{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-0b0a83f38764682c", "name": "Possibly dead Python function: verify_token", "shortDescription": {"text": "Possibly dead Python function: verify_token"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-05eb5e0ba419f3b1", "name": "Possibly dead Python function: log", "shortDescription": {"text": "Possibly dead Python function: log"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3dcb606408e991b1", "name": "Possibly dead Python function: create_trigger", "shortDescription": {"text": "Possibly dead Python function: create_trigger"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-27ccf344935d174c", "name": "Possibly dead Python function: score", "shortDescription": {"text": "Possibly dead Python function: score"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a337fc4cf2ee7a11", "name": "Possibly dead Python function: rank_key", "shortDescription": {"text": "Possibly dead Python function: rank_key"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cbf84ae7cd63adc1", "name": "`truncate` class without `title=` for hover reveal \u2014 dashboard/app/ask/page.tsx:144", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 dashboard/app/ask/page.tsx:144"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0c09239055c6ebb0", "name": "`truncate` class without `title=` for hover reveal \u2014 dashboard/app/companies/[id]/page.tsx:307", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 dashboard/app/companies/[id]/page.tsx:307"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d63da3583b14afc0", "name": "Dockerfile runs as root: Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-de3c1f217d72a063", "name": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e2f1cddf8cbe14d3", "name": "Dockerfile pipes a remote installer into a shell", "shortDescription": {"text": "Dockerfile pipes a remote installer into a shell"}, "fullDescription": {"text": "Executing downloaded code during image build gives the remote endpoint build-time code execution. Prefer pinned packages or verify downloaded installers by checksum/signature."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "high", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ec16e75e20977cd3", "name": "Insecure pattern 'tls_verify_false' in scripts/re_resolve_domains.py:87", "shortDescription": {"text": "Insecure pattern 'tls_verify_false' in scripts/re_resolve_domains.py:87"}, "fullDescription": {"text": "Found a known-risky pattern (tls_verify_false). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2df7ca06004d8a7e", "name": "Insecure pattern 'tls_verify_false' in app/attribution/attribution_engine.py:918", "shortDescription": {"text": "Insecure pattern 'tls_verify_false' in app/attribution/attribution_engine.py:918"}, "fullDescription": {"text": "Found a known-risky pattern (tls_verify_false). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0117f8f0feaf6c3a", "name": "Insecure pattern 'tls_verify_false' in app/discovery/funding_discovery.py:506", "shortDescription": {"text": "Insecure pattern 'tls_verify_false' in app/discovery/funding_discovery.py:506"}, "fullDescription": {"text": "Found a known-risky pattern (tls_verify_false). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-691a4000a4d9c3b1", "name": "Insecure pattern 'tls_verify_false' in app/resolution/domain_resolver.py:185", "shortDescription": {"text": "Insecure pattern 'tls_verify_false' in app/resolution/domain_resolver.py:185"}, "fullDescription": {"text": "Found a known-risky pattern (tls_verify_false). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a55701d0dec02b2f", "name": "Very large file: app/attribution/attribution_engine.py (4055 lines)", "shortDescription": {"text": "Very large file: app/attribution/attribution_engine.py (4055 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea3b5e389d8c9c0f", "name": "Low test-to-source ratio", "shortDescription": {"text": "Low test-to-source ratio"}, "fullDescription": {"text": "7 tests / 64 src (ratio 0.11)."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 256 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 26 placeholder/mock markers across 10 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-61aa3c40607413a3", "name": "Commented-code block (9 lines) in pipeline.py:321", "shortDescription": {"text": "Commented-code block (9 lines) in pipeline.py:321"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-dbe128ca37e3dbb7", "name": "Commented-code block (5 lines) in tests/test_resolution_unit.py:65", "shortDescription": {"text": "Commented-code block (5 lines) in tests/test_resolution_unit.py:65"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-221da3356f6cd5bd", "name": "Commented-code block (5 lines) in dashboard/components/ProviderBadge.tsx:96", "shortDescription": {"text": "Commented-code block (5 lines) in dashboard/components/ProviderBadge.tsx:96"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2e58d39a9312641c", "name": "`fetch()` without try/.catch or AbortSignal \u2014 dashboard/lib/api.ts:37", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 dashboard/lib/api.ts:37"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-db79704655636362", "name": "Commented-code block (10 lines) in app/models.py:366", "shortDescription": {"text": "Commented-code block (10 lines) in app/models.py:366"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ce0ae743b1045c75", "name": "Commented-code block (6 lines) in app/attribution/attribution_engine.py:90", "shortDescription": {"text": "Commented-code block (6 lines) in app/attribution/attribution_engine.py:90"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a168e9ac1dd9d92b", "name": "Commented-code block (6 lines) in app/resolution/domain_resolver.py:124", "shortDescription": {"text": "Commented-code block (6 lines) in app/resolution/domain_resolver.py:124"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3445cb9f140498c2", "name": "FastAPI POST `ask` without auth dependency \u2014 api/routers/ask.py:131", "shortDescription": {"text": "FastAPI POST `ask` without auth dependency \u2014 api/routers/ask.py:131"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c6281b8d1b59e535", "name": "Dangling fetch: POST /api/auth/login (dashboard/app/login/page.tsx:22)", "shortDescription": {"text": "Dangling fetch: POST /api/auth/login (dashboard/app/login/page.tsx:22)"}, "fullDescription": {"text": "`dashboard/app/login/page.tsx:22` calls `POST /api/auth/login` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/auth/login`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6462b053bce69715", "name": "Unused endpoint: POST /api/auth/verify", "shortDescription": {"text": "Unused endpoint: POST /api/auth/verify"}, "fullDescription": {"text": "`api/main.py` declares `POST /api/auth/verify` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`api/main.py` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8e1fadad2500f063", "name": "Unused endpoint: POST /ask", "shortDescription": {"text": "Unused endpoint: POST /ask"}, "fullDescription": {"text": "`api/routers/ask.py` declares `POST /ask` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a4f14b4d228ed2f3", "name": "Unused endpoint: GET /cloud-distribution", "shortDescription": {"text": "Unused endpoint: GET /cloud-distribution"}, "fullDescription": {"text": "`api/routers/analytics.py` declares `GET /cloud-distribution` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8de6a36027fb68d3", "name": "Unused endpoint: GET /ai-distribution", "shortDescription": {"text": "Unused endpoint: GET /ai-distribution"}, "fullDescription": {"text": "`api/routers/analytics.py` declares `GET /ai-distribution` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-398f6bfec6a7e94e", "name": "Unused endpoint: GET /recent-funding", "shortDescription": {"text": "Unused endpoint: GET /recent-funding"}, "fullDescription": {"text": "`api/routers/analytics.py` declares `GET /recent-funding` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5ee4ef7fd7114022", "name": "Unused endpoint: GET /signal-effectiveness", "shortDescription": {"text": "Unused endpoint: GET /signal-effectiveness"}, "fullDescription": {"text": "`api/routers/analytics.py` declares `GET /signal-effectiveness` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e8a650bc2f9d82bc", "name": "Unused endpoint: GET /provider-changes", "shortDescription": {"text": "Unused endpoint: GET /provider-changes"}, "fullDescription": {"text": "`api/routers/analytics.py` declares `GET /provider-changes` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e1b7bee247ffc801", "name": "Unused endpoint: GET /summary", "shortDescription": {"text": "Unused endpoint: GET /summary"}, "fullDescription": {"text": "`api/routers/analytics.py` declares `GET /summary` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5dedfa271725d938", "name": "Unused endpoint: GET /search-usage", "shortDescription": {"text": "Unused endpoint: GET /search-usage"}, "fullDescription": {"text": "`api/routers/analytics.py` declares `GET /search-usage` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4d97aa03023c8b9d", "name": "Unused endpoint: GET /{startup_id}", "shortDescription": {"text": "Unused endpoint: GET /{startup_id}"}, "fullDescription": {"text": "`api/routers/startups.py` declares `GET /{startup_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a009b1a56794f45", "name": "Unused endpoint: POST /", "shortDescription": {"text": "Unused endpoint: POST /"}, "fullDescription": {"text": "`api/routers/startups.py` declares `POST /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cce043d600ab5fac", "name": "Unused endpoint: PATCH /{startup_id}", "shortDescription": {"text": "Unused endpoint: PATCH /{startup_id}"}, "fullDescription": {"text": "`api/routers/startups.py` declares `PATCH /{startup_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-36c6348d9a77fd06", "name": "Unused endpoint: POST /{startup_id}/re-attribute", "shortDescription": {"text": "Unused endpoint: POST /{startup_id}/re-attribute"}, "fullDescription": {"text": "`api/routers/startups.py` declares `POST /{startup_id}/re-attribute` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3be912c6187ea599", "name": "Unused endpoint: GET /runs", "shortDescription": {"text": "Unused endpoint: GET /runs"}, "fullDescription": {"text": "`api/routers/pipeline.py` declares `GET /runs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-55f8c8cf959a5664", "name": "Unused endpoint: GET /runs/{run_id}", "shortDescription": {"text": "Unused endpoint: GET /runs/{run_id}"}, "fullDescription": {"text": "`api/routers/pipeline.py` declares `GET /runs/{run_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2293706d3453c3a3", "name": "Unused endpoint: POST /trigger", "shortDescription": {"text": "Unused endpoint: POST /trigger"}, "fullDescription": {"text": "`api/routers/pipeline.py` declares `POST /trigger` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/18855"}, "properties": {"repository": "samprak-ai/genai-intel", "repoUrl": "https://github.com/samprak-ai/genai-intel", "branch": "main"}, "results": [{"ruleId": "scanner-0b0a83f38764682c", "level": "note", "message": {"text": "Possibly dead Python function: verify_token"}, "properties": {"repobilityId": "6a5c4adccfca0a15", "scanner": "scanner-primary", "fingerprint": "0b0a83f38764682c", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "api/deps.py:32"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-05eb5e0ba419f3b1", "level": "note", "message": {"text": "Possibly dead Python function: log"}, "properties": {"repobilityId": "eb911eadfbb94865", "scanner": "scanner-primary", "fingerprint": "05eb5e0ba419f3b1", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/core/database.py:393"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3dcb606408e991b1", "level": "note", "message": {"text": "Possibly dead Python function: create_trigger"}, "properties": {"repobilityId": "917ccfe86450bd09", "scanner": "scanner-primary", "fingerprint": "3dcb606408e991b1", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/core/database.py:494"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-27ccf344935d174c", "level": "note", "message": {"text": "Possibly dead Python function: score"}, "properties": {"repobilityId": "379227b163d3203e", "scanner": "scanner-primary", "fingerprint": "27ccf344935d174c", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/discovery/funding_discovery.py:301"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a337fc4cf2ee7a11", "level": "note", "message": {"text": "Possibly dead Python function: rank_key"}, "properties": {"repobilityId": "13e600bdd22374b8", "scanner": "scanner-primary", "fingerprint": "a337fc4cf2ee7a11", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/resolution/domain_resolver.py:434"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cbf84ae7cd63adc1", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 dashboard/app/ask/page.tsx:144"}, "properties": {"repobilityId": "0a0aad296f58fc46", "scanner": "scanner-primary", "fingerprint": "cbf84ae7cd63adc1", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-0c09239055c6ebb0", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 dashboard/app/companies/[id]/page.tsx:307"}, "properties": {"repobilityId": "d942eeb044f9b0b8", "scanner": "scanner-primary", "fingerprint": "0c09239055c6ebb0", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-d63da3583b14afc0", "level": "warning", "message": {"text": "Dockerfile runs as root: Dockerfile"}, "properties": {"repobilityId": "a2ed1bd120e507db", "scanner": "scanner-primary", "fingerprint": "d63da3583b14afc0", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-de3c1f217d72a063", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "properties": {"repobilityId": "544eba20a4f6a349", "scanner": "scanner-primary", "fingerprint": "de3c1f217d72a063", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 8}}}]}, {"ruleId": "scanner-e2f1cddf8cbe14d3", "level": "error", "message": {"text": "Dockerfile pipes a remote installer into a shell"}, "properties": {"repobilityId": "b3589933bbda370a", "scanner": "scanner-primary", "fingerprint": "e2f1cddf8cbe14d3", "layer": "hardware", "severity": "high", "confidence": 1.0, "tags": ["supply-chain", "docker", "remote-installer"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 16}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-ec16e75e20977cd3", "level": "error", "message": {"text": "Insecure pattern 'tls_verify_false' in scripts/re_resolve_domains.py:87"}, "properties": {"repobilityId": "52df611aa370cbff", "scanner": "scanner-primary", "fingerprint": "ec16e75e20977cd3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "tls_verify_false"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/re_resolve_domains.py"}, "region": {"startLine": 87}}}]}, {"ruleId": "scanner-2df7ca06004d8a7e", "level": "error", "message": {"text": "Insecure pattern 'tls_verify_false' in app/attribution/attribution_engine.py:918"}, "properties": {"repobilityId": "8200a1205ef028b5", "scanner": "scanner-primary", "fingerprint": "2df7ca06004d8a7e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "tls_verify_false"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/attribution/attribution_engine.py"}, "region": {"startLine": 918}}}]}, {"ruleId": "scanner-0117f8f0feaf6c3a", "level": "error", "message": {"text": "Insecure pattern 'tls_verify_false' in app/discovery/funding_discovery.py:506"}, "properties": {"repobilityId": "92d8c09f7148cea7", "scanner": "scanner-primary", "fingerprint": "0117f8f0feaf6c3a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "tls_verify_false"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/discovery/funding_discovery.py"}, "region": {"startLine": 506}}}]}, {"ruleId": "scanner-691a4000a4d9c3b1", "level": "error", "message": {"text": "Insecure pattern 'tls_verify_false' in app/resolution/domain_resolver.py:185"}, "properties": {"repobilityId": "076366e95b97843c", "scanner": "scanner-primary", "fingerprint": "691a4000a4d9c3b1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "tls_verify_false"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/resolution/domain_resolver.py"}, "region": {"startLine": 185}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-a55701d0dec02b2f", "level": "note", "message": {"text": "Very large file: app/attribution/attribution_engine.py (4055 lines)"}, "properties": {"repobilityId": "67e1bada47dac56a", "scanner": "scanner-primary", "fingerprint": "a55701d0dec02b2f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ea3b5e389d8c9c0f", "level": "note", "message": {"text": "Low test-to-source ratio"}, "properties": {"repobilityId": "ef7b2552cc00a375", "scanner": "scanner-primary", "fingerprint": "ea3b5e389d8c9c0f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["tests"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "5658408eb06e2999", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "fec0097d24af6934", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "c3027d114c1e7dbf", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "9eee869f3a04cc56", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "1e95893183b03ad8", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "9f6be5bad79def66", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "231bee9f17b3d383", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-61aa3c40607413a3", "level": "none", "message": {"text": "Commented-code block (9 lines) in pipeline.py:321"}, "properties": {"repobilityId": "b51534964167c56f", "scanner": "scanner-primary", "fingerprint": "61aa3c40607413a3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-dbe128ca37e3dbb7", "level": "none", "message": {"text": "Commented-code block (5 lines) in tests/test_resolution_unit.py:65"}, "properties": {"repobilityId": "b1af14ac0695c61f", "scanner": "scanner-primary", "fingerprint": "dbe128ca37e3dbb7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-221da3356f6cd5bd", "level": "none", "message": {"text": "Commented-code block (5 lines) in dashboard/components/ProviderBadge.tsx:96"}, "properties": {"repobilityId": "5bd2f51ef858136a", "scanner": "scanner-primary", "fingerprint": "221da3356f6cd5bd", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2e58d39a9312641c", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 dashboard/lib/api.ts:37"}, "properties": {"repobilityId": "9d9a1cde2945fd72", "scanner": "scanner-primary", "fingerprint": "2e58d39a9312641c", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-db79704655636362", "level": "none", "message": {"text": "Commented-code block (10 lines) in app/models.py:366"}, "properties": {"repobilityId": "c40968f380b73abd", "scanner": "scanner-primary", "fingerprint": "db79704655636362", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ce0ae743b1045c75", "level": "none", "message": {"text": "Commented-code block (6 lines) in app/attribution/attribution_engine.py:90"}, "properties": {"repobilityId": "c0527c2c892f3ff1", "scanner": "scanner-primary", "fingerprint": "ce0ae743b1045c75", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a168e9ac1dd9d92b", "level": "none", "message": {"text": "Commented-code block (6 lines) in app/resolution/domain_resolver.py:124"}, "properties": {"repobilityId": "ee747ff2cb739d9b", "scanner": "scanner-primary", "fingerprint": "a168e9ac1dd9d92b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3445cb9f140498c2", "level": "error", "message": {"text": "FastAPI POST `ask` without auth dependency \u2014 api/routers/ask.py:131"}, "properties": {"repobilityId": "6198a0a2b507d3f5", "scanner": "scanner-primary", "fingerprint": "3445cb9f140498c2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "api/routers/ask.py"}, "region": {"startLine": 131}}}]}, {"ruleId": "scanner-c6281b8d1b59e535", "level": "error", "message": {"text": "Dangling fetch: POST /api/auth/login (dashboard/app/login/page.tsx:22)"}, "properties": {"repobilityId": "ad2c391f44e14e82", "scanner": "scanner-primary", "fingerprint": "c6281b8d1b59e535", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-6462b053bce69715", "level": "note", "message": {"text": "Unused endpoint: POST /api/auth/verify"}, "properties": {"repobilityId": "0ba3eaeb5629f762", "scanner": "scanner-primary", "fingerprint": "6462b053bce69715", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "010a849383b56d00", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8e1fadad2500f063", "level": "note", "message": {"text": "Unused endpoint: POST /ask"}, "properties": {"repobilityId": "6f94c2f6608f1b7e", "scanner": "scanner-primary", "fingerprint": "8e1fadad2500f063", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a4f14b4d228ed2f3", "level": "note", "message": {"text": "Unused endpoint: GET /cloud-distribution"}, "properties": {"repobilityId": "6784fca085f8e2b7", "scanner": "scanner-primary", "fingerprint": "a4f14b4d228ed2f3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8de6a36027fb68d3", "level": "note", "message": {"text": "Unused endpoint: GET /ai-distribution"}, "properties": {"repobilityId": "bd28693375c5461d", "scanner": "scanner-primary", "fingerprint": "8de6a36027fb68d3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-398f6bfec6a7e94e", "level": "note", "message": {"text": "Unused endpoint: GET /recent-funding"}, "properties": {"repobilityId": "f239a176df7c66ad", "scanner": "scanner-primary", "fingerprint": "398f6bfec6a7e94e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5ee4ef7fd7114022", "level": "note", "message": {"text": "Unused endpoint: GET /signal-effectiveness"}, "properties": {"repobilityId": "50f16161205ce5be", "scanner": "scanner-primary", "fingerprint": "5ee4ef7fd7114022", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e8a650bc2f9d82bc", "level": "note", "message": {"text": "Unused endpoint: GET /provider-changes"}, "properties": {"repobilityId": "d95420fb734fa4d2", "scanner": "scanner-primary", "fingerprint": "e8a650bc2f9d82bc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e1b7bee247ffc801", "level": "note", "message": {"text": "Unused endpoint: GET /summary"}, "properties": {"repobilityId": "0a0b3cd7779ed7e0", "scanner": "scanner-primary", "fingerprint": "e1b7bee247ffc801", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5dedfa271725d938", "level": "note", "message": {"text": "Unused endpoint: GET /search-usage"}, "properties": {"repobilityId": "0712ded563e5d83e", "scanner": "scanner-primary", "fingerprint": "5dedfa271725d938", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4d97aa03023c8b9d", "level": "note", "message": {"text": "Unused endpoint: GET /{startup_id}"}, "properties": {"repobilityId": "7ad041e86f259756", "scanner": "scanner-primary", "fingerprint": "4d97aa03023c8b9d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a009b1a56794f45", "level": "note", "message": {"text": "Unused endpoint: POST /"}, "properties": {"repobilityId": "ab8037e997542f00", "scanner": "scanner-primary", "fingerprint": "7a009b1a56794f45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cce043d600ab5fac", "level": "note", "message": {"text": "Unused endpoint: PATCH /{startup_id}"}, "properties": {"repobilityId": "866c16da4b865d4d", "scanner": "scanner-primary", "fingerprint": "cce043d600ab5fac", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-36c6348d9a77fd06", "level": "note", "message": {"text": "Unused endpoint: POST /{startup_id}/re-attribute"}, "properties": {"repobilityId": "7a4fa44591105f5a", "scanner": "scanner-primary", "fingerprint": "36c6348d9a77fd06", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3be912c6187ea599", "level": "note", "message": {"text": "Unused endpoint: GET /runs"}, "properties": {"repobilityId": "3ad1c229ca26b186", "scanner": "scanner-primary", "fingerprint": "3be912c6187ea599", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-55f8c8cf959a5664", "level": "note", "message": {"text": "Unused endpoint: GET /runs/{run_id}"}, "properties": {"repobilityId": "57cc08a72b8547bb", "scanner": "scanner-primary", "fingerprint": "55f8c8cf959a5664", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2293706d3453c3a3", "level": "note", "message": {"text": "Unused endpoint: POST /trigger"}, "properties": {"repobilityId": "3859a3a95c120751", "scanner": "scanner-primary", "fingerprint": "2293706d3453c3a3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}