/backup/list"}, "properties": {"repobilityId": "bb4735d43d59caf8", "scanner": "scanner-primary", "fingerprint": "181740bcdce2601b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-eea33de891560665", "level": "note", "message": {"text": "Unused endpoint: POST /api/backup/now"}, "properties": {"repobilityId": "cb654540b6efd877", "scanner": "scanner-primary", "fingerprint": "eea33de891560665", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f59aa1f038ba84be", "level": "note", "message": {"text": "Unused endpoint: POST /api/backup/restore/:id"}, "properties": {"repobilityId": "6ae153e01ee7ceaa", "scanner": "scanner-primary", "fingerprint": "f59aa1f038ba84be", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d8d299959ad992eb", "level": "note", "message": {"text": "Unused endpoint: GET /api/webhooks"}, "properties": {"repobilityId": "932dffb92c48edb5", "scanner": "scanner-primary", "fingerprint": "d8d299959ad992eb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d644b3146644e7cf", "level": "note", "message": {"text": "Unused endpoint: POST /api/webhooks"}, "properties": {"repobilityId": "49d52870cb21e20e", "scanner": "scanner-primary", "fingerprint": "d644b3146644e7cf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0abdb6c00f579d58", "level": "note", "message": {"text": "Unused endpoint: PUT /api/webhooks/:id"}, "properties": {"repobilityId": "16c83812c1714372", "scanner": "scanner-primary", "fingerprint": "0abdb6c00f579d58", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-14d10a6e46af4eb5", "level": "note", "message": {"text": "Unused endpoint: DELETE /api/webhooks/:id"}, "properties": {"repobilityId": "7c0405ae773f3880", "scanner": "scanner-primary", "fingerprint": "14d10a6e46af4eb5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fbf68207ca9636d5", "level": "note", "message": {"text": "Unused endpoint: POST /api/webhooks/:id/test"}, "properties": {"repobilityId": "22aaa9a39982e47e", "scanner": "scanner-primary", "fingerprint": "fbf68207ca9636d5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2e9bd766e9b914c4", "level": "note", "message": {"text": "Unused endpoint: GET /api/materials"}, "properties": {"repobilityId": "02b1ebddd6ebf604", "scanner": "scanner-primary", "fingerprint": "2e9bd766e9b914c4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b37ce3d0c609313e", "level": "note", "message": {"text": "Unused endpoint: POST /api/materials/cost"}, "properties": {"repobilityId": "9726f759002525f2", "scanner": "scanner-primary", "fingerprint": "b37ce3d0c609313e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e0b51011aedb6df9", "level": "note", "message": {"text": "Unused endpoint: POST /api/materials/nesting"}, "properties": {"repobilityId": "9f3a4addee3bf9e5", "scanner": "scanner-primary", "fingerprint": "e0b51011aedb6df9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3eabd22416000be7", "level": "note", "message": {"text": "Unused endpoint: POST /api/cnc/jog"}, "properties": {"repobilityId": "9242dc208f5d0627", "scanner": "scanner-primary", "fingerprint": "3eabd22416000be7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}