{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-abf835431cfdab0c", "name": "Stray `console.log` in TS/JS \u2014 packages/app/lib/widgets-native.ts:98", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/app/lib/widgets-native.ts:98"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0ea108be16a662eb", "name": "Stray `console.log` in TS/JS \u2014 packages/core/scripts/generate-apple-secret.ts:30", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/core/scripts/generate-apple-secret.ts:30"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-156ee1cfb7456a57", "name": "Very large file: design/project/_ds_bundle.js (21309 lines)", "shortDescription": {"text": "Very large file: design/project/_ds_bundle.js (21309 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea3b5e389d8c9c0f", "name": "Low test-to-source ratio", "shortDescription": {"text": "Low test-to-source ratio"}, "fullDescription": {"text": "61 tests / 433 src (ratio 0.14)."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-47c58d42565e2f33", "name": "Node manifest has dependencies but no lockfile: packages/mails/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/mails/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0a0634ffe3eb1107", "name": "Node manifest has dependencies but no lockfile: packages/api/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/api/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4bf95f042f6cdfd9", "name": "Node manifest has dependencies but no lockfile: packages/app/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/app/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fad615c5b91d5115", "name": "Node manifest has dependencies but no lockfile: packages/marketing/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/marketing/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-28e92806c0db3cd2", "name": "Node manifest has dependencies but no lockfile: packages/core/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/core/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-32b90739bf6c25a9", "name": "Node manifest has dependencies but no lockfile: modules/expo-app-blocker/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: modules/expo-app-blocker/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 45 placeholder/mock markers across 25 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing lockfile. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f5f2d616fc41a694", "name": "Agent authority lacks a verifier contract: packages/mails/CLAUDE.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: packages/mails/CLAUDE.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-122f91b7f2906dc4", "name": "Agent authority lacks a verifier contract: .claude/settings.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/settings.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-eae51b9ba9234e77", "name": "Commented-code block (7 lines) in design/project/_ds_bundle.js:210", "shortDescription": {"text": "Commented-code block (7 lines) in design/project/_ds_bundle.js:210"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-87bdbb45e48e8825", "name": "`fetch()` without try/.catch or AbortSignal \u2014 design/project/_ds_bundle.js:9659", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 design/project/_ds_bundle.js:9659"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-44dff568675c727e", "name": "Commented-code block (5 lines) in design/project/index.tsx:52", "shortDescription": {"text": "Commented-code block (5 lines) in design/project/index.tsx:52"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e00eb36fc9a44e5c", "name": "Commented-code block (7 lines) in design/project/(account)/auth.tsx:257", "shortDescription": {"text": "Commented-code block (7 lines) in design/project/(account)/auth.tsx:257"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b7b5580dd67a11ca", "name": "`fetch()` without try/.catch or AbortSignal \u2014 design/project/(settings)/personal-details.tsx:88", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 design/project/(settings)/personal-details.tsx:88"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-930e35f5e2fa164f", "name": "Commented-code block (5 lines) in packages/api/vitest.config.ts:12", "shortDescription": {"text": "Commented-code block (5 lines) in packages/api/vitest.config.ts:12"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b3ad6b45aa1f344a", "name": "Commented-code block (5 lines) in packages/api/src/index.ts:33", "shortDescription": {"text": "Commented-code block (5 lines) in packages/api/src/index.ts:33"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9d520219bf79585e", "name": "`fetch()` without try/.catch or AbortSignal \u2014 packages/api/src/index.ts:49", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/api/src/index.ts:49"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a78cb46fcebe2cb0", "name": "`fetch()` without try/.catch or AbortSignal \u2014 packages/api/src/sync/sync-hub.ts:32", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/api/src/sync/sync-hub.ts:32"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9c2424f98667c73e", "name": "Commented-code block (5 lines) in packages/api/src/lib/configure-open-api.ts:8", "shortDescription": {"text": "Commented-code block (5 lines) in packages/api/src/lib/configure-open-api.ts:8"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-42750382fd70a98d", "name": "Commented-code block (6 lines) in packages/api/src/lib/resend.ts:66", "shortDescription": {"text": "Commented-code block (6 lines) in packages/api/src/lib/resend.ts:66"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0c693abb3a31318b", "name": "Commented-code block (6 lines) in packages/api/src/routes/users/users.service.ts:155", "shortDescription": {"text": "Commented-code block (6 lines) in packages/api/src/routes/users/users.service.ts:155"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b1c57e4f5eabcbb9", "name": "Commented-code block (7 lines) in packages/api/src/routes/dhikr/dhikr.service.ts:107", "shortDescription": {"text": "Commented-code block (7 lines) in packages/api/src/routes/dhikr/dhikr.service.ts:107"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4de1e1409e737e3d", "name": "Commented-code block (6 lines) in packages/api/src/routes/prayer-times/prayer-times.routes.ts:19", "shortDescription": {"text": "Commented-code block (6 lines) in packages/api/src/routes/prayer-times/prayer-times.routes.ts:19"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2bdba00674f2a2f8", "name": "`fetch()` without try/.catch or AbortSignal \u2014 packages/api/src/routes/subscriptions/subscriptions.service.ts:392", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/api/src/routes/subscriptions/subscriptions.service.ts:392"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cd611dc6a291d4a8", "name": "Commented-code block (5 lines) in packages/api/src/routes/prayer-logs/prayer-logs.service.ts:59", "shortDescription": {"text": "Commented-code block (5 lines) in packages/api/src/routes/prayer-logs/prayer-logs.service.ts:59"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f062525c5a3b83fd", "name": "Commented-code block (5 lines) in packages/api/src/test-support/apply-migrations.ts:4", "shortDescription": {"text": "Commented-code block (5 lines) in packages/api/src/test-support/apply-migrations.ts:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2a5b773d9472985b", "name": "Commented-code block (6 lines) in packages/app/widgets/lock-activity.tsx:43", "shortDescription": {"text": "Commented-code block (6 lines) in packages/app/widgets/lock-activity.tsx:43"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-71a1437b05618390", "name": "Commented-code block (5 lines) in packages/app/widgets/dhikr.widget.tsx:37", "shortDescription": {"text": "Commented-code block (5 lines) in packages/app/widgets/dhikr.widget.tsx:37"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-be3414c93b7c4acf", "name": "Commented-code block (7 lines) in packages/app/widgets/salah-arc.widget.tsx:33", "shortDescription": {"text": "Commented-code block (7 lines) in packages/app/widgets/salah-arc.widget.tsx:33"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-fd62ea88fcfdd103", "name": "Commented-code block (11 lines) in packages/app/app/logging-out.tsx:23", "shortDescription": {"text": "Commented-code block (11 lines) in packages/app/app/logging-out.tsx:23"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cbdf0a30d8a5a5aa", "name": "Commented-code block (5 lines) in packages/app/app/index.tsx:52", "shortDescription": {"text": "Commented-code block (5 lines) in packages/app/app/index.tsx:52"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b0fbd0ef91ad4957", "name": "Commented-code block (6 lines) in packages/app/app/(account)/auth.tsx:112", "shortDescription": {"text": "Commented-code block (6 lines) in packages/app/app/(account)/auth.tsx:112"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-939bc6ac0d82ec34", "name": "Commented-code block (5 lines) in packages/app/app/(settings)/personal-details.tsx:95", "shortDescription": {"text": "Commented-code block (5 lines) in packages/app/app/(settings)/personal-details.tsx:95"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-57551cee6d0d030d", "name": "`fetch()` without try/.catch or AbortSignal \u2014 packages/app/app/(settings)/personal-details.tsx:101", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/app/app/(settings)/personal-details.tsx:101"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f5882f21804783e4", "name": "`fetch()` without try/.catch or AbortSignal \u2014 packages/app/lib/api-client.ts:24", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/app/lib/api-client.ts:24"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-54ff4d1e0f3c05ea", "name": "Commented-code block (5 lines) in packages/app/lib/widget-snapshot.ts:107", "shortDescription": {"text": "Commented-code block (5 lines) in packages/app/lib/widget-snapshot.ts:107"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-010753d3fa0618a5", "name": "Commented-code block (5 lines) in packages/app/lib/widget-derive.ts:118", "shortDescription": {"text": "Commented-code block (5 lines) in packages/app/lib/widget-derive.ts:118"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-84fbd954f69c8b5b", "name": "Commented-code block (5 lines) in packages/app/hooks/usePrayerShield.ts:211", "shortDescription": {"text": "Commented-code block (5 lines) in packages/app/hooks/usePrayerShield.ts:211"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-320ba60027c2fd4d", "name": "`fetch()` without try/.catch or AbortSignal \u2014 packages/marketing/src/lib/waitlist.ts:10", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/marketing/src/lib/waitlist.ts:10"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c5135f15c1d8ae80", "name": "Commented-code block (6 lines) in packages/core/src/achievements/calendar.ts:6", "shortDescription": {"text": "Commented-code block (6 lines) in packages/core/src/achievements/calendar.ts:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4ecb75a1a17145c3", "name": "`fetch()` without try/.catch or AbortSignal \u2014 packages/core/src/prayer/aladhan.ts:77", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/core/src/prayer/aladhan.ts:77"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e7f23ca782188503", "name": "Commented-code block (5 lines) in modules/expo-app-blocker/plugin/src/index.js:249", "shortDescription": {"text": "Commented-code block (5 lines) in modules/expo-app-blocker/plugin/src/index.js:249"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-af022f937dd5b7fd", "name": "9 env vars used in code but missing from .env.example", "shortDescription": {"text": "9 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `APPLE_CLIENT_ID`, `APPLE_KEY_ID`, `APPLE_PRIVATE_KEY`, `APPLE_TEAM_ID`, `CLOUDFLARE_ACCOUNT_ID`, `CLOUDFLARE_D1_TOKEN`, `CLOUDFLARE_DATABASE_ID`, `DEV` + 1 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5b318f4322b9ce29", "name": "Dangling fetch: GET /api/auth/get-session (packages/api/src/auth/auth.test.ts:38)", "shortDescription": {"text": "Dangling fetch: GET /api/auth/get-session (packages/api/src/auth/auth.test.ts:38)"}, "fullDescription": {"text": "`packages/api/src/auth/auth.test.ts:38` calls `GET /api/auth/get-session` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/get-session`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0b82dc74af91d99b", "name": "Dangling fetch: GET /api/auth/get-session (packages/api/src/auth/auth.test.ts:83)", "shortDescription": {"text": "Dangling fetch: GET /api/auth/get-session (packages/api/src/auth/auth.test.ts:83)"}, "fullDescription": {"text": "`packages/api/src/auth/auth.test.ts:83` calls `GET /api/auth/get-session` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/get-session`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f3f1bddc056b8c29", "name": "Dangling fetch: GET /boom (packages/api/src/stoker/middlewares/on-error.test.ts:28)", "shortDescription": {"text": "Dangling fetch: GET /boom (packages/api/src/stoker/middlewares/on-error.test.ts:28)"}, "fullDescription": {"text": "`packages/api/src/stoker/middlewares/on-error.test.ts:28` calls `GET /boom` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/boom`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3a6066907412ae18", "name": "Dangling fetch: GET /boom (packages/api/src/stoker/middlewares/on-error.test.ts:45)", "shortDescription": {"text": "Dangling fetch: GET /boom (packages/api/src/stoker/middlewares/on-error.test.ts:45)"}, "fullDescription": {"text": "`packages/api/src/stoker/middlewares/on-error.test.ts:45` calls `GET /boom` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/boom`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8b71a0ee4b96e519", "name": "Dangling fetch: GET /nope (packages/api/src/lib/create-app.test.ts:16)", "shortDescription": {"text": "Dangling fetch: GET /nope (packages/api/src/lib/create-app.test.ts:16)"}, "fullDescription": {"text": "`packages/api/src/lib/create-app.test.ts:16` calls `GET /nope` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/nope`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-28abba0c8a0a366a", "name": "Dangling fetch: GET /ping (packages/api/src/lib/create-app.test.ts:24)", "shortDescription": {"text": "Dangling fetch: GET /ping (packages/api/src/lib/create-app.test.ts:24)"}, "fullDescription": {"text": "`packages/api/src/lib/create-app.test.ts:24` calls `GET /ping` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/ping`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-497148a3abe2051f", "name": "Dangling fetch: GET /ping (packages/api/src/lib/create-app.test.ts:37)", "shortDescription": {"text": "Dangling fetch: GET /ping (packages/api/src/lib/create-app.test.ts:37)"}, "fullDescription": {"text": "`packages/api/src/lib/create-app.test.ts:37` calls `GET /ping` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/ping`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-446dcd47c60a4f52", "name": "Dangling fetch: GET /ping (packages/api/src/lib/create-app.test.ts:49)", "shortDescription": {"text": "Dangling fetch: GET /ping (packages/api/src/lib/create-app.test.ts:49)"}, "fullDescription": {"text": "`packages/api/src/lib/create-app.test.ts:49` calls `GET /ping` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/ping`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c6b1fef7310edd29", "name": "Dangling fetch: GET /ping (packages/api/src/lib/create-app.test.ts:61)", "shortDescription": {"text": "Dangling fetch: GET /ping (packages/api/src/lib/create-app.test.ts:61)"}, "fullDescription": {"text": "`packages/api/src/lib/create-app.test.ts:61` calls `GET /ping` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/ping`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f9ff5d73ae6f75a8", "name": "Dangling fetch: GET /api/auth/get-session (packages/api/src/lib/create-app.test.ts:73)", "shortDescription": {"text": "Dangling fetch: GET /api/auth/get-session (packages/api/src/lib/create-app.test.ts:73)"}, "fullDescription": {"text": "`packages/api/src/lib/create-app.test.ts:73` calls `GET /api/auth/get-session` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/get-session`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-52fe5979daaa5acb", "name": "Dangling fetch: GET /me (packages/api/src/routes/users/users.test.ts:23)", "shortDescription": {"text": "Dangling fetch: GET /me (packages/api/src/routes/users/users.test.ts:23)"}, "fullDescription": {"text": "`packages/api/src/routes/users/users.test.ts:23` calls `GET /me` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/me`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-28c974325c5007f7", "name": "Dangling fetch: GET /me/avatar (packages/api/src/routes/users/users.test.ts:56)", "shortDescription": {"text": "Dangling fetch: GET /me/avatar (packages/api/src/routes/users/users.test.ts:56)"}, "fullDescription": {"text": "`packages/api/src/routes/users/users.test.ts:56` calls `GET /me/avatar` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/me/avatar`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5d0efa64adcb0374", "name": "Dangling fetch: GET /avatars/ghost (packages/api/src/routes/users/users.test.ts:77)", "shortDescription": {"text": "Dangling fetch: GET /avatars/ghost (packages/api/src/routes/users/users.test.ts:77)"}, "fullDescription": {"text": "`packages/api/src/routes/users/users.test.ts:77` calls `GET /avatars/ghost` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/avatars/ghost`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0664fa0e2030779b", "name": "Dangling fetch: GET /avatars/seed-user (packages/api/src/routes/users/users.test.ts:93)", "shortDescription": {"text": "Dangling fetch: GET /avatars/seed-user (packages/api/src/routes/users/users.test.ts:93)"}, "fullDescription": {"text": "`packages/api/src/routes/users/users.test.ts:93` calls `GET /avatars/seed-user` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/avatars/seed-user`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a815b3b74ad7ade9", "name": "Dangling fetch: GET /achievements (packages/api/src/routes/achievements/achievements.test.ts:13)", "shortDescription": {"text": "Dangling fetch: GET /achievements (packages/api/src/routes/achievements/achievements.test.ts:13)"}, "fullDescription": {"text": "`packages/api/src/routes/achievements/achievements.test.ts:13` calls `GET /achievements` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/achievements`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7ab3cf5aa470341a", "name": "Dangling fetch: GET /achievements/unseen (packages/api/src/routes/achievements/achievements.test.ts:26)", "shortDescription": {"text": "Dangling fetch: GET /achievements/unseen (packages/api/src/routes/achievements/achievements.test.ts:26)"}, "fullDescription": {"text": "`packages/api/src/routes/achievements/achievements.test.ts:26` calls `GET /achievements/unseen` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/achievements/unseen`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b7dd0c6e5cdeaf90", "name": "Dangling fetch: GET /dhikr/today?date=2026-06-08 (packages/api/src/routes/dhikr/dhikr.test.ts:21)", "shortDescription": {"text": "Dangling fetch: GET /dhikr/today?date=2026-06-08 (packages/api/src/routes/dhikr/dhikr.test.ts:21)"}, "fullDescription": {"text": "`packages/api/src/routes/dhikr/dhikr.test.ts:21` calls `GET /dhikr/today?date=2026-06-08` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/dhikr/today`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ad662a2fcc7840e3", "name": "Dangling fetch: GET /dhikr/today?date=2026-02-30 (packages/api/src/routes/dhikr/dhikr.test.ts:30)", "shortDescription": {"text": "Dangling fetch: GET /dhikr/today?date=2026-02-30 (packages/api/src/routes/dhikr/dhikr.test.ts:30)"}, "fullDescription": {"text": "`packages/api/src/routes/dhikr/dhikr.test.ts:30` calls `GET /dhikr/today?date=2026-02-30` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/dhikr/today`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a9e2dc4dea59354c", "name": "Dangling fetch: GET /dhikr/today (packages/api/src/routes/dhikr/dhikr.test.ts:66)", "shortDescription": {"text": "Dangling fetch: GET /dhikr/today (packages/api/src/routes/dhikr/dhikr.test.ts:66)"}, "fullDescription": {"text": "`packages/api/src/routes/dhikr/dhikr.test.ts:66` calls `GET /dhikr/today` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/dhikr/today`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-390419b65e46e65d", "name": "Dangling fetch: GET /dhikr/presets (packages/api/src/routes/dhikr/dhikr.test.ts:74)", "shortDescription": {"text": "Dangling fetch: GET /dhikr/presets (packages/api/src/routes/dhikr/dhikr.test.ts:74)"}, "fullDescription": {"text": "`packages/api/src/routes/dhikr/dhikr.test.ts:74` calls `GET /dhikr/presets` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/dhikr/presets`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8d9a82a79315b919", "name": "Dangling fetch: GET /shield (packages/api/src/routes/shield-selection/shield-selection.test.ts:21)", "shortDescription": {"text": "Dangling fetch: GET /shield (packages/api/src/routes/shield-selection/shield-selection.test.ts:21)"}, "fullDescription": {"text": "`packages/api/src/routes/shield-selection/shield-selection.test.ts:21` calls `GET /shield` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/shield`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-05602aa68555881c", "name": "Dangling fetch: GET /app-config (packages/api/src/routes/app-config/app-config.test.ts:15)", "shortDescription": {"text": "Dangling fetch: GET /app-config (packages/api/src/routes/app-config/app-config.test.ts:15)"}, "fullDescription": {"text": "`packages/api/src/routes/app-config/app-config.test.ts:15` calls `GET /app-config` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/app-config`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bff8a4059fb1a4ca", "name": "Dangling fetch: GET /app-config (packages/api/src/routes/app-config/app-config.test.ts:27)", "shortDescription": {"text": "Dangling fetch: GET /app-config (packages/api/src/routes/app-config/app-config.test.ts:27)"}, "fullDescription": {"text": "`packages/api/src/routes/app-config/app-config.test.ts:27` calls `GET /app-config` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/app-config`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-95f74bde828157db", "name": "Dangling fetch: GET /health (packages/api/src/routes/health-check/health-check.test.ts:10)", "shortDescription": {"text": "Dangling fetch: GET /health (packages/api/src/routes/health-check/health-check.test.ts:10)"}, "fullDescription": {"text": "`packages/api/src/routes/health-check/health-check.test.ts:10` calls `GET /health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-11d2482db7e63327", "name": "Dangling fetch: GET /prayer-times?${query} (packages/api/src/routes/prayer-times/prayer-times.test.ts:16)", "shortDescription": {"text": "Dangling fetch: GET /prayer-times?${query} (packages/api/src/routes/prayer-times/prayer-times.test.ts:16)"}, "fullDescription": {"text": "`packages/api/src/routes/prayer-times/prayer-times.test.ts:16` calls `GET /prayer-times?${query}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/prayer-times`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a12f5ab5459eb862", "name": "Dangling fetch: GET /subscription (packages/api/src/routes/subscriptions/subscriptions.test.ts:13)", "shortDescription": {"text": "Dangling fetch: GET /subscription (packages/api/src/routes/subscriptions/subscriptions.test.ts:13)"}, "fullDescription": {"text": "`packages/api/src/routes/subscriptions/subscriptions.test.ts:13` calls `GET /subscription` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/subscription`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0d74e5fae1176eee", "name": "Dangling fetch: GET https://api.revenuecat.com/v1/subscribers/${encodeURIComponent(user.id)} (packages/api/src/routes/su", "shortDescription": {"text": "Dangling fetch: GET https://api.revenuecat.com/v1/subscribers/${encodeURIComponent(user.id)} (packages/api/src/routes/subscriptions/subscriptions.service.ts:392)"}, "fullDescription": {"text": "`packages/api/src/routes/subscriptions/subscriptions.service.ts:392` calls `GET https://api.revenuecat.com/v1/subscribers/${encodeURIComponent(user.id)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.revenuecat.com/v1/subscribers/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bef800c1aac2c1af", "name": "Dangling fetch: GET /locations (packages/api/src/routes/user-locations/user-locations.test.ts:13)", "shortDescription": {"text": "Dangling fetch: GET /locations (packages/api/src/routes/user-locations/user-locations.test.ts:13)"}, "fullDescription": {"text": "`packages/api/src/routes/user-locations/user-locations.test.ts:13` calls `GET /locations` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/locations`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2c45b52a5e95c4d1", "name": "Dangling fetch: GET /prayer-logs/week?startDate=2026-06-08 (packages/api/src/routes/prayer-logs/prayer-logs.test.ts:21)", "shortDescription": {"text": "Dangling fetch: GET /prayer-logs/week?startDate=2026-06-08 (packages/api/src/routes/prayer-logs/prayer-logs.test.ts:21)"}, "fullDescription": {"text": "`packages/api/src/routes/prayer-logs/prayer-logs.test.ts:21` calls `GET /prayer-logs/week?startDate=2026-06-08` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/prayer-logs/week`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-895f3a405f967d06", "name": "Dangling fetch: GET /prayer-logs/streak?today=2026-06-08 (packages/api/src/routes/prayer-logs/prayer-logs.test.ts:32)", "shortDescription": {"text": "Dangling fetch: GET /prayer-logs/streak?today=2026-06-08 (packages/api/src/routes/prayer-logs/prayer-logs.test.ts:32)"}, "fullDescription": {"text": "`packages/api/src/routes/prayer-logs/prayer-logs.test.ts:32` calls `GET /prayer-logs/streak?today=2026-06-08` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/prayer-logs/streak`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-33ca6bae3ab4b50b", "name": "Dangling fetch: GET /prayer-logs/week?startDate=2026-02-30 (packages/api/src/routes/prayer-logs/prayer-logs.test.ts:83)", "shortDescription": {"text": "Dangling fetch: GET /prayer-logs/week?startDate=2026-02-30 (packages/api/src/routes/prayer-logs/prayer-logs.test.ts:83)"}, "fullDescription": {"text": "`packages/api/src/routes/prayer-logs/prayer-logs.test.ts:83` calls `GET /prayer-logs/week?startDate=2026-02-30` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/prayer-logs/week`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2a720d15245233ee", "name": "Dangling fetch: GET /prayer-logs/week (packages/api/src/routes/prayer-logs/prayer-logs.test.ts:93)", "shortDescription": {"text": "Dangling fetch: GET /prayer-logs/week (packages/api/src/routes/prayer-logs/prayer-logs.test.ts:93)"}, "fullDescription": {"text": "`packages/api/src/routes/prayer-logs/prayer-logs.test.ts:93` calls `GET /prayer-logs/week` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/prayer-logs/week`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-85a3e1f622986edb", "name": "Dangling fetch: GET /prayer-logs/streak?today=2026-02-30 (packages/api/src/routes/prayer-logs/prayer-logs.test.ts:99)", "shortDescription": {"text": "Dangling fetch: GET /prayer-logs/streak?today=2026-02-30 (packages/api/src/routes/prayer-logs/prayer-logs.test.ts:99)"}, "fullDescription": {"text": "`packages/api/src/routes/prayer-logs/prayer-logs.test.ts:99` calls `GET /prayer-logs/streak?today=2026-02-30` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/prayer-logs/streak`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5077c8a360d2be3c", "name": "Dangling fetch: GET /prayer-logs/streak (packages/api/src/routes/prayer-logs/prayer-logs.test.ts:109)", "shortDescription": {"text": "Dangling fetch: GET /prayer-logs/streak (packages/api/src/routes/prayer-logs/prayer-logs.test.ts:109)"}, "fullDescription": {"text": "`packages/api/src/routes/prayer-logs/prayer-logs.test.ts:109` calls `GET /prayer-logs/streak` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/prayer-logs/streak`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3d72d47b510a54fa", "name": "Dangling fetch: GET /y (packages/api/src/middlewares/rate-limit.test.ts:14)", "shortDescription": {"text": "Dangling fetch: GET /y (packages/api/src/middlewares/rate-limit.test.ts:14)"}, "fullDescription": {"text": "`packages/api/src/middlewares/rate-limit.test.ts:14` calls `GET /y` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/y`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8017bea128ffb941", "name": "Dangling fetch: GET /z (packages/api/src/middlewares/rate-limit.test.ts:29)", "shortDescription": {"text": "Dangling fetch: GET /z (packages/api/src/middlewares/rate-limit.test.ts:29)"}, "fullDescription": {"text": "`packages/api/src/middlewares/rate-limit.test.ts:29` calls `GET /z` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/z`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0f611c5786881c5b", "name": "Dangling fetch: GET /whoami (packages/api/src/middlewares/auth-session.test.ts:26)", "shortDescription": {"text": "Dangling fetch: GET /whoami (packages/api/src/middlewares/auth-session.test.ts:26)"}, "fullDescription": {"text": "`packages/api/src/middlewares/auth-session.test.ts:26` calls `GET /whoami` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/whoami`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5dfb4d20e6be0241", "name": "Dangling fetch: GET /protected (packages/api/src/middlewares/auth-session.test.ts:35)", "shortDescription": {"text": "Dangling fetch: GET /protected (packages/api/src/middlewares/auth-session.test.ts:35)"}, "fullDescription": {"text": "`packages/api/src/middlewares/auth-session.test.ts:35` calls `GET /protected` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/protected`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-929929951a94358b", "name": "Dangling fetch: GET /whoami (packages/api/src/middlewares/auth-session.test.ts:43)", "shortDescription": {"text": "Dangling fetch: GET /whoami (packages/api/src/middlewares/auth-session.test.ts:43)"}, "fullDescription": {"text": "`packages/api/src/middlewares/auth-session.test.ts:43` calls `GET /whoami` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/whoami`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e0c9700d4e658bba", "name": "Dangling fetch: GET /x (packages/api/src/middlewares/logger.test.ts:16)", "shortDescription": {"text": "Dangling fetch: GET /x (packages/api/src/middlewares/logger.test.ts:16)"}, "fullDescription": {"text": "`packages/api/src/middlewares/logger.test.ts:16` calls `GET /x` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/x`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-41b9749ce7dc04bb", "name": "Unused endpoint: GET /sync", "shortDescription": {"text": "Unused endpoint: GET /sync"}, "fullDescription": {"text": "`packages/api/src/index.ts` declares `GET /sync` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-15f85d9a993ba7cd", "name": "Unused endpoint: USE /doc", "shortDescription": {"text": "Unused endpoint: USE /doc"}, "fullDescription": {"text": "`packages/api/src/lib/configure-open-api.ts` declares `USE /doc` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b82f2c3c8954bf1c", "name": "Unused endpoint: USE /docs", "shortDescription": {"text": "Unused endpoint: USE /docs"}, "fullDescription": {"text": "`packages/api/src/lib/configure-open-api.ts` declares `USE /docs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eb0428442a390121", "name": "Unused endpoint: GET /docs", "shortDescription": {"text": "Unused endpoint: GET /docs"}, "fullDescription": {"text": "`packages/api/src/lib/configure-open-api.ts` declares `GET /docs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5fe0dc8d2b520970", "name": "Unused endpoint: GET /avatars/:authUserId", "shortDescription": {"text": "Unused endpoint: GET /avatars/:authUserId"}, "fullDescription": {"text": "`packages/api/src/routes/users/users.index.ts` declares `GET /avatars/:authUserId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-518208a3c6fff7c9", "name": "Unused endpoint: USE /marketing/waitlist", "shortDescription": {"text": "Unused endpoint: USE /marketing/waitlist"}, "fullDescription": {"text": "`packages/api/src/routes/marketing/marketing.index.ts` declares `USE /marketing/waitlist` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-85258d174dd43b8c", "name": "Unused endpoint: POST /webhooks/resend", "shortDescription": {"text": "Unused endpoint: POST /webhooks/resend"}, "fullDescription": {"text": "`packages/api/src/routes/webhooks/resend/resend.index.ts` declares `POST /webhooks/resend` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f0def27a98d61ec9", "name": "Unused endpoint: POST /webhooks/polar", "shortDescription": {"text": "Unused endpoint: POST /webhooks/polar"}, "fullDescription": {"text": "`packages/api/src/routes/webhooks/polar/polar.index.ts` declares `POST /webhooks/polar` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/20067"}, "properties": {"repository": "souravsspace/heybarakah.app", "repoUrl": "https://github.com/souravsspace/heybarakah.app", "branch": "main"}, "results": [{"ruleId": "scanner-abf835431cfdab0c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/app/lib/widgets-native.ts:98"}, "properties": {"repobilityId": "64964c73498343f5", "scanner": "scanner-primary", "fingerprint": "abf835431cfdab0c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0ea108be16a662eb", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/core/scripts/generate-apple-secret.ts:30"}, "properties": {"repobilityId": "df9f9755c8264504", "scanner": "scanner-primary", "fingerprint": "0ea108be16a662eb", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-156ee1cfb7456a57", "level": "note", "message": {"text": "Very large file: design/project/_ds_bundle.js (21309 lines)"}, "properties": {"repobilityId": "c2adfbddc614356d", "scanner": "scanner-primary", "fingerprint": "156ee1cfb7456a57", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ea3b5e389d8c9c0f", "level": "note", "message": {"text": "Low test-to-source ratio"}, "properties": {"repobilityId": "ef7b2552cc00a375", "scanner": "scanner-primary", "fingerprint": "ea3b5e389d8c9c0f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["tests"]}}, {"ruleId": "scanner-47c58d42565e2f33", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/mails/package.json"}, "properties": {"repobilityId": "e7a816d090aecc5c", "scanner": "scanner-primary", "fingerprint": "47c58d42565e2f33", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/mails/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0a0634ffe3eb1107", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/api/package.json"}, "properties": {"repobilityId": "61aa8b13d545e157", "scanner": "scanner-primary", "fingerprint": "0a0634ffe3eb1107", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/api/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4bf95f042f6cdfd9", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/app/package.json"}, "properties": {"repobilityId": "191a196ac66f8166", "scanner": "scanner-primary", "fingerprint": "4bf95f042f6cdfd9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/app/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fad615c5b91d5115", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/marketing/package.json"}, "properties": {"repobilityId": "0d208fdfc220ef4d", "scanner": "scanner-primary", "fingerprint": "fad615c5b91d5115", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/marketing/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-28e92806c0db3cd2", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/core/package.json"}, "properties": {"repobilityId": "8640e46be7e3f9b2", "scanner": "scanner-primary", "fingerprint": "28e92806c0db3cd2", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/core/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-32b90739bf6c25a9", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: modules/expo-app-blocker/package.json"}, "properties": {"repobilityId": "42c92aa802befffb", "scanner": "scanner-primary", "fingerprint": "32b90739bf6c25a9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "modules/expo-app-blocker/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "53060cf2f8327788", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "f00d554e7f8ed325", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "87fb3a17e31b155f", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "b195762201e822fd", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "9d526254663f22e5", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-f5f2d616fc41a694", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: packages/mails/CLAUDE.md"}, "properties": {"repobilityId": "482d740eeec21958", "scanner": "scanner-primary", "fingerprint": "f5f2d616fc41a694", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/mails/CLAUDE.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-122f91b7f2906dc4", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/settings.json"}, "properties": {"repobilityId": "a2967269048b6a9d", "scanner": "scanner-primary", "fingerprint": "122f91b7f2906dc4", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/settings.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-eae51b9ba9234e77", "level": "none", "message": {"text": "Commented-code block (7 lines) in design/project/_ds_bundle.js:210"}, "properties": {"repobilityId": "88fd01e7b6a1ff9d", "scanner": "scanner-primary", "fingerprint": "eae51b9ba9234e77", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-87bdbb45e48e8825", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 design/project/_ds_bundle.js:9659"}, "properties": {"repobilityId": "04f3297769cdbb4b", "scanner": "scanner-primary", "fingerprint": "87bdbb45e48e8825", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-44dff568675c727e", "level": "none", "message": {"text": "Commented-code block (5 lines) in design/project/index.tsx:52"}, "properties": {"repobilityId": "d947824a3af984a4", "scanner": "scanner-primary", "fingerprint": "44dff568675c727e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e00eb36fc9a44e5c", "level": "none", "message": {"text": "Commented-code block (7 lines) in design/project/(account)/auth.tsx:257"}, "properties": {"repobilityId": "e14b88e551cbb179", "scanner": "scanner-primary", "fingerprint": "e00eb36fc9a44e5c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b7b5580dd67a11ca", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 design/project/(settings)/personal-details.tsx:88"}, "properties": {"repobilityId": "0e343ee4eccd71b7", "scanner": "scanner-primary", "fingerprint": "b7b5580dd67a11ca", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-930e35f5e2fa164f", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/api/vitest.config.ts:12"}, "properties": {"repobilityId": "eb0400556ea7a6dd", "scanner": "scanner-primary", "fingerprint": "930e35f5e2fa164f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b3ad6b45aa1f344a", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/api/src/index.ts:33"}, "properties": {"repobilityId": "73cb20948beb9e15", "scanner": "scanner-primary", "fingerprint": "b3ad6b45aa1f344a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-9d520219bf79585e", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/api/src/index.ts:49"}, "properties": {"repobilityId": "ebf1e19547dfc67f", "scanner": "scanner-primary", "fingerprint": "9d520219bf79585e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-a78cb46fcebe2cb0", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/api/src/sync/sync-hub.ts:32"}, "properties": {"repobilityId": "4d96453bdfe8ecb1", "scanner": "scanner-primary", "fingerprint": "a78cb46fcebe2cb0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-9c2424f98667c73e", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/api/src/lib/configure-open-api.ts:8"}, "properties": {"repobilityId": "cf25278eb6a29e89", "scanner": "scanner-primary", "fingerprint": "9c2424f98667c73e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-42750382fd70a98d", "level": "none", "message": {"text": "Commented-code block (6 lines) in packages/api/src/lib/resend.ts:66"}, "properties": {"repobilityId": "a5b2aa7ba20e864b", "scanner": "scanner-primary", "fingerprint": "42750382fd70a98d", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0c693abb3a31318b", "level": "none", "message": {"text": "Commented-code block (6 lines) in packages/api/src/routes/users/users.service.ts:155"}, "properties": {"repobilityId": "8005ae4e72dd4f25", "scanner": "scanner-primary", "fingerprint": "0c693abb3a31318b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b1c57e4f5eabcbb9", "level": "none", "message": {"text": "Commented-code block (7 lines) in packages/api/src/routes/dhikr/dhikr.service.ts:107"}, "properties": {"repobilityId": "ea788c24e7d09513", "scanner": "scanner-primary", "fingerprint": "b1c57e4f5eabcbb9", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4de1e1409e737e3d", "level": "none", "message": {"text": "Commented-code block (6 lines) in packages/api/src/routes/prayer-times/prayer-times.routes.ts:19"}, "properties": {"repobilityId": "42b9daac2e268e51", "scanner": "scanner-primary", "fingerprint": "4de1e1409e737e3d", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2bdba00674f2a2f8", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/api/src/routes/subscriptions/subscriptions.service.ts:392"}, "properties": {"repobilityId": "9d53d865e3ed9ad2", "scanner": "scanner-primary", "fingerprint": "2bdba00674f2a2f8", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-cd611dc6a291d4a8", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/api/src/routes/prayer-logs/prayer-logs.service.ts:59"}, "properties": {"repobilityId": "269be93aedd139c4", "scanner": "scanner-primary", "fingerprint": "cd611dc6a291d4a8", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f062525c5a3b83fd", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/api/src/test-support/apply-migrations.ts:4"}, "properties": {"repobilityId": "83a3946a076c8a7e", "scanner": "scanner-primary", "fingerprint": "f062525c5a3b83fd", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2a5b773d9472985b", "level": "none", "message": {"text": "Commented-code block (6 lines) in packages/app/widgets/lock-activity.tsx:43"}, "properties": {"repobilityId": "243e7076cd246b6c", "scanner": "scanner-primary", "fingerprint": "2a5b773d9472985b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-71a1437b05618390", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/app/widgets/dhikr.widget.tsx:37"}, "properties": {"repobilityId": "d5ca3681f1ce060f", "scanner": "scanner-primary", "fingerprint": "71a1437b05618390", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-be3414c93b7c4acf", "level": "none", "message": {"text": "Commented-code block (7 lines) in packages/app/widgets/salah-arc.widget.tsx:33"}, "properties": {"repobilityId": "baec00235df40c1c", "scanner": "scanner-primary", "fingerprint": "be3414c93b7c4acf", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-fd62ea88fcfdd103", "level": "none", "message": {"text": "Commented-code block (11 lines) in packages/app/app/logging-out.tsx:23"}, "properties": {"repobilityId": "327c19caa3019d7c", "scanner": "scanner-primary", "fingerprint": "fd62ea88fcfdd103", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-cbdf0a30d8a5a5aa", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/app/app/index.tsx:52"}, "properties": {"repobilityId": "d8d8ec3b96221ae5", "scanner": "scanner-primary", "fingerprint": "cbdf0a30d8a5a5aa", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b0fbd0ef91ad4957", "level": "none", "message": {"text": "Commented-code block (6 lines) in packages/app/app/(account)/auth.tsx:112"}, "properties": {"repobilityId": "b09218b46eb6c6ea", "scanner": "scanner-primary", "fingerprint": "b0fbd0ef91ad4957", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-939bc6ac0d82ec34", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/app/app/(settings)/personal-details.tsx:95"}, "properties": {"repobilityId": "f9beca2df92ab3e2", "scanner": "scanner-primary", "fingerprint": "939bc6ac0d82ec34", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-57551cee6d0d030d", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/app/app/(settings)/personal-details.tsx:101"}, "properties": {"repobilityId": "a9f5625930d244b6", "scanner": "scanner-primary", "fingerprint": "57551cee6d0d030d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-f5882f21804783e4", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/app/lib/api-client.ts:24"}, "properties": {"repobilityId": "2327e507a09d4c6c", "scanner": "scanner-primary", "fingerprint": "f5882f21804783e4", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-54ff4d1e0f3c05ea", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/app/lib/widget-snapshot.ts:107"}, "properties": {"repobilityId": "f9a92c112b02c209", "scanner": "scanner-primary", "fingerprint": "54ff4d1e0f3c05ea", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-010753d3fa0618a5", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/app/lib/widget-derive.ts:118"}, "properties": {"repobilityId": "37fe36085ec52f9f", "scanner": "scanner-primary", "fingerprint": "010753d3fa0618a5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-84fbd954f69c8b5b", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/app/hooks/usePrayerShield.ts:211"}, "properties": {"repobilityId": "7ed9c32c936035f9", "scanner": "scanner-primary", "fingerprint": "84fbd954f69c8b5b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-320ba60027c2fd4d", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/marketing/src/lib/waitlist.ts:10"}, "properties": {"repobilityId": "ebe5098f1d989df2", "scanner": "scanner-primary", "fingerprint": "320ba60027c2fd4d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-c5135f15c1d8ae80", "level": "none", "message": {"text": "Commented-code block (6 lines) in packages/core/src/achievements/calendar.ts:6"}, "properties": {"repobilityId": "0aa205722b96de95", "scanner": "scanner-primary", "fingerprint": "c5135f15c1d8ae80", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4ecb75a1a17145c3", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/core/src/prayer/aladhan.ts:77"}, "properties": {"repobilityId": "84ba782c2a878e3a", "scanner": "scanner-primary", "fingerprint": "4ecb75a1a17145c3", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-e7f23ca782188503", "level": "none", "message": {"text": "Commented-code block (5 lines) in modules/expo-app-blocker/plugin/src/index.js:249"}, "properties": {"repobilityId": "c3ae2d778b16a109", "scanner": "scanner-primary", "fingerprint": "e7f23ca782188503", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-af022f937dd5b7fd", "level": "note", "message": {"text": "9 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "5597384795dea7a4", "scanner": "scanner-primary", "fingerprint": "af022f937dd5b7fd", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-5b318f4322b9ce29", "level": "error", "message": {"text": "Dangling fetch: GET /api/auth/get-session (packages/api/src/auth/auth.test.ts:38)"}, "properties": {"repobilityId": "e68f8beec40da2f2", "scanner": "scanner-primary", "fingerprint": "5b318f4322b9ce29", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-0b82dc74af91d99b", "level": "error", "message": {"text": "Dangling fetch: GET /api/auth/get-session (packages/api/src/auth/auth.test.ts:83)"}, "properties": {"repobilityId": "4c2232d5784f65c0", "scanner": "scanner-primary", "fingerprint": "0b82dc74af91d99b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-f3f1bddc056b8c29", "level": "error", "message": {"text": "Dangling fetch: GET /boom (packages/api/src/stoker/middlewares/on-error.test.ts:28)"}, "properties": {"repobilityId": "28fb312d2b500501", "scanner": "scanner-primary", "fingerprint": "f3f1bddc056b8c29", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-3a6066907412ae18", "level": "error", "message": {"text": "Dangling fetch: GET /boom (packages/api/src/stoker/middlewares/on-error.test.ts:45)"}, "properties": {"repobilityId": "127cbbc1c76cc0b6", "scanner": "scanner-primary", "fingerprint": "3a6066907412ae18", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-8b71a0ee4b96e519", "level": "error", "message": {"text": "Dangling fetch: GET /nope (packages/api/src/lib/create-app.test.ts:16)"}, "properties": {"repobilityId": "4f335ca2bd313e09", "scanner": "scanner-primary", "fingerprint": "8b71a0ee4b96e519", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-28abba0c8a0a366a", "level": "error", "message": {"text": "Dangling fetch: GET /ping (packages/api/src/lib/create-app.test.ts:24)"}, "properties": {"repobilityId": "2f81947155c36cff", "scanner": "scanner-primary", "fingerprint": "28abba0c8a0a366a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-497148a3abe2051f", "level": "error", "message": {"text": "Dangling fetch: GET /ping (packages/api/src/lib/create-app.test.ts:37)"}, "properties": {"repobilityId": "4f80d4d2eca7d0d7", "scanner": "scanner-primary", "fingerprint": "497148a3abe2051f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-446dcd47c60a4f52", "level": "error", "message": {"text": "Dangling fetch: GET /ping (packages/api/src/lib/create-app.test.ts:49)"}, "properties": {"repobilityId": "ab53751b59461a15", "scanner": "scanner-primary", "fingerprint": "446dcd47c60a4f52", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-c6b1fef7310edd29", "level": "error", "message": {"text": "Dangling fetch: GET /ping (packages/api/src/lib/create-app.test.ts:61)"}, "properties": {"repobilityId": "1c912382e8cd04a2", "scanner": "scanner-primary", "fingerprint": "c6b1fef7310edd29", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-f9ff5d73ae6f75a8", "level": "error", "message": {"text": "Dangling fetch: GET /api/auth/get-session (packages/api/src/lib/create-app.test.ts:73)"}, "properties": {"repobilityId": "b5c5aed6417bf6dc", "scanner": "scanner-primary", "fingerprint": "f9ff5d73ae6f75a8", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-52fe5979daaa5acb", "level": "error", "message": {"text": "Dangling fetch: GET /me (packages/api/src/routes/users/users.test.ts:23)"}, "properties": {"repobilityId": "82ae330d43685b9f", "scanner": "scanner-primary", "fingerprint": "52fe5979daaa5acb", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-28c974325c5007f7", "level": "error", "message": {"text": "Dangling fetch: GET /me/avatar (packages/api/src/routes/users/users.test.ts:56)"}, "properties": {"repobilityId": "9aadbc0969efc4ce", "scanner": "scanner-primary", "fingerprint": "28c974325c5007f7", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-5d0efa64adcb0374", "level": "error", "message": {"text": "Dangling fetch: GET /avatars/ghost (packages/api/src/routes/users/users.test.ts:77)"}, "properties": {"repobilityId": "4bca1c70dc6322c6", "scanner": "scanner-primary", "fingerprint": "5d0efa64adcb0374", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-0664fa0e2030779b", "level": "error", "message": {"text": "Dangling fetch: GET /avatars/seed-user (packages/api/src/routes/users/users.test.ts:93)"}, "properties": {"repobilityId": "f257e0b2ab3a0529", "scanner": "scanner-primary", "fingerprint": "0664fa0e2030779b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-a815b3b74ad7ade9", "level": "error", "message": {"text": "Dangling fetch: GET /achievements (packages/api/src/routes/achievements/achievements.test.ts:13)"}, "properties": {"repobilityId": "ea043ba62d441ee5", "scanner": "scanner-primary", "fingerprint": "a815b3b74ad7ade9", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-7ab3cf5aa470341a", "level": "error", "message": {"text": "Dangling fetch: GET /achievements/unseen (packages/api/src/routes/achievements/achievements.test.ts:26)"}, "properties": {"repobilityId": "c3c72c7fc2f72127", "scanner": "scanner-primary", "fingerprint": "7ab3cf5aa470341a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-b7dd0c6e5cdeaf90", "level": "error", "message": {"text": "Dangling fetch: GET /dhikr/today?date=2026-06-08 (packages/api/src/routes/dhikr/dhikr.test.ts:21)"}, "properties": {"repobilityId": "79cf3bc01dcac214", "scanner": "scanner-primary", "fingerprint": "b7dd0c6e5cdeaf90", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-ad662a2fcc7840e3", "level": "error", "message": {"text": "Dangling fetch: GET /dhikr/today?date=2026-02-30 (packages/api/src/routes/dhikr/dhikr.test.ts:30)"}, "properties": {"repobilityId": "867a759446cadc15", "scanner": "scanner-primary", "fingerprint": "ad662a2fcc7840e3", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-a9e2dc4dea59354c", "level": "error", "message": {"text": "Dangling fetch: GET /dhikr/today (packages/api/src/routes/dhikr/dhikr.test.ts:66)"}, "properties": {"repobilityId": "26591ee98236c782", "scanner": "scanner-primary", "fingerprint": "a9e2dc4dea59354c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-390419b65e46e65d", "level": "error", "message": {"text": "Dangling fetch: GET /dhikr/presets (packages/api/src/routes/dhikr/dhikr.test.ts:74)"}, "properties": {"repobilityId": "5d5ce18bccd7d8ba", "scanner": "scanner-primary", "fingerprint": "390419b65e46e65d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-8d9a82a79315b919", "level": "error", "message": {"text": "Dangling fetch: GET /shield (packages/api/src/routes/shield-selection/shield-selection.test.ts:21)"}, "properties": {"repobilityId": "a82c960c98dccfc9", "scanner": "scanner-primary", "fingerprint": "8d9a82a79315b919", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-05602aa68555881c", "level": "error", "message": {"text": "Dangling fetch: GET /app-config (packages/api/src/routes/app-config/app-config.test.ts:15)"}, "properties": {"repobilityId": "73227830d88bd8c2", "scanner": "scanner-primary", "fingerprint": "05602aa68555881c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-bff8a4059fb1a4ca", "level": "error", "message": {"text": "Dangling fetch: GET /app-config (packages/api/src/routes/app-config/app-config.test.ts:27)"}, "properties": {"repobilityId": "017354b0b2d0a773", "scanner": "scanner-primary", "fingerprint": "bff8a4059fb1a4ca", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-95f74bde828157db", "level": "error", "message": {"text": "Dangling fetch: GET /health (packages/api/src/routes/health-check/health-check.test.ts:10)"}, "properties": {"repobilityId": "7522eeeb56f43612", "scanner": "scanner-primary", "fingerprint": "95f74bde828157db", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-11d2482db7e63327", "level": "error", "message": {"text": "Dangling fetch: GET /prayer-times?${query} (packages/api/src/routes/prayer-times/prayer-times.test.ts:16)"}, "properties": {"repobilityId": "186a985d954be688", "scanner": "scanner-primary", "fingerprint": "11d2482db7e63327", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-a12f5ab5459eb862", "level": "error", "message": {"text": "Dangling fetch: GET /subscription (packages/api/src/routes/subscriptions/subscriptions.test.ts:13)"}, "properties": {"repobilityId": "c18f31683013eb23", "scanner": "scanner-primary", "fingerprint": "a12f5ab5459eb862", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-0d74e5fae1176eee", "level": "error", "message": {"text": "Dangling fetch: GET https://api.revenuecat.com/v1/subscribers/${encodeURIComponent(user.id)} (packages/api/src/routes/subscriptions/subscriptions.service.ts:392)"}, "properties": {"repobilityId": "cf5d664db68fe598", "scanner": "scanner-primary", "fingerprint": "0d74e5fae1176eee", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-bef800c1aac2c1af", "level": "error", "message": {"text": "Dangling fetch: GET /locations (packages/api/src/routes/user-locations/user-locations.test.ts:13)"}, "properties": {"repobilityId": "33d9f1a153b363a9", "scanner": "scanner-primary", "fingerprint": "bef800c1aac2c1af", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-2c45b52a5e95c4d1", "level": "error", "message": {"text": "Dangling fetch: GET /prayer-logs/week?startDate=2026-06-08 (packages/api/src/routes/prayer-logs/prayer-logs.test.ts:21)"}, "properties": {"repobilityId": "aa13bee285161713", "scanner": "scanner-primary", "fingerprint": "2c45b52a5e95c4d1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-895f3a405f967d06", "level": "error", "message": {"text": "Dangling fetch: GET /prayer-logs/streak?today=2026-06-08 (packages/api/src/routes/prayer-logs/prayer-logs.test.ts:32)"}, "properties": {"repobilityId": "b77daba28ec05f57", "scanner": "scanner-primary", "fingerprint": "895f3a405f967d06", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-33ca6bae3ab4b50b", "level": "error", "message": {"text": "Dangling fetch: GET /prayer-logs/week?startDate=2026-02-30 (packages/api/src/routes/prayer-logs/prayer-logs.test.ts:83)"}, "properties": {"repobilityId": "a3fad404129d3aa8", "scanner": "scanner-primary", "fingerprint": "33ca6bae3ab4b50b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-2a720d15245233ee", "level": "error", "message": {"text": "Dangling fetch: GET /prayer-logs/week (packages/api/src/routes/prayer-logs/prayer-logs.test.ts:93)"}, "properties": {"repobilityId": "d9870bed243d5372", "scanner": "scanner-primary", "fingerprint": "2a720d15245233ee", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-85a3e1f622986edb", "level": "error", "message": {"text": "Dangling fetch: GET /prayer-logs/streak?today=2026-02-30 (packages/api/src/routes/prayer-logs/prayer-logs.test.ts:99)"}, "properties": {"repobilityId": "25718e850e496307", "scanner": "scanner-primary", "fingerprint": "85a3e1f622986edb", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-5077c8a360d2be3c", "level": "error", "message": {"text": "Dangling fetch: GET /prayer-logs/streak (packages/api/src/routes/prayer-logs/prayer-logs.test.ts:109)"}, "properties": {"repobilityId": "0cc8ae53aa3f32b1", "scanner": "scanner-primary", "fingerprint": "5077c8a360d2be3c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-3d72d47b510a54fa", "level": "error", "message": {"text": "Dangling fetch: GET /y (packages/api/src/middlewares/rate-limit.test.ts:14)"}, "properties": {"repobilityId": "fa9ef545afbfd326", "scanner": "scanner-primary", "fingerprint": "3d72d47b510a54fa", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-8017bea128ffb941", "level": "error", "message": {"text": "Dangling fetch: GET /z (packages/api/src/middlewares/rate-limit.test.ts:29)"}, "properties": {"repobilityId": "138cf2f8a05d68bc", "scanner": "scanner-primary", "fingerprint": "8017bea128ffb941", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-0f611c5786881c5b", "level": "error", "message": {"text": "Dangling fetch: GET /whoami (packages/api/src/middlewares/auth-session.test.ts:26)"}, "properties": {"repobilityId": "2517b3999b49f11e", "scanner": "scanner-primary", "fingerprint": "0f611c5786881c5b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-5dfb4d20e6be0241", "level": "error", "message": {"text": "Dangling fetch: GET /protected (packages/api/src/middlewares/auth-session.test.ts:35)"}, "properties": {"repobilityId": "81686543c2f66b99", "scanner": "scanner-primary", "fingerprint": "5dfb4d20e6be0241", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-929929951a94358b", "level": "error", "message": {"text": "Dangling fetch: GET /whoami (packages/api/src/middlewares/auth-session.test.ts:43)"}, "properties": {"repobilityId": "33b945ea74a2561d", "scanner": "scanner-primary", "fingerprint": "929929951a94358b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-e0c9700d4e658bba", "level": "error", "message": {"text": "Dangling fetch: GET /x (packages/api/src/middlewares/logger.test.ts:16)"}, "properties": {"repobilityId": "c7463ce1f0c3061b", "scanner": "scanner-primary", "fingerprint": "e0c9700d4e658bba", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-41b9749ce7dc04bb", "level": "note", "message": {"text": "Unused endpoint: GET /sync"}, "properties": {"repobilityId": "31fb21c6eb2614df", "scanner": "scanner-primary", "fingerprint": "41b9749ce7dc04bb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-15f85d9a993ba7cd", "level": "note", "message": {"text": "Unused endpoint: USE /doc"}, "properties": {"repobilityId": "569ea141d018cd68", "scanner": "scanner-primary", "fingerprint": "15f85d9a993ba7cd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b82f2c3c8954bf1c", "level": "note", "message": {"text": "Unused endpoint: USE /docs"}, "properties": {"repobilityId": "e0b492fc44e00f9a", "scanner": "scanner-primary", "fingerprint": "b82f2c3c8954bf1c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-eb0428442a390121", "level": "note", "message": {"text": "Unused endpoint: GET /docs"}, "properties": {"repobilityId": "b190700d48ca949d", "scanner": "scanner-primary", "fingerprint": "eb0428442a390121", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5fe0dc8d2b520970", "level": "note", "message": {"text": "Unused endpoint: GET /avatars/:authUserId"}, "properties": {"repobilityId": "b2e2564e0658d2d4", "scanner": "scanner-primary", "fingerprint": "5fe0dc8d2b520970", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-518208a3c6fff7c9", "level": "note", "message": {"text": "Unused endpoint: USE /marketing/waitlist"}, "properties": {"repobilityId": "7e6cebc0aecc3ad6", "scanner": "scanner-primary", "fingerprint": "518208a3c6fff7c9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-85258d174dd43b8c", "level": "note", "message": {"text": "Unused endpoint: POST /webhooks/resend"}, "properties": {"repobilityId": "32f6512c4106dd7f", "scanner": "scanner-primary", "fingerprint": "85258d174dd43b8c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f0def27a98d61ec9", "level": "note", "message": {"text": "Unused endpoint: POST /webhooks/polar"}, "properties": {"repobilityId": "06bf0973d354735b", "scanner": "scanner-primary", "fingerprint": "f0def27a98d61ec9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}