{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "foundry_unresolved_feedback", "name": "Foundry mined unresolved feedback: SamuelBrudner/lab-tracker", "shortDescription": {"text": "Foundry mined unresolved feedback: SamuelBrudner/lab-tracker"}, "fullDescription": {"text": "Graph query export: Human feedback without linked fix evidence\nQuery id: unresolved_feedback\nQuery type: motif_query\nIntent: Negative/unresolved examples that should not be hallucinated into fixes.\nMotif: unlinked_feedback_needs_evidence\nTraining usage: negative_or_unresolved\nGraph gold label: needs_more_evidence\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#6\nEvidence:\nGraph motif: Human feedback exists without a linked fix\nMotif id: unlinked_feedback_needs_evidence\nPolarity: bad\nTraining usage: negative_or_unresolved\nSeverity: medium\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#6\nGraph gold label: needs_more_evidence\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: SamuelBrudner/lab-tracker#6\nRepo: SamuelBrudner/lab-tracker\nIssue/PR number: 6\nGraph consistency label: needs_more_evidence\nNodes: 67\nEdges: 93\nNode types: {'pr_file': 58, 'link_quality': 3, 'thread': 1, 'repo': 1, 'comment': 1, 'comment_chain': 1, 'issue_chain': 1, "}, "properties": {"scanner": "foundry_dataset", "category": "practices", "severity": "medium", "confidence": 0.7, "cwe": "", "owasp": ""}}, {"id": "foundry_blueprint_gap", "name": "Foundry mined blueprint gap alignment: SamuelBrudner/lab-tracker", "shortDescription": {"text": "Foundry mined blueprint gap alignment: SamuelBrudner/lab-tracker"}, "fullDescription": {"text": "Graph query export: Human feedback aligned with blueprint or architecture gaps\nQuery id: blueprint_gap_alignment\nQuery type: motif_query\nIntent: Curriculum-gap examples connecting issue threads to helicopter-view gaps.\nMotif: blueprint_gap_alignment\nTraining usage: curriculum_gap\nGraph gold label: weak_supervision_needs_review\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#7\nEvidence:\nGraph motif: Human feedback aligns with blueprint or architecture gaps\nMotif id: blueprint_gap_alignment\nPolarity: mixed\nTraining usage: curriculum_gap\nSeverity: medium\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#7\nGraph gold label: weak_supervision_needs_review\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: SamuelBrudner/lab-tracker#7\nRepo: SamuelBrudner/lab-tracker\nIssue/PR number: 7\nGraph consistency label: weak_supervision_needs_review\nNodes: 24\nEdges: 37\nNode types: {'link_quality': 6, 'pr_file': 4, 'alignment': 3, 'blueprint_finding': 3, 'co"}, "properties": {"scanner": "foundry_dataset", "category": "tech_debt", "severity": "medium", "confidence": 0.7, "cwe": "", "owasp": ""}}, {"id": "foundry_assumption_check", "name": "Foundry mined assumption checks: SamuelBrudner/lab-tracker", "shortDescription": {"text": "Foundry mined assumption checks: SamuelBrudner/lab-tracker"}, "fullDescription": {"text": "Comment chain pattern product: assumption_checks\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#7\nOutcome: claimed_resolved_unverified\nThread label: thread_has_human_issue_and_fix_context\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, repo_has_isolated_helicopter_views, link_quality_weak_supervision, high_risk_human_feedback_label\nChain evidence:\nIssue/PR evidence chain: SamuelBrudner/lab-tracker#7\nRepo: SamuelBrudner/lab-tracker\nThread label: thread_has_human_issue_and_fix_context\nOutcome: claimed_resolved_unverified\nComment count: 1\nLinked commit count: 2\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 4\nLabels: {'test_ci_gap': 1}\nPolarities: {'bad': 1}\nChanged file labels: {'source_or_other': 1, 'docs_or_claims': 3}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-b7f998bb7ce05e21\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"test_ci_gap\",\n    \"polarity"}, "properties": {"scanner": "foundry_dataset", "category": "practices", "severity": "medium", "confidence": 0.62, "cwe": "", "owasp": ""}}, {"id": "foundry_test_ci_gap", "name": "Foundry mined test ci gap after feedback: SamuelBrudner/lab-tracker", "shortDescription": {"text": "Foundry mined test ci gap after feedback: SamuelBrudner/lab-tracker"}, "fullDescription": {"text": "Graph query export: Feedback exposes missing tests or CI\nQuery id: test_ci_gap_after_feedback\nQuery type: motif_query\nIntent: Hard negatives for feedback/fix chains without adequate guardrails.\nMotif: test_ci_gap_after_feedback\nTraining usage: hard_negative\nGraph gold label: weak_supervision_needs_review\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#7\nEvidence:\nGraph motif: Feedback or fix context exposes missing test/CI guardrails\nMotif id: test_ci_gap_after_feedback\nPolarity: bad\nTraining usage: hard_negative\nSeverity: high\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#7\nGraph gold label: weak_supervision_needs_review\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: SamuelBrudner/lab-tracker#7\nRepo: SamuelBrudner/lab-tracker\nIssue/PR number: 7\nGraph consistency label: weak_supervision_needs_review\nNodes: 24\nEdges: 37\nNode types: {'link_quality': 6, 'pr_file': 4, 'alignment': 3, 'blueprint_finding': 3, 'commit': 2, 'thread': 1, '"}, "properties": {"scanner": "foundry_dataset", "category": "testing", "severity": "high", "confidence": 0.78, "cwe": "", "owasp": ""}}, {"id": "foundry_docs_only_fix", "name": "Foundry mined docs only runtime fix: SamuelBrudner/lab-tracker", "shortDescription": {"text": "Foundry mined docs only runtime fix: SamuelBrudner/lab-tracker"}, "fullDescription": {"text": "Graph query export: Docs-only response to runtime or integration issue\nQuery id: docs_only_runtime_fix\nQuery type: motif_query\nIntent: Assumption-check examples where docs or claims are not enough proof.\nMotif: docs_only_runtime_fix\nTraining usage: assumption_check\nGraph gold label: weak_supervision_needs_review\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#7\nEvidence:\nGraph motif: Runtime/integration complaint answered mostly with docs or claims\nMotif id: docs_only_runtime_fix\nPolarity: bad\nTraining usage: assumption_check\nSeverity: high\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#7\nGraph gold label: weak_supervision_needs_review\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: SamuelBrudner/lab-tracker#7\nRepo: SamuelBrudner/lab-tracker\nIssue/PR number: 7\nGraph consistency label: weak_supervision_needs_review\nNodes: 24\nEdges: 37\nNode types: {'link_quality': 6, 'pr_file': 4, 'alignment': 3, 'blueprint_finding': 3, 'commit': 2, '"}, "properties": {"scanner": "foundry_dataset", "category": "practices", "severity": "high", "confidence": 0.8, "cwe": "", "owasp": ""}}, {"id": "scanner-2d0f098776c51e82", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4c6b0286ab4d2b6c", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dc5d6493100fc105", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9620d92ceaf50070", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a0746b50b9939ba5", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e72ea5b290664db1", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a5dad06476079cb1", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ffbd11fdd1316b39", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1185828c7783ed89", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eec5fc2b683ed80d", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c25eb7d20db7d286", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ba79691b1cd26128", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-52368cce8c384135", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dc18ab2e40b231fb", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f3a0107f0f264add", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8e0a210b83f311db", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-429af003d4c0d3f3", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eb15ab101b70c692", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aba0982b01d35ab2", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b668dacccbe969f1", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a2efb49c2760cf90", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fec5782dcc1bc0e4", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-66be5358628f4943", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-df612ec27307cd1e", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b596df67d2f8d397", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-07deda149b604f41", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c835b3075642b1c", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0fa25ea2445f2a49", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7839e88e304d65f9", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2399a2ef432947d2", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5a0a0800450a9fb0", "name": "Stray `console.log` in TS/JS \u2014 src/lab_tracker/frontend/app.js:14", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/lab_tracker/frontend/app.js:14"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9f6f69820d8ed65c", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 src/lab_tracker/frontend/app.js:2", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 src/lab_tracker/frontend/app.js:2"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3ba0167dbdb33778", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 src/lab_tracker/frontend_src/features/devices.jsx:117", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 src/lab_tracker/frontend_src/features/devices.jsx:117"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d63da3583b14afc0", "name": "Dockerfile runs as root: Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e066691601852931", "name": "Docker base image is tag-pinned but not digest-pinned: python:3.11-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.11-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-732b2a9030f8a398", "name": "Insecure pattern 'dangerous_innerhtml' in src/lab_tracker/frontend/app.js:2", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in src/lab_tracker/frontend/app.js:2"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1bcec543aea83e93", "name": "Insecure pattern 'direct_innerhtml_assignment' in src/lab_tracker/frontend/app.js:6", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in src/lab_tracker/frontend/app.js:6"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cee30e0f4f7d7e57", "name": "Insecure pattern 'dangerous_innerhtml' in src/lab_tracker/frontend_src/features/devices.jsx:117", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in src/lab_tracker/frontend_src/features/devices.jsx:117"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dbeb8f68f27ce2e8", "name": "Very large file: tests/test_graph_drafts.py (1687 lines)", "shortDescription": {"text": "Very large file: tests/test_graph_drafts.py (1687 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a58f55fe5f77fe5b", "name": "Very large file: src/lab_tracker/frontend_src/App.test.jsx (3077 lines)", "shortDescription": {"text": "Very large file: src/lab_tracker/frontend_src/App.test.jsx (3077 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 9 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 15 placeholder/mock markers across 7 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cc55229a7a3c078d", "name": "Agent authority lacks a verifier contract: .mcp.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .mcp.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6d0eff8faf856969", "name": "Legacy-named symbol `expected_legacy` in tests/test_persistence_flows.py:102", "shortDescription": {"text": "Legacy-named symbol `expected_legacy` in tests/test_persistence_flows.py:102"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3b6d332a3e91e417", "name": "Legacy-named symbol `model_copy` in tests/test_project_authorization_policy.py:48", "shortDescription": {"text": "Legacy-named symbol `model_copy` in tests/test_project_authorization_policy.py:48"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-06a0160348f3f0a5", "name": "Legacy-named symbol `model_copy` in tests/test_sqlalchemy_repository.py:137", "shortDescription": {"text": "Legacy-named symbol `model_copy` in tests/test_sqlalchemy_repository.py:137"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0bf767a2c4d97c4b", "name": "Legacy-named symbol `model_copy` in tests/test_sqlalchemy_mappers.py:90", "shortDescription": {"text": "Legacy-named symbol `model_copy` in tests/test_sqlalchemy_mappers.py:90"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-35a2bac0ff1a78da", "name": "Stub function `upgrade` (body is just `pass`/`return`) \u2014 alembic/versions/0019_merge_daily_reviews_and_project_collabora", "shortDescription": {"text": "Stub function `upgrade` (body is just `pass`/`return`) \u2014 alembic/versions/0019_merge_daily_reviews_and_project_collaboration.py:14"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c5b215c75c279f1a", "name": "Commented-code block (5 lines) in src/lab_tracker/frontend/sw.js:57", "shortDescription": {"text": "Commented-code block (5 lines) in src/lab_tracker/frontend/sw.js:57"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8f11e854f13fa64a", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/lab_tracker/frontend/app.js:9", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/lab_tracker/frontend/app.js:9"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b46683afb511f991", "name": "Commented-code block (6 lines) in src/lab_tracker/app_parts/frontend.py:57", "shortDescription": {"text": "Commented-code block (6 lines) in src/lab_tracker/app_parts/frontend.py:57"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4a9e0f9472ff6175", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/lab_tracker/frontend_src/shared/api.js:66", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/lab_tracker/frontend_src/shared/api.js:66"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-44c25fce4471993e", "name": "Commented-code block (6 lines) in src/lab_tracker/frontend_src/features/project-graph.jsx:74", "shortDescription": {"text": "Commented-code block (6 lines) in src/lab_tracker/frontend_src/features/project-graph.jsx:74"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-75db23d0757fbcd9", "name": "Commented-code block (5 lines) in src/lab_tracker/frontend_src/features/mobile-capture.jsx:338", "shortDescription": {"text": "Commented-code block (5 lines) in src/lab_tracker/frontend_src/features/mobile-capture.jsx:338"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-71ec38d7ad268208", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/lab_tracker/frontend_src/features/analysis/VisualizationDetailCard.jsx", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/lab_tracker/frontend_src/features/analysis/VisualizationDetailCard.jsx:26"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ba6e38217f2d20e1", "name": "Legacy-named symbol `model_copy` in src/lab_tracker/services/question_service.py:360", "shortDescription": {"text": "Legacy-named symbol `model_copy` in src/lab_tracker/services/question_service.py:360"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8e047ab7af03962f", "name": "7 env vars used in code but missing from .env.example", "shortDescription": {"text": "7 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `LAB_TRACKER_ACCESS_TOKEN`, `LAB_TRACKER_BASE_URL`, `LAB_TRACKER_HTTP_TIMEOUT`, `LAB_TRACKER_PASSWORD`, `LAB_TRACKER_PROJECT_ID`, `LAB_TRACKER_USERNAME`, `NODE_ENV`. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nsrc/lab_tracker/mcp_api_client.py:access_token, src/lab_tracker_client/client.py:access_token\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be46ea126aa5d8dc", "name": "Near-duplicate function bodies in 3 places", "shortDescription": {"text": "Near-duplicate function bodies in 3 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nsrc/lab_tracker/mcp_api_client.py:health, src/lab_tracker_client/client.py:health, src/lab_tracker_client/client.py:health\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-02525d39071dd2c7", "name": "Near-duplicate function bodies in 5 places", "shortDescription": {"text": "Near-duplicate function bodies in 5 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nsrc/lab_tracker/mcp_api_client.py:list_questions, src/lab_tracker/decision_context_types.py:list_questions, src/lab_tracker/decision_context_query.py:list_questions, src/lab_tracker_client/client.py:list_questions\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-33a6b62e30ce7ab4", "name": "Near-duplicate function bodies in 6 places", "shortDescription": {"text": "Near-duplicate function bodies in 6 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nsrc/lab_tracker/mcp_api_client.py:list_notes, src/lab_tracker/mcp_api_client.py:list_datasets, src/lab_tracker/decision_context_types.py:list_notes, src/lab_tracker/decision_context_types.py:list_datasets\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-76a2f6818267a9a8", "name": "Near-duplicate function bodies in 8 places", "shortDescription": {"text": "Near-duplicate function bodies in 8 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nsrc/lab_tracker/repository.py:query_projects, src/lab_tracker/sqlalchemy_repository_parts/repository.py:query_projects, src/lab_tracker/sqlalchemy_repository_parts/core.py:query, src/lab_tracker/sqlalchemy_repository_parts/core.py:query\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-49c98f7cedd9c977", "name": "Near-duplicate function bodies in 4 places", "shortDescription": {"text": "Near-duplicate function bodies in 4 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nsrc/lab_tracker/repository.py:query_supervision_edges, src/lab_tracker/sqlalchemy_repository_parts/repository.py:query_supervision_edges, src/lab_tracker/sqlalchemy_repository_parts/supervision.py:query, src/lab_tracker/services/supervision_service.py:list_supervision_edges\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-82ba709d6e6b8786", "name": "FastAPI POST `share_target_fallback` without auth dependency \u2014 src/lab_tracker/app_parts/frontend.py:55", "shortDescription": {"text": "FastAPI POST `share_target_fallback` without auth dependency \u2014 src/lab_tracker/app_parts/frontend.py:55"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1435c4f82d5da321", "name": "FastAPI POST `create_project` without auth dependency \u2014 src/lab_tracker/routes/projects.py:67", "shortDescription": {"text": "FastAPI POST `create_project` without auth dependency \u2014 src/lab_tracker/routes/projects.py:67"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4ac4ea3295304c32", "name": "FastAPI PATCH `update_project` without auth dependency \u2014 src/lab_tracker/routes/projects.py:106", "shortDescription": {"text": "FastAPI PATCH `update_project` without auth dependency \u2014 src/lab_tracker/routes/projects.py:106"}, "fullDescription": {"text": "`@router.patch` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eca1b3be8fba0ca1", "name": "FastAPI DELETE `delete_project` without auth dependency \u2014 src/lab_tracker/routes/projects.py:124", "shortDescription": {"text": "FastAPI DELETE `delete_project` without auth dependency \u2014 src/lab_tracker/routes/projects.py:124"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ed4d37846cf3c912", "name": "FastAPI POST `create_project_member` without auth dependency \u2014 src/lab_tracker/routes/projects.py:201", "shortDescription": {"text": "FastAPI POST `create_project_member` without auth dependency \u2014 src/lab_tracker/routes/projects.py:201"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6d063472e4cadead", "name": "FastAPI PATCH `update_project_member` without auth dependency \u2014 src/lab_tracker/routes/projects.py:221", "shortDescription": {"text": "FastAPI PATCH `update_project_member` without auth dependency \u2014 src/lab_tracker/routes/projects.py:221"}, "fullDescription": {"text": "`@router.patch` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cf3fd706b55641f7", "name": "FastAPI DELETE `delete_project_member` without auth dependency \u2014 src/lab_tracker/routes/projects.py:240", "shortDescription": {"text": "FastAPI DELETE `delete_project_member` without auth dependency \u2014 src/lab_tracker/routes/projects.py:240"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b5d3420dd18ab79f", "name": "FastAPI POST `create_enrollment` without auth dependency \u2014 src/lab_tracker/routes/device_auth.py:86", "shortDescription": {"text": "FastAPI POST `create_enrollment` without auth dependency \u2014 src/lab_tracker/routes/device_auth.py:86"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-179e18ec81e2626b", "name": "FastAPI POST `consume_enrollment` without auth dependency \u2014 src/lab_tracker/routes/device_auth.py:110", "shortDescription": {"text": "FastAPI POST `consume_enrollment` without auth dependency \u2014 src/lab_tracker/routes/device_auth.py:110"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fddd62ca2bf13fe3", "name": "FastAPI DELETE `revoke_device` without auth dependency \u2014 src/lab_tracker/routes/device_auth.py:153", "shortDescription": {"text": "FastAPI DELETE `revoke_device` without auth dependency \u2014 src/lab_tracker/routes/device_auth.py:153"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9e3fb4e9aaf30b50", "name": "FastAPI POST `get_decision_context` without auth dependency \u2014 src/lab_tracker/routes/assistant.py:25", "shortDescription": {"text": "FastAPI POST `get_decision_context` without auth dependency \u2014 src/lab_tracker/routes/assistant.py:25"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1c51bc13e1b2d424", "name": "FastAPI POST `create_spanning_goal` without auth dependency \u2014 src/lab_tracker/routes/goals.py:58", "shortDescription": {"text": "FastAPI POST `create_spanning_goal` without auth dependency \u2014 src/lab_tracker/routes/goals.py:58"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-33f0bd6955aad975", "name": "FastAPI POST `create_goal` without auth dependency \u2014 src/lab_tracker/routes/goals.py:99", "shortDescription": {"text": "FastAPI POST `create_goal` without auth dependency \u2014 src/lab_tracker/routes/goals.py:99"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-84aa1cbc320e6cb4", "name": "FastAPI PATCH `update_goal` without auth dependency \u2014 src/lab_tracker/routes/goals.py:147", "shortDescription": {"text": "FastAPI PATCH `update_goal` without auth dependency \u2014 src/lab_tracker/routes/goals.py:147"}, "fullDescription": {"text": "`@router.patch` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1928143a598572ed", "name": "FastAPI DELETE `delete_goal` without auth dependency \u2014 src/lab_tracker/routes/goals.py:164", "shortDescription": {"text": "FastAPI DELETE `delete_goal` without auth dependency \u2014 src/lab_tracker/routes/goals.py:164"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-623c0a447ab723e0", "name": "FastAPI POST `link_node_to_goal` without auth dependency \u2014 src/lab_tracker/routes/goals.py:170", "shortDescription": {"text": "FastAPI POST `link_node_to_goal` without auth dependency \u2014 src/lab_tracker/routes/goals.py:170"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3a9755dd138f4da2", "name": "FastAPI PATCH `update_goal_link` without auth dependency \u2014 src/lab_tracker/routes/goals.py:187", "shortDescription": {"text": "FastAPI PATCH `update_goal_link` without auth dependency \u2014 src/lab_tracker/routes/goals.py:187"}, "fullDescription": {"text": "`@router.patch` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ed4e1ac6b563c86c", "name": "FastAPI DELETE `delete_goal_link` without auth dependency \u2014 src/lab_tracker/routes/goals.py:205", "shortDescription": {"text": "FastAPI DELETE `delete_goal_link` without auth dependency \u2014 src/lab_tracker/routes/goals.py:205"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f678e7458d39f330", "name": "FastAPI POST `create_ownership_reassignment` without auth dependency \u2014 src/lab_tracker/routes/ownership.py:25", "shortDescription": {"text": "FastAPI POST `create_ownership_reassignment` without auth dependency \u2014 src/lab_tracker/routes/ownership.py:25"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b0036c0e8ed0a153", "name": "FastAPI POST `create_dataset` without auth dependency \u2014 src/lab_tracker/routes/datasets.py:36", "shortDescription": {"text": "FastAPI POST `create_dataset` without auth dependency \u2014 src/lab_tracker/routes/datasets.py:36"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1cab35469e9cd204", "name": "FastAPI PATCH `update_dataset` without auth dependency \u2014 src/lab_tracker/routes/datasets.py:83", "shortDescription": {"text": "FastAPI PATCH `update_dataset` without auth dependency \u2014 src/lab_tracker/routes/datasets.py:83"}, "fullDescription": {"text": "`@router.patch` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ce7ce58f635f3079", "name": "FastAPI DELETE `delete_dataset` without auth dependency \u2014 src/lab_tracker/routes/datasets.py:98", "shortDescription": {"text": "FastAPI DELETE `delete_dataset` without auth dependency \u2014 src/lab_tracker/routes/datasets.py:98"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c0c7b3815777b9f1", "name": "FastAPI PATCH `update_batch_settings` without auth dependency \u2014 src/lab_tracker/routes/graph_batches.py:98", "shortDescription": {"text": "FastAPI PATCH `update_batch_settings` without auth dependency \u2014 src/lab_tracker/routes/graph_batches.py:98"}, "fullDescription": {"text": "`@router.patch` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-315bfe7baf4c42f6", "name": "FastAPI POST `run_batch_now` without auth dependency \u2014 src/lab_tracker/routes/graph_batches.py:137", "shortDescription": {"text": "FastAPI POST `run_batch_now` without auth dependency \u2014 src/lab_tracker/routes/graph_batches.py:137"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4398c87350564e4c", "name": "FastAPI POST `run_due_batches` without auth dependency \u2014 src/lab_tracker/routes/graph_batches.py:161", "shortDescription": {"text": "FastAPI POST `run_due_batches` without auth dependency \u2014 src/lab_tracker/routes/graph_batches.py:161"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8925b1ba43942da7", "name": "FastAPI POST `refresh_auth` without auth dependency \u2014 src/lab_tracker/routes/auth.py:77", "shortDescription": {"text": "FastAPI POST `refresh_auth` without auth dependency \u2014 src/lab_tracker/routes/auth.py:77"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b3379140d21ff2cf", "name": "FastAPI POST `create_graph_draft` without auth dependency \u2014 src/lab_tracker/routes/graph_drafts.py:39", "shortDescription": {"text": "FastAPI POST `create_graph_draft` without auth dependency \u2014 src/lab_tracker/routes/graph_drafts.py:39"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1b0bbb183329025d", "name": "FastAPI PATCH `update_graph_draft_operation` without auth dependency \u2014 src/lab_tracker/routes/graph_drafts.py:98", "shortDescription": {"text": "FastAPI PATCH `update_graph_draft_operation` without auth dependency \u2014 src/lab_tracker/routes/graph_drafts.py:98"}, "fullDescription": {"text": "`@router.patch` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-95b6204035d77233", "name": "FastAPI POST `submit_graph_draft` without auth dependency \u2014 src/lab_tracker/routes/graph_drafts.py:121", "shortDescription": {"text": "FastAPI POST `submit_graph_draft` without auth dependency \u2014 src/lab_tracker/routes/graph_drafts.py:121"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a7ef5620e1adace4", "name": "FastAPI POST `review_graph_draft` without auth dependency \u2014 src/lab_tracker/routes/graph_drafts.py:133", "shortDescription": {"text": "FastAPI POST `review_graph_draft` without auth dependency \u2014 src/lab_tracker/routes/graph_drafts.py:133"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eb0a4bd19e3c8cb9", "name": "FastAPI POST `revise_graph_draft` without auth dependency \u2014 src/lab_tracker/routes/graph_drafts.py:151", "shortDescription": {"text": "FastAPI POST `revise_graph_draft` without auth dependency \u2014 src/lab_tracker/routes/graph_drafts.py:151"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e14ad64bcc869d24", "name": "FastAPI POST `commit_graph_draft` without auth dependency \u2014 src/lab_tracker/routes/graph_drafts.py:175", "shortDescription": {"text": "FastAPI POST `commit_graph_draft` without auth dependency \u2014 src/lab_tracker/routes/graph_drafts.py:175"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-13fe894bcac53a54", "name": "FastAPI POST `create_supervision_edge` without auth dependency \u2014 src/lab_tracker/routes/supervision.py:50", "shortDescription": {"text": "FastAPI POST `create_supervision_edge` without auth dependency \u2014 src/lab_tracker/routes/supervision.py:50"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9f55955b5d597539", "name": "FastAPI PATCH `update_supervision_edge` without auth dependency \u2014 src/lab_tracker/routes/supervision.py:75", "shortDescription": {"text": "FastAPI PATCH `update_supervision_edge` without auth dependency \u2014 src/lab_tracker/routes/supervision.py:75"}, "fullDescription": {"text": "`@router.patch` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-df6a650a799e7e6e", "name": "FastAPI DELETE `delete_supervision_edge` without auth dependency \u2014 src/lab_tracker/routes/supervision.py:96", "shortDescription": {"text": "FastAPI DELETE `delete_supervision_edge` without auth dependency \u2014 src/lab_tracker/routes/supervision.py:96"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-93d94adc5d732e78", "name": "FastAPI POST `create_question` without auth dependency \u2014 src/lab_tracker/routes/questions.py:38", "shortDescription": {"text": "FastAPI POST `create_question` without auth dependency \u2014 src/lab_tracker/routes/questions.py:38"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4e2a93d6b8fbe3cf", "name": "FastAPI PATCH `update_question` without auth dependency \u2014 src/lab_tracker/routes/questions.py:95", "shortDescription": {"text": "FastAPI PATCH `update_question` without auth dependency \u2014 src/lab_tracker/routes/questions.py:95"}, "fullDescription": {"text": "`@router.patch` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-566f97a05758e3fc", "name": "FastAPI POST `refactor_question` without auth dependency \u2014 src/lab_tracker/routes/questions.py:111", "shortDescription": {"text": "FastAPI POST `refactor_question` without auth dependency \u2014 src/lab_tracker/routes/questions.py:111"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-83396b9912ab167a", "name": "FastAPI DELETE `delete_question` without auth dependency \u2014 src/lab_tracker/routes/questions.py:167", "shortDescription": {"text": "FastAPI DELETE `delete_question` without auth dependency \u2014 src/lab_tracker/routes/questions.py:167"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-096cbe408cd1b1c5", "name": "FastAPI POST `create_visualization` without auth dependency \u2014 src/lab_tracker/routes/visualizations.py:55", "shortDescription": {"text": "FastAPI POST `create_visualization` without auth dependency \u2014 src/lab_tracker/routes/visualizations.py:55"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4bf222dfc1e44bec", "name": "FastAPI POST `upload_visualization_file` without auth dependency \u2014 src/lab_tracker/routes/visualizations.py:102", "shortDescription": {"text": "FastAPI POST `upload_visualization_file` without auth dependency \u2014 src/lab_tracker/routes/visualizations.py:102"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-52b6812a93c4269b", "name": "FastAPI PATCH `update_visualization` without auth dependency \u2014 src/lab_tracker/routes/visualizations.py:201", "shortDescription": {"text": "FastAPI PATCH `update_visualization` without auth dependency \u2014 src/lab_tracker/routes/visualizations.py:201"}, "fullDescription": {"text": "`@router.patch` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a6d34205cc81eb71", "name": "FastAPI DELETE `delete_visualization` without auth dependency \u2014 src/lab_tracker/routes/visualizations.py:217", "shortDescription": {"text": "FastAPI DELETE `delete_visualization` without auth dependency \u2014 src/lab_tracker/routes/visualizations.py:217"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c56faef02b59e373", "name": "FastAPI POST `create_claim` without auth dependency \u2014 src/lab_tracker/routes/claims.py:30", "shortDescription": {"text": "FastAPI POST `create_claim` without auth dependency \u2014 src/lab_tracker/routes/claims.py:30"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4617f3a1c00f8830", "name": "FastAPI PATCH `update_claim` without auth dependency \u2014 src/lab_tracker/routes/claims.py:82", "shortDescription": {"text": "FastAPI PATCH `update_claim` without auth dependency \u2014 src/lab_tracker/routes/claims.py:82"}, "fullDescription": {"text": "`@router.patch` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7c315117cbb195f4", "name": "FastAPI DELETE `delete_claim` without auth dependency \u2014 src/lab_tracker/routes/claims.py:99", "shortDescription": {"text": "FastAPI DELETE `delete_claim` without auth dependency \u2014 src/lab_tracker/routes/claims.py:99"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ab18a3738df3430c", "name": "FastAPI POST `create_group` without auth dependency \u2014 src/lab_tracker/routes/groups.py:43", "shortDescription": {"text": "FastAPI POST `create_group` without auth dependency \u2014 src/lab_tracker/routes/groups.py:43"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7e495b5635fd8b72", "name": "FastAPI PATCH `update_group` without auth dependency \u2014 src/lab_tracker/routes/groups.py:80", "shortDescription": {"text": "FastAPI PATCH `update_group` without auth dependency \u2014 src/lab_tracker/routes/groups.py:80"}, "fullDescription": {"text": "`@router.patch` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f71a22f8658f3b8a", "name": "FastAPI DELETE `delete_group` without auth dependency \u2014 src/lab_tracker/routes/groups.py:93", "shortDescription": {"text": "FastAPI DELETE `delete_group` without auth dependency \u2014 src/lab_tracker/routes/groups.py:93"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-971800f53fbf5470", "name": "FastAPI POST `create_group_member` without auth dependency \u2014 src/lab_tracker/routes/groups.py:118", "shortDescription": {"text": "FastAPI POST `create_group_member` without auth dependency \u2014 src/lab_tracker/routes/groups.py:118"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ad1fdaef7825f2a4", "name": "FastAPI PATCH `update_group_member` without auth dependency \u2014 src/lab_tracker/routes/groups.py:138", "shortDescription": {"text": "FastAPI PATCH `update_group_member` without auth dependency \u2014 src/lab_tracker/routes/groups.py:138"}, "fullDescription": {"text": "`@router.patch` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0d3edf1a1b45a94b", "name": "FastAPI DELETE `delete_group_member` without auth dependency \u2014 src/lab_tracker/routes/groups.py:157", "shortDescription": {"text": "FastAPI DELETE `delete_group_member` without auth dependency \u2014 src/lab_tracker/routes/groups.py:157"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-781f5aaf27cfcbdb", "name": "FastAPI POST `bulk_upsert_group_project_memberships` without auth dependency \u2014 src/lab_tracker/routes/groups.py:170", "shortDescription": {"text": "FastAPI POST `bulk_upsert_group_project_memberships` without auth dependency \u2014 src/lab_tracker/routes/groups.py:170"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7f52fd4b69cdfaf1", "name": "FastAPI DELETE `bulk_delete_group_project_memberships` without auth dependency \u2014 src/lab_tracker/routes/groups.py:190", "shortDescription": {"text": "FastAPI DELETE `bulk_delete_group_project_memberships` without auth dependency \u2014 src/lab_tracker/routes/groups.py:190"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9c5f2623500cf0f7", "name": "FastAPI POST `create_analysis` without auth dependency \u2014 src/lab_tracker/routes/analyses.py:43", "shortDescription": {"text": "FastAPI POST `create_analysis` without auth dependency \u2014 src/lab_tracker/routes/analyses.py:43"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4aa5558653c5aed3", "name": "FastAPI PATCH `update_analysis` without auth dependency \u2014 src/lab_tracker/routes/analyses.py:94", "shortDescription": {"text": "FastAPI PATCH `update_analysis` without auth dependency \u2014 src/lab_tracker/routes/analyses.py:94"}, "fullDescription": {"text": "`@router.patch` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3dc49c49737326dc", "name": "FastAPI POST `commit_analysis` without auth dependency \u2014 src/lab_tracker/routes/analyses.py:107", "shortDescription": {"text": "FastAPI POST `commit_analysis` without auth dependency \u2014 src/lab_tracker/routes/analyses.py:107"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e9db74e825dd9757", "name": "FastAPI DELETE `delete_analysis` without auth dependency \u2014 src/lab_tracker/routes/analyses.py:127", "shortDescription": {"text": "FastAPI DELETE `delete_analysis` without auth dependency \u2014 src/lab_tracker/routes/analyses.py:127"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dd91cfc0d84d5361", "name": "FastAPI POST `create_note` without auth dependency \u2014 src/lab_tracker/routes/notes.py:56", "shortDescription": {"text": "FastAPI POST `create_note` without auth dependency \u2014 src/lab_tracker/routes/notes.py:56"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-785edeeae1ea2c14", "name": "FastAPI POST `upload_note_file` without auth dependency \u2014 src/lab_tracker/routes/notes.py:75", "shortDescription": {"text": "FastAPI POST `upload_note_file` without auth dependency \u2014 src/lab_tracker/routes/notes.py:75"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c56212d3e3f8f621", "name": "FastAPI POST `quick_capture_note` without auth dependency \u2014 src/lab_tracker/routes/notes.py:116", "shortDescription": {"text": "FastAPI POST `quick_capture_note` without auth dependency \u2014 src/lab_tracker/routes/notes.py:116"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-28ec3b0d7c7c7b87", "name": "FastAPI PATCH `update_note` without auth dependency \u2014 src/lab_tracker/routes/notes.py:208", "shortDescription": {"text": "FastAPI PATCH `update_note` without auth dependency \u2014 src/lab_tracker/routes/notes.py:208"}, "fullDescription": {"text": "`@router.patch` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0b4e27b78d173299", "name": "FastAPI POST `transcribe_note` without auth dependency \u2014 src/lab_tracker/routes/notes.py:223", "shortDescription": {"text": "FastAPI POST `transcribe_note` without auth dependency \u2014 src/lab_tracker/routes/notes.py:223"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-de2b24f63fdc6dcf", "name": "FastAPI DELETE `delete_note` without auth dependency \u2014 src/lab_tracker/routes/notes.py:246", "shortDescription": {"text": "FastAPI DELETE `delete_note` without auth dependency \u2014 src/lab_tracker/routes/notes.py:246"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0ac0b2f20930c83f", "name": "FastAPI POST `upload_dataset_file` without auth dependency \u2014 src/lab_tracker/routes/dataset_files.py:56", "shortDescription": {"text": "FastAPI POST `upload_dataset_file` without auth dependency \u2014 src/lab_tracker/routes/dataset_files.py:56"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6f80506a30892ed9", "name": "FastAPI DELETE `delete_dataset_file` without auth dependency \u2014 src/lab_tracker/routes/dataset_files.py:194", "shortDescription": {"text": "FastAPI DELETE `delete_dataset_file` without auth dependency \u2014 src/lab_tracker/routes/dataset_files.py:194"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-08b2208688cd9a5a", "name": "FastAPI POST `create_session` without auth dependency \u2014 src/lab_tracker/routes/sessions.py:45", "shortDescription": {"text": "FastAPI POST `create_session` without auth dependency \u2014 src/lab_tracker/routes/sessions.py:45"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-25b68f55db0905d5", "name": "FastAPI PATCH `update_session` without auth dependency \u2014 src/lab_tracker/routes/sessions.py:95", "shortDescription": {"text": "FastAPI PATCH `update_session` without auth dependency \u2014 src/lab_tracker/routes/sessions.py:95"}, "fullDescription": {"text": "`@router.patch` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0d05d8924124b41b", "name": "FastAPI POST `create_session_output` without auth dependency \u2014 src/lab_tracker/routes/sessions.py:125", "shortDescription": {"text": "FastAPI POST `create_session_output` without auth dependency \u2014 src/lab_tracker/routes/sessions.py:125"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-120cec9c17ef17a9", "name": "FastAPI DELETE `delete_session` without auth dependency \u2014 src/lab_tracker/routes/sessions.py:147", "shortDescription": {"text": "FastAPI DELETE `delete_session` without auth dependency \u2014 src/lab_tracker/routes/sessions.py:147"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d4d8879b45665d94", "name": "FastAPI POST `promote_operational_session` without auth dependency \u2014 src/lab_tracker/routes/sessions.py:155", "shortDescription": {"text": "FastAPI POST `promote_operational_session` without auth dependency \u2014 src/lab_tracker/routes/sessions.py:155"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1dd1a5dfb45e19e7", "name": "FastAPI POST `promote_operational_session_to_dataset` without auth dependency \u2014 src/lab_tracker/routes/sessions.py:171", "shortDescription": {"text": "FastAPI POST `promote_operational_session_to_dataset` without auth dependency \u2014 src/lab_tracker/routes/sessions.py:171"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`src/lab_tracker/app_parts/frontend.py` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2ed628e7048329e1", "name": "Unused endpoint: GET /app/sw.js", "shortDescription": {"text": "Unused endpoint: GET /app/sw.js"}, "fullDescription": {"text": "`src/lab_tracker/app_parts/frontend.py` declares `GET /app/sw.js` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-81e05bdb1b0a7253", "name": "Unused endpoint: POST /app/share-target", "shortDescription": {"text": "Unused endpoint: POST /app/share-target"}, "fullDescription": {"text": "`src/lab_tracker/app_parts/frontend.py` declares `POST /app/share-target` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-769398a8a95bd693", "name": "Unused endpoint: GET /app", "shortDescription": {"text": "Unused endpoint: GET /app"}, "fullDescription": {"text": "`src/lab_tracker/app_parts/frontend.py` declares `GET /app` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-84382cce6d6c3791", "name": "Unused endpoint: GET /app/{_path:path}", "shortDescription": {"text": "Unused endpoint: GET /app/{_path:path}"}, "fullDescription": {"text": "`src/lab_tracker/app_parts/frontend.py` declares `GET /app/{_path:path}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b2fb03327ec7e635", "name": "Unused endpoint: GET /readiness", "shortDescription": {"text": "Unused endpoint: GET /readiness"}, "fullDescription": {"text": "`src/lab_tracker/app_parts/observability.py` declares `GET /readiness` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-58666816ba500374", "name": "Unused endpoint: POST /projects", "shortDescription": {"text": "Unused endpoint: POST /projects"}, "fullDescription": {"text": "`src/lab_tracker/routes/projects.py` declares `POST /projects` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c1e1ee09590b0a49", "name": "Unused endpoint: GET /projects", "shortDescription": {"text": "Unused endpoint: GET /projects"}, "fullDescription": {"text": "`src/lab_tracker/routes/projects.py` declares `GET /projects` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8276e9a42f5cb13a", "name": "Unused endpoint: GET /projects/{project_id}", "shortDescription": {"text": "Unused endpoint: GET /projects/{project_id}"}, "fullDescription": {"text": "`src/lab_tracker/routes/projects.py` declares `GET /projects/{project_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d1293cf39e94c35a", "name": "Unused endpoint: PATCH /projects/{project_id}", "shortDescription": {"text": "Unused endpoint: PATCH /projects/{project_id}"}, "fullDescription": {"text": "`src/lab_tracker/routes/projects.py` declares `PATCH /projects/{project_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-757ec6dc0d84b69c", "name": "Unused endpoint: DELETE /projects/{project_id}", "shortDescription": {"text": "Unused endpoint: DELETE /projects/{project_id}"}, "fullDescription": {"text": "`src/lab_tracker/routes/projects.py` declares `DELETE /projects/{project_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-225d6d117d7d0dba", "name": "Unused endpoint: GET /projects/{project_id}/members", "shortDescription": {"text": "Unused endpoint: GET /projects/{project_id}/members"}, "fullDescription": {"text": "`src/lab_tracker/routes/projects.py` declares `GET /projects/{project_id}/members` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-50b1378c17a252f6", "name": "Unused endpoint: POST /projects/{project_id}/members", "shortDescription": {"text": "Unused endpoint: POST /projects/{project_id}/members"}, "fullDescription": {"text": "`src/lab_tracker/routes/projects.py` declares `POST /projects/{project_id}/members` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ca196e8b59512f0c", "name": "Unused endpoint: PATCH /projects/{project_id}/members/{user_id:uuid}", "shortDescription": {"text": "Unused endpoint: PATCH /projects/{project_id}/members/{user_id:uuid}"}, "fullDescription": {"text": "`src/lab_tracker/routes/projects.py` declares `PATCH /projects/{project_id}/members/{user_id:uuid}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bd75f26e3a08baf9", "name": "Unused endpoint: DELETE /projects/{project_id}/members/{user_id:uuid}", "shortDescription": {"text": "Unused endpoint: DELETE /projects/{project_id}/members/{user_id:uuid}"}, "fullDescription": {"text": "`src/lab_tracker/routes/projects.py` declares `DELETE /projects/{project_id}/members/{user_id:uuid}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-93de8f95bbd1b060", "name": "Unused endpoint: POST /auth/devices/enrollment", "shortDescription": {"text": "Unused endpoint: POST /auth/devices/enrollment"}, "fullDescription": {"text": "`src/lab_tracker/routes/device_auth.py` declares `POST /auth/devices/enrollment` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5b180035bc798392", "name": "Unused endpoint: POST /auth/devices/consume", "shortDescription": {"text": "Unused endpoint: POST /auth/devices/consume"}, "fullDescription": {"text": "`src/lab_tracker/routes/device_auth.py` declares `POST /auth/devices/consume` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3adf6df4f909d004", "name": "Unused endpoint: GET /auth/devices", "shortDescription": {"text": "Unused endpoint: GET /auth/devices"}, "fullDescription": {"text": "`src/lab_tracker/routes/device_auth.py` declares `GET /auth/devices` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c28b274261b2adcc", "name": "Unused endpoint: DELETE /auth/devices/{device_token_id}", "shortDescription": {"text": "Unused endpoint: DELETE /auth/devices/{device_token_id}"}, "fullDescription": {"text": "`src/lab_tracker/routes/device_auth.py` declares `DELETE /auth/devices/{device_token_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8d648a3c553b4f50", "name": "Unused endpoint: GET /projects/{project_id}/graph", "shortDescription": {"text": "Unused endpoint: GET /projects/{project_id}/graph"}, "fullDescription": {"text": "`src/lab_tracker/routes/project_graph.py` declares `GET /projects/{project_id}/graph` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-578732581a99640a", "name": "Unused endpoint: GET /projects/{project_id}/graph/mermaid", "shortDescription": {"text": "Unused endpoint: GET /projects/{project_id}/graph/mermaid"}, "fullDescription": {"text": "`src/lab_tracker/routes/project_graph.py` declares `GET /projects/{project_id}/graph/mermaid` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f53c8d6d8c64b7ca", "name": "Unused endpoint: POST /assistant/decision-context", "shortDescription": {"text": "Unused endpoint: POST /assistant/decision-context"}, "fullDescription": {"text": "`src/lab_tracker/routes/assistant.py` declares `POST /assistant/decision-context` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-827392c0226680bd", "name": "Unused endpoint: POST /goals", "shortDescription": {"text": "Unused endpoint: POST /goals"}, "fullDescription": {"text": "`src/lab_tracker/routes/goals.py` declares `POST /goals` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-50207204ed781305", "name": "Unused endpoint: GET /goals", "shortDescription": {"text": "Unused endpoint: GET /goals"}, "fullDescription": {"text": "`src/lab_tracker/routes/goals.py` declares `GET /goals` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5e6f79c00b0cc2ff", "name": "Unused endpoint: POST /projects/{project_id}/goals", "shortDescription": {"text": "Unused endpoint: POST /projects/{project_id}/goals"}, "fullDescription": {"text": "`src/lab_tracker/routes/goals.py` declares `POST /projects/{project_id}/goals` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f5d18f19be278e73", "name": "Unused endpoint: GET /projects/{project_id}/goals", "shortDescription": {"text": "Unused endpoint: GET /projects/{project_id}/goals"}, "fullDescription": {"text": "`src/lab_tracker/routes/goals.py` declares `GET /projects/{project_id}/goals` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-14524f93aef43d33", "name": "Unused endpoint: GET /goals/{goal_id}", "shortDescription": {"text": "Unused endpoint: GET /goals/{goal_id}"}, "fullDescription": {"text": "`src/lab_tracker/routes/goals.py` declares `GET /goals/{goal_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bdd5c4430ca79530", "name": "Unused endpoint: PATCH /goals/{goal_id}", "shortDescription": {"text": "Unused endpoint: PATCH /goals/{goal_id}"}, "fullDescription": {"text": "`src/lab_tracker/routes/goals.py` declares `PATCH /goals/{goal_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8ff63a67ae08f4e2", "name": "Unused endpoint: DELETE /goals/{goal_id}", "shortDescription": {"text": "Unused endpoint: DELETE /goals/{goal_id}"}, "fullDescription": {"text": "`src/lab_tracker/routes/goals.py` declares `DELETE /goals/{goal_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2a2d790f319d468b", "name": "Unused endpoint: POST /goals/{goal_id}/links", "shortDescription": {"text": "Unused endpoint: POST /goals/{goal_id}/links"}, "fullDescription": {"text": "`src/lab_tracker/routes/goals.py` declares `POST /goals/{goal_id}/links` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ee8cdc7a486b151d", "name": "Unused endpoint: PATCH /goals/{goal_id}/links/{link_id}", "shortDescription": {"text": "Unused endpoint: PATCH /goals/{goal_id}/links/{link_id}"}, "fullDescription": {"text": "`src/lab_tracker/routes/goals.py` declares `PATCH /goals/{goal_id}/links/{link_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e9ce0a800b030b3a", "name": "Unused endpoint: DELETE /goals/{goal_id}/links/{link_id}", "shortDescription": {"text": "Unused endpoint: DELETE /goals/{goal_id}/links/{link_id}"}, "fullDescription": {"text": "`src/lab_tracker/routes/goals.py` declares `DELETE /goals/{goal_id}/links/{link_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b78e6c8302d570a3", "name": "Unused endpoint: GET /projects/{project_id}/nodes/{entity_type}/{entity_id}/goals", "shortDescription": {"text": "Unused endpoint: GET /projects/{project_id}/nodes/{entity_type}/{entity_id}/goals"}, "fullDescription": {"text": "`src/lab_tracker/routes/goals.py` declares `GET /projects/{project_id}/nodes/{entity_type}/{entity_id}/goals` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eb6846a75f1e65f4", "name": "Unused endpoint: POST /ownership-reassignments", "shortDescription": {"text": "Unused endpoint: POST /ownership-reassignments"}, "fullDescription": {"text": "`src/lab_tracker/routes/ownership.py` declares `POST /ownership-reassignments` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dbcc8d857a1e87ae", "name": "Unused endpoint: GET /ownership-reassignments", "shortDescription": {"text": "Unused endpoint: GET /ownership-reassignments"}, "fullDescription": {"text": "`src/lab_tracker/routes/ownership.py` declares `GET /ownership-reassignments` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1951b9b7cc604826", "name": "Unused endpoint: GET /ownership-reassignments/{reassignment_id:uuid}", "shortDescription": {"text": "Unused endpoint: GET /ownership-reassignments/{reassignment_id:uuid}"}, "fullDescription": {"text": "`src/lab_tracker/routes/ownership.py` declares `GET /ownership-reassignments/{reassignment_id:uuid}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7b3e81a6180fbf70", "name": "Unused endpoint: POST /datasets", "shortDescription": {"text": "Unused endpoint: POST /datasets"}, "fullDescription": {"text": "`src/lab_tracker/routes/datasets.py` declares `POST /datasets` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5b6173f3f7bbf753", "name": "Unused endpoint: GET /datasets", "shortDescription": {"text": "Unused endpoint: GET /datasets"}, "fullDescription": {"text": "`src/lab_tracker/routes/datasets.py` declares `GET /datasets` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9068b2a1e04b7cff", "name": "Unused endpoint: GET /datasets/{dataset_id}", "shortDescription": {"text": "Unused endpoint: GET /datasets/{dataset_id}"}, "fullDescription": {"text": "`src/lab_tracker/routes/datasets.py` declares `GET /datasets/{dataset_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4933d95584491f6f", "name": "Unused endpoint: PATCH /datasets/{dataset_id}", "shortDescription": {"text": "Unused endpoint: PATCH /datasets/{dataset_id}"}, "fullDescription": {"text": "`src/lab_tracker/routes/datasets.py` declares `PATCH /datasets/{dataset_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a3121f4efc3a2ffd", "name": "Unused endpoint: DELETE /datasets/{dataset_id}", "shortDescription": {"text": "Unused endpoint: DELETE /datasets/{dataset_id}"}, "fullDescription": {"text": "`src/lab_tracker/routes/datasets.py` declares `DELETE /datasets/{dataset_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8eefec7059b0a0ce", "name": "Unused endpoint: GET /batches", "shortDescription": {"text": "Unused endpoint: GET /batches"}, "fullDescription": {"text": "`src/lab_tracker/routes/graph_batches.py` declares `GET /batches` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d61535b1868c0894", "name": "Unused endpoint: GET /batches/{change_set_id:uuid}", "shortDescription": {"text": "Unused endpoint: GET /batches/{change_set_id:uuid}"}, "fullDescription": {"text": "`src/lab_tracker/routes/graph_batches.py` declares `GET /batches/{change_set_id:uuid}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f1123e337f8e174e", "name": "Unused endpoint: GET /projects/{project_id:uuid}/graph-draft-batch-settings", "shortDescription": {"text": "Unused endpoint: GET /projects/{project_id:uuid}/graph-draft-batch-settings"}, "fullDescription": {"text": "`src/lab_tracker/routes/graph_batches.py` declares `GET /projects/{project_id:uuid}/graph-draft-batch-settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d42ad61959a2771a", "name": "Unused endpoint: PATCH /projects/{project_id:uuid}/graph-draft-batch-settings", "shortDescription": {"text": "Unused endpoint: PATCH /projects/{project_id:uuid}/graph-draft-batch-settings"}, "fullDescription": {"text": "`src/lab_tracker/routes/graph_batches.py` declares `PATCH /projects/{project_id:uuid}/graph-draft-batch-settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c4900c2eb789b86b", "name": "Unused endpoint: GET /batches/runs", "shortDescription": {"text": "Unused endpoint: GET /batches/runs"}, "fullDescription": {"text": "`src/lab_tracker/routes/graph_batches.py` declares `GET /batches/runs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3c8311925abca621", "name": "Unused endpoint: POST /batches/run-now", "shortDescription": {"text": "Unused endpoint: POST /batches/run-now"}, "fullDescription": {"text": "`src/lab_tracker/routes/graph_batches.py` declares `POST /batches/run-now` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ebe79fbc0c00c8b8", "name": "Unused endpoint: POST /batches/run-due", "shortDescription": {"text": "Unused endpoint: POST /batches/run-due"}, "fullDescription": {"text": "`src/lab_tracker/routes/graph_batches.py` declares `POST /batches/run-due` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8292c0931391749a", "name": "Unused endpoint: POST /auth/register", "shortDescription": {"text": "Unused endpoint: POST /auth/register"}, "fullDescription": {"text": "`src/lab_tracker/routes/auth.py` declares `POST /auth/register` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8fdbacfe9430a6ed", "name": "Unused endpoint: POST /auth/login", "shortDescription": {"text": "Unused endpoint: POST /auth/login"}, "fullDescription": {"text": "`src/lab_tracker/routes/auth.py` declares `POST /auth/login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/18864"}, "properties": {"repository": "SamuelBrudner/lab-tracker", "repoUrl": "https://github.com/SamuelBrudner/lab-tracker", "branch": "main"}, "results": [{"ruleId": "foundry_unresolved_feedback", "level": "warning", "message": {"text": "Foundry mined unresolved feedback: SamuelBrudner/lab-tracker"}, "properties": {"repobilityId": 423259, "scanner": "foundry_dataset", "fingerprint": "0b9b85e6e6894727c4718c019d83befe146b0e456f4ba9deb879434e6ae1b09d", "category": "practices", "severity": "medium", "confidence": 0.7, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Human feedback without linked fix evidence", "intent": "Negative/unresolved examples that should not be hallucinated into fixes.", "labels": {"test_or_ci": 8, "api_or_backend": 5, "docs_or_claims": 2, "schema_or_data": 1, "ui_or_frontend": 41, "source_or_other": 1, "human_feedback_general": 1, "unlinked_human_feedback": 1, "thread_needs_classification": 2, "issue_or_pull_request_thread": 1, "ambiguous_needs_more_evidence": 3}, "source": "graph_query_export", "motif_id": "unlinked_feedback_needs_evidence", "outcomes": {"ambiguous_needs_more_evidence": 6}, "polarity": "bad", "query_id": "unresolved_feedback", "severity": "medium", "ci_labels": {}, "synthetic": false, "edge_count": 93, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "thread_touches_file": 58, "chain_has_link_quality": 3, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 12, "thread_has_comment_chain": 1, "comment_chain_touches_file": 12, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 67, "node_types": {"repo": 1, "thread": 1, "comment": 1, "pr_file": 58, "fix_outcome": 1, "issue_chain": 1, "link_quality": 3, "comment_chain": 1}, "query_type": "motif_query", "thread_key": "SamuelBrudner/lab-tracker#6", "issue_number": "6", "quality_tiers": {"unresolved": 3}, "repo_full_name": "SamuelBrudner/lab-tracker", "training_usage": "negative_or_unresolved", "source_motif_id": "graph-pattern-motif-thread-5fb0c01a78aa68a2", "graph_gold_label": "needs_more_evidence", "changed_file_labels": {"test_or_ci": 32, "api_or_backend": 20, "docs_or_claims": 8, "schema_or_data": 4, "ui_or_frontend": 164, "source_or_other": 4}}, "text": "Graph query export: Human feedback without linked fix evidence\nQuery id: unresolved_feedback\nQuery type: motif_query\nIntent: Negative/unresolved examples that should not be hallucinated into fixes.\nMotif: unlinked_feedback_needs_evidence\nTraining usage: negative_or_unresolved\nGraph gold label: needs_more_evidence\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#6\nEvidence:\nGraph motif: Human feedback exists without a linked fix\nMotif id: unlinked_feedback_needs_evidence\nPolarity: bad\nTraining usage: negative_or_unresolved\nSeverity: medium\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#6\nGraph gold label: needs_more_evidence\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: SamuelBrudner/lab-tracker#6\nRepo: SamuelBrudner/lab-tracker\nIssue/PR number: 6\nGraph consistency label: needs_more_evidence\nNodes: 67\nEdges: 93\nNode types: {'pr_file': 58, 'link_quality': 3, 'thread': 1, 'repo': 1, 'comment': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'thread_touches_file': 58, 'comment_chain_touches_file': 12, 'issue_chain_touches_file': 12, 'chain_has_link_quality': 3, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'ui_or_frontend': 41, 'test_or_ci': 8, 'api_or_backend': 5, 'ambiguous_needs_more_evidence': 3, 'docs_or_claims': 2, 'thread_needs_classification': 2, 'issue_or_pull_request_thread': 1, 'human_feedback_general': 1, 'source_or_other': 1, 'schema_or_data': 1, 'unlinked_human_feedback': 1}\nOutcomes: {'ambiguous_needs_more_evidence': 6}\nQuality tiers: {'unresolved': 3}\nCI labels: {}\nCurriculum targets:\n- Teach models to preserve unresolved human feedback instead of hallucinating fixes.\n- Build issue-to-regression examples where no accepted fix exists yet.\nAssumption checks:\n- Can a commit be linked by issue number, SHA, changed path, or time window?\n- If no link exists, is this explicitly labelled unresolved?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/SamuelBrudner/lab-tracker", "source_id": "graph-query-motif_query-66c09e30696965f2", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/unresolved_feedback/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "SamuelBrudner/lab-tracker", "source_dataset": "graph_queries/unresolved_feedback", "training_usage": "negative_or_unresolved"}}}, {"ruleId": "foundry_unresolved_feedback", "level": "warning", "message": {"text": "Foundry mined unresolved feedback: SamuelBrudner/lab-tracker"}, "properties": {"repobilityId": 423258, "scanner": "foundry_dataset", "fingerprint": "5f958f3d1c29ae422be3ad41b12aaf87b38ddd86a4c9ac5331798cc7f947342b", "category": "practices", "severity": "medium", "confidence": 0.7, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Human feedback without linked fix evidence", "intent": "Negative/unresolved examples that should not be hallucinated into fixes.", "labels": {"test_or_ci": 4, "api_or_backend": 21, "docs_or_claims": 3, "schema_or_data": 1, "ui_or_frontend": 62, "source_or_other": 7, "dependency_or_build": 2, "human_feedback_general": 1, "unlinked_human_feedback": 1, "thread_needs_classification": 2, "issue_or_pull_request_thread": 1, "ambiguous_needs_more_evidence": 3}, "source": "graph_query_export", "motif_id": "unlinked_feedback_needs_evidence", "outcomes": {"ambiguous_needs_more_evidence": 6}, "polarity": "bad", "query_id": "unresolved_feedback", "severity": "medium", "ci_labels": {}, "synthetic": false, "edge_count": 135, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "thread_touches_file": 100, "chain_has_link_quality": 3, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 12, "thread_has_comment_chain": 1, "comment_chain_touches_file": 12, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 109, "node_types": {"repo": 1, "thread": 1, "comment": 1, "pr_file": 100, "fix_outcome": 1, "issue_chain": 1, "link_quality": 3, "comment_chain": 1}, "query_type": "motif_query", "thread_key": "SamuelBrudner/lab-tracker#5", "issue_number": "5", "quality_tiers": {"unresolved": 3}, "repo_full_name": "SamuelBrudner/lab-tracker", "training_usage": "negative_or_unresolved", "source_motif_id": "graph-pattern-motif-thread-b083302b226a5775", "graph_gold_label": "needs_more_evidence", "changed_file_labels": {"test_or_ci": 16, "api_or_backend": 84, "docs_or_claims": 12, "schema_or_data": 4, "ui_or_frontend": 248, "source_or_other": 28, "dependency_or_build": 8}}, "text": "Graph query export: Human feedback without linked fix evidence\nQuery id: unresolved_feedback\nQuery type: motif_query\nIntent: Negative/unresolved examples that should not be hallucinated into fixes.\nMotif: unlinked_feedback_needs_evidence\nTraining usage: negative_or_unresolved\nGraph gold label: needs_more_evidence\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#5\nEvidence:\nGraph motif: Human feedback exists without a linked fix\nMotif id: unlinked_feedback_needs_evidence\nPolarity: bad\nTraining usage: negative_or_unresolved\nSeverity: medium\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#5\nGraph gold label: needs_more_evidence\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: SamuelBrudner/lab-tracker#5\nRepo: SamuelBrudner/lab-tracker\nIssue/PR number: 5\nGraph consistency label: needs_more_evidence\nNodes: 109\nEdges: 135\nNode types: {'pr_file': 100, 'link_quality': 3, 'thread': 1, 'repo': 1, 'comment': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'thread_touches_file': 100, 'comment_chain_touches_file': 12, 'issue_chain_touches_file': 12, 'chain_has_link_quality': 3, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'ui_or_frontend': 62, 'api_or_backend': 21, 'source_or_other': 7, 'test_or_ci': 4, 'docs_or_claims': 3, 'ambiguous_needs_more_evidence': 3, 'dependency_or_build': 2, 'thread_needs_classification': 2, 'issue_or_pull_request_thread': 1, 'human_feedback_general': 1, 'schema_or_data': 1, 'unlinked_human_feedback': 1}\nOutcomes: {'ambiguous_needs_more_evidence': 6}\nQuality tiers: {'unresolved': 3}\nCI labels: {}\nCurriculum targets:\n- Teach models to preserve unresolved human feedback instead of hallucinating fixes.\n- Build issue-to-regression examples where no accepted fix exists yet.\nAssumption checks:\n- Can a commit be linked by issue number, SHA, changed path, or time window?\n- If no link exists, is this explicitly labelled unresolved?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/SamuelBrudner/lab-tracker", "source_id": "graph-query-motif_query-ffc6d78331b6217e", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/unresolved_feedback/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "SamuelBrudner/lab-tracker", "source_dataset": "graph_queries/unresolved_feedback", "training_usage": "negative_or_unresolved"}}}, {"ruleId": "foundry_unresolved_feedback", "level": "warning", "message": {"text": "Foundry mined unresolved feedback: SamuelBrudner/lab-tracker"}, "properties": {"repobilityId": 423257, "scanner": "foundry_dataset", "fingerprint": "40c02b50fe87cd1989bd923fa6abf4ebb72ca54f93eba99650465c42b448d165", "category": "practices", "severity": "medium", "confidence": 0.7, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Human feedback without linked fix evidence", "intent": "Negative/unresolved examples that should not be hallucinated into fixes.", "labels": {"test_or_ci": 26, "api_or_backend": 9, "docs_or_claims": 2, "schema_or_data": 1, "ui_or_frontend": 33, "source_or_other": 14, "dependency_or_build": 2, "human_feedback_general": 1, "unlinked_human_feedback": 1, "thread_needs_classification": 2, "issue_or_pull_request_thread": 1, "ambiguous_needs_more_evidence": 3}, "source": "graph_query_export", "motif_id": "unlinked_feedback_needs_evidence", "outcomes": {"ambiguous_needs_more_evidence": 6}, "polarity": "bad", "query_id": "unresolved_feedback", "severity": "medium", "ci_labels": {}, "synthetic": false, "edge_count": 122, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "thread_touches_file": 87, "chain_has_link_quality": 3, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 12, "thread_has_comment_chain": 1, "comment_chain_touches_file": 12, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 96, "node_types": {"repo": 1, "thread": 1, "comment": 1, "pr_file": 87, "fix_outcome": 1, "issue_chain": 1, "link_quality": 3, "comment_chain": 1}, "query_type": "motif_query", "thread_key": "SamuelBrudner/lab-tracker#3", "issue_number": "3", "quality_tiers": {"unresolved": 3}, "repo_full_name": "SamuelBrudner/lab-tracker", "training_usage": "negative_or_unresolved", "source_motif_id": "graph-pattern-motif-thread-6df357be66fad9b4", "graph_gold_label": "needs_more_evidence", "changed_file_labels": {"test_or_ci": 104, "api_or_backend": 36, "docs_or_claims": 8, "schema_or_data": 4, "ui_or_frontend": 132, "source_or_other": 56, "dependency_or_build": 8}}, "text": "Graph query export: Human feedback without linked fix evidence\nQuery id: unresolved_feedback\nQuery type: motif_query\nIntent: Negative/unresolved examples that should not be hallucinated into fixes.\nMotif: unlinked_feedback_needs_evidence\nTraining usage: negative_or_unresolved\nGraph gold label: needs_more_evidence\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#3\nEvidence:\nGraph motif: Human feedback exists without a linked fix\nMotif id: unlinked_feedback_needs_evidence\nPolarity: bad\nTraining usage: negative_or_unresolved\nSeverity: medium\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#3\nGraph gold label: needs_more_evidence\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: SamuelBrudner/lab-tracker#3\nRepo: SamuelBrudner/lab-tracker\nIssue/PR number: 3\nGraph consistency label: needs_more_evidence\nNodes: 96\nEdges: 122\nNode types: {'pr_file': 87, 'link_quality': 3, 'thread': 1, 'repo': 1, 'comment': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'thread_touches_file': 87, 'comment_chain_touches_file': 12, 'issue_chain_touches_file': 12, 'chain_has_link_quality': 3, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'ui_or_frontend': 33, 'test_or_ci': 26, 'source_or_other': 14, 'api_or_backend': 9, 'ambiguous_needs_more_evidence': 3, 'docs_or_claims': 2, 'dependency_or_build': 2, 'thread_needs_classification': 2, 'issue_or_pull_request_thread': 1, 'human_feedback_general': 1, 'schema_or_data': 1, 'unlinked_human_feedback': 1}\nOutcomes: {'ambiguous_needs_more_evidence': 6}\nQuality tiers: {'unresolved': 3}\nCI labels: {}\nCurriculum targets:\n- Teach models to preserve unresolved human feedback instead of hallucinating fixes.\n- Build issue-to-regression examples where no accepted fix exists yet.\nAssumption checks:\n- Can a commit be linked by issue number, SHA, changed path, or time window?\n- If no link exists, is this explicitly labelled unresolved?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/SamuelBrudner/lab-tracker", "source_id": "graph-query-motif_query-0eac7a10e4bcfbe7", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/unresolved_feedback/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "SamuelBrudner/lab-tracker", "source_dataset": "graph_queries/unresolved_feedback", "training_usage": "negative_or_unresolved"}}}, {"ruleId": "foundry_unresolved_feedback", "level": "warning", "message": {"text": "Foundry mined unresolved feedback: SamuelBrudner/lab-tracker"}, "properties": {"repobilityId": 423256, "scanner": "foundry_dataset", "fingerprint": "7ba9bfcfdaaaaa2a3f5b216ac438aeab5b91f99febdd44496a1e4e1476ff3160", "category": "practices", "severity": "medium", "confidence": 0.7, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Human feedback without linked fix evidence", "intent": "Negative/unresolved examples that should not be hallucinated into fixes.", "labels": {"test_or_ci": 1, "api_or_backend": 1, "ui_or_frontend": 4, "source_or_other": 3, "human_feedback_general": 1, "unlinked_human_feedback": 1, "thread_needs_classification": 2, "issue_or_pull_request_thread": 1, "ambiguous_needs_more_evidence": 3}, "source": "graph_query_export", "motif_id": "unlinked_feedback_needs_evidence", "outcomes": {"ambiguous_needs_more_evidence": 6}, "polarity": "bad", "query_id": "unresolved_feedback", "severity": "medium", "ci_labels": {}, "synthetic": false, "edge_count": 38, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "thread_touches_file": 9, "chain_has_link_quality": 3, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 9, "thread_has_comment_chain": 1, "comment_chain_touches_file": 9, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 18, "node_types": {"repo": 1, "thread": 1, "comment": 1, "pr_file": 9, "fix_outcome": 1, "issue_chain": 1, "link_quality": 3, "comment_chain": 1}, "query_type": "motif_query", "thread_key": "SamuelBrudner/lab-tracker#2", "issue_number": "2", "quality_tiers": {"unresolved": 3}, "repo_full_name": "SamuelBrudner/lab-tracker", "training_usage": "negative_or_unresolved", "source_motif_id": "graph-pattern-motif-thread-25e0fec0f8d872f0", "graph_gold_label": "needs_more_evidence", "changed_file_labels": {"test_or_ci": 4, "api_or_backend": 4, "ui_or_frontend": 16, "source_or_other": 12}}, "text": "Graph query export: Human feedback without linked fix evidence\nQuery id: unresolved_feedback\nQuery type: motif_query\nIntent: Negative/unresolved examples that should not be hallucinated into fixes.\nMotif: unlinked_feedback_needs_evidence\nTraining usage: negative_or_unresolved\nGraph gold label: needs_more_evidence\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#2\nEvidence:\nGraph motif: Human feedback exists without a linked fix\nMotif id: unlinked_feedback_needs_evidence\nPolarity: bad\nTraining usage: negative_or_unresolved\nSeverity: medium\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#2\nGraph gold label: needs_more_evidence\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: SamuelBrudner/lab-tracker#2\nRepo: SamuelBrudner/lab-tracker\nIssue/PR number: 2\nGraph consistency label: needs_more_evidence\nNodes: 18\nEdges: 38\nNode types: {'pr_file': 9, 'link_quality': 3, 'thread': 1, 'repo': 1, 'comment': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'thread_touches_file': 9, 'comment_chain_touches_file': 9, 'issue_chain_touches_file': 9, 'chain_has_link_quality': 3, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'ui_or_frontend': 4, 'source_or_other': 3, 'ambiguous_needs_more_evidence': 3, 'thread_needs_classification': 2, 'issue_or_pull_request_thread': 1, 'human_feedback_general': 1, 'api_or_backend': 1, 'test_or_ci': 1, 'unlinked_human_feedback': 1}\nOutcomes: {'ambiguous_needs_more_evidence': 6}\nQuality tiers: {'unresolved': 3}\nCI labels: {}\nCurriculum targets:\n- Teach models to preserve unresolved human feedback instead of hallucinating fixes.\n- Build issue-to-regression examples where no accepted fix exists yet.\nAssumption checks:\n- Can a commit be linked by issue number, SHA, changed path, or time window?\n- If no link exists, is this explicitly labelled unresolved?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/SamuelBrudner/lab-tracker", "source_id": "graph-query-motif_query-5d54a7fd0577eda7", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/unresolved_feedback/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "SamuelBrudner/lab-tracker", "source_dataset": "graph_queries/unresolved_feedback", "training_usage": "negative_or_unresolved"}}}, {"ruleId": "foundry_unresolved_feedback", "level": "warning", "message": {"text": "Foundry mined unresolved feedback: SamuelBrudner/lab-tracker"}, "properties": {"repobilityId": 423255, "scanner": "foundry_dataset", "fingerprint": "fa282e7293e46dfd9e124ccb341e6999b5e0a976f5973187a1e9ef39e1a328b1", "category": "practices", "severity": "medium", "confidence": 0.7, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Human feedback without linked fix evidence", "intent": "Negative/unresolved examples that should not be hallucinated into fixes.", "labels": {"docs_or_claims": 1, "schema_or_data": 3, "source_or_other": 14, "dependency_or_build": 1, "human_feedback_general": 1, "unlinked_human_feedback": 1, "thread_needs_classification": 2, "issue_or_pull_request_thread": 1, "ambiguous_needs_more_evidence": 3}, "source": "graph_query_export", "motif_id": "unlinked_feedback_needs_evidence", "outcomes": {"ambiguous_needs_more_evidence": 6}, "polarity": "bad", "query_id": "unresolved_feedback", "severity": "medium", "ci_labels": {}, "synthetic": false, "edge_count": 54, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "thread_touches_file": 19, "chain_has_link_quality": 3, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 12, "thread_has_comment_chain": 1, "comment_chain_touches_file": 12, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 28, "node_types": {"repo": 1, "thread": 1, "comment": 1, "pr_file": 19, "fix_outcome": 1, "issue_chain": 1, "link_quality": 3, "comment_chain": 1}, "query_type": "motif_query", "thread_key": "SamuelBrudner/lab-tracker#1", "issue_number": "1", "quality_tiers": {"unresolved": 3}, "repo_full_name": "SamuelBrudner/lab-tracker", "training_usage": "negative_or_unresolved", "source_motif_id": "graph-pattern-motif-thread-742388c6086402fb", "graph_gold_label": "needs_more_evidence", "changed_file_labels": {"docs_or_claims": 4, "schema_or_data": 12, "source_or_other": 56, "dependency_or_build": 4}}, "text": "Graph query export: Human feedback without linked fix evidence\nQuery id: unresolved_feedback\nQuery type: motif_query\nIntent: Negative/unresolved examples that should not be hallucinated into fixes.\nMotif: unlinked_feedback_needs_evidence\nTraining usage: negative_or_unresolved\nGraph gold label: needs_more_evidence\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#1\nEvidence:\nGraph motif: Human feedback exists without a linked fix\nMotif id: unlinked_feedback_needs_evidence\nPolarity: bad\nTraining usage: negative_or_unresolved\nSeverity: medium\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#1\nGraph gold label: needs_more_evidence\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: SamuelBrudner/lab-tracker#1\nRepo: SamuelBrudner/lab-tracker\nIssue/PR number: 1\nGraph consistency label: needs_more_evidence\nNodes: 28\nEdges: 54\nNode types: {'pr_file': 19, 'link_quality': 3, 'thread': 1, 'repo': 1, 'comment': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'thread_touches_file': 19, 'comment_chain_touches_file': 12, 'issue_chain_touches_file': 12, 'chain_has_link_quality': 3, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'source_or_other': 14, 'schema_or_data': 3, 'ambiguous_needs_more_evidence': 3, 'thread_needs_classification': 2, 'issue_or_pull_request_thread': 1, 'human_feedback_general': 1, 'docs_or_claims': 1, 'dependency_or_build': 1, 'unlinked_human_feedback': 1}\nOutcomes: {'ambiguous_needs_more_evidence': 6}\nQuality tiers: {'unresolved': 3}\nCI labels: {}\nCurriculum targets:\n- Teach models to preserve unresolved human feedback instead of hallucinating fixes.\n- Build issue-to-regression examples where no accepted fix exists yet.\nAssumption checks:\n- Can a commit be linked by issue number, SHA, changed path, or time window?\n- If no link exists, is this explicitly labelled unresolved?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/SamuelBrudner/lab-tracker", "source_id": "graph-query-motif_query-dd53345bac95e29e", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/unresolved_feedback/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "SamuelBrudner/lab-tracker", "source_dataset": "graph_queries/unresolved_feedback", "training_usage": "negative_or_unresolved"}}}, {"ruleId": "foundry_blueprint_gap", "level": "warning", "message": {"text": "Foundry mined blueprint gap alignment: SamuelBrudner/lab-tracker"}, "properties": {"repobilityId": 394977, "scanner": "foundry_dataset", "fingerprint": "7a94e0c587fbd20a1332f6e0e7a9c8aa7ff08e44826556a164ac7dc629336ae9", "category": "tech_debt", "severity": "medium", "confidence": 0.7, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Human feedback aligned with blueprint or architecture gaps", "intent": "Curriculum-gap examples connecting issue threads to helicopter-view gaps.", "labels": {"test_ci_gap": 1, "docs_or_chore": 1, "docs_or_claims": 3, "source_or_other": 1, "dependency_or_build": 1, "partial blueprint fit": 2, "mostly follows blueprint": 1, "claimed_resolved_unverified": 3, "issue_or_pull_request_thread": 1, "blueprint_human_gap_alignment": 2, "blueprint_human_gap_disagreement": 1, "human_reported_issue_then_fix_attempt": 1, "thread_has_human_issue_and_fix_context": 2}, "source": "graph_query_export", "motif_id": "blueprint_gap_alignment", "outcomes": {"claimed_resolved_unverified": 6}, "polarity": "mixed", "query_id": "blueprint_gap_alignment", "severity": "medium", "ci_labels": {}, "synthetic": false, "edge_count": 37, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "thread_touches_file": 4, "alignment_uses_comment": 3, "alignment_uses_finding": 3, "chain_has_link_quality": 6, "comment_aligns_finding": 3, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 4, "thread_has_comment_chain": 1, "comment_chain_links_commit": 2, "comment_chain_touches_file": 4, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 24, "node_types": {"repo": 1, "commit": 2, "thread": 1, "comment": 1, "pr_file": 4, "alignment": 3, "fix_outcome": 1, "issue_chain": 1, "link_quality": 6, "comment_chain": 1, "blueprint_finding": 3}, "query_type": "motif_query", "thread_key": "SamuelBrudner/lab-tracker#7", "issue_number": "7", "quality_tiers": {"assumption_check": 3, "weak_supervision": 3}, "repo_full_name": "SamuelBrudner/lab-tracker", "training_usage": "curriculum_gap", "source_motif_id": "graph-pattern-motif-thread-abf782bc688561fa", "graph_gold_label": "weak_supervision_needs_review", "changed_file_labels": {"docs_or_claims": 12, "source_or_other": 4}}, "text": "Graph query export: Human feedback aligned with blueprint or architecture gaps\nQuery id: blueprint_gap_alignment\nQuery type: motif_query\nIntent: Curriculum-gap examples connecting issue threads to helicopter-view gaps.\nMotif: blueprint_gap_alignment\nTraining usage: curriculum_gap\nGraph gold label: weak_supervision_needs_review\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#7\nEvidence:\nGraph motif: Human feedback aligns with blueprint or architecture gaps\nMotif id: blueprint_gap_alignment\nPolarity: mixed\nTraining usage: curriculum_gap\nSeverity: medium\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#7\nGraph gold label: weak_supervision_needs_review\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: SamuelBrudner/lab-tracker#7\nRepo: SamuelBrudner/lab-tracker\nIssue/PR number: 7\nGraph consistency label: weak_supervision_needs_review\nNodes: 24\nEdges: 37\nNode types: {'link_quality': 6, 'pr_file': 4, 'alignment': 3, 'blueprint_finding': 3, 'commit': 2, 'thread': 1, 'repo': 1, 'comment': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'chain_has_link_quality': 6, 'thread_touches_file': 4, 'comment_chain_touches_file': 4, 'issue_chain_touches_file': 4, 'alignment_uses_comment': 3, 'alignment_uses_finding': 3, 'comment_aligns_finding': 3, 'comment_chain_links_commit': 2, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'docs_or_claims': 3, 'claimed_resolved_unverified': 3, 'thread_has_human_issue_and_fix_context': 2, 'blueprint_human_gap_alignment': 2, 'partial blueprint fit': 2, 'issue_or_pull_request_thread': 1, 'test_ci_gap': 1, 'source_or_other': 1, 'human_reported_issue_then_fix_attempt': 1, 'docs_or_chore': 1, 'dependency_or_build': 1, 'blueprint_human_gap_disagreement': 1, 'mostly follows blueprint': 1}\nOutcomes: {'claimed_resolved_unverified': 6}\nQuality tiers: {'weak_supervision': 3, 'assumption_check': 3}\nCI labels: {}\nCurriculum targets:\n- Use helicopter-view architecture/schema/design evidence beside issue threads.\n- Teach models to compare requested product class against implementation layers.\nAssumption checks:\n- Which blueprint layer is absent: frontend, API, data, auth, tests, or deployment?\n- Does human feedback confirm the same architectural gap?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/SamuelBrudner/lab-tracker", "source_id": "graph-query-motif_query-7426448abc01c05e", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/blueprint_gap_alignment/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "SamuelBrudner/lab-tracker", "source_dataset": "graph_queries/blueprint_gap_alignment", "training_usage": "curriculum_gap"}}}, {"ruleId": "foundry_assumption_check", "level": "warning", "message": {"text": "Foundry mined assumption checks: SamuelBrudner/lab-tracker"}, "properties": {"repobilityId": 374143, "scanner": "foundry_dataset", "fingerprint": "178500af5783f4212570a8407097d0a8b7c1702c6d9e847273d52462c0e35e9b", "category": "practices", "severity": "medium", "confidence": 0.62, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "comment_chain_pattern_product", "source": "comment_chain_pattern_miner", "product": "assumption_checks", "synthetic": false, "thread_key": "SamuelBrudner/lab-tracker#7", "human_labels": ["docs_or_claims", "source_or_other", "test_ci_gap"], "issue_number": "7", "thread_label": "thread_has_human_issue_and_fix_context", "outcome_label": "claimed_resolved_unverified", "source_backed": true, "max_confidence": 0.777, "repo_full_name": "SamuelBrudner/lab-tracker", "training_usage": "weak_supervision", "confidence_tier": "weak_supervision", "source_chain_id": "evidence-chain-issue_chain-fac89aad0ad38f1f", "helicopter_views": {"schemas": 2}, "artifact_families": {"ci": 2, "docs": 4, "schemas": 1, "generated_claims": 1}, "source_chain_kind": "issue_chain", "changed_file_count": 4, "source_graph_label": "source_backed_multi_signal_graph", "changed_file_labels": {"docs_or_claims": 3, "source_or_other": 1}, "linked_commit_count": 2, "helicopter_view_count": 2, "source_artifact_count": 8, "classification_reasons": ["source_graph_has_real_artifacts", "source_graph_has_verification_artifacts", "repo_has_isolated_helicopter_views", "link_quality_weak_supervision", "high_risk_human_feedback_label"], "linked_ci_commit_count": 0, "verification_artifact_count": 3, "design_schema_api_artifact_count": 1}, "text": "Comment chain pattern product: assumption_checks\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#7\nOutcome: claimed_resolved_unverified\nThread label: thread_has_human_issue_and_fix_context\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, repo_has_isolated_helicopter_views, link_quality_weak_supervision, high_risk_human_feedback_label\nChain evidence:\nIssue/PR evidence chain: SamuelBrudner/lab-tracker#7\nRepo: SamuelBrudner/lab-tracker\nThread label: thread_has_human_issue_and_fix_context\nOutcome: claimed_resolved_unverified\nComment count: 1\nLinked commit count: 2\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 4\nLabels: {'test_ci_gap': 1}\nPolarities: {'bad': 1}\nChanged file labels: {'source_or_other': 1, 'docs_or_claims': 3}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-b7f998bb7ce05e21\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"test_ci_gap\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.com/SamuelBrudner/lab-tracker/pull/7\",\n    \"text\": \"GitHub feedback: test_ci_gap\\nPolarity: bad\\nKind: pull_request_body\\nRepo: SamuelBrudner/lab-tracker\\nAuthor: SamuelBrudner (User)\\nURL: https://github.com/SamuelBrudner/lab-tracker/pull/7\\nTitle: docs: rewrite README as a slim, enjoyable front door\\nBody:\\n## What & why\\n\\nThe README was a 402-line wall that front-loaded friendly framing but then buried readers in install / Postgres / config / MCP / Dolt detail. This makes the front door an **easy, almost-enjoyable read** whose job is to get a scientist *using* the product \u2014 technical depth moves into docs you dig into.\\n\\n## README: 402 \u2192 ~80 lines\\n\\nReads top-to-bottom as: the missing-*why* hook \u2192 **See it live** (demo + screenshots) \u2192 plain-language **What you can do** (no `parent_question_ids`/`GraphChangeSet` jargon) \u2192 **Who it's for** \u2192 a zero-install **Scientists start here** \u2192 a one-button **Set it up for your lab** \u2192 a tidy **Documentation** map.\\n\\n## Relocated depth into docs/\\n\\n- **`docs/setup.md`** (new) \u2014 install (uv + pip), `lab-tracker serve`, Postgres/LAN runtime, frontend build, migrations, first-admin, validation.\\n- **`docs/configuration.md`** (new) \u2014 full `LAB_TRACKER_*` reference, the multimodal graph-draft-review config, an\"\n  }\n]\nChanged files:\n[\n  {\n    \"id\": \"github-pr-file-file-bc2f2f9dfb11209c\",\n    \"filename\": \".beads/issues.jsonl\",\n    \"label\": \"source_or_other\",\n    \"status\": \"modified\",\n    \"additions\": 10,\n    \"deletions\": 3,\n    \"changes\": 13,\n    \"blob_url\": \"https://github.com/SamuelBrudner/lab-tracker/blob/e83af6518313b175775075cfc9b16bb51c58bd58/.beads%2Fissues.jsonl\"\n  },\n  {\n    \"id\": \"github-pr-file-file-e71f1810ff9fc789\",\n    \"filename\": \"README.md\",\n    \"label\": \"docs_or_claims\",\n    \"status\": \"modified\",\n    \"additions\": 49,\n    \"deletions\": 371,\n    \"changes\": 420,\n    \"blob_url\": \"https://github.com/SamuelBrudner/lab-tracker/blob/e83af6518313b17577\n[truncated by importer]", "source": "foundry_mined_dataset", "repo_url": "https://github.com/SamuelBrudner/lab-tracker", "source_id": "comment-chain-pattern-assumption_checks-b2355d5de360a5f3", "synthetic": false, "gold_label": "", "graph_label": "source_backed_multi_signal_graph", "source_path": "/data/distillate/foundry_data/comment_chain_patterns/assumption_checks/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "SamuelBrudner/lab-tracker", "source_dataset": "comment_chain_patterns/assumption_checks", "training_usage": "weak_supervision"}}}, {"ruleId": "foundry_assumption_check", "level": "warning", "message": {"text": "Foundry mined assumption checks: SamuelBrudner/lab-tracker"}, "properties": {"repobilityId": 374142, "scanner": "foundry_dataset", "fingerprint": "4efa7049013f0d71c936242f3464a3a6bdcab24d5a1fb4b1dd68955d3e4042ec", "category": "practices", "severity": "medium", "confidence": 0.62, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "comment_chain_pattern_product", "source": "comment_chain_pattern_miner", "product": "assumption_checks", "synthetic": false, "thread_key": "SamuelBrudner/lab-tracker#6", "human_labels": ["api_or_backend", "docs_or_claims", "human_feedback_general", "schema_or_data", "source_or_other", "test_or_ci", "ui_or_frontend"], "issue_number": "6", "thread_label": "thread_needs_classification", "outcome_label": "ambiguous_needs_more_evidence", "source_backed": true, "max_confidence": 0.0, "repo_full_name": "SamuelBrudner/lab-tracker", "training_usage": "negative_or_unresolved", "confidence_tier": "unresolved", "source_chain_id": "evidence-chain-issue_chain-95f33a65b8b2e264", "helicopter_views": {"schemas": 2}, "artifact_families": {"ci": 2, "docs": 4, "schemas": 1, "generated_claims": 1}, "source_chain_kind": "issue_chain", "changed_file_count": 58, "source_graph_label": "source_backed_multi_signal_graph", "changed_file_labels": {"test_or_ci": 8, "api_or_backend": 5, "docs_or_claims": 2, "schema_or_data": 1, "ui_or_frontend": 41, "source_or_other": 1}, "linked_commit_count": 0, "helicopter_view_count": 2, "source_artifact_count": 8, "classification_reasons": ["source_graph_has_real_artifacts", "source_graph_has_verification_artifacts", "repo_has_isolated_helicopter_views", "link_quality_unresolved"], "linked_ci_commit_count": 0, "verification_artifact_count": 3, "design_schema_api_artifact_count": 1}, "text": "Comment chain pattern product: assumption_checks\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#6\nOutcome: ambiguous_needs_more_evidence\nThread label: thread_needs_classification\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, repo_has_isolated_helicopter_views, link_quality_unresolved\nChain evidence:\nIssue/PR evidence chain: SamuelBrudner/lab-tracker#6\nRepo: SamuelBrudner/lab-tracker\nThread label: thread_needs_classification\nOutcome: ambiguous_needs_more_evidence\nComment count: 1\nLinked commit count: 0\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 58\nLabels: {'human_feedback_general': 1}\nPolarities: {'neutral': 1}\nChanged file labels: {'source_or_other': 1, 'docs_or_claims': 2, 'api_or_backend': 5, 'ui_or_frontend': 41, 'test_or_ci': 8, 'schema_or_data': 1}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-d356e22bafae3eb0\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"human_feedback_general\",\n    \"polarity\": \"neutral\",\n    \"url\": \"https://github.com/SamuelBrudner/lab-tracker/pull/6\",\n    \"text\": \"GitHub feedback: human_feedback_general\\nPolarity: neutral\\nKind: pull_request_body\\nRepo: SamuelBrudner/lab-tracker\\nAuthor: SamuelBrudner (User)\\nURL: https://github.com/SamuelBrudner/lab-tracker/pull/6\\nTitle: Codex/cleanup sprint retire upload and residue\\nBody:\\n\"\n  }\n]\nChanged files:\n[\n  {\n    \"id\": \"github-pr-file-file-915f0a6b57244a79\",\n    \"filename\": \".env.example\",\n    \"label\": \"source_or_other\",\n    \"status\": \"modified\",\n    \"additions\": 0,\n    \"deletions\": 3,\n    \"changes\": 3,\n    \"blob_url\": \"https://github.com/SamuelBrudner/lab-tracker/blob/045d49e83094af7e1ac51f7fbf061811ddc12662/.env.example\"\n  },\n  {\n    \"id\": \"github-pr-file-file-a5e5a5c9e586606f\",\n    \"filename\": \"README.md\",\n    \"label\": \"docs_or_claims\",\n    \"status\": \"modified\",\n    \"additions\": 2,\n    \"deletions\": 2,\n    \"changes\": 4,\n    \"blob_url\": \"https://github.com/SamuelBrudner/lab-tracker/blob/045d49e83094af7e1ac51f7fbf061811ddc12662/README.md\"\n  },\n  {\n    \"id\": \"github-pr-file-file-f4fddf6d819663a2\",\n    \"filename\": \"docs/retained-v1-surface.md\",\n    \"label\": \"docs_or_claims\",\n    \"status\": \"modified\",\n    \"additions\": 1,\n    \"deletions\": 1,\n    \"changes\": 2,\n    \"blob_url\": \"https://github.com/SamuelBrudner/lab-tracker/blob/045d49e83094af7e1ac51f7fbf061811ddc12662/docs%2Fretained-v1-surface.md\"\n  },\n  {\n    \"id\": \"github-pr-file-file-89dbfa7620195718\",\n    \"filename\": \"src/lab_tracker/api.py\",\n    \"label\": \"api_or_backend\",\n    \"status\": \"modified\",\n    \"additions\": 59,\n    \"deletions\": 49,\n    \"changes\": 108,\n    \"blob_url\": \"https://github.com/SamuelBrudner/lab-tracker/blob/045d49e83094af7e1ac51f7fbf061811ddc12662/src%2Flab_tracker%2Fapi.py\"\n  },\n  {\n    \"id\": \"github-pr-file-file-1dc6eea810c9b932\",\n    \"filename\": \"src/lab_tracker/app.py\",\n    \"label\": \"ui_or_frontend\",\n    \"status\": \"modified\",\n    \"addit\n[truncated by importer]", "source": "foundry_mined_dataset", "repo_url": "https://github.com/SamuelBrudner/lab-tracker", "source_id": "comment-chain-pattern-assumption_checks-d265db59f04970e6", "synthetic": false, "gold_label": "", "graph_label": "source_backed_multi_signal_graph", "source_path": "/data/distillate/foundry_data/comment_chain_patterns/assumption_checks/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "SamuelBrudner/lab-tracker", "source_dataset": "comment_chain_patterns/assumption_checks", "training_usage": "negative_or_unresolved"}}}, {"ruleId": "foundry_assumption_check", "level": "warning", "message": {"text": "Foundry mined assumption checks: SamuelBrudner/lab-tracker"}, "properties": {"repobilityId": 374141, "scanner": "foundry_dataset", "fingerprint": "671d936dad1499803faf954935eb0d62d83dbbda2eadc0d3bd5c7caa600b78f6", "category": "practices", "severity": "medium", "confidence": 0.62, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "comment_chain_pattern_product", "source": "comment_chain_pattern_miner", "product": "assumption_checks", "synthetic": false, "thread_key": "SamuelBrudner/lab-tracker#5", "human_labels": ["api_or_backend", "dependency_or_build", "docs_or_claims", "human_feedback_general", "schema_or_data", "source_or_other", "test_or_ci", "ui_or_frontend"], "issue_number": "5", "thread_label": "thread_needs_classification", "outcome_label": "ambiguous_needs_more_evidence", "source_backed": true, "max_confidence": 0.0, "repo_full_name": "SamuelBrudner/lab-tracker", "training_usage": "negative_or_unresolved", "confidence_tier": "unresolved", "source_chain_id": "evidence-chain-issue_chain-06c95a5ec1e80712", "helicopter_views": {"schemas": 2}, "artifact_families": {"ci": 2, "docs": 4, "schemas": 1, "generated_claims": 1}, "source_chain_kind": "issue_chain", "changed_file_count": 100, "source_graph_label": "source_backed_multi_signal_graph", "changed_file_labels": {"test_or_ci": 4, "api_or_backend": 21, "docs_or_claims": 3, "schema_or_data": 1, "ui_or_frontend": 62, "source_or_other": 7, "dependency_or_build": 2}, "linked_commit_count": 0, "helicopter_view_count": 2, "source_artifact_count": 8, "classification_reasons": ["source_graph_has_real_artifacts", "source_graph_has_verification_artifacts", "repo_has_isolated_helicopter_views", "link_quality_unresolved"], "linked_ci_commit_count": 0, "verification_artifact_count": 3, "design_schema_api_artifact_count": 1}, "text": "Comment chain pattern product: assumption_checks\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#5\nOutcome: ambiguous_needs_more_evidence\nThread label: thread_needs_classification\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, repo_has_isolated_helicopter_views, link_quality_unresolved\nChain evidence:\nIssue/PR evidence chain: SamuelBrudner/lab-tracker#5\nRepo: SamuelBrudner/lab-tracker\nThread label: thread_needs_classification\nOutcome: ambiguous_needs_more_evidence\nComment count: 1\nLinked commit count: 0\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 100\nLabels: {'human_feedback_general': 1}\nPolarities: {'neutral': 1}\nChanged file labels: {'docs_or_claims': 3, 'source_or_other': 7, 'dependency_or_build': 2, 'ui_or_frontend': 62, 'api_or_backend': 21, 'test_or_ci': 4, 'schema_or_data': 1}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-efb5d01f02983e89\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"human_feedback_general\",\n    \"polarity\": \"neutral\",\n    \"url\": \"https://github.com/SamuelBrudner/lab-tracker/pull/5\",\n    \"text\": \"GitHub feedback: human_feedback_general\\nPolarity: neutral\\nKind: pull_request_body\\nRepo: SamuelBrudner/lab-tracker\\nAuthor: SamuelBrudner (User)\\nURL: https://github.com/SamuelBrudner/lab-tracker/pull/5\\nTitle: Run/20260422 175423 009dcf6f\\nBody:\\n\"\n  }\n]\nChanged files:\n[\n  {\n    \"id\": \"github-pr-file-file-cff110ba481165f5\",\n    \"filename\": \"README.md\",\n    \"label\": \"docs_or_claims\",\n    \"status\": \"modified\",\n    \"additions\": 31,\n    \"deletions\": 20,\n    \"changes\": 51,\n    \"blob_url\": \"https://github.com/SamuelBrudner/lab-tracker/blob/96653caa46ab5fb00706d421b1e27cda07c72f93/README.md\"\n  },\n  {\n    \"id\": \"github-pr-file-file-19510b3e00e3455b\",\n    \"filename\": \"alembic/versions/0010_query_indexes.py\",\n    \"label\": \"source_or_other\",\n    \"status\": \"added\",\n    \"additions\": 74,\n    \"deletions\": 0,\n    \"changes\": 74,\n    \"blob_url\": \"https://github.com/SamuelBrudner/lab-tracker/blob/96653caa46ab5fb00706d421b1e27cda07c72f93/alembic%2Fversions%2F0010_query_indexes.py\"\n  },\n  {\n    \"id\": \"github-pr-file-file-adfe7bdbea2e251a\",\n    \"filename\": \"alembic/versions/0011_note_raw_asset_fields.py\",\n    \"label\": \"source_or_other\",\n    \"status\": \"added\",\n    \"additions\": 30,\n    \"deletions\": 0,\n    \"changes\": 30,\n    \"blob_url\": \"https://github.com/SamuelBrudner/lab-tracker/blob/96653caa46ab5fb00706d421b1e27cda07c72f93/alembic%2Fversions%2F0011_note_raw_asset_fields.py\"\n  },\n  {\n    \"id\": \"github-pr-file-file-180718761bb24ddb\",\n    \"filename\": \"alembic/versions/0012_manifest_and_note_metadata.py\",\n    \"label\": \"source_or_other\",\n    \"status\": \"added\",\n    \"additions\": 48,\n    \"deletions\": 0,\n    \"changes\": 48,\n    \"blob_url\": \"https://github.com/SamuelBrudner/lab-tracker/blob/96653caa46ab5fb00706d421b1e27cda07c72f93/alembic%2Fversions%2F0012_manifest_and_note_metadata.py\"\n  },\n[truncated by importer]", "source": "foundry_mined_dataset", "repo_url": "https://github.com/SamuelBrudner/lab-tracker", "source_id": "comment-chain-pattern-assumption_checks-1ab3ab2bf0245df5", "synthetic": false, "gold_label": "", "graph_label": "source_backed_multi_signal_graph", "source_path": "/data/distillate/foundry_data/comment_chain_patterns/assumption_checks/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "SamuelBrudner/lab-tracker", "source_dataset": "comment_chain_patterns/assumption_checks", "training_usage": "negative_or_unresolved"}}}, {"ruleId": "foundry_assumption_check", "level": "warning", "message": {"text": "Foundry mined assumption checks: SamuelBrudner/lab-tracker"}, "properties": {"repobilityId": 374140, "scanner": "foundry_dataset", "fingerprint": "c744a9f571c3ddfc9178883cf0ac72fc93ae59e688a7894b63aab2d55cfb1e95", "category": "practices", "severity": "medium", "confidence": 0.62, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "comment_chain_pattern_product", "source": "comment_chain_pattern_miner", "product": "assumption_checks", "synthetic": false, "thread_key": "SamuelBrudner/lab-tracker#4", "human_labels": ["api_or_backend", "dependency_or_build", "runtime_failure", "source_or_other", "test_or_ci", "ui_or_frontend"], "issue_number": "4", "thread_label": "thread_has_human_issue_and_fix_context", "outcome_label": "claimed_resolved_unverified", "source_backed": true, "max_confidence": 0.59, "repo_full_name": "SamuelBrudner/lab-tracker", "training_usage": "weak_supervision", "confidence_tier": "weak_supervision", "source_chain_id": "evidence-chain-issue_chain-1f1e6593cfa1b3b8", "helicopter_views": {"schemas": 2}, "artifact_families": {"ci": 2, "docs": 4, "schemas": 1, "generated_claims": 1}, "source_chain_kind": "issue_chain", "changed_file_count": 44, "source_graph_label": "source_backed_multi_signal_graph", "changed_file_labels": {"test_or_ci": 10, "api_or_backend": 5, "ui_or_frontend": 24, "source_or_other": 2, "dependency_or_build": 3}, "linked_commit_count": 1, "helicopter_view_count": 2, "source_artifact_count": 8, "classification_reasons": ["source_graph_has_real_artifacts", "source_graph_has_verification_artifacts", "repo_has_isolated_helicopter_views", "link_quality_weak_supervision", "high_risk_human_feedback_label"], "linked_ci_commit_count": 0, "verification_artifact_count": 3, "design_schema_api_artifact_count": 1}, "text": "Comment chain pattern product: assumption_checks\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#4\nOutcome: claimed_resolved_unverified\nThread label: thread_has_human_issue_and_fix_context\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, repo_has_isolated_helicopter_views, link_quality_weak_supervision, high_risk_human_feedback_label\nChain evidence:\nIssue/PR evidence chain: SamuelBrudner/lab-tracker#4\nRepo: SamuelBrudner/lab-tracker\nThread label: thread_has_human_issue_and_fix_context\nOutcome: claimed_resolved_unverified\nComment count: 1\nLinked commit count: 1\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 44\nLabels: {'runtime_failure': 1}\nPolarities: {'bad': 1}\nChanged file labels: {'source_or_other': 2, 'dependency_or_build': 3, 'api_or_backend': 5, 'ui_or_frontend': 24, 'test_or_ci': 10}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-feaadc8ac73f1ee1\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"runtime_failure\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.com/SamuelBrudner/lab-tracker/pull/4\",\n    \"text\": \"GitHub feedback: runtime_failure\\nPolarity: bad\\nKind: pull_request_body\\nRepo: SamuelBrudner/lab-tracker\\nAuthor: SamuelBrudner (User)\\nURL: https://github.com/SamuelBrudner/lab-tracker/pull/4\\nTitle: [codex] stabilize backend persistence and modularize frontend shell\\nBody:\\n## Summary\\nThis PR implements the repository stabilization pass across the backend and frontend.\\n\\nOn the backend, it replaces the long-lived mutable process cache with request-scoped repository-backed reads and writes, makes repository-managed request flows atomic, adds full SQLAlchemy persistence for acquisition outputs, streams dataset file uploads instead of buffering them in memory, hardens readiness and metrics database checks, and updates the Chroma integration to a tested `chromadb>=1.5.8,<1.6` range.\\n\\nOn the frontend, it decomposes the monolithic React app into a small app shell plus shared API, routing, formatting, hooks, and feature modules for questions, notes, datasets/reviews, sessions, and analysis/search. It also adds a Vitest + React Testing Library harness for session bootstrap, route rendering, review detail loading, and approval flow behavior.\\n\\n## Why\\nThe repo had several prototype-grade failure mo\"\n  }\n]\nChanged files:\n[\n  {\n    \"id\": \"github-pr-file-file-4d8b91c7bbc53d48\",\n    \"filename\": \"alembic/versions/0009_acquisition_outputs.py\",\n    \"label\": \"source_or_other\",\n    \"status\": \"added\",\n    \"additions\": 46,\n    \"deletions\": 0,\n    \"changes\": 46,\n    \"blob_url\": \"https://github.com/SamuelBrudner/lab-tracker/blob/653e89c2b57cab830b192b050ccdcb467f9979a3/alembic%2Fversions%2F0009_acquisition_outputs.py\"\n  },\n  {\n    \"id\": \"github-pr-file-file-517c411f84b490a1\",\n    \"filename\": \"package-lock.json\",\n    \"label\": \"dependency_or_build\",\n    \"status\": \"modified\",\n    \"additions\n[truncated by importer]", "source": "foundry_mined_dataset", "repo_url": "https://github.com/SamuelBrudner/lab-tracker", "source_id": "comment-chain-pattern-assumption_checks-afb7bc70c0c387d3", "synthetic": false, "gold_label": "", "graph_label": "source_backed_multi_signal_graph", "source_path": "/data/distillate/foundry_data/comment_chain_patterns/assumption_checks/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "SamuelBrudner/lab-tracker", "source_dataset": "comment_chain_patterns/assumption_checks", "training_usage": "weak_supervision"}}}, {"ruleId": "foundry_assumption_check", "level": "warning", "message": {"text": "Foundry mined assumption checks: SamuelBrudner/lab-tracker"}, "properties": {"repobilityId": 374139, "scanner": "foundry_dataset", "fingerprint": "1fc88cbb70fdc71ba1c6e8740b1ef11bde750b5cd2782e2f4eacda01da038417", "category": "practices", "severity": "medium", "confidence": 0.62, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "comment_chain_pattern_product", "source": "comment_chain_pattern_miner", "product": "assumption_checks", "synthetic": false, "thread_key": "SamuelBrudner/lab-tracker#3", "human_labels": ["api_or_backend", "dependency_or_build", "docs_or_claims", "human_feedback_general", "schema_or_data", "source_or_other", "test_or_ci", "ui_or_frontend"], "issue_number": "3", "thread_label": "thread_needs_classification", "outcome_label": "ambiguous_needs_more_evidence", "source_backed": true, "max_confidence": 0.0, "repo_full_name": "SamuelBrudner/lab-tracker", "training_usage": "negative_or_unresolved", "confidence_tier": "unresolved", "source_chain_id": "evidence-chain-issue_chain-2db85b259c225ee9", "helicopter_views": {"schemas": 2}, "artifact_families": {"ci": 2, "docs": 4, "schemas": 1, "generated_claims": 1}, "source_chain_kind": "issue_chain", "changed_file_count": 87, "source_graph_label": "source_backed_multi_signal_graph", "changed_file_labels": {"test_or_ci": 26, "api_or_backend": 9, "docs_or_claims": 2, "schema_or_data": 1, "ui_or_frontend": 33, "source_or_other": 14, "dependency_or_build": 2}, "linked_commit_count": 0, "helicopter_view_count": 2, "source_artifact_count": 8, "classification_reasons": ["source_graph_has_real_artifacts", "source_graph_has_verification_artifacts", "repo_has_isolated_helicopter_views", "link_quality_unresolved"], "linked_ci_commit_count": 0, "verification_artifact_count": 3, "design_schema_api_artifact_count": 1}, "text": "Comment chain pattern product: assumption_checks\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#3\nOutcome: ambiguous_needs_more_evidence\nThread label: thread_needs_classification\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, repo_has_isolated_helicopter_views, link_quality_unresolved\nChain evidence:\nIssue/PR evidence chain: SamuelBrudner/lab-tracker#3\nRepo: SamuelBrudner/lab-tracker\nThread label: thread_needs_classification\nOutcome: ambiguous_needs_more_evidence\nComment count: 1\nLinked commit count: 0\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 87\nLabels: {'human_feedback_general': 1}\nPolarities: {'neutral': 1}\nChanged file labels: {'source_or_other': 14, 'test_or_ci': 26, 'docs_or_claims': 2, 'dependency_or_build': 2, 'api_or_backend': 9, 'ui_or_frontend': 33, 'schema_or_data': 1}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-317cd7dc01e65cdd\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"human_feedback_general\",\n    \"polarity\": \"neutral\",\n    \"url\": \"https://github.com/SamuelBrudner/lab-tracker/pull/3\",\n    \"text\": \"GitHub feedback: human_feedback_general\\nPolarity: neutral\\nKind: pull_request_body\\nRepo: SamuelBrudner/lab-tracker\\nAuthor: SamuelBrudner (User)\\nURL: https://github.com/SamuelBrudner/lab-tracker/pull/3\\nTitle: Run/20260129 200229 76129ac3\\nBody:\\n\"\n  }\n]\nChanged files:\n[\n  {\n    \"id\": \"github-pr-file-file-1d35c80fea2de9be\",\n    \"filename\": \".beads/.gitignore\",\n    \"label\": \"source_or_other\",\n    \"status\": \"modified\",\n    \"additions\": 6,\n    \"deletions\": 0,\n    \"changes\": 6,\n    \"blob_url\": \"https://github.com/SamuelBrudner/lab-tracker/blob/38b6fa435c133a2627aa0b5cc0553464440246bf/.beads%2F.gitignore\"\n  },\n  {\n    \"id\": \"github-pr-file-file-3ad8b646f3af6bfa\",\n    \"filename\": \".env.example\",\n    \"label\": \"source_or_other\",\n    \"status\": \"added\",\n    \"additions\": 22,\n    \"deletions\": 0,\n    \"changes\": 22,\n    \"blob_url\": \"https://github.com/SamuelBrudner/lab-tracker/blob/38b6fa435c133a2627aa0b5cc0553464440246bf/.env.example\"\n  },\n  {\n    \"id\": \"github-pr-file-file-1f105581500be92a\",\n    \"filename\": \".github/workflows/ci.yml\",\n    \"label\": \"test_or_ci\",\n    \"status\": \"modified\",\n    \"additions\": 6,\n    \"deletions\": 5,\n    \"changes\": 11,\n    \"blob_url\": \"https://github.com/SamuelBrudner/lab-tracker/blob/38b6fa435c133a2627aa0b5cc0553464440246bf/.github%2Fworkflows%2Fci.yml\"\n  },\n  {\n    \"id\": \"github-pr-file-file-54edbd8c7d1522f3\",\n    \"filename\": \".gitignore\",\n    \"label\": \"source_or_other\",\n    \"status\": \"modified\",\n    \"additions\": 3,\n    \"deletions\": 0,\n    \"changes\": 3,\n    \"blob_url\": \"https://github.com/SamuelBrudner/lab-tracker/blob/38b6fa435c133a2627aa0b5cc0553464440246bf/.gitignore\"\n  },\n  {\n    \"id\": \"github-pr-file-file-d79f98020c52919d\",\n    \"filename\": \"Dockerfile\",\n    \"label\": \"source_or_other\",\n    \"status\": \"added\",\n    \"additions\": 29,\n    \"deletion\n[truncated by importer]", "source": "foundry_mined_dataset", "repo_url": "https://github.com/SamuelBrudner/lab-tracker", "source_id": "comment-chain-pattern-assumption_checks-14a7f1c067da53b8", "synthetic": false, "gold_label": "", "graph_label": "source_backed_multi_signal_graph", "source_path": "/data/distillate/foundry_data/comment_chain_patterns/assumption_checks/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "SamuelBrudner/lab-tracker", "source_dataset": "comment_chain_patterns/assumption_checks", "training_usage": "negative_or_unresolved"}}}, {"ruleId": "foundry_assumption_check", "level": "warning", "message": {"text": "Foundry mined assumption checks: SamuelBrudner/lab-tracker"}, "properties": {"repobilityId": 374138, "scanner": "foundry_dataset", "fingerprint": "90e1f6dc85944df4627081731ccf9ec76588005a7580d58b94e0916912040623", "category": "practices", "severity": "medium", "confidence": 0.62, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "comment_chain_pattern_product", "source": "comment_chain_pattern_miner", "product": "assumption_checks", "synthetic": false, "thread_key": "SamuelBrudner/lab-tracker#2", "human_labels": ["api_or_backend", "human_feedback_general", "source_or_other", "test_or_ci", "ui_or_frontend"], "issue_number": "2", "thread_label": "thread_needs_classification", "outcome_label": "ambiguous_needs_more_evidence", "source_backed": true, "max_confidence": 0.0, "repo_full_name": "SamuelBrudner/lab-tracker", "training_usage": "negative_or_unresolved", "confidence_tier": "unresolved", "source_chain_id": "evidence-chain-issue_chain-6d574d6c38b8698b", "helicopter_views": {"schemas": 2}, "artifact_families": {"ci": 2, "docs": 4, "schemas": 1, "generated_claims": 1}, "source_chain_kind": "issue_chain", "changed_file_count": 9, "source_graph_label": "source_backed_multi_signal_graph", "changed_file_labels": {"test_or_ci": 1, "api_or_backend": 1, "ui_or_frontend": 4, "source_or_other": 3}, "linked_commit_count": 0, "helicopter_view_count": 2, "source_artifact_count": 8, "classification_reasons": ["source_graph_has_real_artifacts", "source_graph_has_verification_artifacts", "repo_has_isolated_helicopter_views", "link_quality_unresolved"], "linked_ci_commit_count": 0, "verification_artifact_count": 3, "design_schema_api_artifact_count": 1}, "text": "Comment chain pattern product: assumption_checks\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#2\nOutcome: ambiguous_needs_more_evidence\nThread label: thread_needs_classification\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, repo_has_isolated_helicopter_views, link_quality_unresolved\nChain evidence:\nIssue/PR evidence chain: SamuelBrudner/lab-tracker#2\nRepo: SamuelBrudner/lab-tracker\nThread label: thread_needs_classification\nOutcome: ambiguous_needs_more_evidence\nComment count: 1\nLinked commit count: 0\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 9\nLabels: {'human_feedback_general': 1}\nPolarities: {'neutral': 1}\nChanged file labels: {'source_or_other': 3, 'ui_or_frontend': 4, 'api_or_backend': 1, 'test_or_ci': 1}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-1af04cbd98b6a852\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"human_feedback_general\",\n    \"polarity\": \"neutral\",\n    \"url\": \"https://github.com/SamuelBrudner/lab-tracker/pull/2\",\n    \"text\": \"GitHub feedback: human_feedback_general\\nPolarity: neutral\\nKind: pull_request_body\\nRepo: SamuelBrudner/lab-tracker\\nAuthor: SamuelBrudner (User)\\nURL: https://github.com/SamuelBrudner/lab-tracker/pull/2\\nTitle: Run/20260115 223127 85286445\\nBody:\\n\"\n  }\n]\nChanged files:\n[\n  {\n    \"id\": \"github-pr-file-file-4cf49d71894f3532\",\n    \"filename\": \".beads/issues.jsonl\",\n    \"label\": \"source_or_other\",\n    \"status\": \"modified\",\n    \"additions\": 6,\n    \"deletions\": 5,\n    \"changes\": 11,\n    \"blob_url\": \"https://github.com/SamuelBrudner/lab-tracker/blob/73a7250fe21aa1783bf2afb7ac9d3c6ea9dea139/.beads%2Fissues.jsonl\"\n  },\n  {\n    \"id\": \"github-pr-file-file-af26215f17fc423f\",\n    \"filename\": \".gitignore\",\n    \"label\": \"source_or_other\",\n    \"status\": \"modified\",\n    \"additions\": 2,\n    \"deletions\": 0,\n    \"changes\": 2,\n    \"blob_url\": \"https://github.com/SamuelBrudner/lab-tracker/blob/73a7250fe21aa1783bf2afb7ac9d3c6ea9dea139/.gitignore\"\n  },\n  {\n    \"id\": \"github-pr-file-file-c185610ac977e69f\",\n    \"filename\": \"pyproject.toml\",\n    \"label\": \"source_or_other\",\n    \"status\": \"modified\",\n    \"additions\": 5,\n    \"deletions\": 0,\n    \"changes\": 5,\n    \"blob_url\": \"https://github.com/SamuelBrudner/lab-tracker/blob/73a7250fe21aa1783bf2afb7ac9d3c6ea9dea139/pyproject.toml\"\n  },\n  {\n    \"id\": \"github-pr-file-file-2b86e4fa925298ec\",\n    \"filename\": \"src/lab_tracker/__init__.py\",\n    \"label\": \"ui_or_frontend\",\n    \"status\": \"modified\",\n    \"additions\": 62,\n    \"deletions\": 0,\n    \"changes\": 62,\n    \"blob_url\": \"https://github.com/SamuelBrudner/lab-tracker/blob/73a7250fe21aa1783bf2afb7ac9d3c6ea9dea139/src%2Flab_tracker%2F__init__.py\"\n  },\n  {\n    \"id\": \"github-pr-file-file-05e38a4cc2f8d4a9\",\n    \"filename\": \"src/lab_tracker/api.py\",\n    \"label\": \"api_or_backend\",\n    \"status\": \"added\",\n    \"additions\": 528,\n    \"deletions\": 0,\n    \"changes\": 528,\n    \"blob_ur\n[truncated by importer]", "source": "foundry_mined_dataset", "repo_url": "https://github.com/SamuelBrudner/lab-tracker", "source_id": "comment-chain-pattern-assumption_checks-de58a841e09bfaf5", "synthetic": false, "gold_label": "", "graph_label": "source_backed_multi_signal_graph", "source_path": "/data/distillate/foundry_data/comment_chain_patterns/assumption_checks/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "SamuelBrudner/lab-tracker", "source_dataset": "comment_chain_patterns/assumption_checks", "training_usage": "negative_or_unresolved"}}}, {"ruleId": "foundry_assumption_check", "level": "warning", "message": {"text": "Foundry mined assumption checks: SamuelBrudner/lab-tracker"}, "properties": {"repobilityId": 374137, "scanner": "foundry_dataset", "fingerprint": "99b91b24793e0ee622fb40ef38dd2b7c8fb7417bd6357d3049ab340171f7208d", "category": "practices", "severity": "medium", "confidence": 0.62, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "comment_chain_pattern_product", "source": "comment_chain_pattern_miner", "product": "assumption_checks", "synthetic": false, "thread_key": "SamuelBrudner/lab-tracker#1", "human_labels": ["dependency_or_build", "docs_or_claims", "human_feedback_general", "schema_or_data", "source_or_other"], "issue_number": "1", "thread_label": "thread_needs_classification", "outcome_label": "ambiguous_needs_more_evidence", "source_backed": true, "max_confidence": 0.0, "repo_full_name": "SamuelBrudner/lab-tracker", "training_usage": "negative_or_unresolved", "confidence_tier": "unresolved", "source_chain_id": "evidence-chain-issue_chain-8a49dc3507a04232", "helicopter_views": {"schemas": 2}, "artifact_families": {"ci": 2, "docs": 4, "schemas": 1, "generated_claims": 1}, "source_chain_kind": "issue_chain", "changed_file_count": 19, "source_graph_label": "source_backed_multi_signal_graph", "changed_file_labels": {"docs_or_claims": 1, "schema_or_data": 3, "source_or_other": 14, "dependency_or_build": 1}, "linked_commit_count": 0, "helicopter_view_count": 2, "source_artifact_count": 8, "classification_reasons": ["source_graph_has_real_artifacts", "source_graph_has_verification_artifacts", "repo_has_isolated_helicopter_views", "link_quality_unresolved"], "linked_ci_commit_count": 0, "verification_artifact_count": 3, "design_schema_api_artifact_count": 1}, "text": "Comment chain pattern product: assumption_checks\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#1\nOutcome: ambiguous_needs_more_evidence\nThread label: thread_needs_classification\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, repo_has_isolated_helicopter_views, link_quality_unresolved\nChain evidence:\nIssue/PR evidence chain: SamuelBrudner/lab-tracker#1\nRepo: SamuelBrudner/lab-tracker\nThread label: thread_needs_classification\nOutcome: ambiguous_needs_more_evidence\nComment count: 1\nLinked commit count: 0\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 19\nLabels: {'human_feedback_general': 1}\nPolarities: {'neutral': 1}\nChanged file labels: {'docs_or_claims': 1, 'source_or_other': 14, 'schema_or_data': 3, 'dependency_or_build': 1}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-3e57fb8692e0e8aa\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"human_feedback_general\",\n    \"polarity\": \"neutral\",\n    \"url\": \"https://github.com/SamuelBrudner/lab-tracker/pull/1\",\n    \"text\": \"GitHub feedback: human_feedback_general\\nPolarity: neutral\\nKind: pull_request_body\\nRepo: SamuelBrudner/lab-tracker\\nAuthor: SamuelBrudner (User)\\nURL: https://github.com/SamuelBrudner/lab-tracker/pull/1\\nTitle: define goals behavior\\nBody:\\n\"\n  }\n]\nChanged files:\n[\n  {\n    \"id\": \"github-pr-file-file-6fe9a12ed21e8242\",\n    \"filename\": \"README.md\",\n    \"label\": \"docs_or_claims\",\n    \"status\": \"added\",\n    \"additions\": 99,\n    \"deletions\": 0,\n    \"changes\": 99,\n    \"blob_url\": \"https://github.com/SamuelBrudner/lab-tracker/blob/65966d5cccda04080321d07808f082f21892b408/README.md\"\n  },\n  {\n    \"id\": \"github-pr-file-file-2dd910940c064876\",\n    \"filename\": \"core/__init__.py\",\n    \"label\": \"source_or_other\",\n    \"status\": \"added\",\n    \"additions\": 0,\n    \"deletions\": 0,\n    \"changes\": 0,\n    \"blob_url\": \"https://github.com/SamuelBrudner/lab-tracker/blob/65966d5cccda04080321d07808f082f21892b408/core%2F__init__.py\"\n  },\n  {\n    \"id\": \"github-pr-file-file-b26f825ddf51b539\",\n    \"filename\": \"core/admin.py\",\n    \"label\": \"source_or_other\",\n    \"status\": \"added\",\n    \"additions\": 537,\n    \"deletions\": 0,\n    \"changes\": 537,\n    \"blob_url\": \"https://github.com/SamuelBrudner/lab-tracker/blob/65966d5cccda04080321d07808f082f21892b408/core%2Fadmin.py\"\n  },\n  {\n    \"id\": \"github-pr-file-file-9e493ba090de9293\",\n    \"filename\": \"core/apps.py\",\n    \"label\": \"source_or_other\",\n    \"status\": \"added\",\n    \"additions\": 6,\n    \"deletions\": 0,\n    \"changes\": 6,\n    \"blob_url\": \"https://github.com/SamuelBrudner/lab-tracker/blob/65966d5cccda04080321d07808f082f21892b408/core%2Fapps.py\"\n  },\n  {\n    \"id\": \"github-pr-file-file-c622423d86490879\",\n    \"filename\": \"core/migrations/0001_initial.py\",\n    \"label\": \"schema_or_data\",\n    \"status\": \"added\",\n    \"additions\": 1230,\n    \"deletions\": 0,\n    \"changes\": 1230,\n    \"blob_url\": \"https://github.com/SamuelBrud\n[truncated by importer]", "source": "foundry_mined_dataset", "repo_url": "https://github.com/SamuelBrudner/lab-tracker", "source_id": "comment-chain-pattern-assumption_checks-99ef5e2323c732d8", "synthetic": false, "gold_label": "", "graph_label": "source_backed_multi_signal_graph", "source_path": "/data/distillate/foundry_data/comment_chain_patterns/assumption_checks/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "SamuelBrudner/lab-tracker", "source_dataset": "comment_chain_patterns/assumption_checks", "training_usage": "negative_or_unresolved"}}}, {"ruleId": "foundry_test_ci_gap", "level": "error", "message": {"text": "Foundry mined test ci gap after feedback: SamuelBrudner/lab-tracker"}, "properties": {"repobilityId": 416508, "scanner": "foundry_dataset", "fingerprint": "c73c73b05e3e5bd6a7f4eae021e4ae57662e2eb41ef8b05c874f1dbfdc47a45f", "category": "testing", "severity": "high", "confidence": 0.78, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Feedback exposes missing tests or CI", "intent": "Hard negatives for feedback/fix chains without adequate guardrails.", "labels": {"test_ci_gap": 1, "docs_or_chore": 1, "docs_or_claims": 3, "source_or_other": 1, "dependency_or_build": 1, "partial blueprint fit": 2, "mostly follows blueprint": 1, "claimed_resolved_unverified": 3, "issue_or_pull_request_thread": 1, "blueprint_human_gap_alignment": 2, "blueprint_human_gap_disagreement": 1, "human_reported_issue_then_fix_attempt": 1, "thread_has_human_issue_and_fix_context": 2}, "source": "graph_query_export", "motif_id": "test_ci_gap_after_feedback", "outcomes": {"claimed_resolved_unverified": 6}, "polarity": "bad", "query_id": "test_ci_gap_after_feedback", "severity": "high", "ci_labels": {}, "synthetic": false, "edge_count": 37, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "thread_touches_file": 4, "alignment_uses_comment": 3, "alignment_uses_finding": 3, "chain_has_link_quality": 6, "comment_aligns_finding": 3, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 4, "thread_has_comment_chain": 1, "comment_chain_links_commit": 2, "comment_chain_touches_file": 4, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 24, "node_types": {"repo": 1, "commit": 2, "thread": 1, "comment": 1, "pr_file": 4, "alignment": 3, "fix_outcome": 1, "issue_chain": 1, "link_quality": 6, "comment_chain": 1, "blueprint_finding": 3}, "query_type": "motif_query", "thread_key": "SamuelBrudner/lab-tracker#7", "issue_number": "7", "quality_tiers": {"assumption_check": 3, "weak_supervision": 3}, "repo_full_name": "SamuelBrudner/lab-tracker", "training_usage": "hard_negative", "source_motif_id": "graph-pattern-motif-thread-317bfdafb816010e", "graph_gold_label": "weak_supervision_needs_review", "changed_file_labels": {"docs_or_claims": 12, "source_or_other": 4}}, "text": "Graph query export: Feedback exposes missing tests or CI\nQuery id: test_ci_gap_after_feedback\nQuery type: motif_query\nIntent: Hard negatives for feedback/fix chains without adequate guardrails.\nMotif: test_ci_gap_after_feedback\nTraining usage: hard_negative\nGraph gold label: weak_supervision_needs_review\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#7\nEvidence:\nGraph motif: Feedback or fix context exposes missing test/CI guardrails\nMotif id: test_ci_gap_after_feedback\nPolarity: bad\nTraining usage: hard_negative\nSeverity: high\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#7\nGraph gold label: weak_supervision_needs_review\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: SamuelBrudner/lab-tracker#7\nRepo: SamuelBrudner/lab-tracker\nIssue/PR number: 7\nGraph consistency label: weak_supervision_needs_review\nNodes: 24\nEdges: 37\nNode types: {'link_quality': 6, 'pr_file': 4, 'alignment': 3, 'blueprint_finding': 3, 'commit': 2, 'thread': 1, 'repo': 1, 'comment': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'chain_has_link_quality': 6, 'thread_touches_file': 4, 'comment_chain_touches_file': 4, 'issue_chain_touches_file': 4, 'alignment_uses_comment': 3, 'alignment_uses_finding': 3, 'comment_aligns_finding': 3, 'comment_chain_links_commit': 2, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'docs_or_claims': 3, 'claimed_resolved_unverified': 3, 'thread_has_human_issue_and_fix_context': 2, 'blueprint_human_gap_alignment': 2, 'partial blueprint fit': 2, 'issue_or_pull_request_thread': 1, 'test_ci_gap': 1, 'source_or_other': 1, 'human_reported_issue_then_fix_attempt': 1, 'docs_or_chore': 1, 'dependency_or_build': 1, 'blueprint_human_gap_disagreement': 1, 'mostly follows blueprint': 1}\nOutcomes: {'claimed_resolved_unverified': 6}\nQuality tiers: {'weak_supervision': 3, 'assumption_check': 3}\nCI labels: {}\nCurriculum targets:\n- Turn human feedback into regression tests and CI gates.\n- Penalize fixes that do not add or exercise verification for affected workflows.\nAssumption checks:\n- Did the fix add tests for the exact complaint?\n- Does CI run those tests, or is verification only implied?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/SamuelBrudner/lab-tracker", "source_id": "graph-query-motif_query-7ad71beba67fb22a", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/test_ci_gap_after_feedback/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "SamuelBrudner/lab-tracker", "source_dataset": "graph_queries/test_ci_gap_after_feedback", "training_usage": "hard_negative"}}}, {"ruleId": "foundry_docs_only_fix", "level": "error", "message": {"text": "Foundry mined docs only runtime fix: SamuelBrudner/lab-tracker"}, "properties": {"repobilityId": 406235, "scanner": "foundry_dataset", "fingerprint": "c92a8c3a2d1a811abb71965143edd1626951122c33cb4eecb937ac820e9137b4", "category": "practices", "severity": "high", "confidence": 0.8, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Docs-only response to runtime or integration issue", "intent": "Assumption-check examples where docs or claims are not enough proof.", "labels": {"test_ci_gap": 1, "docs_or_chore": 1, "docs_or_claims": 3, "source_or_other": 1, "dependency_or_build": 1, "partial blueprint fit": 2, "mostly follows blueprint": 1, "claimed_resolved_unverified": 3, "issue_or_pull_request_thread": 1, "blueprint_human_gap_alignment": 2, "blueprint_human_gap_disagreement": 1, "human_reported_issue_then_fix_attempt": 1, "thread_has_human_issue_and_fix_context": 2}, "source": "graph_query_export", "motif_id": "docs_only_runtime_fix", "outcomes": {"claimed_resolved_unverified": 6}, "polarity": "bad", "query_id": "docs_only_runtime_fix", "severity": "high", "ci_labels": {}, "synthetic": false, "edge_count": 37, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "thread_touches_file": 4, "alignment_uses_comment": 3, "alignment_uses_finding": 3, "chain_has_link_quality": 6, "comment_aligns_finding": 3, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 4, "thread_has_comment_chain": 1, "comment_chain_links_commit": 2, "comment_chain_touches_file": 4, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 24, "node_types": {"repo": 1, "commit": 2, "thread": 1, "comment": 1, "pr_file": 4, "alignment": 3, "fix_outcome": 1, "issue_chain": 1, "link_quality": 6, "comment_chain": 1, "blueprint_finding": 3}, "query_type": "motif_query", "thread_key": "SamuelBrudner/lab-tracker#7", "issue_number": "7", "quality_tiers": {"assumption_check": 3, "weak_supervision": 3}, "repo_full_name": "SamuelBrudner/lab-tracker", "training_usage": "assumption_check", "source_motif_id": "graph-pattern-motif-thread-e2f41bed714fd898", "graph_gold_label": "weak_supervision_needs_review", "changed_file_labels": {"docs_or_claims": 12, "source_or_other": 4}}, "text": "Graph query export: Docs-only response to runtime or integration issue\nQuery id: docs_only_runtime_fix\nQuery type: motif_query\nIntent: Assumption-check examples where docs or claims are not enough proof.\nMotif: docs_only_runtime_fix\nTraining usage: assumption_check\nGraph gold label: weak_supervision_needs_review\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#7\nEvidence:\nGraph motif: Runtime/integration complaint answered mostly with docs or claims\nMotif id: docs_only_runtime_fix\nPolarity: bad\nTraining usage: assumption_check\nSeverity: high\nRepo: SamuelBrudner/lab-tracker\nThread: SamuelBrudner/lab-tracker#7\nGraph gold label: weak_supervision_needs_review\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: SamuelBrudner/lab-tracker#7\nRepo: SamuelBrudner/lab-tracker\nIssue/PR number: 7\nGraph consistency label: weak_supervision_needs_review\nNodes: 24\nEdges: 37\nNode types: {'link_quality': 6, 'pr_file': 4, 'alignment': 3, 'blueprint_finding': 3, 'commit': 2, 'thread': 1, 'repo': 1, 'comment': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'chain_has_link_quality': 6, 'thread_touches_file': 4, 'comment_chain_touches_file': 4, 'issue_chain_touches_file': 4, 'alignment_uses_comment': 3, 'alignment_uses_finding': 3, 'comment_aligns_finding': 3, 'comment_chain_links_commit': 2, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'docs_or_claims': 3, 'claimed_resolved_unverified': 3, 'thread_has_human_issue_and_fix_context': 2, 'blueprint_human_gap_alignment': 2, 'partial blueprint fit': 2, 'issue_or_pull_request_thread': 1, 'test_ci_gap': 1, 'source_or_other': 1, 'human_reported_issue_then_fix_attempt': 1, 'docs_or_chore': 1, 'dependency_or_build': 1, 'blueprint_human_gap_disagreement': 1, 'mostly follows blueprint': 1}\nOutcomes: {'claimed_resolved_unverified': 6}\nQuality tiers: {'weak_supervision': 3, 'assumption_check': 3}\nCI labels: {}\nCurriculum targets:\n- Train models to reject docs-only fixes for runtime, integration, data, or security failures.\n- Add paired examples where the correct fix changes executable paths and adds verification.\nAssumption checks:\n- Do changed files include executable code or only documentation/claims?\n- Does the complaint require runtime behavior that docs cannot prove?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/SamuelBrudner/lab-tracker", "source_id": "graph-query-motif_query-b29ba430cf4650dd", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/docs_only_runtime_fix/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "SamuelBrudner/lab-tracker", "source_dataset": "graph_queries/docs_only_runtime_fix", "training_usage": "assumption_check"}}}, {"ruleId": "scanner-2d0f098776c51e82", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "2d0f098776c51e82", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0005_projects_created_by.py:27"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4c6b0286ab4d2b6c", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "4c6b0286ab4d2b6c", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0028_backfill_attribution_user_fks.py:51"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dc5d6493100fc105", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "dc5d6493100fc105", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0023_goal_link_slot_not_null.py:24"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9620d92ceaf50070", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "9620d92ceaf50070", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0001_initial.py:32"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a0746b50b9939ba5", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "a0746b50b9939ba5", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0013_retained_v1_cleanup.py:31"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e72ea5b290664db1", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "e72ea5b290664db1", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0002_core_entities.py:151"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a5dad06476079cb1", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "a5dad06476079cb1", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0025_dataset_external_artifacts.py:20"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ffbd11fdd1316b39", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "ffbd11fdd1316b39", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0017_device_tokens.py:69"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1185828c7783ed89", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "1185828c7783ed89", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0009_acquisition_outputs.py:45"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-eec5fc2b683ed80d", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "eec5fc2b683ed80d", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0026_project_groups.py:64"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c25eb7d20db7d286", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "c25eb7d20db7d286", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0032_record_export_events.py:56"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ba79691b1cd26128", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "ba79691b1cd26128", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0020_visualization_assets.py:24"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-52368cce8c384135", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "52368cce8c384135", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0004_claims_visualizations.py:69"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dc18ab2e40b231fb", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "dc18ab2e40b231fb", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0007_dataset_reviews.py:52"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f3a0107f0f264add", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "f3a0107f0f264add", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0027_attribution_user_fks.py:68"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8e0a210b83f311db", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "8e0a210b83f311db", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0021_claim_questions.py:31"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-429af003d4c0d3f3", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "429af003d4c0d3f3", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0029_supervision_edges.py:57"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-eb15ab101b70c692", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "eb15ab101b70c692", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0015_graph_context_draft_metadata.py:50"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aba0982b01d35ab2", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "aba0982b01d35ab2", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0011_note_raw_asset_fields.py:24"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b668dacccbe969f1", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "b668dacccbe969f1", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0014_graph_draft_review.py:90"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a2efb49c2760cf90", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "a2efb49c2760cf90", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0008_project_review_policy.py:51"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fec5782dcc1bc0e4", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "fec5782dcc1bc0e4", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0022_goals.py:77"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-66be5358628f4943", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "66be5358628f4943", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0024_graph_draft_batches.py:103"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-df612ec27307cd1e", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "df612ec27307cd1e", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0017_daily_graph_reviews.py:81"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b596df67d2f8d397", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "b596df67d2f8d397", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0006_dataset_files.py:43"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-07deda149b604f41", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "07deda149b604f41", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0010_query_indexes.py:56"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2c835b3075642b1c", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "2c835b3075642b1c", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0003_entity_tag_suggestions.py:45"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0fa25ea2445f2a49", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "0fa25ea2445f2a49", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0018_project_memberships_graph_review.py:56"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7839e88e304d65f9", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "7839e88e304d65f9", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0030_nullable_goal_project.py:29"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2399a2ef432947d2", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "2399a2ef432947d2", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "alembic/versions/0019_merge_daily_reviews_and_project_collaboration.py:18"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5a0a0800450a9fb0", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/lab_tracker/frontend/app.js:14"}, "properties": {"repobilityId": "daf2c7099bb7f354", "scanner": "scanner-primary", "fingerprint": "5a0a0800450a9fb0", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9f6f69820d8ed65c", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 src/lab_tracker/frontend/app.js:2"}, "properties": {"repobilityId": "cd2d2e0d576e2f29", "scanner": "scanner-primary", "fingerprint": "9f6f69820d8ed65c", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-3ba0167dbdb33778", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 src/lab_tracker/frontend_src/features/devices.jsx:117"}, "properties": {"repobilityId": "84afda5f12d7df1f", "scanner": "scanner-primary", "fingerprint": "3ba0167dbdb33778", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-d63da3583b14afc0", "level": "warning", "message": {"text": "Dockerfile runs as root: Dockerfile"}, "properties": {"repobilityId": "a2ed1bd120e507db", "scanner": "scanner-primary", "fingerprint": "d63da3583b14afc0", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-e066691601852931", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.11-slim"}, "properties": {"repobilityId": "f391052c9bfd7e8b", "scanner": "scanner-primary", "fingerprint": "e066691601852931", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-732b2a9030f8a398", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in src/lab_tracker/frontend/app.js:2"}, "properties": {"repobilityId": "dc13b2ca6919e484", "scanner": "scanner-primary", "fingerprint": "732b2a9030f8a398", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/frontend/app.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-1bcec543aea83e93", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in src/lab_tracker/frontend/app.js:6"}, "properties": {"repobilityId": "ca8c41d8fbf629db", "scanner": "scanner-primary", "fingerprint": "1bcec543aea83e93", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/frontend/app.js"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-cee30e0f4f7d7e57", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in src/lab_tracker/frontend_src/features/devices.jsx:117"}, "properties": {"repobilityId": "6f1b552e5183b15f", "scanner": "scanner-primary", "fingerprint": "cee30e0f4f7d7e57", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/frontend_src/features/devices.jsx"}, "region": {"startLine": 117}}}]}, {"ruleId": "scanner-dbeb8f68f27ce2e8", "level": "note", "message": {"text": "Very large file: tests/test_graph_drafts.py (1687 lines)"}, "properties": {"repobilityId": "fc23a799b595bf7c", "scanner": "scanner-primary", "fingerprint": "dbeb8f68f27ce2e8", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-a58f55fe5f77fe5b", "level": "note", "message": {"text": "Very large file: src/lab_tracker/frontend_src/App.test.jsx (3077 lines)"}, "properties": {"repobilityId": "b816ba8d4e68adf6", "scanner": "scanner-primary", "fingerprint": "a58f55fe5f77fe5b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "a31fb86ecdcd954d", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "5c17ef9b7336cd2d", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "ede66227472ac8da", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "474ec25298a3bd47", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "8ed60a871102db3c", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "368169ae72e0e447", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "8a91c186dbea9e74", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-cc55229a7a3c078d", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .mcp.json"}, "properties": {"repobilityId": "51942fb3d5b8b5b4", "scanner": "scanner-primary", "fingerprint": "cc55229a7a3c078d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "mcp_config"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".mcp.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6d0eff8faf856969", "level": "note", "message": {"text": "Legacy-named symbol `expected_legacy` in tests/test_persistence_flows.py:102"}, "properties": {"repobilityId": "d405e2b748d7265f", "scanner": "scanner-primary", "fingerprint": "6d0eff8faf856969", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-3b6d332a3e91e417", "level": "note", "message": {"text": "Legacy-named symbol `model_copy` in tests/test_project_authorization_policy.py:48"}, "properties": {"repobilityId": "ea921836c365b3fa", "scanner": "scanner-primary", "fingerprint": "3b6d332a3e91e417", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-06a0160348f3f0a5", "level": "note", "message": {"text": "Legacy-named symbol `model_copy` in tests/test_sqlalchemy_repository.py:137"}, "properties": {"repobilityId": "c450feb818121494", "scanner": "scanner-primary", "fingerprint": "06a0160348f3f0a5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-0bf767a2c4d97c4b", "level": "note", "message": {"text": "Legacy-named symbol `model_copy` in tests/test_sqlalchemy_mappers.py:90"}, "properties": {"repobilityId": "95f037c8767dddc0", "scanner": "scanner-primary", "fingerprint": "0bf767a2c4d97c4b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-35a2bac0ff1a78da", "level": "note", "message": {"text": "Stub function `upgrade` (body is just `pass`/`return`) \u2014 alembic/versions/0019_merge_daily_reviews_and_project_collaboration.py:14"}, "properties": {"repobilityId": "44bb95b3d123f2c0", "scanner": "scanner-primary", "fingerprint": "35a2bac0ff1a78da", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-c5b215c75c279f1a", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/lab_tracker/frontend/sw.js:57"}, "properties": {"repobilityId": "d4b6750fc2c55022", "scanner": "scanner-primary", "fingerprint": "c5b215c75c279f1a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8f11e854f13fa64a", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/lab_tracker/frontend/app.js:9"}, "properties": {"repobilityId": "81ce954ac6ce2fcf", "scanner": "scanner-primary", "fingerprint": "8f11e854f13fa64a", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-b46683afb511f991", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/lab_tracker/app_parts/frontend.py:57"}, "properties": {"repobilityId": "be1076396b29edda", "scanner": "scanner-primary", "fingerprint": "b46683afb511f991", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4a9e0f9472ff6175", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/lab_tracker/frontend_src/shared/api.js:66"}, "properties": {"repobilityId": "3b91ed6462d724cc", "scanner": "scanner-primary", "fingerprint": "4a9e0f9472ff6175", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-44c25fce4471993e", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/lab_tracker/frontend_src/features/project-graph.jsx:74"}, "properties": {"repobilityId": "9f87a3bd2636bf4e", "scanner": "scanner-primary", "fingerprint": "44c25fce4471993e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-75db23d0757fbcd9", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/lab_tracker/frontend_src/features/mobile-capture.jsx:338"}, "properties": {"repobilityId": "2b92d164987a8b58", "scanner": "scanner-primary", "fingerprint": "75db23d0757fbcd9", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-71ec38d7ad268208", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/lab_tracker/frontend_src/features/analysis/VisualizationDetailCard.jsx:26"}, "properties": {"repobilityId": "a6c0f38e5a46bf42", "scanner": "scanner-primary", "fingerprint": "71ec38d7ad268208", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-ba6e38217f2d20e1", "level": "note", "message": {"text": "Legacy-named symbol `model_copy` in src/lab_tracker/services/question_service.py:360"}, "properties": {"repobilityId": "69c6667467ffe686", "scanner": "scanner-primary", "fingerprint": "ba6e38217f2d20e1", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-8e047ab7af03962f", "level": "note", "message": {"text": "7 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "5a0455f6498c27ad", "scanner": "scanner-primary", "fingerprint": "8e047ab7af03962f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "e99d1b5294e85a77", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "9c2d99ddf22e76d6", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "fb49f6cfcae7fd80", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-02525d39071dd2c7", "level": "note", "message": {"text": "Near-duplicate function bodies in 5 places"}, "properties": {"repobilityId": "8c522cc83c210fff", "scanner": "scanner-primary", "fingerprint": "02525d39071dd2c7", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-33a6b62e30ce7ab4", "level": "note", "message": {"text": "Near-duplicate function bodies in 6 places"}, "properties": {"repobilityId": "c735d76876cc8817", "scanner": "scanner-primary", "fingerprint": "33a6b62e30ce7ab4", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-02525d39071dd2c7", "level": "note", "message": {"text": "Near-duplicate function bodies in 5 places"}, "properties": {"repobilityId": "409846fede89fa21", "scanner": "scanner-primary", "fingerprint": "02525d39071dd2c7", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-02525d39071dd2c7", "level": "note", "message": {"text": "Near-duplicate function bodies in 5 places"}, "properties": {"repobilityId": "aa3f85f58b857b44", "scanner": "scanner-primary", "fingerprint": "02525d39071dd2c7", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-02525d39071dd2c7", "level": "note", "message": {"text": "Near-duplicate function bodies in 5 places"}, "properties": {"repobilityId": "6400fbeb8eb7816e", "scanner": "scanner-primary", "fingerprint": "02525d39071dd2c7", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-02525d39071dd2c7", "level": "note", "message": {"text": "Near-duplicate function bodies in 5 places"}, "properties": {"repobilityId": "2e1c309206c98a61", "scanner": "scanner-primary", "fingerprint": "02525d39071dd2c7", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-76a2f6818267a9a8", "level": "note", "message": {"text": "Near-duplicate function bodies in 8 places"}, "properties": {"repobilityId": "e6b886af4e51cab4", "scanner": "scanner-primary", "fingerprint": "76a2f6818267a9a8", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "0e0d3e208d81d60c", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "159052e98f53a23d", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "93f2121b1968b57c", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "ad3d5293c6bc9f1b", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "cd040c2960198b0f", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "780efd4083556c94", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "f875bb67a473ba8f", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "c583761bc9ba5a8f", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "c3dc1f19f6ac1af0", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "60f3795a08688a7f", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-82ba709d6e6b8786", "level": "error", "message": {"text": "FastAPI POST `share_target_fallback` without auth dependency \u2014 src/lab_tracker/app_parts/frontend.py:55"}, "properties": {"repobilityId": "a3b52d146d34da45", "scanner": "scanner-primary", "fingerprint": "82ba709d6e6b8786", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/app_parts/frontend.py"}, "region": {"startLine": 55}}}]}, {"ruleId": "scanner-1435c4f82d5da321", "level": "error", "message": {"text": "FastAPI POST `create_project` without auth dependency \u2014 src/lab_tracker/routes/projects.py:67"}, "properties": {"repobilityId": "13e3fa25a4323cd5", "scanner": "scanner-primary", "fingerprint": "1435c4f82d5da321", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/projects.py"}, "region": {"startLine": 67}}}]}, {"ruleId": "scanner-4ac4ea3295304c32", "level": "error", "message": {"text": "FastAPI PATCH `update_project` without auth dependency \u2014 src/lab_tracker/routes/projects.py:106"}, "properties": {"repobilityId": "11a29b2472f0efdf", "scanner": "scanner-primary", "fingerprint": "4ac4ea3295304c32", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/projects.py"}, "region": {"startLine": 106}}}]}, {"ruleId": "scanner-eca1b3be8fba0ca1", "level": "error", "message": {"text": "FastAPI DELETE `delete_project` without auth dependency \u2014 src/lab_tracker/routes/projects.py:124"}, "properties": {"repobilityId": "631474b0deab71c9", "scanner": "scanner-primary", "fingerprint": "eca1b3be8fba0ca1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/projects.py"}, "region": {"startLine": 124}}}]}, {"ruleId": "scanner-ed4d37846cf3c912", "level": "error", "message": {"text": "FastAPI POST `create_project_member` without auth dependency \u2014 src/lab_tracker/routes/projects.py:201"}, "properties": {"repobilityId": "bc87a33e76088c68", "scanner": "scanner-primary", "fingerprint": "ed4d37846cf3c912", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/projects.py"}, "region": {"startLine": 201}}}]}, {"ruleId": "scanner-6d063472e4cadead", "level": "error", "message": {"text": "FastAPI PATCH `update_project_member` without auth dependency \u2014 src/lab_tracker/routes/projects.py:221"}, "properties": {"repobilityId": "74406e73ff39228d", "scanner": "scanner-primary", "fingerprint": "6d063472e4cadead", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/projects.py"}, "region": {"startLine": 221}}}]}, {"ruleId": "scanner-cf3fd706b55641f7", "level": "error", "message": {"text": "FastAPI DELETE `delete_project_member` without auth dependency \u2014 src/lab_tracker/routes/projects.py:240"}, "properties": {"repobilityId": "ed1cb85f8c0fb29c", "scanner": "scanner-primary", "fingerprint": "cf3fd706b55641f7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/projects.py"}, "region": {"startLine": 240}}}]}, {"ruleId": "scanner-b5d3420dd18ab79f", "level": "error", "message": {"text": "FastAPI POST `create_enrollment` without auth dependency \u2014 src/lab_tracker/routes/device_auth.py:86"}, "properties": {"repobilityId": "e004cc375d090171", "scanner": "scanner-primary", "fingerprint": "b5d3420dd18ab79f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/device_auth.py"}, "region": {"startLine": 86}}}]}, {"ruleId": "scanner-179e18ec81e2626b", "level": "error", "message": {"text": "FastAPI POST `consume_enrollment` without auth dependency \u2014 src/lab_tracker/routes/device_auth.py:110"}, "properties": {"repobilityId": "9aa8dfc2ec84aad8", "scanner": "scanner-primary", "fingerprint": "179e18ec81e2626b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/device_auth.py"}, "region": {"startLine": 110}}}]}, {"ruleId": "scanner-fddd62ca2bf13fe3", "level": "error", "message": {"text": "FastAPI DELETE `revoke_device` without auth dependency \u2014 src/lab_tracker/routes/device_auth.py:153"}, "properties": {"repobilityId": "0f6129af0af674c0", "scanner": "scanner-primary", "fingerprint": "fddd62ca2bf13fe3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/device_auth.py"}, "region": {"startLine": 153}}}]}, {"ruleId": "scanner-9e3fb4e9aaf30b50", "level": "error", "message": {"text": "FastAPI POST `get_decision_context` without auth dependency \u2014 src/lab_tracker/routes/assistant.py:25"}, "properties": {"repobilityId": "f8e113a07b8cc955", "scanner": "scanner-primary", "fingerprint": "9e3fb4e9aaf30b50", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/assistant.py"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-1c51bc13e1b2d424", "level": "error", "message": {"text": "FastAPI POST `create_spanning_goal` without auth dependency \u2014 src/lab_tracker/routes/goals.py:58"}, "properties": {"repobilityId": "2ddd2bf11e662855", "scanner": "scanner-primary", "fingerprint": "1c51bc13e1b2d424", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/goals.py"}, "region": {"startLine": 58}}}]}, {"ruleId": "scanner-33f0bd6955aad975", "level": "error", "message": {"text": "FastAPI POST `create_goal` without auth dependency \u2014 src/lab_tracker/routes/goals.py:99"}, "properties": {"repobilityId": "4428cafa5cdf26ae", "scanner": "scanner-primary", "fingerprint": "33f0bd6955aad975", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/goals.py"}, "region": {"startLine": 99}}}]}, {"ruleId": "scanner-84aa1cbc320e6cb4", "level": "error", "message": {"text": "FastAPI PATCH `update_goal` without auth dependency \u2014 src/lab_tracker/routes/goals.py:147"}, "properties": {"repobilityId": "213128b5c4e3fee2", "scanner": "scanner-primary", "fingerprint": "84aa1cbc320e6cb4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/goals.py"}, "region": {"startLine": 147}}}]}, {"ruleId": "scanner-1928143a598572ed", "level": "error", "message": {"text": "FastAPI DELETE `delete_goal` without auth dependency \u2014 src/lab_tracker/routes/goals.py:164"}, "properties": {"repobilityId": "d09a5afa7cd0ab89", "scanner": "scanner-primary", "fingerprint": "1928143a598572ed", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/goals.py"}, "region": {"startLine": 164}}}]}, {"ruleId": "scanner-623c0a447ab723e0", "level": "error", "message": {"text": "FastAPI POST `link_node_to_goal` without auth dependency \u2014 src/lab_tracker/routes/goals.py:170"}, "properties": {"repobilityId": "dabeca2027397ab4", "scanner": "scanner-primary", "fingerprint": "623c0a447ab723e0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/goals.py"}, "region": {"startLine": 170}}}]}, {"ruleId": "scanner-3a9755dd138f4da2", "level": "error", "message": {"text": "FastAPI PATCH `update_goal_link` without auth dependency \u2014 src/lab_tracker/routes/goals.py:187"}, "properties": {"repobilityId": "0d4026e76946c681", "scanner": "scanner-primary", "fingerprint": "3a9755dd138f4da2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/goals.py"}, "region": {"startLine": 187}}}]}, {"ruleId": "scanner-ed4e1ac6b563c86c", "level": "error", "message": {"text": "FastAPI DELETE `delete_goal_link` without auth dependency \u2014 src/lab_tracker/routes/goals.py:205"}, "properties": {"repobilityId": "12198a9afd4dba2d", "scanner": "scanner-primary", "fingerprint": "ed4e1ac6b563c86c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/goals.py"}, "region": {"startLine": 205}}}]}, {"ruleId": "scanner-f678e7458d39f330", "level": "error", "message": {"text": "FastAPI POST `create_ownership_reassignment` without auth dependency \u2014 src/lab_tracker/routes/ownership.py:25"}, "properties": {"repobilityId": "a4cd0adeb2fe1258", "scanner": "scanner-primary", "fingerprint": "f678e7458d39f330", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/ownership.py"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-b0036c0e8ed0a153", "level": "error", "message": {"text": "FastAPI POST `create_dataset` without auth dependency \u2014 src/lab_tracker/routes/datasets.py:36"}, "properties": {"repobilityId": "9120bc25a25b111d", "scanner": "scanner-primary", "fingerprint": "b0036c0e8ed0a153", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/datasets.py"}, "region": {"startLine": 36}}}]}, {"ruleId": "scanner-1cab35469e9cd204", "level": "error", "message": {"text": "FastAPI PATCH `update_dataset` without auth dependency \u2014 src/lab_tracker/routes/datasets.py:83"}, "properties": {"repobilityId": "3a8dbb6f4a5c05ea", "scanner": "scanner-primary", "fingerprint": "1cab35469e9cd204", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/datasets.py"}, "region": {"startLine": 83}}}]}, {"ruleId": "scanner-ce7ce58f635f3079", "level": "error", "message": {"text": "FastAPI DELETE `delete_dataset` without auth dependency \u2014 src/lab_tracker/routes/datasets.py:98"}, "properties": {"repobilityId": "d98386efea8d1a9d", "scanner": "scanner-primary", "fingerprint": "ce7ce58f635f3079", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/datasets.py"}, "region": {"startLine": 98}}}]}, {"ruleId": "scanner-c0c7b3815777b9f1", "level": "error", "message": {"text": "FastAPI PATCH `update_batch_settings` without auth dependency \u2014 src/lab_tracker/routes/graph_batches.py:98"}, "properties": {"repobilityId": "ad32c516383e9904", "scanner": "scanner-primary", "fingerprint": "c0c7b3815777b9f1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/graph_batches.py"}, "region": {"startLine": 98}}}]}, {"ruleId": "scanner-315bfe7baf4c42f6", "level": "error", "message": {"text": "FastAPI POST `run_batch_now` without auth dependency \u2014 src/lab_tracker/routes/graph_batches.py:137"}, "properties": {"repobilityId": "9a69ee87e25a3996", "scanner": "scanner-primary", "fingerprint": "315bfe7baf4c42f6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/graph_batches.py"}, "region": {"startLine": 137}}}]}, {"ruleId": "scanner-4398c87350564e4c", "level": "error", "message": {"text": "FastAPI POST `run_due_batches` without auth dependency \u2014 src/lab_tracker/routes/graph_batches.py:161"}, "properties": {"repobilityId": "0e46fa2f5c47e475", "scanner": "scanner-primary", "fingerprint": "4398c87350564e4c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/graph_batches.py"}, "region": {"startLine": 161}}}]}, {"ruleId": "scanner-8925b1ba43942da7", "level": "error", "message": {"text": "FastAPI POST `refresh_auth` without auth dependency \u2014 src/lab_tracker/routes/auth.py:77"}, "properties": {"repobilityId": "f2828c4919219aa6", "scanner": "scanner-primary", "fingerprint": "8925b1ba43942da7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/auth.py"}, "region": {"startLine": 77}}}]}, {"ruleId": "scanner-b3379140d21ff2cf", "level": "error", "message": {"text": "FastAPI POST `create_graph_draft` without auth dependency \u2014 src/lab_tracker/routes/graph_drafts.py:39"}, "properties": {"repobilityId": "bf650cf1d77f5a2d", "scanner": "scanner-primary", "fingerprint": "b3379140d21ff2cf", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/graph_drafts.py"}, "region": {"startLine": 39}}}]}, {"ruleId": "scanner-1b0bbb183329025d", "level": "error", "message": {"text": "FastAPI PATCH `update_graph_draft_operation` without auth dependency \u2014 src/lab_tracker/routes/graph_drafts.py:98"}, "properties": {"repobilityId": "82fb2ef13891274e", "scanner": "scanner-primary", "fingerprint": "1b0bbb183329025d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/graph_drafts.py"}, "region": {"startLine": 98}}}]}, {"ruleId": "scanner-95b6204035d77233", "level": "error", "message": {"text": "FastAPI POST `submit_graph_draft` without auth dependency \u2014 src/lab_tracker/routes/graph_drafts.py:121"}, "properties": {"repobilityId": "41e3105d33a4bf11", "scanner": "scanner-primary", "fingerprint": "95b6204035d77233", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/graph_drafts.py"}, "region": {"startLine": 121}}}]}, {"ruleId": "scanner-a7ef5620e1adace4", "level": "error", "message": {"text": "FastAPI POST `review_graph_draft` without auth dependency \u2014 src/lab_tracker/routes/graph_drafts.py:133"}, "properties": {"repobilityId": "96e8921d80d9167e", "scanner": "scanner-primary", "fingerprint": "a7ef5620e1adace4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/graph_drafts.py"}, "region": {"startLine": 133}}}]}, {"ruleId": "scanner-eb0a4bd19e3c8cb9", "level": "error", "message": {"text": "FastAPI POST `revise_graph_draft` without auth dependency \u2014 src/lab_tracker/routes/graph_drafts.py:151"}, "properties": {"repobilityId": "ad0b9dd0ac9c7921", "scanner": "scanner-primary", "fingerprint": "eb0a4bd19e3c8cb9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/graph_drafts.py"}, "region": {"startLine": 151}}}]}, {"ruleId": "scanner-e14ad64bcc869d24", "level": "error", "message": {"text": "FastAPI POST `commit_graph_draft` without auth dependency \u2014 src/lab_tracker/routes/graph_drafts.py:175"}, "properties": {"repobilityId": "30084782eeb9e1a5", "scanner": "scanner-primary", "fingerprint": "e14ad64bcc869d24", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/graph_drafts.py"}, "region": {"startLine": 175}}}]}, {"ruleId": "scanner-13fe894bcac53a54", "level": "error", "message": {"text": "FastAPI POST `create_supervision_edge` without auth dependency \u2014 src/lab_tracker/routes/supervision.py:50"}, "properties": {"repobilityId": "be78f0a623d2b991", "scanner": "scanner-primary", "fingerprint": "13fe894bcac53a54", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/supervision.py"}, "region": {"startLine": 50}}}]}, {"ruleId": "scanner-9f55955b5d597539", "level": "error", "message": {"text": "FastAPI PATCH `update_supervision_edge` without auth dependency \u2014 src/lab_tracker/routes/supervision.py:75"}, "properties": {"repobilityId": "ede71a455838d601", "scanner": "scanner-primary", "fingerprint": "9f55955b5d597539", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/supervision.py"}, "region": {"startLine": 75}}}]}, {"ruleId": "scanner-df6a650a799e7e6e", "level": "error", "message": {"text": "FastAPI DELETE `delete_supervision_edge` without auth dependency \u2014 src/lab_tracker/routes/supervision.py:96"}, "properties": {"repobilityId": "8a219d42a51e8e79", "scanner": "scanner-primary", "fingerprint": "df6a650a799e7e6e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/supervision.py"}, "region": {"startLine": 96}}}]}, {"ruleId": "scanner-93d94adc5d732e78", "level": "error", "message": {"text": "FastAPI POST `create_question` without auth dependency \u2014 src/lab_tracker/routes/questions.py:38"}, "properties": {"repobilityId": "0d2fce0731daca75", "scanner": "scanner-primary", "fingerprint": "93d94adc5d732e78", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/questions.py"}, "region": {"startLine": 38}}}]}, {"ruleId": "scanner-4e2a93d6b8fbe3cf", "level": "error", "message": {"text": "FastAPI PATCH `update_question` without auth dependency \u2014 src/lab_tracker/routes/questions.py:95"}, "properties": {"repobilityId": "ab9f2cfd044ca300", "scanner": "scanner-primary", "fingerprint": "4e2a93d6b8fbe3cf", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/questions.py"}, "region": {"startLine": 95}}}]}, {"ruleId": "scanner-566f97a05758e3fc", "level": "error", "message": {"text": "FastAPI POST `refactor_question` without auth dependency \u2014 src/lab_tracker/routes/questions.py:111"}, "properties": {"repobilityId": "f0d3a341c1c37e6e", "scanner": "scanner-primary", "fingerprint": "566f97a05758e3fc", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/questions.py"}, "region": {"startLine": 111}}}]}, {"ruleId": "scanner-83396b9912ab167a", "level": "error", "message": {"text": "FastAPI DELETE `delete_question` without auth dependency \u2014 src/lab_tracker/routes/questions.py:167"}, "properties": {"repobilityId": "3d2754a4f6165375", "scanner": "scanner-primary", "fingerprint": "83396b9912ab167a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/questions.py"}, "region": {"startLine": 167}}}]}, {"ruleId": "scanner-096cbe408cd1b1c5", "level": "error", "message": {"text": "FastAPI POST `create_visualization` without auth dependency \u2014 src/lab_tracker/routes/visualizations.py:55"}, "properties": {"repobilityId": "9546cc3074c8de1a", "scanner": "scanner-primary", "fingerprint": "096cbe408cd1b1c5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/visualizations.py"}, "region": {"startLine": 55}}}]}, {"ruleId": "scanner-4bf222dfc1e44bec", "level": "error", "message": {"text": "FastAPI POST `upload_visualization_file` without auth dependency \u2014 src/lab_tracker/routes/visualizations.py:102"}, "properties": {"repobilityId": "aa17529970926f30", "scanner": "scanner-primary", "fingerprint": "4bf222dfc1e44bec", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/visualizations.py"}, "region": {"startLine": 102}}}]}, {"ruleId": "scanner-52b6812a93c4269b", "level": "error", "message": {"text": "FastAPI PATCH `update_visualization` without auth dependency \u2014 src/lab_tracker/routes/visualizations.py:201"}, "properties": {"repobilityId": "4625faa93bdac00a", "scanner": "scanner-primary", "fingerprint": "52b6812a93c4269b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/visualizations.py"}, "region": {"startLine": 201}}}]}, {"ruleId": "scanner-a6d34205cc81eb71", "level": "error", "message": {"text": "FastAPI DELETE `delete_visualization` without auth dependency \u2014 src/lab_tracker/routes/visualizations.py:217"}, "properties": {"repobilityId": "45f2bba97f228cfa", "scanner": "scanner-primary", "fingerprint": "a6d34205cc81eb71", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/visualizations.py"}, "region": {"startLine": 217}}}]}, {"ruleId": "scanner-c56faef02b59e373", "level": "error", "message": {"text": "FastAPI POST `create_claim` without auth dependency \u2014 src/lab_tracker/routes/claims.py:30"}, "properties": {"repobilityId": "007a284d640901d6", "scanner": "scanner-primary", "fingerprint": "c56faef02b59e373", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/claims.py"}, "region": {"startLine": 30}}}]}, {"ruleId": "scanner-4617f3a1c00f8830", "level": "error", "message": {"text": "FastAPI PATCH `update_claim` without auth dependency \u2014 src/lab_tracker/routes/claims.py:82"}, "properties": {"repobilityId": "b57a077ce1472798", "scanner": "scanner-primary", "fingerprint": "4617f3a1c00f8830", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/claims.py"}, "region": {"startLine": 82}}}]}, {"ruleId": "scanner-7c315117cbb195f4", "level": "error", "message": {"text": "FastAPI DELETE `delete_claim` without auth dependency \u2014 src/lab_tracker/routes/claims.py:99"}, "properties": {"repobilityId": "37e584e1a57e5052", "scanner": "scanner-primary", "fingerprint": "7c315117cbb195f4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/claims.py"}, "region": {"startLine": 99}}}]}, {"ruleId": "scanner-ab18a3738df3430c", "level": "error", "message": {"text": "FastAPI POST `create_group` without auth dependency \u2014 src/lab_tracker/routes/groups.py:43"}, "properties": {"repobilityId": "bd0490a4f5e86f6c", "scanner": "scanner-primary", "fingerprint": "ab18a3738df3430c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/groups.py"}, "region": {"startLine": 43}}}]}, {"ruleId": "scanner-7e495b5635fd8b72", "level": "error", "message": {"text": "FastAPI PATCH `update_group` without auth dependency \u2014 src/lab_tracker/routes/groups.py:80"}, "properties": {"repobilityId": "eb1feddd178d7c56", "scanner": "scanner-primary", "fingerprint": "7e495b5635fd8b72", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/groups.py"}, "region": {"startLine": 80}}}]}, {"ruleId": "scanner-f71a22f8658f3b8a", "level": "error", "message": {"text": "FastAPI DELETE `delete_group` without auth dependency \u2014 src/lab_tracker/routes/groups.py:93"}, "properties": {"repobilityId": "ac7cd849853c5f64", "scanner": "scanner-primary", "fingerprint": "f71a22f8658f3b8a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/groups.py"}, "region": {"startLine": 93}}}]}, {"ruleId": "scanner-971800f53fbf5470", "level": "error", "message": {"text": "FastAPI POST `create_group_member` without auth dependency \u2014 src/lab_tracker/routes/groups.py:118"}, "properties": {"repobilityId": "8291c1fb7e196cff", "scanner": "scanner-primary", "fingerprint": "971800f53fbf5470", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/groups.py"}, "region": {"startLine": 118}}}]}, {"ruleId": "scanner-ad1fdaef7825f2a4", "level": "error", "message": {"text": "FastAPI PATCH `update_group_member` without auth dependency \u2014 src/lab_tracker/routes/groups.py:138"}, "properties": {"repobilityId": "7c6e4f9b377d7429", "scanner": "scanner-primary", "fingerprint": "ad1fdaef7825f2a4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/groups.py"}, "region": {"startLine": 138}}}]}, {"ruleId": "scanner-0d3edf1a1b45a94b", "level": "error", "message": {"text": "FastAPI DELETE `delete_group_member` without auth dependency \u2014 src/lab_tracker/routes/groups.py:157"}, "properties": {"repobilityId": "3ebe4b906e3796bc", "scanner": "scanner-primary", "fingerprint": "0d3edf1a1b45a94b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/groups.py"}, "region": {"startLine": 157}}}]}, {"ruleId": "scanner-781f5aaf27cfcbdb", "level": "error", "message": {"text": "FastAPI POST `bulk_upsert_group_project_memberships` without auth dependency \u2014 src/lab_tracker/routes/groups.py:170"}, "properties": {"repobilityId": "766ce8d56f8ac19b", "scanner": "scanner-primary", "fingerprint": "781f5aaf27cfcbdb", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/groups.py"}, "region": {"startLine": 170}}}]}, {"ruleId": "scanner-7f52fd4b69cdfaf1", "level": "error", "message": {"text": "FastAPI DELETE `bulk_delete_group_project_memberships` without auth dependency \u2014 src/lab_tracker/routes/groups.py:190"}, "properties": {"repobilityId": "6de909b8573c23f1", "scanner": "scanner-primary", "fingerprint": "7f52fd4b69cdfaf1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/groups.py"}, "region": {"startLine": 190}}}]}, {"ruleId": "scanner-9c5f2623500cf0f7", "level": "error", "message": {"text": "FastAPI POST `create_analysis` without auth dependency \u2014 src/lab_tracker/routes/analyses.py:43"}, "properties": {"repobilityId": "ee4ff12ad3cc5226", "scanner": "scanner-primary", "fingerprint": "9c5f2623500cf0f7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/analyses.py"}, "region": {"startLine": 43}}}]}, {"ruleId": "scanner-4aa5558653c5aed3", "level": "error", "message": {"text": "FastAPI PATCH `update_analysis` without auth dependency \u2014 src/lab_tracker/routes/analyses.py:94"}, "properties": {"repobilityId": "c9bf63d33b4cf439", "scanner": "scanner-primary", "fingerprint": "4aa5558653c5aed3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/analyses.py"}, "region": {"startLine": 94}}}]}, {"ruleId": "scanner-3dc49c49737326dc", "level": "error", "message": {"text": "FastAPI POST `commit_analysis` without auth dependency \u2014 src/lab_tracker/routes/analyses.py:107"}, "properties": {"repobilityId": "624243ba4198fa40", "scanner": "scanner-primary", "fingerprint": "3dc49c49737326dc", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/analyses.py"}, "region": {"startLine": 107}}}]}, {"ruleId": "scanner-e9db74e825dd9757", "level": "error", "message": {"text": "FastAPI DELETE `delete_analysis` without auth dependency \u2014 src/lab_tracker/routes/analyses.py:127"}, "properties": {"repobilityId": "125e04c5d6212acf", "scanner": "scanner-primary", "fingerprint": "e9db74e825dd9757", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/analyses.py"}, "region": {"startLine": 127}}}]}, {"ruleId": "scanner-dd91cfc0d84d5361", "level": "error", "message": {"text": "FastAPI POST `create_note` without auth dependency \u2014 src/lab_tracker/routes/notes.py:56"}, "properties": {"repobilityId": "15989f79ef5637da", "scanner": "scanner-primary", "fingerprint": "dd91cfc0d84d5361", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/notes.py"}, "region": {"startLine": 56}}}]}, {"ruleId": "scanner-785edeeae1ea2c14", "level": "error", "message": {"text": "FastAPI POST `upload_note_file` without auth dependency \u2014 src/lab_tracker/routes/notes.py:75"}, "properties": {"repobilityId": "402adc825ff9e651", "scanner": "scanner-primary", "fingerprint": "785edeeae1ea2c14", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/notes.py"}, "region": {"startLine": 75}}}]}, {"ruleId": "scanner-c56212d3e3f8f621", "level": "error", "message": {"text": "FastAPI POST `quick_capture_note` without auth dependency \u2014 src/lab_tracker/routes/notes.py:116"}, "properties": {"repobilityId": "4a06bbd135294dcc", "scanner": "scanner-primary", "fingerprint": "c56212d3e3f8f621", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/notes.py"}, "region": {"startLine": 116}}}]}, {"ruleId": "scanner-28ec3b0d7c7c7b87", "level": "error", "message": {"text": "FastAPI PATCH `update_note` without auth dependency \u2014 src/lab_tracker/routes/notes.py:208"}, "properties": {"repobilityId": "03e60b22a8704ac6", "scanner": "scanner-primary", "fingerprint": "28ec3b0d7c7c7b87", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/notes.py"}, "region": {"startLine": 208}}}]}, {"ruleId": "scanner-0b4e27b78d173299", "level": "error", "message": {"text": "FastAPI POST `transcribe_note` without auth dependency \u2014 src/lab_tracker/routes/notes.py:223"}, "properties": {"repobilityId": "c15172ea22cd889b", "scanner": "scanner-primary", "fingerprint": "0b4e27b78d173299", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/notes.py"}, "region": {"startLine": 223}}}]}, {"ruleId": "scanner-de2b24f63fdc6dcf", "level": "error", "message": {"text": "FastAPI DELETE `delete_note` without auth dependency \u2014 src/lab_tracker/routes/notes.py:246"}, "properties": {"repobilityId": "c0595c314a06a639", "scanner": "scanner-primary", "fingerprint": "de2b24f63fdc6dcf", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/notes.py"}, "region": {"startLine": 246}}}]}, {"ruleId": "scanner-0ac0b2f20930c83f", "level": "error", "message": {"text": "FastAPI POST `upload_dataset_file` without auth dependency \u2014 src/lab_tracker/routes/dataset_files.py:56"}, "properties": {"repobilityId": "d8506166ff21b714", "scanner": "scanner-primary", "fingerprint": "0ac0b2f20930c83f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/dataset_files.py"}, "region": {"startLine": 56}}}]}, {"ruleId": "scanner-6f80506a30892ed9", "level": "error", "message": {"text": "FastAPI DELETE `delete_dataset_file` without auth dependency \u2014 src/lab_tracker/routes/dataset_files.py:194"}, "properties": {"repobilityId": "c54bf4edf58f2f33", "scanner": "scanner-primary", "fingerprint": "6f80506a30892ed9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/dataset_files.py"}, "region": {"startLine": 194}}}]}, {"ruleId": "scanner-08b2208688cd9a5a", "level": "error", "message": {"text": "FastAPI POST `create_session` without auth dependency \u2014 src/lab_tracker/routes/sessions.py:45"}, "properties": {"repobilityId": "9356ff895a573d62", "scanner": "scanner-primary", "fingerprint": "08b2208688cd9a5a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/sessions.py"}, "region": {"startLine": 45}}}]}, {"ruleId": "scanner-25b68f55db0905d5", "level": "error", "message": {"text": "FastAPI PATCH `update_session` without auth dependency \u2014 src/lab_tracker/routes/sessions.py:95"}, "properties": {"repobilityId": "e7efd90c990a8fcf", "scanner": "scanner-primary", "fingerprint": "25b68f55db0905d5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/sessions.py"}, "region": {"startLine": 95}}}]}, {"ruleId": "scanner-0d05d8924124b41b", "level": "error", "message": {"text": "FastAPI POST `create_session_output` without auth dependency \u2014 src/lab_tracker/routes/sessions.py:125"}, "properties": {"repobilityId": "202f85985057e3a6", "scanner": "scanner-primary", "fingerprint": "0d05d8924124b41b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/sessions.py"}, "region": {"startLine": 125}}}]}, {"ruleId": "scanner-120cec9c17ef17a9", "level": "error", "message": {"text": "FastAPI DELETE `delete_session` without auth dependency \u2014 src/lab_tracker/routes/sessions.py:147"}, "properties": {"repobilityId": "3237edd0830b17ca", "scanner": "scanner-primary", "fingerprint": "120cec9c17ef17a9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/sessions.py"}, "region": {"startLine": 147}}}]}, {"ruleId": "scanner-d4d8879b45665d94", "level": "error", "message": {"text": "FastAPI POST `promote_operational_session` without auth dependency \u2014 src/lab_tracker/routes/sessions.py:155"}, "properties": {"repobilityId": "a68604a79a8cef36", "scanner": "scanner-primary", "fingerprint": "d4d8879b45665d94", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/sessions.py"}, "region": {"startLine": 155}}}]}, {"ruleId": "scanner-1dd1a5dfb45e19e7", "level": "error", "message": {"text": "FastAPI POST `promote_operational_session_to_dataset` without auth dependency \u2014 src/lab_tracker/routes/sessions.py:171"}, "properties": {"repobilityId": "8b837ca47828cc2f", "scanner": "scanner-primary", "fingerprint": "1dd1a5dfb45e19e7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lab_tracker/routes/sessions.py"}, "region": {"startLine": 171}}}]}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "a49620f9cfa9f697", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2ed628e7048329e1", "level": "note", "message": {"text": "Unused endpoint: GET /app/sw.js"}, "properties": {"repobilityId": "39a7a0dd22a909b1", "scanner": "scanner-primary", "fingerprint": "2ed628e7048329e1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-81e05bdb1b0a7253", "level": "note", "message": {"text": "Unused endpoint: POST /app/share-target"}, "properties": {"repobilityId": "c6c1a7840d1c38cf", "scanner": "scanner-primary", "fingerprint": "81e05bdb1b0a7253", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-769398a8a95bd693", "level": "note", "message": {"text": "Unused endpoint: GET /app"}, "properties": {"repobilityId": "de353c74b722a9f8", "scanner": "scanner-primary", "fingerprint": "769398a8a95bd693", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-84382cce6d6c3791", "level": "note", "message": {"text": "Unused endpoint: GET /app/{_path:path}"}, "properties": {"repobilityId": "5deb4df438d13b53", "scanner": "scanner-primary", "fingerprint": "84382cce6d6c3791", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b2fb03327ec7e635", "level": "note", "message": {"text": "Unused endpoint: GET /readiness"}, "properties": {"repobilityId": "cd94e617a7bc143c", "scanner": "scanner-primary", "fingerprint": "b2fb03327ec7e635", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-58666816ba500374", "level": "note", "message": {"text": "Unused endpoint: POST /projects"}, "properties": {"repobilityId": "84614410ccdeb764", "scanner": "scanner-primary", "fingerprint": "58666816ba500374", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c1e1ee09590b0a49", "level": "note", "message": {"text": "Unused endpoint: GET /projects"}, "properties": {"repobilityId": "9594bae9d12a88eb", "scanner": "scanner-primary", "fingerprint": "c1e1ee09590b0a49", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8276e9a42f5cb13a", "level": "note", "message": {"text": "Unused endpoint: GET /projects/{project_id}"}, "properties": {"repobilityId": "7236354fe0a9ce2c", "scanner": "scanner-primary", "fingerprint": "8276e9a42f5cb13a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d1293cf39e94c35a", "level": "note", "message": {"text": "Unused endpoint: PATCH /projects/{project_id}"}, "properties": {"repobilityId": "ba1b7cf20eb89789", "scanner": "scanner-primary", "fingerprint": "d1293cf39e94c35a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-757ec6dc0d84b69c", "level": "note", "message": {"text": "Unused endpoint: DELETE /projects/{project_id}"}, "properties": {"repobilityId": "f60c29889367bbc2", "scanner": "scanner-primary", "fingerprint": "757ec6dc0d84b69c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-225d6d117d7d0dba", "level": "note", "message": {"text": "Unused endpoint: GET /projects/{project_id}/members"}, "properties": {"repobilityId": "9a643cb6c2704936", "scanner": "scanner-primary", "fingerprint": "225d6d117d7d0dba", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-50b1378c17a252f6", "level": "note", "message": {"text": "Unused endpoint: POST /projects/{project_id}/members"}, "properties": {"repobilityId": "3343c7be1f5c5d22", "scanner": "scanner-primary", "fingerprint": "50b1378c17a252f6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ca196e8b59512f0c", "level": "note", "message": {"text": "Unused endpoint: PATCH /projects/{project_id}/members/{user_id:uuid}"}, "properties": {"repobilityId": "d23c1d426d9728af", "scanner": "scanner-primary", "fingerprint": "ca196e8b59512f0c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bd75f26e3a08baf9", "level": "note", "message": {"text": "Unused endpoint: DELETE /projects/{project_id}/members/{user_id:uuid}"}, "properties": {"repobilityId": "550435cdcd2ab2be", "scanner": "scanner-primary", "fingerprint": "bd75f26e3a08baf9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-93de8f95bbd1b060", "level": "note", "message": {"text": "Unused endpoint: POST /auth/devices/enrollment"}, "properties": {"repobilityId": "f0b113a7bb48473b", "scanner": "scanner-primary", "fingerprint": "93de8f95bbd1b060", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5b180035bc798392", "level": "note", "message": {"text": "Unused endpoint: POST /auth/devices/consume"}, "properties": {"repobilityId": "1537e09142c17bf6", "scanner": "scanner-primary", "fingerprint": "5b180035bc798392", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3adf6df4f909d004", "level": "note", "message": {"text": "Unused endpoint: GET /auth/devices"}, "properties": {"repobilityId": "bff4766b0a8aad01", "scanner": "scanner-primary", "fingerprint": "3adf6df4f909d004", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c28b274261b2adcc", "level": "note", "message": {"text": "Unused endpoint: DELETE /auth/devices/{device_token_id}"}, "properties": {"repobilityId": "473a0ab04caa514f", "scanner": "scanner-primary", "fingerprint": "c28b274261b2adcc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8d648a3c553b4f50", "level": "note", "message": {"text": "Unused endpoint: GET /projects/{project_id}/graph"}, "properties": {"repobilityId": "128543a3afba0ea4", "scanner": "scanner-primary", "fingerprint": "8d648a3c553b4f50", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-578732581a99640a", "level": "note", "message": {"text": "Unused endpoint: GET /projects/{project_id}/graph/mermaid"}, "properties": {"repobilityId": "3494c91ff633803d", "scanner": "scanner-primary", "fingerprint": "578732581a99640a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f53c8d6d8c64b7ca", "level": "note", "message": {"text": "Unused endpoint: POST /assistant/decision-context"}, "properties": {"repobilityId": "445e5c8a4b9bc506", "scanner": "scanner-primary", "fingerprint": "f53c8d6d8c64b7ca", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-827392c0226680bd", "level": "note", "message": {"text": "Unused endpoint: POST /goals"}, "properties": {"repobilityId": "57284be60ef0753d", "scanner": "scanner-primary", "fingerprint": "827392c0226680bd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-50207204ed781305", "level": "note", "message": {"text": "Unused endpoint: GET /goals"}, "properties": {"repobilityId": "66532f39a0b700db", "scanner": "scanner-primary", "fingerprint": "50207204ed781305", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5e6f79c00b0cc2ff", "level": "note", "message": {"text": "Unused endpoint: POST /projects/{project_id}/goals"}, "properties": {"repobilityId": "97f4c2b5315256af", "scanner": "scanner-primary", "fingerprint": "5e6f79c00b0cc2ff", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f5d18f19be278e73", "level": "note", "message": {"text": "Unused endpoint: GET /projects/{project_id}/goals"}, "properties": {"repobilityId": "a3e420460011454d", "scanner": "scanner-primary", "fingerprint": "f5d18f19be278e73", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-14524f93aef43d33", "level": "note", "message": {"text": "Unused endpoint: GET /goals/{goal_id}"}, "properties": {"repobilityId": "6bbacb9e8ec88dfe", "scanner": "scanner-primary", "fingerprint": "14524f93aef43d33", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bdd5c4430ca79530", "level": "note", "message": {"text": "Unused endpoint: PATCH /goals/{goal_id}"}, "properties": {"repobilityId": "a17f5a0257974e2a", "scanner": "scanner-primary", "fingerprint": "bdd5c4430ca79530", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8ff63a67ae08f4e2", "level": "note", "message": {"text": "Unused endpoint: DELETE /goals/{goal_id}"}, "properties": {"repobilityId": "0fad7402ccbac5fd", "scanner": "scanner-primary", "fingerprint": "8ff63a67ae08f4e2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2a2d790f319d468b", "level": "note", "message": {"text": "Unused endpoint: POST /goals/{goal_id}/links"}, "properties": {"repobilityId": "153a05b636e4386e", "scanner": "scanner-primary", "fingerprint": "2a2d790f319d468b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ee8cdc7a486b151d", "level": "note", "message": {"text": "Unused endpoint: PATCH /goals/{goal_id}/links/{link_id}"}, "properties": {"repobilityId": "ebcb4558c97561cc", "scanner": "scanner-primary", "fingerprint": "ee8cdc7a486b151d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e9ce0a800b030b3a", "level": "note", "message": {"text": "Unused endpoint: DELETE /goals/{goal_id}/links/{link_id}"}, "properties": {"repobilityId": "9a5f3bfbb674d645", "scanner": "scanner-primary", "fingerprint": "e9ce0a800b030b3a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b78e6c8302d570a3", "level": "note", "message": {"text": "Unused endpoint: GET /projects/{project_id}/nodes/{entity_type}/{entity_id}/goals"}, "properties": {"repobilityId": "091abd778149f4fc", "scanner": "scanner-primary", "fingerprint": "b78e6c8302d570a3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-eb6846a75f1e65f4", "level": "note", "message": {"text": "Unused endpoint: POST /ownership-reassignments"}, "properties": {"repobilityId": "7e92dedefc32eda6", "scanner": "scanner-primary", "fingerprint": "eb6846a75f1e65f4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dbcc8d857a1e87ae", "level": "note", "message": {"text": "Unused endpoint: GET /ownership-reassignments"}, "properties": {"repobilityId": "8b7067aa7160cebf", "scanner": "scanner-primary", "fingerprint": "dbcc8d857a1e87ae", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1951b9b7cc604826", "level": "note", "message": {"text": "Unused endpoint: GET /ownership-reassignments/{reassignment_id:uuid}"}, "properties": {"repobilityId": "1cdd9e7979a85f4d", "scanner": "scanner-primary", "fingerprint": "1951b9b7cc604826", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7b3e81a6180fbf70", "level": "note", "message": {"text": "Unused endpoint: POST /datasets"}, "properties": {"repobilityId": "3f219ccdb1a360e9", "scanner": "scanner-primary", "fingerprint": "7b3e81a6180fbf70", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5b6173f3f7bbf753", "level": "note", "message": {"text": "Unused endpoint: GET /datasets"}, "properties": {"repobilityId": "696951920f6e3380", "scanner": "scanner-primary", "fingerprint": "5b6173f3f7bbf753", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9068b2a1e04b7cff", "level": "note", "message": {"text": "Unused endpoint: GET /datasets/{dataset_id}"}, "properties": {"repobilityId": "47dba18f5fc15024", "scanner": "scanner-primary", "fingerprint": "9068b2a1e04b7cff", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4933d95584491f6f", "level": "note", "message": {"text": "Unused endpoint: PATCH /datasets/{dataset_id}"}, "properties": {"repobilityId": "648c95a2bcc64d8f", "scanner": "scanner-primary", "fingerprint": "4933d95584491f6f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a3121f4efc3a2ffd", "level": "note", "message": {"text": "Unused endpoint: DELETE /datasets/{dataset_id}"}, "properties": {"repobilityId": "b259905d49ca57cf", "scanner": "scanner-primary", "fingerprint": "a3121f4efc3a2ffd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8eefec7059b0a0ce", "level": "note", "message": {"text": "Unused endpoint: GET /batches"}, "properties": {"repobilityId": "6259eae8315f85d9", "scanner": "scanner-primary", "fingerprint": "8eefec7059b0a0ce", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d61535b1868c0894", "level": "note", "message": {"text": "Unused endpoint: GET /batches/{change_set_id:uuid}"}, "properties": {"repobilityId": "57dac2a270cdc859", "scanner": "scanner-primary", "fingerprint": "d61535b1868c0894", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f1123e337f8e174e", "level": "note", "message": {"text": "Unused endpoint: GET /projects/{project_id:uuid}/graph-draft-batch-settings"}, "properties": {"repobilityId": "ce0a5d490fab1590", "scanner": "scanner-primary", "fingerprint": "f1123e337f8e174e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d42ad61959a2771a", "level": "note", "message": {"text": "Unused endpoint: PATCH /projects/{project_id:uuid}/graph-draft-batch-settings"}, "properties": {"repobilityId": "12f70e70c4dfeba4", "scanner": "scanner-primary", "fingerprint": "d42ad61959a2771a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c4900c2eb789b86b", "level": "note", "message": {"text": "Unused endpoint: GET /batches/runs"}, "properties": {"repobilityId": "474d598fe2462368", "scanner": "scanner-primary", "fingerprint": "c4900c2eb789b86b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3c8311925abca621", "level": "note", "message": {"text": "Unused endpoint: POST /batches/run-now"}, "properties": {"repobilityId": "b667375e2ddf9937", "scanner": "scanner-primary", "fingerprint": "3c8311925abca621", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ebe79fbc0c00c8b8", "level": "note", "message": {"text": "Unused endpoint: POST /batches/run-due"}, "properties": {"repobilityId": "8082da8868a090d1", "scanner": "scanner-primary", "fingerprint": "ebe79fbc0c00c8b8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8292c0931391749a", "level": "note", "message": {"text": "Unused endpoint: POST /auth/register"}, "properties": {"repobilityId": "b88a662269a7d5d2", "scanner": "scanner-primary", "fingerprint": "8292c0931391749a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8fdbacfe9430a6ed", "level": "note", "message": {"text": "Unused endpoint: POST /auth/login"}, "properties": {"repobilityId": "46e88f12b88107cd", "scanner": "scanner-primary", "fingerprint": "8fdbacfe9430a6ed", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}