{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-1ce5a7cbaf3a4db8", "name": "Stray `console.log` in TS/JS \u2014 scripts/backfill-photo-ocr.ts:210", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/backfill-photo-ocr.ts:210"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-53002129e808ac4b", "name": "Stray `console.log` in TS/JS \u2014 scripts/generate-openapi.ts:22", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/generate-openapi.ts:22"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e75a15ea905d0048", "name": "Stray `console.log` in TS/JS \u2014 scripts/eval-dedup.ts:208", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/eval-dedup.ts:208"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-97cb0f03245a5928", "name": "Stray `console.log` in TS/JS \u2014 scripts/backfill-phash.ts:60", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/backfill-phash.ts:60"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-558dd7c97bc8c1f5", "name": "Stray `console.log` in TS/JS \u2014 scripts/seed.ts:11", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/seed.ts:11"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cfcc795c66a861d9", "name": "Stray `console.log` in TS/JS \u2014 scripts/backfill-multilingual-places.ts:185", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/backfill-multilingual-places.ts:185"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-56e400c4ae9c6497", "name": "Stray `console.log` in TS/JS \u2014 scripts/backfill-merchants.ts:156", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/backfill-merchants.ts:156"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-24b897ac64059d5f", "name": "Stray `console.log` in TS/JS \u2014 scripts/smoke-v1-ingest.ts:604", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/smoke-v1-ingest.ts:604"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-587502c4ba4747d6", "name": "Stray `console.log` in TS/JS \u2014 scripts/migrate.ts:11", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/migrate.ts:11"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b3b8843064785307", "name": "Stray `console.log` in TS/JS \u2014 scripts/backfill-channel-parties.ts:29", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/backfill-channel-parties.ts:29"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6866a2a20fbad599", "name": "Stray `console.log` in TS/JS \u2014 src/server.ts:21", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server.ts:21"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a66431ac90e45210", "name": "Stray `console.log` in TS/JS \u2014 src/langfuse.ts:363", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/langfuse.ts:363"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4cc0f20830df8095", "name": "Stray `console.log` in TS/JS \u2014 src/enrichment/merchants.ts:180", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/enrichment/merchants.ts:180"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-57977a7f91e7c7b5", "name": "Stray `console.log` in TS/JS \u2014 src/ingest/extractor.ts:137", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/ingest/extractor.ts:137"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c26abdec07321def", "name": "Stray `console.log` in TS/JS \u2014 src/ingest/worker.ts:483", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/ingest/worker.ts:483"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e07e5801ac709917", "name": "Docker base image is tag-pinned but not digest-pinned: node:22-bookworm", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-bookworm"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7ad29beacb6864db", "name": "Insecure pattern 'node_child_process' in scripts/backfill-photo-ocr.ts:30", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/backfill-photo-ocr.ts:30"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6abec2528ebc075d", "name": "Insecure pattern 'node_child_process' in scripts/eval-dedup.ts:42", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/eval-dedup.ts:42"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-555cf3d4ba94316c", "name": "Insecure pattern 'node_child_process' in scripts/backfill-merchants.ts:27", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/backfill-merchants.ts:27"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-27a46fa28040a9c8", "name": "Insecure pattern 'node_child_process' in scripts/eval-dates.ts:33", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/eval-dates.ts:33"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-eb55ef4440a4ab74", "name": "Insecure pattern 'node_child_process' in scripts/generate-build-info.mjs:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/generate-build-info.mjs:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cfd3f94f8799d0dc", "name": "Insecure pattern 'node_child_process' in scripts/smoke-v1-ingest.ts:26", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/smoke-v1-ingest.ts:26"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4719647accc6a19a", "name": "Insecure pattern 'node_child_process' in src/claude.ts:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/claude.ts:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1f532368e4231056", "name": "Insecure pattern 'node_child_process' in src/ingest/extractor.ts:9", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/ingest/extractor.ts:9"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-054c6369aa03e6f1", "name": "Very large file: src/ingest/prompt.ts (1489 lines)", "shortDescription": {"text": "Very large file: src/ingest/prompt.ts (1489 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5a9fa1fa495e93e8", "name": "Very large file: src/routes/transactions.service.ts (1536 lines)", "shortDescription": {"text": "Very large file: src/routes/transactions.service.ts (1536 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "0 test file(s) for 114 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 104 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci, tests. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license, ci, tests. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cea0e0dc42359bd9", "name": "Commented-code block (5 lines) in scripts/eval-dedup.ts:73", "shortDescription": {"text": "Commented-code block (5 lines) in scripts/eval-dedup.ts:73"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ec79f53db5f41a80", "name": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/eval-dedup.ts:115", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/eval-dedup.ts:115"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1f7352c58a3c9459", "name": "Commented-code block (7 lines) in scripts/eval-dates.ts:268", "shortDescription": {"text": "Commented-code block (7 lines) in scripts/eval-dates.ts:268"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4a4f16305df05790", "name": "Commented-code block (6 lines) in scripts/smoke-v1-ingest.ts:342", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/smoke-v1-ingest.ts:342"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6b92aa33891689af", "name": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/smoke-v1-ingest.ts:256", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/smoke-v1-ingest.ts:256"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9aab8d472a8b8a61", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/langfuse.ts:133", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/langfuse.ts:133"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d62c9fbb06118bf2", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/ingest/brand-icon-prompt.ts:114", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/ingest/brand-icon-prompt.ts:114"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1da6a5edab84bb38", "name": "Commented-code block (5 lines) in src/ingest/extractor.ts:18", "shortDescription": {"text": "Commented-code block (5 lines) in src/ingest/extractor.ts:18"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b55c6647bffdeb54", "name": "Commented-code block (6 lines) in src/ingest/worker.ts:361", "shortDescription": {"text": "Commented-code block (6 lines) in src/ingest/worker.ts:361"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4f8ba08c08236f88", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/http/sse.ts:40", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/http/sse.ts:40"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4c15cb4e6890afe0", "name": "Commented-code block (5 lines) in src/insights/discover.ts:41", "shortDescription": {"text": "Commented-code block (5 lines) in src/insights/discover.ts:41"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9ffb28785c1da051", "name": "Commented-code block (18 lines) in src/schema/enums.ts:56", "shortDescription": {"text": "Commented-code block (18 lines) in src/schema/enums.ts:56"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2f57b59bbc23f403", "name": "Commented-code block (5 lines) in src/projection/derive.ts:256", "shortDescription": {"text": "Commented-code block (5 lines) in src/projection/derive.ts:256"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-46c2c345e2f3e143", "name": "Commented-code block (5 lines) in src/projection/layer3.ts:63", "shortDescription": {"text": "Commented-code block (5 lines) in src/projection/layer3.ts:63"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3723fae1dff62a33", "name": "Legacy-named symbol `has_local_copy` in src/routes/places.service.ts:89", "shortDescription": {"text": "Legacy-named symbol `has_local_copy` in src/routes/places.service.ts:89"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8b8dace3beef82c7", "name": "Commented-code block (6 lines) in src/routes/ingest.ts:147", "shortDescription": {"text": "Commented-code block (6 lines) in src/routes/ingest.ts:147"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a45249700655937c", "name": "Commented-code block (10 lines) in src/routes/reconcile.ts:74", "shortDescription": {"text": "Commented-code block (10 lines) in src/routes/reconcile.ts:74"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-eedf1ec11bc92873", "name": "Commented-code block (5 lines) in src/routes/accounts.ts:490", "shortDescription": {"text": "Commented-code block (5 lines) in src/routes/accounts.ts:490"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-eaa741daca6003af", "name": "Commented-code block (7 lines) in src/routes/merchants.ts:64", "shortDescription": {"text": "Commented-code block (7 lines) in src/routes/merchants.ts:64"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9a37eefe5600a572", "name": "Commented-code block (8 lines) in src/routes/documents.service.ts:251", "shortDescription": {"text": "Commented-code block (8 lines) in src/routes/documents.service.ts:251"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b7a5dffdea98e316", "name": "Commented-code block (6 lines) in src/routes/brands.ts:383", "shortDescription": {"text": "Commented-code block (6 lines) in src/routes/brands.ts:383"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-020e147ee7e92fc8", "name": "Commented-code block (5 lines) in src/routes/documents.ts:188", "shortDescription": {"text": "Commented-code block (5 lines) in src/routes/documents.ts:188"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a0791f7d5350c0fd", "name": "Commented-code block (5 lines) in src/routes/transactions.service.ts:860", "shortDescription": {"text": "Commented-code block (5 lines) in src/routes/transactions.service.ts:860"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ca1572a2312408f7", "name": "Commented-code block (5 lines) in src/routes/ingest.service.ts:201", "shortDescription": {"text": "Commented-code block (5 lines) in src/routes/ingest.service.ts:201"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-308ff9377340c0b8", "name": "Commented-code block (5 lines) in src/routes/transactions.ts:67", "shortDescription": {"text": "Commented-code block (5 lines) in src/routes/transactions.ts:67"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5013e255f21a8f4a", "name": "Commented-code block (11 lines) in src/reconcile/dedup.ts:130", "shortDescription": {"text": "Commented-code block (11 lines) in src/reconcile/dedup.ts:130"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-77e3ba3ed004edee", "name": "Commented-code block (6 lines) in src/reconcile/engine.ts:383", "shortDescription": {"text": "Commented-code block (6 lines) in src/reconcile/engine.ts:383"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4c029305abe99197", "name": "Commented-code block (5 lines) in src/db/seed.ts:72", "shortDescription": {"text": "Commented-code block (5 lines) in src/db/seed.ts:72"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-35a68a7dc94ced65", "name": "Legacy-named symbol `has_local_copy` in src/schemas/v1/place.ts:79", "shortDescription": {"text": "Legacy-named symbol `has_local_copy` in src/schemas/v1/place.ts:79"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-968d4311ce08cfe9", "name": "Unused endpoint: GET /openapi.json", "shortDescription": {"text": "Unused endpoint: GET /openapi.json"}, "fullDescription": {"text": "`src/app.ts` declares `GET /openapi.json` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b82f2c3c8954bf1c", "name": "Unused endpoint: USE /docs", "shortDescription": {"text": "Unused endpoint: USE /docs"}, "fullDescription": {"text": "`src/app.ts` declares `USE /docs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8c6ec3ab8b5cca71", "name": "Unused endpoint: USE /v1/accounts", "shortDescription": {"text": "Unused endpoint: USE /v1/accounts"}, "fullDescription": {"text": "`src/app.ts` declares `USE /v1/accounts` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9a56c8cfbf391d66", "name": "Unused endpoint: USE /v1/transactions", "shortDescription": {"text": "Unused endpoint: USE /v1/transactions"}, "fullDescription": {"text": "`src/app.ts` declares `USE /v1/transactions` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8742f22200602243", "name": "Unused endpoint: USE /v1/items", "shortDescription": {"text": "Unused endpoint: USE /v1/items"}, "fullDescription": {"text": "`src/app.ts` declares `USE /v1/items` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-97c3d84c93db38ef", "name": "Unused endpoint: USE /v1/products", "shortDescription": {"text": "Unused endpoint: USE /v1/products"}, "fullDescription": {"text": "`src/app.ts` declares `USE /v1/products` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7304ec104e5fc862", "name": "Unused endpoint: USE /v1/owned-items", "shortDescription": {"text": "Unused endpoint: USE /v1/owned-items"}, "fullDescription": {"text": "`src/app.ts` declares `USE /v1/owned-items` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8fdf7e7451bbd18a", "name": "Unused endpoint: USE /v1/wish-items", "shortDescription": {"text": "Unused endpoint: USE /v1/wish-items"}, "fullDescription": {"text": "`src/app.ts` declares `USE /v1/wish-items` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3e3ab6a3e17c727e", "name": "Unused endpoint: USE /v1/insights", "shortDescription": {"text": "Unused endpoint: USE /v1/insights"}, "fullDescription": {"text": "`src/app.ts` declares `USE /v1/insights` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c1766e6d593b047a", "name": "Unused endpoint: USE /v1", "shortDescription": {"text": "Unused endpoint: USE /v1"}, "fullDescription": {"text": "`src/app.ts` declares `USE /v1` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c244acadb74df3e2", "name": "Unused endpoint: USE /v1/brands", "shortDescription": {"text": "Unused endpoint: USE /v1/brands"}, "fullDescription": {"text": "`src/app.ts` declares `USE /v1/brands` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4b13342c0cddfde7", "name": "Unused endpoint: USE /v1/postings", "shortDescription": {"text": "Unused endpoint: USE /v1/postings"}, "fullDescription": {"text": "`src/app.ts` declares `USE /v1/postings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d854077d20c1e6c", "name": "Unused endpoint: USE /v1/documents", "shortDescription": {"text": "Unused endpoint: USE /v1/documents"}, "fullDescription": {"text": "`src/app.ts` declares `USE /v1/documents` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-921ed6b380b0c0cd", "name": "Unused endpoint: USE /v1/ingest", "shortDescription": {"text": "Unused endpoint: USE /v1/ingest"}, "fullDescription": {"text": "`src/app.ts` declares `USE /v1/ingest` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2ce9aa0c5c0dae34", "name": "Unused endpoint: USE /v1/batches", "shortDescription": {"text": "Unused endpoint: USE /v1/batches"}, "fullDescription": {"text": "`src/app.ts` declares `USE /v1/batches` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-21368f21599debfa", "name": "Unused endpoint: USE /v1/ingests", "shortDescription": {"text": "Unused endpoint: USE /v1/ingests"}, "fullDescription": {"text": "`src/app.ts` declares `USE /v1/ingests` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b233a496d1ed0ab5", "name": "Unused endpoint: USE /v1/reports", "shortDescription": {"text": "Unused endpoint: USE /v1/reports"}, "fullDescription": {"text": "`src/app.ts` declares `USE /v1/reports` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-10e06a76d9100b6f", "name": "Unused endpoint: USE /v1/merchants", "shortDescription": {"text": "Unused endpoint: USE /v1/merchants"}, "fullDescription": {"text": "`src/app.ts` declares `USE /v1/merchants` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4156d2e0654e7b54", "name": "Unused endpoint: USE /v1/places", "shortDescription": {"text": "Unused endpoint: USE /v1/places"}, "fullDescription": {"text": "`src/app.ts` declares `USE /v1/places` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0ce96799aac655", "name": "Unused endpoint: USE /v1/admin", "shortDescription": {"text": "Unused endpoint: USE /v1/admin"}, "fullDescription": {"text": "`src/app.ts` declares `USE /v1/admin` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-52c85377cc38e474", "name": "Unused endpoint: POST /batch", "shortDescription": {"text": "Unused endpoint: POST /batch"}, "fullDescription": {"text": "`src/routes/ingest.ts` declares `POST /batch` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`src/routes/ingest.ts` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ca5756175765b49d", "name": "Unused endpoint: GET /:id", "shortDescription": {"text": "Unused endpoint: GET /:id"}, "fullDescription": {"text": "`src/routes/ingest.ts` declares `GET /:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-644328d1ddb8907a", "name": "Unused endpoint: GET /:id/stream", "shortDescription": {"text": "Unused endpoint: GET /:id/stream"}, "fullDescription": {"text": "`src/routes/ingest.ts` declares `GET /:id/stream` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a009b1a56794f45", "name": "Unused endpoint: POST /", "shortDescription": {"text": "Unused endpoint: POST /"}, "fullDescription": {"text": "`src/routes/owned-items.ts` declares `POST /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5fbc954f63526821", "name": "Unused endpoint: PATCH /:id", "shortDescription": {"text": "Unused endpoint: PATCH /:id"}, "fullDescription": {"text": "`src/routes/owned-items.ts` declares `PATCH /:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a61c112b611f4bb", "name": "Unused endpoint: DELETE /:id", "shortDescription": {"text": "Unused endpoint: DELETE /:id"}, "fullDescription": {"text": "`src/routes/owned-items.ts` declares `DELETE /:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-732957bfec30af0f", "name": "Unused endpoint: POST /:id/reconcile", "shortDescription": {"text": "Unused endpoint: POST /:id/reconcile"}, "fullDescription": {"text": "`src/routes/reconcile.ts` declares `POST /:id/reconcile` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-896c0d942fae74a2", "name": "Unused endpoint: GET /:id/reconcile", "shortDescription": {"text": "Unused endpoint: GET /:id/reconcile"}, "fullDescription": {"text": "`src/routes/reconcile.ts` declares `GET /:id/reconcile` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1ade3545625ca9a7", "name": "Unused endpoint: POST /:id/reconcile/apply", "shortDescription": {"text": "Unused endpoint: POST /:id/reconcile/apply"}, "fullDescription": {"text": "`src/routes/reconcile.ts` declares `POST /:id/reconcile/apply` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fc979c066e1f51b9", "name": "Unused endpoint: POST /:id/reconcile/reject", "shortDescription": {"text": "Unused endpoint: POST /:id/reconcile/reject"}, "fullDescription": {"text": "`src/routes/reconcile.ts` declares `POST /:id/reconcile/reject` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-63d4475f58176f51", "name": "Unused endpoint: GET /:id/balance", "shortDescription": {"text": "Unused endpoint: GET /:id/balance"}, "fullDescription": {"text": "`src/routes/accounts.ts` declares `GET /:id/balance` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0b5718c150d20639", "name": "Unused endpoint: GET /:id/register", "shortDescription": {"text": "Unused endpoint: GET /:id/register"}, "fullDescription": {"text": "`src/routes/accounts.ts` declares `GET /:id/register` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7ce17d6b092a81ca", "name": "Unused endpoint: POST /refresh", "shortDescription": {"text": "Unused endpoint: POST /refresh"}, "fullDescription": {"text": "`src/routes/insights.ts` declares `POST /refresh` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9cd7f757f48d7ba7", "name": "Unused endpoint: POST /:id/dismiss", "shortDescription": {"text": "Unused endpoint: POST /:id/dismiss"}, "fullDescription": {"text": "`src/routes/insights.ts` declares `POST /:id/dismiss` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8e1fadad2500f063", "name": "Unused endpoint: POST /ask", "shortDescription": {"text": "Unused endpoint: POST /ask"}, "fullDescription": {"text": "`src/routes/insights.ts` declares `POST /ask` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a07035088daa002e", "name": "Unused endpoint: GET /transactions/:id/parties", "shortDescription": {"text": "Unused endpoint: GET /transactions/:id/parties"}, "fullDescription": {"text": "`src/routes/parties.ts` declares `GET /transactions/:id/parties` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-013b36018742cf69", "name": "Unused endpoint: GET /brands/:brandId/party-summary", "shortDescription": {"text": "Unused endpoint: GET /brands/:brandId/party-summary"}, "fullDescription": {"text": "`src/routes/parties.ts` declares `GET /brands/:brandId/party-summary` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1896dc74314ee3d0", "name": "Unused endpoint: GET /:id/transactions", "shortDescription": {"text": "Unused endpoint: GET /:id/transactions"}, "fullDescription": {"text": "`src/routes/merchants.ts` declares `GET /:id/transactions` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5f187c655d8cf6e3", "name": "Unused endpoint: GET /:id/photo", "shortDescription": {"text": "Unused endpoint: GET /:id/photo"}, "fullDescription": {"text": "`src/routes/merchants.ts` declares `GET /:id/photo` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4af6fe1eaed0ccdc", "name": "Unused endpoint: POST /:id/re-derive", "shortDescription": {"text": "Unused endpoint: POST /:id/re-derive"}, "fullDescription": {"text": "`src/routes/places.ts` declares `POST /:id/re-derive` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ac5a5689c3224905", "name": "Unused endpoint: POST /:id/refresh", "shortDescription": {"text": "Unused endpoint: POST /:id/refresh"}, "fullDescription": {"text": "`src/routes/places.ts` declares `POST /:id/refresh` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-304cf8a1bd10a7fc", "name": "Unused endpoint: GET /:id/map", "shortDescription": {"text": "Unused endpoint: GET /:id/map"}, "fullDescription": {"text": "`src/routes/places.ts` declares `GET /:id/map` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6c97c5b98b2829b4", "name": "Unused endpoint: GET /:id/photos/:rank/content", "shortDescription": {"text": "Unused endpoint: GET /:id/photos/:rank/content"}, "fullDescription": {"text": "`src/routes/places.ts` declares `GET /:id/photos/:rank/content` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e1b7bee247ffc801", "name": "Unused endpoint: GET /summary", "shortDescription": {"text": "Unused endpoint: GET /summary"}, "fullDescription": {"text": "`src/routes/reports.ts` declares `GET /summary` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-db5b5837abddb8b5", "name": "Unused endpoint: GET /trends", "shortDescription": {"text": "Unused endpoint: GET /trends"}, "fullDescription": {"text": "`src/routes/reports.ts` declares `GET /trends` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-416c5b1448a3fec7", "name": "Unused endpoint: GET /net_worth", "shortDescription": {"text": "Unused endpoint: GET /net_worth"}, "fullDescription": {"text": "`src/routes/reports.ts` declares `GET /net_worth` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a7066397da2bb292", "name": "Unused endpoint: GET /cashflow", "shortDescription": {"text": "Unused endpoint: GET /cashflow"}, "fullDescription": {"text": "`src/routes/reports.ts` declares `GET /cashflow` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2e403c9f80079a31", "name": "Unused endpoint: GET /:brandId", "shortDescription": {"text": "Unused endpoint: GET /:brandId"}, "fullDescription": {"text": "`src/routes/brands.ts` declares `GET /:brandId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ca2bee4c17fd3189", "name": "Unused endpoint: GET /:brandId/assets", "shortDescription": {"text": "Unused endpoint: GET /:brandId/assets"}, "fullDescription": {"text": "`src/routes/brands.ts` declares `GET /:brandId/assets` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/21322"}, "properties": {"repository": "TINKPA/receipt-assistant", "repoUrl": "https://github.com/TINKPA/receipt-assistant", "branch": "main"}, "results": [{"ruleId": "scanner-1ce5a7cbaf3a4db8", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/backfill-photo-ocr.ts:210"}, "properties": {"repobilityId": "bfff2b10c0eaa4bd", "scanner": "scanner-primary", "fingerprint": "1ce5a7cbaf3a4db8", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-53002129e808ac4b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/generate-openapi.ts:22"}, "properties": {"repobilityId": "e17146a09e731eb1", "scanner": "scanner-primary", "fingerprint": "53002129e808ac4b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e75a15ea905d0048", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/eval-dedup.ts:208"}, "properties": {"repobilityId": "9b87d76efc2a8e5b", "scanner": "scanner-primary", "fingerprint": "e75a15ea905d0048", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-97cb0f03245a5928", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/backfill-phash.ts:60"}, "properties": {"repobilityId": "776bb545495d8b81", "scanner": "scanner-primary", "fingerprint": "97cb0f03245a5928", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-558dd7c97bc8c1f5", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/seed.ts:11"}, "properties": {"repobilityId": "6b45b8d4fff61a2c", "scanner": "scanner-primary", "fingerprint": "558dd7c97bc8c1f5", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-cfcc795c66a861d9", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/backfill-multilingual-places.ts:185"}, "properties": {"repobilityId": "a334127d80a887ba", "scanner": "scanner-primary", "fingerprint": "cfcc795c66a861d9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-56e400c4ae9c6497", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/backfill-merchants.ts:156"}, "properties": {"repobilityId": "2cc99d5b895fcc1c", "scanner": "scanner-primary", "fingerprint": "56e400c4ae9c6497", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-24b897ac64059d5f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/smoke-v1-ingest.ts:604"}, "properties": {"repobilityId": "686e3d9e53b6cc40", "scanner": "scanner-primary", "fingerprint": "24b897ac64059d5f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-587502c4ba4747d6", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/migrate.ts:11"}, "properties": {"repobilityId": "886ea65b2e117422", "scanner": "scanner-primary", "fingerprint": "587502c4ba4747d6", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b3b8843064785307", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/backfill-channel-parties.ts:29"}, "properties": {"repobilityId": "da5b32a65ca59790", "scanner": "scanner-primary", "fingerprint": "b3b8843064785307", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-6866a2a20fbad599", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server.ts:21"}, "properties": {"repobilityId": "7753d6bdd8ad49dd", "scanner": "scanner-primary", "fingerprint": "6866a2a20fbad599", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a66431ac90e45210", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/langfuse.ts:363"}, "properties": {"repobilityId": "aa94c8454c234c82", "scanner": "scanner-primary", "fingerprint": "a66431ac90e45210", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4cc0f20830df8095", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/enrichment/merchants.ts:180"}, "properties": {"repobilityId": "7118b4dee7a7014b", "scanner": "scanner-primary", "fingerprint": "4cc0f20830df8095", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-57977a7f91e7c7b5", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/ingest/extractor.ts:137"}, "properties": {"repobilityId": "1c59ccebbf9c20b2", "scanner": "scanner-primary", "fingerprint": "57977a7f91e7c7b5", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c26abdec07321def", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/ingest/worker.ts:483"}, "properties": {"repobilityId": "0c0a4653db395d80", "scanner": "scanner-primary", "fingerprint": "c26abdec07321def", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e07e5801ac709917", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-bookworm"}, "properties": {"repobilityId": "fac6e722b564f69c", "scanner": "scanner-primary", "fingerprint": "e07e5801ac709917", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 15}}}]}, {"ruleId": "scanner-e07e5801ac709917", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-bookworm"}, "properties": {"repobilityId": "2e738da2d2a6394e", "scanner": "scanner-primary", "fingerprint": "e07e5801ac709917", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 37}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-7ad29beacb6864db", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/backfill-photo-ocr.ts:30"}, "properties": {"repobilityId": "12cf101728fcf3f6", "scanner": "scanner-primary", "fingerprint": "7ad29beacb6864db", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/backfill-photo-ocr.ts"}, "region": {"startLine": 30}}}]}, {"ruleId": "scanner-6abec2528ebc075d", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/eval-dedup.ts:42"}, "properties": {"repobilityId": "5a6d72cb20d38240", "scanner": "scanner-primary", "fingerprint": "6abec2528ebc075d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/eval-dedup.ts"}, "region": {"startLine": 42}}}]}, {"ruleId": "scanner-555cf3d4ba94316c", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/backfill-merchants.ts:27"}, "properties": {"repobilityId": "1d2304ba989903bf", "scanner": "scanner-primary", "fingerprint": "555cf3d4ba94316c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/backfill-merchants.ts"}, "region": {"startLine": 27}}}]}, {"ruleId": "scanner-27a46fa28040a9c8", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/eval-dates.ts:33"}, "properties": {"repobilityId": "d993922cee83dbc3", "scanner": "scanner-primary", "fingerprint": "27a46fa28040a9c8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/eval-dates.ts"}, "region": {"startLine": 33}}}]}, {"ruleId": "scanner-eb55ef4440a4ab74", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/generate-build-info.mjs:1"}, "properties": {"repobilityId": "9173e2eb3a12d051", "scanner": "scanner-primary", "fingerprint": "eb55ef4440a4ab74", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/generate-build-info.mjs"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cfd3f94f8799d0dc", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/smoke-v1-ingest.ts:26"}, "properties": {"repobilityId": "49707f4e04eece75", "scanner": "scanner-primary", "fingerprint": "cfd3f94f8799d0dc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/smoke-v1-ingest.ts"}, "region": {"startLine": 26}}}]}, {"ruleId": "scanner-4719647accc6a19a", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/claude.ts:1"}, "properties": {"repobilityId": "4302b9bf4f85c04a", "scanner": "scanner-primary", "fingerprint": "4719647accc6a19a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/claude.ts"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1f532368e4231056", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/ingest/extractor.ts:9"}, "properties": {"repobilityId": "a673b342ddc70212", "scanner": "scanner-primary", "fingerprint": "1f532368e4231056", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/ingest/extractor.ts"}, "region": {"startLine": 9}}}]}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-054c6369aa03e6f1", "level": "note", "message": {"text": "Very large file: src/ingest/prompt.ts (1489 lines)"}, "properties": {"repobilityId": "0b24605f5cdd1328", "scanner": "scanner-primary", "fingerprint": "054c6369aa03e6f1", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-5a9fa1fa495e93e8", "level": "note", "message": {"text": "Very large file: src/routes/transactions.service.ts (1536 lines)"}, "properties": {"repobilityId": "85e5de9c31acfa8e", "scanner": "scanner-primary", "fingerprint": "5a9fa1fa495e93e8", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "279b28a8f7be2545", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "520f6aa2f050d5f1", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "b66339f5c10d6362", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "warning", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "6a8fbabae33d5680", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "9474e453c5f1fd1d", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "5151719cabad9260", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "6a113944405c02ce", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-cea0e0dc42359bd9", "level": "none", "message": {"text": "Commented-code block (5 lines) in scripts/eval-dedup.ts:73"}, "properties": {"repobilityId": "d3160c91dfc2d5f4", "scanner": "scanner-primary", "fingerprint": "cea0e0dc42359bd9", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ec79f53db5f41a80", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/eval-dedup.ts:115"}, "properties": {"repobilityId": "6b7c3f65cc714c97", "scanner": "scanner-primary", "fingerprint": "ec79f53db5f41a80", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-1f7352c58a3c9459", "level": "none", "message": {"text": "Commented-code block (7 lines) in scripts/eval-dates.ts:268"}, "properties": {"repobilityId": "2b7cc943f5bb0ef1", "scanner": "scanner-primary", "fingerprint": "1f7352c58a3c9459", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4a4f16305df05790", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/smoke-v1-ingest.ts:342"}, "properties": {"repobilityId": "0ef8705f3ee3b231", "scanner": "scanner-primary", "fingerprint": "4a4f16305df05790", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6b92aa33891689af", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/smoke-v1-ingest.ts:256"}, "properties": {"repobilityId": "80ef3257aa632890", "scanner": "scanner-primary", "fingerprint": "6b92aa33891689af", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-9aab8d472a8b8a61", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/langfuse.ts:133"}, "properties": {"repobilityId": "7f2ad5d320ded47d", "scanner": "scanner-primary", "fingerprint": "9aab8d472a8b8a61", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-d62c9fbb06118bf2", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/ingest/brand-icon-prompt.ts:114"}, "properties": {"repobilityId": "6d4eec736c2e508f", "scanner": "scanner-primary", "fingerprint": "d62c9fbb06118bf2", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-1da6a5edab84bb38", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/ingest/extractor.ts:18"}, "properties": {"repobilityId": "34ae03942d590559", "scanner": "scanner-primary", "fingerprint": "1da6a5edab84bb38", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b55c6647bffdeb54", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/ingest/worker.ts:361"}, "properties": {"repobilityId": "a93f7e09dba50c74", "scanner": "scanner-primary", "fingerprint": "b55c6647bffdeb54", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4f8ba08c08236f88", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/http/sse.ts:40"}, "properties": {"repobilityId": "a284c61e8d2f55d6", "scanner": "scanner-primary", "fingerprint": "4f8ba08c08236f88", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-4c15cb4e6890afe0", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/insights/discover.ts:41"}, "properties": {"repobilityId": "f0d4fbe903356bc8", "scanner": "scanner-primary", "fingerprint": "4c15cb4e6890afe0", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-9ffb28785c1da051", "level": "none", "message": {"text": "Commented-code block (18 lines) in src/schema/enums.ts:56"}, "properties": {"repobilityId": "70c944e5d8c898e9", "scanner": "scanner-primary", "fingerprint": "9ffb28785c1da051", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2f57b59bbc23f403", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/projection/derive.ts:256"}, "properties": {"repobilityId": "2b97b154d8ecab8e", "scanner": "scanner-primary", "fingerprint": "2f57b59bbc23f403", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-46c2c345e2f3e143", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/projection/layer3.ts:63"}, "properties": {"repobilityId": "bd9a4f23987682a5", "scanner": "scanner-primary", "fingerprint": "46c2c345e2f3e143", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3723fae1dff62a33", "level": "note", "message": {"text": "Legacy-named symbol `has_local_copy` in src/routes/places.service.ts:89"}, "properties": {"repobilityId": "dba22b23d481bb66", "scanner": "scanner-primary", "fingerprint": "3723fae1dff62a33", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-8b8dace3beef82c7", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/routes/ingest.ts:147"}, "properties": {"repobilityId": "7dae70c4bd501458", "scanner": "scanner-primary", "fingerprint": "8b8dace3beef82c7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a45249700655937c", "level": "none", "message": {"text": "Commented-code block (10 lines) in src/routes/reconcile.ts:74"}, "properties": {"repobilityId": "e5390691cd2ef226", "scanner": "scanner-primary", "fingerprint": "a45249700655937c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-eedf1ec11bc92873", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/routes/accounts.ts:490"}, "properties": {"repobilityId": "3021f74c9e6bf26d", "scanner": "scanner-primary", "fingerprint": "eedf1ec11bc92873", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-eaa741daca6003af", "level": "none", "message": {"text": "Commented-code block (7 lines) in src/routes/merchants.ts:64"}, "properties": {"repobilityId": "c7ecafe84589ef98", "scanner": "scanner-primary", "fingerprint": "eaa741daca6003af", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-9a37eefe5600a572", "level": "none", "message": {"text": "Commented-code block (8 lines) in src/routes/documents.service.ts:251"}, "properties": {"repobilityId": "3a1adeb4faa9994c", "scanner": "scanner-primary", "fingerprint": "9a37eefe5600a572", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b7a5dffdea98e316", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/routes/brands.ts:383"}, "properties": {"repobilityId": "5db2534b7fa78d20", "scanner": "scanner-primary", "fingerprint": "b7a5dffdea98e316", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-020e147ee7e92fc8", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/routes/documents.ts:188"}, "properties": {"repobilityId": "37dea70d8699934b", "scanner": "scanner-primary", "fingerprint": "020e147ee7e92fc8", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a0791f7d5350c0fd", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/routes/transactions.service.ts:860"}, "properties": {"repobilityId": "6e0970b4e4dbde41", "scanner": "scanner-primary", "fingerprint": "a0791f7d5350c0fd", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ca1572a2312408f7", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/routes/ingest.service.ts:201"}, "properties": {"repobilityId": "4217ea63a1886a65", "scanner": "scanner-primary", "fingerprint": "ca1572a2312408f7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-308ff9377340c0b8", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/routes/transactions.ts:67"}, "properties": {"repobilityId": "7fd32e7132a10bca", "scanner": "scanner-primary", "fingerprint": "308ff9377340c0b8", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5013e255f21a8f4a", "level": "none", "message": {"text": "Commented-code block (11 lines) in src/reconcile/dedup.ts:130"}, "properties": {"repobilityId": "700874a45e8b5254", "scanner": "scanner-primary", "fingerprint": "5013e255f21a8f4a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-77e3ba3ed004edee", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/reconcile/engine.ts:383"}, "properties": {"repobilityId": "54bdbdce683c7374", "scanner": "scanner-primary", "fingerprint": "77e3ba3ed004edee", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4c029305abe99197", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/db/seed.ts:72"}, "properties": {"repobilityId": "45771cf585a7313c", "scanner": "scanner-primary", "fingerprint": "4c029305abe99197", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-35a68a7dc94ced65", "level": "note", "message": {"text": "Legacy-named symbol `has_local_copy` in src/schemas/v1/place.ts:79"}, "properties": {"repobilityId": "ff5d21ccfa78ec6e", "scanner": "scanner-primary", "fingerprint": "35a68a7dc94ced65", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-968d4311ce08cfe9", "level": "note", "message": {"text": "Unused endpoint: GET /openapi.json"}, "properties": {"repobilityId": "31ef0831025fa229", "scanner": "scanner-primary", "fingerprint": "968d4311ce08cfe9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b82f2c3c8954bf1c", "level": "note", "message": {"text": "Unused endpoint: USE /docs"}, "properties": {"repobilityId": "21e1825f968a7ad8", "scanner": "scanner-primary", "fingerprint": "b82f2c3c8954bf1c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8c6ec3ab8b5cca71", "level": "note", "message": {"text": "Unused endpoint: USE /v1/accounts"}, "properties": {"repobilityId": "e33fe391b34f4bf3", "scanner": "scanner-primary", "fingerprint": "8c6ec3ab8b5cca71", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9a56c8cfbf391d66", "level": "note", "message": {"text": "Unused endpoint: USE /v1/transactions"}, "properties": {"repobilityId": "8875c32c69ea3fbf", "scanner": "scanner-primary", "fingerprint": "9a56c8cfbf391d66", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8742f22200602243", "level": "note", "message": {"text": "Unused endpoint: USE /v1/items"}, "properties": {"repobilityId": "2da751f9c85030f0", "scanner": "scanner-primary", "fingerprint": "8742f22200602243", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-97c3d84c93db38ef", "level": "note", "message": {"text": "Unused endpoint: USE /v1/products"}, "properties": {"repobilityId": "a61da6d2ef4cfa19", "scanner": "scanner-primary", "fingerprint": "97c3d84c93db38ef", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7304ec104e5fc862", "level": "note", "message": {"text": "Unused endpoint: USE /v1/owned-items"}, "properties": {"repobilityId": "25b17b41e11c8a44", "scanner": "scanner-primary", "fingerprint": "7304ec104e5fc862", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8fdf7e7451bbd18a", "level": "note", "message": {"text": "Unused endpoint: USE /v1/wish-items"}, "properties": {"repobilityId": "f4392c75570632cb", "scanner": "scanner-primary", "fingerprint": "8fdf7e7451bbd18a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3e3ab6a3e17c727e", "level": "note", "message": {"text": "Unused endpoint: USE /v1/insights"}, "properties": {"repobilityId": "79cfac6078676669", "scanner": "scanner-primary", "fingerprint": "3e3ab6a3e17c727e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c1766e6d593b047a", "level": "note", "message": {"text": "Unused endpoint: USE /v1"}, "properties": {"repobilityId": "d5875d04f464b9da", "scanner": "scanner-primary", "fingerprint": "c1766e6d593b047a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c244acadb74df3e2", "level": "note", "message": {"text": "Unused endpoint: USE /v1/brands"}, "properties": {"repobilityId": "645aae5d55223b5b", "scanner": "scanner-primary", "fingerprint": "c244acadb74df3e2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4b13342c0cddfde7", "level": "note", "message": {"text": "Unused endpoint: USE /v1/postings"}, "properties": {"repobilityId": "3da0ed9d4729e080", "scanner": "scanner-primary", "fingerprint": "4b13342c0cddfde7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2d854077d20c1e6c", "level": "note", "message": {"text": "Unused endpoint: USE /v1/documents"}, "properties": {"repobilityId": "6a660aad895a4fd5", "scanner": "scanner-primary", "fingerprint": "2d854077d20c1e6c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-921ed6b380b0c0cd", "level": "note", "message": {"text": "Unused endpoint: USE /v1/ingest"}, "properties": {"repobilityId": "9b3d979d7e7647db", "scanner": "scanner-primary", "fingerprint": "921ed6b380b0c0cd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2ce9aa0c5c0dae34", "level": "note", "message": {"text": "Unused endpoint: USE /v1/batches"}, "properties": {"repobilityId": "064b98591b5e39d9", "scanner": "scanner-primary", "fingerprint": "2ce9aa0c5c0dae34", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-21368f21599debfa", "level": "note", "message": {"text": "Unused endpoint: USE /v1/ingests"}, "properties": {"repobilityId": "eb0fcc05bc64b62b", "scanner": "scanner-primary", "fingerprint": "21368f21599debfa", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b233a496d1ed0ab5", "level": "note", "message": {"text": "Unused endpoint: USE /v1/reports"}, "properties": {"repobilityId": "c7f08389234a30e7", "scanner": "scanner-primary", "fingerprint": "b233a496d1ed0ab5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-10e06a76d9100b6f", "level": "note", "message": {"text": "Unused endpoint: USE /v1/merchants"}, "properties": {"repobilityId": "1991167120ea40dc", "scanner": "scanner-primary", "fingerprint": "10e06a76d9100b6f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4156d2e0654e7b54", "level": "note", "message": {"text": "Unused endpoint: USE /v1/places"}, "properties": {"repobilityId": "e7c986bc79ee7c4e", "scanner": "scanner-primary", "fingerprint": "4156d2e0654e7b54", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2d0ce96799aac655", "level": "note", "message": {"text": "Unused endpoint: USE /v1/admin"}, "properties": {"repobilityId": "355fa140cda6b9af", "scanner": "scanner-primary", "fingerprint": "2d0ce96799aac655", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-52c85377cc38e474", "level": "note", "message": {"text": "Unused endpoint: POST /batch"}, "properties": {"repobilityId": "9140dc5d81c49410", "scanner": "scanner-primary", "fingerprint": "52c85377cc38e474", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "6acd242055c131ef", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ca5756175765b49d", "level": "note", "message": {"text": "Unused endpoint: GET /:id"}, "properties": {"repobilityId": "b67c1210f50319e5", "scanner": "scanner-primary", "fingerprint": "ca5756175765b49d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-644328d1ddb8907a", "level": "note", "message": {"text": "Unused endpoint: GET /:id/stream"}, "properties": {"repobilityId": "91fd5c5b6ce52346", "scanner": "scanner-primary", "fingerprint": "644328d1ddb8907a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a009b1a56794f45", "level": "note", "message": {"text": "Unused endpoint: POST /"}, "properties": {"repobilityId": "690d50f4f41dab96", "scanner": "scanner-primary", "fingerprint": "7a009b1a56794f45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5fbc954f63526821", "level": "note", "message": {"text": "Unused endpoint: PATCH /:id"}, "properties": {"repobilityId": "18b1cfdbc9e37b01", "scanner": "scanner-primary", "fingerprint": "5fbc954f63526821", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a61c112b611f4bb", "level": "note", "message": {"text": "Unused endpoint: DELETE /:id"}, "properties": {"repobilityId": "61ae5d8d7352b78d", "scanner": "scanner-primary", "fingerprint": "7a61c112b611f4bb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-732957bfec30af0f", "level": "note", "message": {"text": "Unused endpoint: POST /:id/reconcile"}, "properties": {"repobilityId": "ab1c41ce6b47c358", "scanner": "scanner-primary", "fingerprint": "732957bfec30af0f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-896c0d942fae74a2", "level": "note", "message": {"text": "Unused endpoint: GET /:id/reconcile"}, "properties": {"repobilityId": "cc2164e93d0b598b", "scanner": "scanner-primary", "fingerprint": "896c0d942fae74a2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1ade3545625ca9a7", "level": "note", "message": {"text": "Unused endpoint: POST /:id/reconcile/apply"}, "properties": {"repobilityId": "802d337b4517b879", "scanner": "scanner-primary", "fingerprint": "1ade3545625ca9a7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fc979c066e1f51b9", "level": "note", "message": {"text": "Unused endpoint: POST /:id/reconcile/reject"}, "properties": {"repobilityId": "bb4e28a05bd64d3d", "scanner": "scanner-primary", "fingerprint": "fc979c066e1f51b9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-63d4475f58176f51", "level": "note", "message": {"text": "Unused endpoint: GET /:id/balance"}, "properties": {"repobilityId": "565efc9500474aa7", "scanner": "scanner-primary", "fingerprint": "63d4475f58176f51", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0b5718c150d20639", "level": "note", "message": {"text": "Unused endpoint: GET /:id/register"}, "properties": {"repobilityId": "2a4d7ba184310538", "scanner": "scanner-primary", "fingerprint": "0b5718c150d20639", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7ce17d6b092a81ca", "level": "note", "message": {"text": "Unused endpoint: POST /refresh"}, "properties": {"repobilityId": "94b069a641f5795f", "scanner": "scanner-primary", "fingerprint": "7ce17d6b092a81ca", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9cd7f757f48d7ba7", "level": "note", "message": {"text": "Unused endpoint: POST /:id/dismiss"}, "properties": {"repobilityId": "6cb1a015a10eeba4", "scanner": "scanner-primary", "fingerprint": "9cd7f757f48d7ba7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8e1fadad2500f063", "level": "note", "message": {"text": "Unused endpoint: POST /ask"}, "properties": {"repobilityId": "2babf0ff70685cec", "scanner": "scanner-primary", "fingerprint": "8e1fadad2500f063", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a07035088daa002e", "level": "note", "message": {"text": "Unused endpoint: GET /transactions/:id/parties"}, "properties": {"repobilityId": "fe0a127e19a8876a", "scanner": "scanner-primary", "fingerprint": "a07035088daa002e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-013b36018742cf69", "level": "note", "message": {"text": "Unused endpoint: GET /brands/:brandId/party-summary"}, "properties": {"repobilityId": "dddb873f56d4df89", "scanner": "scanner-primary", "fingerprint": "013b36018742cf69", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1896dc74314ee3d0", "level": "note", "message": {"text": "Unused endpoint: GET /:id/transactions"}, "properties": {"repobilityId": "3f7c261daf55797f", "scanner": "scanner-primary", "fingerprint": "1896dc74314ee3d0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5f187c655d8cf6e3", "level": "note", "message": {"text": "Unused endpoint: GET /:id/photo"}, "properties": {"repobilityId": "327770d7fb9c9936", "scanner": "scanner-primary", "fingerprint": "5f187c655d8cf6e3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4af6fe1eaed0ccdc", "level": "note", "message": {"text": "Unused endpoint: POST /:id/re-derive"}, "properties": {"repobilityId": "c801f44f3308bc6a", "scanner": "scanner-primary", "fingerprint": "4af6fe1eaed0ccdc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ac5a5689c3224905", "level": "note", "message": {"text": "Unused endpoint: POST /:id/refresh"}, "properties": {"repobilityId": "af580e54cf22897a", "scanner": "scanner-primary", "fingerprint": "ac5a5689c3224905", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-304cf8a1bd10a7fc", "level": "note", "message": {"text": "Unused endpoint: GET /:id/map"}, "properties": {"repobilityId": "ad160116d4f32987", "scanner": "scanner-primary", "fingerprint": "304cf8a1bd10a7fc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6c97c5b98b2829b4", "level": "note", "message": {"text": "Unused endpoint: GET /:id/photos/:rank/content"}, "properties": {"repobilityId": "dccde6c46bb58078", "scanner": "scanner-primary", "fingerprint": "6c97c5b98b2829b4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e1b7bee247ffc801", "level": "note", "message": {"text": "Unused endpoint: GET /summary"}, "properties": {"repobilityId": "99c92e98395ed08f", "scanner": "scanner-primary", "fingerprint": "e1b7bee247ffc801", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-db5b5837abddb8b5", "level": "note", "message": {"text": "Unused endpoint: GET /trends"}, "properties": {"repobilityId": "46656bcfeb96c3d7", "scanner": "scanner-primary", "fingerprint": "db5b5837abddb8b5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-416c5b1448a3fec7", "level": "note", "message": {"text": "Unused endpoint: GET /net_worth"}, "properties": {"repobilityId": "6f78119811564043", "scanner": "scanner-primary", "fingerprint": "416c5b1448a3fec7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a7066397da2bb292", "level": "note", "message": {"text": "Unused endpoint: GET /cashflow"}, "properties": {"repobilityId": "59a36ced34128ebb", "scanner": "scanner-primary", "fingerprint": "a7066397da2bb292", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2e403c9f80079a31", "level": "note", "message": {"text": "Unused endpoint: GET /:brandId"}, "properties": {"repobilityId": "b522b81bf1d1b61f", "scanner": "scanner-primary", "fingerprint": "2e403c9f80079a31", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ca2bee4c17fd3189", "level": "note", "message": {"text": "Unused endpoint: GET /:brandId/assets"}, "properties": {"repobilityId": "80e83934cad213b9", "scanner": "scanner-primary", "fingerprint": "ca2bee4c17fd3189", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}