{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-81747e21b79d38a0", "name": "Stray `console.log` in TS/JS \u2014 scripts/seed-tags.ts:22", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/seed-tags.ts:22"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a2b74f31402d7ff6", "name": "Stray `console.log` in TS/JS \u2014 prisma/seed-demo.ts:17", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 prisma/seed-demo.ts:17"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c9aa1638a97dd567", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/sidebar.tsx:181", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/sidebar.tsx:181"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3e6dbc035f414dac", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 src/app/layout.tsx:15", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 src/app/layout.tsx:15"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-85f296d31f3ba810", "name": "`truncate` class without `title=` for hover reveal \u2014 src/app/(dashboard)/dashboard/reminders/reminders-view.tsx:307", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/app/(dashboard)/dashboard/reminders/reminders-view.tsx:307"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-37be04b088fad4a0", "name": "`truncate` class without `title=` for hover reveal \u2014 src/app/(dashboard)/dashboard/companies/companies-view.tsx:174", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/app/(dashboard)/dashboard/companies/companies-view.tsx:174"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f221071f4c31c396", "name": "Stray `console.log` in TS/JS \u2014 src/scratch/test-search.ts:6", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scratch/test-search.ts:6"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b085c1b0229ff5ca", "name": "Stray `console.log` in TS/JS \u2014 src/scratch/check-db-contacts.ts:19", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scratch/check-db-contacts.ts:19"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bbb275cbf25ec249", "name": "Stray `console.log` in TS/JS \u2014 src/scratch/test-api.ts:3", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scratch/test-api.ts:3"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c88e1ecdac6f315f", "name": "Stray `console.log` in TS/JS \u2014 src/scratch/check-beeper-db.ts:8", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scratch/check-beeper-db.ts:8"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-389b277a8285e051", "name": "Stray `console.log` in TS/JS \u2014 src/scratch/test-local-api.ts:6", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scratch/test-local-api.ts:6"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-db8fc654f26f4996", "name": "Stray `console.log` in TS/JS \u2014 src/scratch/migrate-userid.ts:5", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scratch/migrate-userid.ts:5"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e8651dfa0566dc49", "name": "Stray `console.log` in TS/JS \u2014 src/scratch/check-messages.ts:49", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scratch/check-messages.ts:49"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f20d15134d4dab6f", "name": "Stray `console.log` in TS/JS \u2014 src/scratch/test-beeper.ts:6", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scratch/test-beeper.ts:6"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c4141cbb224b6099", "name": "Stray `console.log` in TS/JS \u2014 src/scratch/test-local-decrypt.ts:6", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scratch/test-local-decrypt.ts:6"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2862a19a1e6da3a2", "name": "Stray `console.log` in TS/JS \u2014 src/scratch/check-userids.ts:5", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scratch/check-userids.ts:5"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-63085e5d0141c09e", "name": "Stray `console.log` in TS/JS \u2014 src/scratch/cleanup-dups.ts:26", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scratch/cleanup-dups.ts:26"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8be12cf9841da87e", "name": "Stray `console.log` in TS/JS \u2014 src/scratch/test-local-send.ts:20", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/scratch/test-local-send.ts:20"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d4d9a54a9bec6f72", "name": "Stray `console.log` in TS/JS \u2014 src/server/index.ts:11", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/index.ts:11"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cab0f581281e71aa", "name": "Stray `console.log` in TS/JS \u2014 src/server/import/beeper.ts:111", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/import/beeper.ts:111"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ff1b7162789c909c", "name": "Stray `console.log` in TS/JS \u2014 src/server/lib/redis.ts:8", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/lib/redis.ts:8"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-581996b6a578d0ad", "name": "Stray `console.log` in TS/JS \u2014 src/server/lib/media-store.ts:100", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/lib/media-store.ts:100"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c34a5d5f4920cd7f", "name": "Stray `console.log` in TS/JS \u2014 src/server/routes/gmail.routes.ts:32", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/routes/gmail.routes.ts:32"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c9b2606e71c51976", "name": "Stray `console.log` in TS/JS \u2014 src/server/routes/calendar.routes.ts:34", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/routes/calendar.routes.ts:34"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-62e9435ec33dad6b", "name": "Stray `console.log` in TS/JS \u2014 src/server/routes/x.routes.ts:81", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/routes/x.routes.ts:81"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0e8412318817c045", "name": "Stray `console.log` in TS/JS \u2014 src/server/workers/beeper-sync.worker.ts:23", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/workers/beeper-sync.worker.ts:23"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c0a66b095eb0c66c", "name": "Stray `console.log` in TS/JS \u2014 src/server/workers/daily-brief.worker.ts:154", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/workers/daily-brief.worker.ts:154"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0a6100f5133fa731", "name": "Stray `console.log` in TS/JS \u2014 src/server/workers/voice-capture.worker.ts:17", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/workers/voice-capture.worker.ts:17"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7f00fd06c7bbb13d", "name": "Stray `console.log` in TS/JS \u2014 src/server/workers/index.ts:17", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/workers/index.ts:17"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-43eeab3991e06610", "name": "Stray `console.log` in TS/JS \u2014 src/server/workers/sequence-tick.worker.ts:28", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/workers/sequence-tick.worker.ts:28"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-91ac6f5c73becfdb", "name": "Stray `console.log` in TS/JS \u2014 src/server/workers/gmail-sync.worker.ts:23", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/workers/gmail-sync.worker.ts:23"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8105525274003209", "name": "Stray `console.log` in TS/JS \u2014 src/server/workers/ai-prep.worker.ts:42", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/workers/ai-prep.worker.ts:42"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c1d9628c96bf6a95", "name": "Stray `console.log` in TS/JS \u2014 src/server/workers/ai-classify.worker.ts:50", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/workers/ai-classify.worker.ts:50"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5e0216500b5d0577", "name": "Stray `console.log` in TS/JS \u2014 src/server/workers/outcome-prompt.worker.ts:56", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/workers/outcome-prompt.worker.ts:56"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3c5ff30333176f4c", "name": "Stray `console.log` in TS/JS \u2014 src/server/workers/enrich-contact.worker.ts:16", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/workers/enrich-contact.worker.ts:16"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-339c57b01b50eacb", "name": "Stray `console.log` in TS/JS \u2014 src/server/workers/ai-summary.worker.ts:82", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/workers/ai-summary.worker.ts:82"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d8c15a8b54e6dbfd", "name": "Stray `console.log` in TS/JS \u2014 src/server/cron/staleCheck.ts:8", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/cron/staleCheck.ts:8"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0d8bc38f8893cfb6", "name": "Stray `console.log` in TS/JS \u2014 src/server/services/dedup.service.ts:173", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/services/dedup.service.ts:173"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5cde93a9096c4aad", "name": "Stray `console.log` in TS/JS \u2014 src/server/services/enrichment.service.ts:296", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/services/enrichment.service.ts:296"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f17c1b3159a8e7b2", "name": "Stray `console.log` in TS/JS \u2014 src/server/services/gmail.service.ts:140", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/services/gmail.service.ts:140"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5fe9df3491988311", "name": "Stray `console.log` in TS/JS \u2014 src/server/services/linkedin.service.ts:128", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/services/linkedin.service.ts:128"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-926531c8893dde7e", "name": "Stray `console.log` in TS/JS \u2014 src/server/services/beeper.service.ts:149", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/services/beeper.service.ts:149"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ebb009ee7bf79af0", "name": "Stray `console.log` in TS/JS \u2014 src/server/services/calendar.service.ts:138", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/services/calendar.service.ts:138"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-909f0c5ff364ced3", "name": "Stray `console.log` in TS/JS \u2014 src/server/services/x.service.ts:217", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/services/x.service.ts:217"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6214989656f1b4f5", "name": "Stray `console.log` in TS/JS \u2014 src/server/services/telegram-bot.service.ts:152", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/services/telegram-bot.service.ts:152"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b4ae6ed468ef8c8f", "name": "Stray `console.log` in TS/JS \u2014 src/server/services/import.service.ts:30", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/services/import.service.ts:30"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d63da3583b14afc0", "name": "Dockerfile runs as root: Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-835eae4c7f17a2f8", "name": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-830c0890307884cb", "name": "Dockerfile runs as root: railway/mautrix-linkedin/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: railway/mautrix-linkedin/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d7be5c093a06e3a6", "name": "Docker base image uses a mutable or implicit tag: dock.mau.dev/mautrix/linkedin:latest", "shortDescription": {"text": "Docker base image uses a mutable or implicit tag: dock.mau.dev/mautrix/linkedin:latest"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b230dab44310a0fd", "name": "Dockerfile runs as root: railway/mautrix-twitter/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: railway/mautrix-twitter/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-667f6cbad10c3341", "name": "Docker base image uses a mutable or implicit tag: dock.mau.dev/mautrix/twitter:latest", "shortDescription": {"text": "Docker base image uses a mutable or implicit tag: dock.mau.dev/mautrix/twitter:latest"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-06bdd85820d1ee7d", "name": "Insecure pattern 'dangerous_innerhtml' in src/app/layout.tsx:15", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in src/app/layout.tsx:15"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c323df3c89d14e14", "name": "Very large file: src/app/(dashboard)/dashboard/contacts/[id]/contact-detail-view.tsx (1126 lines)", "shortDescription": {"text": "Very large file: src/app/(dashboard)/dashboard/contacts/[id]/contact-detail-view.tsx (1126 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-844603e953018384", "name": "Very large file: src/app/(dashboard)/dashboard/inbox/inbox-view.tsx (1423 lines)", "shortDescription": {"text": "Very large file: src/app/(dashboard)/dashboard/inbox/inbox-view.tsx (1423 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ff3b1f39bea7caf4", "name": "Very large file: src/server/services/beeper.service.ts (1297 lines)", "shortDescription": {"text": "Very large file: src/server/services/beeper.service.ts (1297 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "6 test file(s) for 134 source file(s) (ratio 0.04). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-faccb9061e9b52a0", "name": "No README detected", "shortDescription": {"text": "No README detected"}, "fullDescription": {"text": "No README file was found. Generated repos without README context are hard to operate, validate, or safely hand off."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 189 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 94 placeholder/mock markers across 23 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci, tests, operator-readme. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-384e33c634b329f8", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/app/(dashboard)/dashboard/contacts/[id]/contact-timeline.tsx:11", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/app/(dashboard)/dashboard/contacts/[id]/contact-timeline.tsx:11"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-de7fb1d306c992be", "name": "Commented-code block (6 lines) in src/app/(dashboard)/dashboard/inbox/inbox-view.tsx:534", "shortDescription": {"text": "Commented-code block (6 lines) in src/app/(dashboard)/dashboard/inbox/inbox-view.tsx:534"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4f80be0d419f4271", "name": "Legacy-named symbol `isOld` in src/server/import/beeper.ts:294", "shortDescription": {"text": "Legacy-named symbol `isOld` in src/server/import/beeper.ts:294"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-da188167b4080a42", "name": "Commented-code block (6 lines) in src/server/lib/media-store.ts:6", "shortDescription": {"text": "Commented-code block (6 lines) in src/server/lib/media-store.ts:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f7ab66ff8a5e74f1", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/server/services/enrichment.service.ts:29", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/server/services/enrichment.service.ts:29"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-033f48082f3c14f2", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/server/services/linkedin.service.ts:54", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/server/services/linkedin.service.ts:54"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5893345a69782dc8", "name": "Commented-code block (5 lines) in src/server/services/beeper.service.ts:101", "shortDescription": {"text": "Commented-code block (5 lines) in src/server/services/beeper.service.ts:101"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5e190a032c5a8c5b", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/server/services/beeper.service.ts:197", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/server/services/beeper.service.ts:197"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea375893a719c835", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/server/services/x.service.ts:9", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/server/services/x.service.ts:9"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0f51574de357cc91", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/server/services/telegram-bot.service.ts:51", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/server/services/telegram-bot.service.ts:51"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f57f10e1b0dc15d4", "name": "Legacy-named symbol `isOld` in src/server/services/inbox.service.ts:183", "shortDescription": {"text": "Legacy-named symbol `isOld` in src/server/services/inbox.service.ts:183"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-87acb4066071a15a", "name": "19 env vars used in code but missing from .env.example", "shortDescription": {"text": "19 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `API_PORT`, `BEEPER_LOCAL_TOKEN`, `ENCRYPTION_KEY`, `LINKEDIN_CLIENT_ID`, `LINKEDIN_CLIENT_SECRET`, `MATRIX_AS_TOKEN`, `MATRIX_BRIDGE_OWNER_USER_ID`, `NEXT_PUBLIC_APP_URL` + 11 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ff07b40b0f1a0644", "name": "Dangling fetch: GET http://localhost:23373/v1/spec (src/scratch/test-local-api.ts:4)", "shortDescription": {"text": "Dangling fetch: GET http://localhost:23373/v1/spec (src/scratch/test-local-api.ts:4)"}, "fullDescription": {"text": "`src/scratch/test-local-api.ts:4` calls `GET http://localhost:23373/v1/spec` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/localhost:23373/v1/spec`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-58313edb43dfcfc6", "name": "Dangling fetch: POST https://www.linkedin.com/oauth/v2/accessToken (src/server/services/linkedin.service.ts:54)", "shortDescription": {"text": "Dangling fetch: POST https://www.linkedin.com/oauth/v2/accessToken (src/server/services/linkedin.service.ts:54)"}, "fullDescription": {"text": "`src/server/services/linkedin.service.ts:54` calls `POST https://www.linkedin.com/oauth/v2/accessToken` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/www.linkedin.com/oauth/v2/accesstoken`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0f2a2157a47b6116", "name": "Dangling fetch: GET https://api.linkedin.com/v2/userinfo (src/server/services/linkedin.service.ts:76)", "shortDescription": {"text": "Dangling fetch: GET https://api.linkedin.com/v2/userinfo (src/server/services/linkedin.service.ts:76)"}, "fullDescription": {"text": "`src/server/services/linkedin.service.ts:76` calls `GET https://api.linkedin.com/v2/userinfo` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.linkedin.com/v2/userinfo`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-13c8a1e68f13d86d", "name": "Dangling fetch: GET https://api.linkedin.com/v2/me?projection=(id,localizedFirstName,localizedLastName) (src/server/serv", "shortDescription": {"text": "Dangling fetch: GET https://api.linkedin.com/v2/me?projection=(id,localizedFirstName,localizedLastName) (src/server/services/linkedin.service.ts:85)"}, "fullDescription": {"text": "`src/server/services/linkedin.service.ts:85` calls `GET https://api.linkedin.com/v2/me?projection=(id,localizedFirstName,localizedLastName)` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.linkedin.com/v2/me`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-49a3ae63ab7311a4", "name": "Dangling fetch: GET https://www.linkedin.com/voyager/api/messaging/conversations?keyVersion=LEGACY_INBOX&q=inbox (src/se", "shortDescription": {"text": "Dangling fetch: GET https://www.linkedin.com/voyager/api/messaging/conversations?keyVersion=LEGACY_INBOX&q=inbox (src/server/services/linkedin.service.ts:177)"}, "fullDescription": {"text": "`src/server/services/linkedin.service.ts:177` calls `GET https://www.linkedin.com/voyager/api/messaging/conversations?keyVersion=LEGACY_INBOX&q=inbox` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/www.linkedin.com/voyager/api/messaging/conversations`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a8d6c7498b2441c7", "name": "Dangling fetch: GET https://www.linkedin.com/voyager/api/messaging/conversations/${encodeURIComponent(convId)}/events?ke", "shortDescription": {"text": "Dangling fetch: GET https://www.linkedin.com/voyager/api/messaging/conversations/${encodeURIComponent(convId)}/events?keyVersion=LEGACY_INBOX (src/server/services/linkedin.service.ts:245)"}, "fullDescription": {"text": "`src/server/services/linkedin.service.ts:245` calls `GET https://www.linkedin.com/voyager/api/messaging/conversations/${encodeURIComponent(convId)}/events?keyVersion=LEGACY_INBOX` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/www.linkedin.com/voyager/api/messaging/conversations/<p>/events`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b48fcf8ce26f8467", "name": "Dangling fetch: GET https://twitter.com${path} (src/server/services/x.service.ts:9)", "shortDescription": {"text": "Dangling fetch: GET https://twitter.com${path} (src/server/services/x.service.ts:9)"}, "fullDescription": {"text": "`src/server/services/x.service.ts:9` calls `GET https://twitter.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/twitter.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4274890eaf4c29e9", "name": "Unused endpoint: USE /admin/queues", "shortDescription": {"text": "Unused endpoint: USE /admin/queues"}, "fullDescription": {"text": "`src/server/index.ts` declares `USE /admin/queues` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-853b42b49e99f770", "name": "Unused endpoint: ALL /api/auth/{*any}", "shortDescription": {"text": "Unused endpoint: ALL /api/auth/{*any}"}, "fullDescription": {"text": "`src/server/index.ts` declares `ALL /api/auth/{*any}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aebdad2655c302c7", "name": "Unused endpoint: USE /api/calendar", "shortDescription": {"text": "Unused endpoint: USE /api/calendar"}, "fullDescription": {"text": "`src/server/index.ts` declares `USE /api/calendar` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd2e71b303292bdf", "name": "Unused endpoint: USE /api/gmail", "shortDescription": {"text": "Unused endpoint: USE /api/gmail"}, "fullDescription": {"text": "`src/server/index.ts` declares `USE /api/gmail` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dcb31968c5222475", "name": "Unused endpoint: USE /api/x", "shortDescription": {"text": "Unused endpoint: USE /api/x"}, "fullDescription": {"text": "`src/server/index.ts` declares `USE /api/x` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-680835faa6edbf6e", "name": "Unused endpoint: USE /api/linkedin", "shortDescription": {"text": "Unused endpoint: USE /api/linkedin"}, "fullDescription": {"text": "`src/server/index.ts` declares `USE /api/linkedin` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2070b9d25a1950b9", "name": "Unused endpoint: USE /api/matrix", "shortDescription": {"text": "Unused endpoint: USE /api/matrix"}, "fullDescription": {"text": "`src/server/index.ts` declares `USE /api/matrix` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-23846d4701bd172d", "name": "Unused endpoint: USE /media", "shortDescription": {"text": "Unused endpoint: USE /media"}, "fullDescription": {"text": "`src/server/index.ts` declares `USE /media` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dde3adb27bf7eebe", "name": "Unused endpoint: USE /api", "shortDescription": {"text": "Unused endpoint: USE /api"}, "fullDescription": {"text": "`src/server/index.ts` declares `USE /api` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5c1545494ab6166c", "name": "Unused endpoint: GET /api/me", "shortDescription": {"text": "Unused endpoint: GET /api/me"}, "fullDescription": {"text": "`src/server/index.ts` declares `GET /api/me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-70583fbeefb962c2", "name": "Unused endpoint: USE /api/contacts", "shortDescription": {"text": "Unused endpoint: USE /api/contacts"}, "fullDescription": {"text": "`src/server/index.ts` declares `USE /api/contacts` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-53cfbec65b30b169", "name": "Unused endpoint: USE /api/tags", "shortDescription": {"text": "Unused endpoint: USE /api/tags"}, "fullDescription": {"text": "`src/server/index.ts` declares `USE /api/tags` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1b6c609850c719b2", "name": "Unused endpoint: USE /api/notes", "shortDescription": {"text": "Unused endpoint: USE /api/notes"}, "fullDescription": {"text": "`src/server/index.ts` declares `USE /api/notes` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd9601980cbe25bc", "name": "Unused endpoint: USE /api/imports", "shortDescription": {"text": "Unused endpoint: USE /api/imports"}, "fullDescription": {"text": "`src/server/index.ts` declares `USE /api/imports` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-316c43db307befc3", "name": "Unused endpoint: USE /api/ai", "shortDescription": {"text": "Unused endpoint: USE /api/ai"}, "fullDescription": {"text": "`src/server/index.ts` declares `USE /api/ai` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bb789cf847f59e24", "name": "Unused endpoint: USE /api/companies", "shortDescription": {"text": "Unused endpoint: USE /api/companies"}, "fullDescription": {"text": "`src/server/index.ts` declares `USE /api/companies` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7acee280a96329f0", "name": "Unused endpoint: USE /api/reminders", "shortDescription": {"text": "Unused endpoint: USE /api/reminders"}, "fullDescription": {"text": "`src/server/index.ts` declares `USE /api/reminders` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b1fad5c9a5616e", "name": "Unused endpoint: USE /api/voice", "shortDescription": {"text": "Unused endpoint: USE /api/voice"}, "fullDescription": {"text": "`src/server/index.ts` declares `USE /api/voice` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-54b22f7e03a52a84", "name": "Unused endpoint: USE /api/inbox", "shortDescription": {"text": "Unused endpoint: USE /api/inbox"}, "fullDescription": {"text": "`src/server/index.ts` declares `USE /api/inbox` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-94ddd00dc84af41d", "name": "Unused endpoint: USE /api/email", "shortDescription": {"text": "Unused endpoint: USE /api/email"}, "fullDescription": {"text": "`src/server/index.ts` declares `USE /api/email` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cbc2069b0ad4e4ce", "name": "Unused endpoint: USE /api/beeper", "shortDescription": {"text": "Unused endpoint: USE /api/beeper"}, "fullDescription": {"text": "`src/server/index.ts` declares `USE /api/beeper` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6aa456b28221a743", "name": "Unused endpoint: USE /api/sequences", "shortDescription": {"text": "Unused endpoint: USE /api/sequences"}, "fullDescription": {"text": "`src/server/index.ts` declares `USE /api/sequences` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0ab055a45f0b96b6", "name": "Unused endpoint: USE /api/pipeline", "shortDescription": {"text": "Unused endpoint: USE /api/pipeline"}, "fullDescription": {"text": "`src/server/index.ts` declares `USE /api/pipeline` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9b90090379f5d72c", "name": "Unused endpoint: USE /api/telegram-bot", "shortDescription": {"text": "Unused endpoint: USE /api/telegram-bot"}, "fullDescription": {"text": "`src/server/index.ts` declares `USE /api/telegram-bot` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`src/server/routes/contact.routes.ts` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cd8dc4599ec52a08", "name": "Unused endpoint: GET /stats", "shortDescription": {"text": "Unused endpoint: GET /stats"}, "fullDescription": {"text": "`src/server/routes/contact.routes.ts` declares `GET /stats` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ca5756175765b49d", "name": "Unused endpoint: GET /:id", "shortDescription": {"text": "Unused endpoint: GET /:id"}, "fullDescription": {"text": "`src/server/routes/contact.routes.ts` declares `GET /:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a009b1a56794f45", "name": "Unused endpoint: POST /", "shortDescription": {"text": "Unused endpoint: POST /"}, "fullDescription": {"text": "`src/server/routes/contact.routes.ts` declares `POST /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5fbc954f63526821", "name": "Unused endpoint: PATCH /:id", "shortDescription": {"text": "Unused endpoint: PATCH /:id"}, "fullDescription": {"text": "`src/server/routes/contact.routes.ts` declares `PATCH /:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a61c112b611f4bb", "name": "Unused endpoint: DELETE /:id", "shortDescription": {"text": "Unused endpoint: DELETE /:id"}, "fullDescription": {"text": "`src/server/routes/contact.routes.ts` declares `DELETE /:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-666fb422429d5f1e", "name": "Unused endpoint: POST /:id/merge", "shortDescription": {"text": "Unused endpoint: POST /:id/merge"}, "fullDescription": {"text": "`src/server/routes/contact.routes.ts` declares `POST /:id/merge` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-20ad983b98baf21d", "name": "Unused endpoint: POST /:id/enrich", "shortDescription": {"text": "Unused endpoint: POST /:id/enrich"}, "fullDescription": {"text": "`src/server/routes/contact.routes.ts` declares `POST /:id/enrich` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a7436bbd633834b4", "name": "Unused endpoint: GET /enrich-job/:jobId", "shortDescription": {"text": "Unused endpoint: GET /enrich-job/:jobId"}, "fullDescription": {"text": "`src/server/routes/contact.routes.ts` declares `GET /enrich-job/:jobId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b1c6b43f820b8518", "name": "Unused endpoint: POST /bulk-delete", "shortDescription": {"text": "Unused endpoint: POST /bulk-delete"}, "fullDescription": {"text": "`src/server/routes/contact.routes.ts` declares `POST /bulk-delete` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-99c5d4958fd78940", "name": "Unused endpoint: POST /bulk-tag", "shortDescription": {"text": "Unused endpoint: POST /bulk-tag"}, "fullDescription": {"text": "`src/server/routes/contact.routes.ts` declares `POST /bulk-tag` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4ff50bd4f79c87a3", "name": "Unused endpoint: POST /:id/platforms", "shortDescription": {"text": "Unused endpoint: POST /:id/platforms"}, "fullDescription": {"text": "`src/server/routes/contact.routes.ts` declares `POST /:id/platforms` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1c5d5c2e67a0552e", "name": "Unused endpoint: PUT /:id/platforms/:pid", "shortDescription": {"text": "Unused endpoint: PUT /:id/platforms/:pid"}, "fullDescription": {"text": "`src/server/routes/contact.routes.ts` declares `PUT /:id/platforms/:pid` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-119b8328aa3c3e5c", "name": "Unused endpoint: DELETE /:id/platforms/:pid", "shortDescription": {"text": "Unused endpoint: DELETE /:id/platforms/:pid"}, "fullDescription": {"text": "`src/server/routes/contact.routes.ts` declares `DELETE /:id/platforms/:pid` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a5428e9d1b816731", "name": "Unused endpoint: GET /username", "shortDescription": {"text": "Unused endpoint: GET /username"}, "fullDescription": {"text": "`src/server/routes/telegram-bot.routes.ts` declares `GET /username` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-76818c29a282da00", "name": "Unused endpoint: POST /generate-token", "shortDescription": {"text": "Unused endpoint: POST /generate-token"}, "fullDescription": {"text": "`src/server/routes/telegram-bot.routes.ts` declares `POST /generate-token` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3295d44f7b6283c3", "name": "Unused endpoint: POST /unlink", "shortDescription": {"text": "Unused endpoint: POST /unlink"}, "fullDescription": {"text": "`src/server/routes/telegram-bot.routes.ts` declares `POST /unlink` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f7c2d12ac97167d8", "name": "Unused endpoint: GET /contacts/:id/timeline", "shortDescription": {"text": "Unused endpoint: GET /contacts/:id/timeline"}, "fullDescription": {"text": "`src/server/routes/timeline.routes.ts` declares `GET /contacts/:id/timeline` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f2fa3b5d85e1d74d", "name": "Unused endpoint: GET /connect-url", "shortDescription": {"text": "Unused endpoint: GET /connect-url"}, "fullDescription": {"text": "`src/server/routes/gmail.routes.ts` declares `GET /connect-url` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-612648bbd62b68ab", "name": "Unused endpoint: DELETE /disconnect", "shortDescription": {"text": "Unused endpoint: DELETE /disconnect"}, "fullDescription": {"text": "`src/server/routes/gmail.routes.ts` declares `DELETE /disconnect` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fa413208496243a5", "name": "Unused endpoint: POST /sync", "shortDescription": {"text": "Unused endpoint: POST /sync"}, "fullDescription": {"text": "`src/server/routes/gmail.routes.ts` declares `POST /sync` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a2de4317039c9a7f", "name": "Unused endpoint: GET /threads", "shortDescription": {"text": "Unused endpoint: GET /threads"}, "fullDescription": {"text": "`src/server/routes/gmail.routes.ts` declares `GET /threads` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cdfb578618cf2542", "name": "Unused endpoint: GET /callback", "shortDescription": {"text": "Unused endpoint: GET /callback"}, "fullDescription": {"text": "`src/server/routes/gmail.routes.ts` declares `GET /callback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-43269e4e79c2e69e", "name": "Unused endpoint: GET /events", "shortDescription": {"text": "Unused endpoint: GET /events"}, "fullDescription": {"text": "`src/server/routes/inbox.routes.ts` declares `GET /events` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6f0fc82742855439", "name": "Unused endpoint: GET /conversations", "shortDescription": {"text": "Unused endpoint: GET /conversations"}, "fullDescription": {"text": "`src/server/routes/inbox.routes.ts` declares `GET /conversations` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3e59d3824648f87d", "name": "Unused endpoint: GET /thread", "shortDescription": {"text": "Unused endpoint: GET /thread"}, "fullDescription": {"text": "`src/server/routes/inbox.routes.ts` declares `GET /thread` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/22247"}, "properties": {"repository": "vinayjjjj/SubyCRM2", "repoUrl": "https://github.com/vinayjjjj/SubyCRM2", "branch": "main"}, "results": [{"ruleId": "scanner-81747e21b79d38a0", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/seed-tags.ts:22"}, "properties": {"repobilityId": "8f9b1553e4250b2c", "scanner": "scanner-primary", "fingerprint": "81747e21b79d38a0", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a2b74f31402d7ff6", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 prisma/seed-demo.ts:17"}, "properties": {"repobilityId": "04408501143ae10b", "scanner": "scanner-primary", "fingerprint": "a2b74f31402d7ff6", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c9aa1638a97dd567", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/sidebar.tsx:181"}, "properties": {"repobilityId": "b6d9ddc60e182673", "scanner": "scanner-primary", "fingerprint": "c9aa1638a97dd567", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-3e6dbc035f414dac", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 src/app/layout.tsx:15"}, "properties": {"repobilityId": "0d72350965068f5b", "scanner": "scanner-primary", "fingerprint": "3e6dbc035f414dac", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-85f296d31f3ba810", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/app/(dashboard)/dashboard/reminders/reminders-view.tsx:307"}, "properties": {"repobilityId": "b7882fe7786294c4", "scanner": "scanner-primary", "fingerprint": "85f296d31f3ba810", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-37be04b088fad4a0", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/app/(dashboard)/dashboard/companies/companies-view.tsx:174"}, "properties": {"repobilityId": "c9e4c3296d3c515c", "scanner": "scanner-primary", "fingerprint": "37be04b088fad4a0", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-f221071f4c31c396", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scratch/test-search.ts:6"}, "properties": {"repobilityId": "0f0c6fa93366cc21", "scanner": "scanner-primary", "fingerprint": "f221071f4c31c396", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b085c1b0229ff5ca", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scratch/check-db-contacts.ts:19"}, "properties": {"repobilityId": "518e63e3f3d99c61", "scanner": "scanner-primary", "fingerprint": "b085c1b0229ff5ca", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-bbb275cbf25ec249", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scratch/test-api.ts:3"}, "properties": {"repobilityId": "53b690d3801d8f1c", "scanner": "scanner-primary", "fingerprint": "bbb275cbf25ec249", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c88e1ecdac6f315f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scratch/check-beeper-db.ts:8"}, "properties": {"repobilityId": "29fda62f79715b54", "scanner": "scanner-primary", "fingerprint": "c88e1ecdac6f315f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-389b277a8285e051", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scratch/test-local-api.ts:6"}, "properties": {"repobilityId": "9c672b21b4c381cd", "scanner": "scanner-primary", "fingerprint": "389b277a8285e051", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-db8fc654f26f4996", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scratch/migrate-userid.ts:5"}, "properties": {"repobilityId": "c5a68c224589a9f3", "scanner": "scanner-primary", "fingerprint": "db8fc654f26f4996", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e8651dfa0566dc49", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scratch/check-messages.ts:49"}, "properties": {"repobilityId": "ce25189435c913eb", "scanner": "scanner-primary", "fingerprint": "e8651dfa0566dc49", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f20d15134d4dab6f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scratch/test-beeper.ts:6"}, "properties": {"repobilityId": "ade214e9bf74b2c8", "scanner": "scanner-primary", "fingerprint": "f20d15134d4dab6f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c4141cbb224b6099", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scratch/test-local-decrypt.ts:6"}, "properties": {"repobilityId": "2d86bb65097ac99a", "scanner": "scanner-primary", "fingerprint": "c4141cbb224b6099", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2862a19a1e6da3a2", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scratch/check-userids.ts:5"}, "properties": {"repobilityId": "3f6983ac9066d01f", "scanner": "scanner-primary", "fingerprint": "2862a19a1e6da3a2", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-63085e5d0141c09e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scratch/cleanup-dups.ts:26"}, "properties": {"repobilityId": "d3ebf6be4a4fbe1d", "scanner": "scanner-primary", "fingerprint": "63085e5d0141c09e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8be12cf9841da87e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/scratch/test-local-send.ts:20"}, "properties": {"repobilityId": "7aea43939883aa57", "scanner": "scanner-primary", "fingerprint": "8be12cf9841da87e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d4d9a54a9bec6f72", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/index.ts:11"}, "properties": {"repobilityId": "cc5d38780f9577eb", "scanner": "scanner-primary", "fingerprint": "d4d9a54a9bec6f72", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-cab0f581281e71aa", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/import/beeper.ts:111"}, "properties": {"repobilityId": "a715c78edbf7108c", "scanner": "scanner-primary", "fingerprint": "cab0f581281e71aa", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ff1b7162789c909c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/lib/redis.ts:8"}, "properties": {"repobilityId": "fabe699bf2cf2b28", "scanner": "scanner-primary", "fingerprint": "ff1b7162789c909c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-581996b6a578d0ad", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/lib/media-store.ts:100"}, "properties": {"repobilityId": "dd931d02541d7e57", "scanner": "scanner-primary", "fingerprint": "581996b6a578d0ad", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c34a5d5f4920cd7f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/routes/gmail.routes.ts:32"}, "properties": {"repobilityId": "db95acc6d250c478", "scanner": "scanner-primary", "fingerprint": "c34a5d5f4920cd7f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c9b2606e71c51976", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/routes/calendar.routes.ts:34"}, "properties": {"repobilityId": "b6af8448694ff02b", "scanner": "scanner-primary", "fingerprint": "c9b2606e71c51976", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-62e9435ec33dad6b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/routes/x.routes.ts:81"}, "properties": {"repobilityId": "a88f5b7e08ba0c48", "scanner": "scanner-primary", "fingerprint": "62e9435ec33dad6b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0e8412318817c045", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/workers/beeper-sync.worker.ts:23"}, "properties": {"repobilityId": "e1cbfa47dc5afaa3", "scanner": "scanner-primary", "fingerprint": "0e8412318817c045", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c0a66b095eb0c66c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/workers/daily-brief.worker.ts:154"}, "properties": {"repobilityId": "5856cd4c943f0912", "scanner": "scanner-primary", "fingerprint": "c0a66b095eb0c66c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0a6100f5133fa731", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/workers/voice-capture.worker.ts:17"}, "properties": {"repobilityId": "5d5cfddda59bc75d", "scanner": "scanner-primary", "fingerprint": "0a6100f5133fa731", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7f00fd06c7bbb13d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/workers/index.ts:17"}, "properties": {"repobilityId": "01c1843399d0f99a", "scanner": "scanner-primary", "fingerprint": "7f00fd06c7bbb13d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-43eeab3991e06610", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/workers/sequence-tick.worker.ts:28"}, "properties": {"repobilityId": "b503453b4059e5b4", "scanner": "scanner-primary", "fingerprint": "43eeab3991e06610", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-91ac6f5c73becfdb", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/workers/gmail-sync.worker.ts:23"}, "properties": {"repobilityId": "9ef1051a4c9bd9d6", "scanner": "scanner-primary", "fingerprint": "91ac6f5c73becfdb", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8105525274003209", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/workers/ai-prep.worker.ts:42"}, "properties": {"repobilityId": "4c9fb27ecf8ebc02", "scanner": "scanner-primary", "fingerprint": "8105525274003209", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c1d9628c96bf6a95", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/workers/ai-classify.worker.ts:50"}, "properties": {"repobilityId": "a47f09be17196a0e", "scanner": "scanner-primary", "fingerprint": "c1d9628c96bf6a95", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5e0216500b5d0577", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/workers/outcome-prompt.worker.ts:56"}, "properties": {"repobilityId": "9ab88f8a2a2bcab3", "scanner": "scanner-primary", "fingerprint": "5e0216500b5d0577", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3c5ff30333176f4c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/workers/enrich-contact.worker.ts:16"}, "properties": {"repobilityId": "06e36df14a613f4c", "scanner": "scanner-primary", "fingerprint": "3c5ff30333176f4c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-339c57b01b50eacb", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/workers/ai-summary.worker.ts:82"}, "properties": {"repobilityId": "460897e691cab568", "scanner": "scanner-primary", "fingerprint": "339c57b01b50eacb", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d8c15a8b54e6dbfd", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/cron/staleCheck.ts:8"}, "properties": {"repobilityId": "e32fe6479bc4c520", "scanner": "scanner-primary", "fingerprint": "d8c15a8b54e6dbfd", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0d8bc38f8893cfb6", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/services/dedup.service.ts:173"}, "properties": {"repobilityId": "756fffd5afb31e8a", "scanner": "scanner-primary", "fingerprint": "0d8bc38f8893cfb6", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5cde93a9096c4aad", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/services/enrichment.service.ts:296"}, "properties": {"repobilityId": "3f5356bec3b745eb", "scanner": "scanner-primary", "fingerprint": "5cde93a9096c4aad", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f17c1b3159a8e7b2", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/services/gmail.service.ts:140"}, "properties": {"repobilityId": "b28d2edc17ed9ef1", "scanner": "scanner-primary", "fingerprint": "f17c1b3159a8e7b2", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5fe9df3491988311", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/services/linkedin.service.ts:128"}, "properties": {"repobilityId": "9115385f5a925f2a", "scanner": "scanner-primary", "fingerprint": "5fe9df3491988311", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-926531c8893dde7e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/services/beeper.service.ts:149"}, "properties": {"repobilityId": "934a01b1619d9e57", "scanner": "scanner-primary", "fingerprint": "926531c8893dde7e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ebb009ee7bf79af0", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/services/calendar.service.ts:138"}, "properties": {"repobilityId": "02cd42fd7ca24d00", "scanner": "scanner-primary", "fingerprint": "ebb009ee7bf79af0", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-909f0c5ff364ced3", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/services/x.service.ts:217"}, "properties": {"repobilityId": "906580d6ee1c2219", "scanner": "scanner-primary", "fingerprint": "909f0c5ff364ced3", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-6214989656f1b4f5", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/services/telegram-bot.service.ts:152"}, "properties": {"repobilityId": "bc680cf7ae502d41", "scanner": "scanner-primary", "fingerprint": "6214989656f1b4f5", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b4ae6ed468ef8c8f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/services/import.service.ts:30"}, "properties": {"repobilityId": "6426f1fd7e9ba5cd", "scanner": "scanner-primary", "fingerprint": "b4ae6ed468ef8c8f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d63da3583b14afc0", "level": "warning", "message": {"text": "Dockerfile runs as root: Dockerfile"}, "properties": {"repobilityId": "a2ed1bd120e507db", "scanner": "scanner-primary", "fingerprint": "d63da3583b14afc0", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-835eae4c7f17a2f8", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine"}, "properties": {"repobilityId": "e469cde27591e1b7", "scanner": "scanner-primary", "fingerprint": "835eae4c7f17a2f8", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-830c0890307884cb", "level": "warning", "message": {"text": "Dockerfile runs as root: railway/mautrix-linkedin/Dockerfile"}, "properties": {"repobilityId": "c4279035f7c3d550", "scanner": "scanner-primary", "fingerprint": "830c0890307884cb", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-d7be5c093a06e3a6", "level": "warning", "message": {"text": "Docker base image uses a mutable or implicit tag: dock.mau.dev/mautrix/linkedin:latest"}, "properties": {"repobilityId": "5c2f90292cfb2d56", "scanner": "scanner-primary", "fingerprint": "d7be5c093a06e3a6", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "railway/mautrix-linkedin/Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b230dab44310a0fd", "level": "warning", "message": {"text": "Dockerfile runs as root: railway/mautrix-twitter/Dockerfile"}, "properties": {"repobilityId": "0fe68ebcb064937e", "scanner": "scanner-primary", "fingerprint": "b230dab44310a0fd", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-667f6cbad10c3341", "level": "warning", "message": {"text": "Docker base image uses a mutable or implicit tag: dock.mau.dev/mautrix/twitter:latest"}, "properties": {"repobilityId": "16c0c86eca02d5cf", "scanner": "scanner-primary", "fingerprint": "667f6cbad10c3341", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "railway/mautrix-twitter/Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-06bdd85820d1ee7d", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in src/app/layout.tsx:15"}, "properties": {"repobilityId": "0bca654fa2052eb0", "scanner": "scanner-primary", "fingerprint": "06bdd85820d1ee7d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/app/layout.tsx"}, "region": {"startLine": 15}}}]}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-c323df3c89d14e14", "level": "note", "message": {"text": "Very large file: src/app/(dashboard)/dashboard/contacts/[id]/contact-detail-view.tsx (1126 lines)"}, "properties": {"repobilityId": "9eaf914d09755a48", "scanner": "scanner-primary", "fingerprint": "c323df3c89d14e14", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-844603e953018384", "level": "note", "message": {"text": "Very large file: src/app/(dashboard)/dashboard/inbox/inbox-view.tsx (1423 lines)"}, "properties": {"repobilityId": "62e7d55e82b0163e", "scanner": "scanner-primary", "fingerprint": "844603e953018384", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ff3b1f39bea7caf4", "level": "note", "message": {"text": "Very large file: src/server/services/beeper.service.ts (1297 lines)"}, "properties": {"repobilityId": "c72cd3bcbdfcf113", "scanner": "scanner-primary", "fingerprint": "ff3b1f39bea7caf4", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "0c522ac757257136", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-faccb9061e9b52a0", "level": "note", "message": {"text": "No README detected"}, "properties": {"repobilityId": "23a04b22c851a33c", "scanner": "scanner-primary", "fingerprint": "faccb9061e9b52a0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["docs", "readme", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "e731f04e711189b3", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "2086412f1c96669f", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "0c65817628cf647b", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "warning", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "83b935c2b4086cc4", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "fa21eb2d3636326e", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "ad5fc4d6f4ec33f7", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-384e33c634b329f8", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/app/(dashboard)/dashboard/contacts/[id]/contact-timeline.tsx:11"}, "properties": {"repobilityId": "f0f5e71baa3f84af", "scanner": "scanner-primary", "fingerprint": "384e33c634b329f8", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-de7fb1d306c992be", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/app/(dashboard)/dashboard/inbox/inbox-view.tsx:534"}, "properties": {"repobilityId": "0f756e63de918463", "scanner": "scanner-primary", "fingerprint": "de7fb1d306c992be", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4f80be0d419f4271", "level": "note", "message": {"text": "Legacy-named symbol `isOld` in src/server/import/beeper.ts:294"}, "properties": {"repobilityId": "113c797f93119b8b", "scanner": "scanner-primary", "fingerprint": "4f80be0d419f4271", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-da188167b4080a42", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/server/lib/media-store.ts:6"}, "properties": {"repobilityId": "6179a8ff727d85f8", "scanner": "scanner-primary", "fingerprint": "da188167b4080a42", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f7ab66ff8a5e74f1", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/server/services/enrichment.service.ts:29"}, "properties": {"repobilityId": "524f93e6bef53a7b", "scanner": "scanner-primary", "fingerprint": "f7ab66ff8a5e74f1", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-033f48082f3c14f2", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/server/services/linkedin.service.ts:54"}, "properties": {"repobilityId": "b55b871f410dafaa", "scanner": "scanner-primary", "fingerprint": "033f48082f3c14f2", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-5893345a69782dc8", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/server/services/beeper.service.ts:101"}, "properties": {"repobilityId": "c21a6e2193f84723", "scanner": "scanner-primary", "fingerprint": "5893345a69782dc8", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5e190a032c5a8c5b", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/server/services/beeper.service.ts:197"}, "properties": {"repobilityId": "e8b84674d4cc01da", "scanner": "scanner-primary", "fingerprint": "5e190a032c5a8c5b", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-ea375893a719c835", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/server/services/x.service.ts:9"}, "properties": {"repobilityId": "4737b4519c803ae7", "scanner": "scanner-primary", "fingerprint": "ea375893a719c835", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-0f51574de357cc91", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/server/services/telegram-bot.service.ts:51"}, "properties": {"repobilityId": "cad401bf4d9c77a1", "scanner": "scanner-primary", "fingerprint": "0f51574de357cc91", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-f57f10e1b0dc15d4", "level": "note", "message": {"text": "Legacy-named symbol `isOld` in src/server/services/inbox.service.ts:183"}, "properties": {"repobilityId": "3f8f03960719ec78", "scanner": "scanner-primary", "fingerprint": "f57f10e1b0dc15d4", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-87acb4066071a15a", "level": "note", "message": {"text": "19 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "b1f30c58de7ffb20", "scanner": "scanner-primary", "fingerprint": "87acb4066071a15a", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-ff07b40b0f1a0644", "level": "error", "message": {"text": "Dangling fetch: GET http://localhost:23373/v1/spec (src/scratch/test-local-api.ts:4)"}, "properties": {"repobilityId": "ecd32a9c94bc7221", "scanner": "scanner-primary", "fingerprint": "ff07b40b0f1a0644", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-58313edb43dfcfc6", "level": "error", "message": {"text": "Dangling fetch: POST https://www.linkedin.com/oauth/v2/accessToken (src/server/services/linkedin.service.ts:54)"}, "properties": {"repobilityId": "3a77576fd31e17f9", "scanner": "scanner-primary", "fingerprint": "58313edb43dfcfc6", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-0f2a2157a47b6116", "level": "error", "message": {"text": "Dangling fetch: GET https://api.linkedin.com/v2/userinfo (src/server/services/linkedin.service.ts:76)"}, "properties": {"repobilityId": "9e867543332d7b0f", "scanner": "scanner-primary", "fingerprint": "0f2a2157a47b6116", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-13c8a1e68f13d86d", "level": "error", "message": {"text": "Dangling fetch: GET https://api.linkedin.com/v2/me?projection=(id,localizedFirstName,localizedLastName) (src/server/services/linkedin.service.ts:85)"}, "properties": {"repobilityId": "6fcc23d28f31365a", "scanner": "scanner-primary", "fingerprint": "13c8a1e68f13d86d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-49a3ae63ab7311a4", "level": "error", "message": {"text": "Dangling fetch: GET https://www.linkedin.com/voyager/api/messaging/conversations?keyVersion=LEGACY_INBOX&q=inbox (src/server/services/linkedin.service.ts:177)"}, "properties": {"repobilityId": "f07e2b00b81b50fa", "scanner": "scanner-primary", "fingerprint": "49a3ae63ab7311a4", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-a8d6c7498b2441c7", "level": "error", "message": {"text": "Dangling fetch: GET https://www.linkedin.com/voyager/api/messaging/conversations/${encodeURIComponent(convId)}/events?keyVersion=LEGACY_INBOX (src/server/services/linkedin.service.ts:245)"}, "properties": {"repobilityId": "15274c084c322056", "scanner": "scanner-primary", "fingerprint": "a8d6c7498b2441c7", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-b48fcf8ce26f8467", "level": "error", "message": {"text": "Dangling fetch: GET https://twitter.com${path} (src/server/services/x.service.ts:9)"}, "properties": {"repobilityId": "baeab16bccea07e7", "scanner": "scanner-primary", "fingerprint": "b48fcf8ce26f8467", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-4274890eaf4c29e9", "level": "note", "message": {"text": "Unused endpoint: USE /admin/queues"}, "properties": {"repobilityId": "530bb76b79417b3c", "scanner": "scanner-primary", "fingerprint": "4274890eaf4c29e9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-853b42b49e99f770", "level": "note", "message": {"text": "Unused endpoint: ALL /api/auth/{*any}"}, "properties": {"repobilityId": "e1ea2d23fe367b4f", "scanner": "scanner-primary", "fingerprint": "853b42b49e99f770", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-aebdad2655c302c7", "level": "note", "message": {"text": "Unused endpoint: USE /api/calendar"}, "properties": {"repobilityId": "7628a9f2c901243e", "scanner": "scanner-primary", "fingerprint": "aebdad2655c302c7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd2e71b303292bdf", "level": "note", "message": {"text": "Unused endpoint: USE /api/gmail"}, "properties": {"repobilityId": "ead3586d509caa78", "scanner": "scanner-primary", "fingerprint": "fd2e71b303292bdf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dcb31968c5222475", "level": "note", "message": {"text": "Unused endpoint: USE /api/x"}, "properties": {"repobilityId": "a8b2935321666041", "scanner": "scanner-primary", "fingerprint": "dcb31968c5222475", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-680835faa6edbf6e", "level": "note", "message": {"text": "Unused endpoint: USE /api/linkedin"}, "properties": {"repobilityId": "3441f2b6bbcdff63", "scanner": "scanner-primary", "fingerprint": "680835faa6edbf6e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2070b9d25a1950b9", "level": "note", "message": {"text": "Unused endpoint: USE /api/matrix"}, "properties": {"repobilityId": "468da8ceb392f980", "scanner": "scanner-primary", "fingerprint": "2070b9d25a1950b9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-23846d4701bd172d", "level": "note", "message": {"text": "Unused endpoint: USE /media"}, "properties": {"repobilityId": "83afe1e1ca2c5e22", "scanner": "scanner-primary", "fingerprint": "23846d4701bd172d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dde3adb27bf7eebe", "level": "note", "message": {"text": "Unused endpoint: USE /api"}, "properties": {"repobilityId": "dedf7e836e58a6aa", "scanner": "scanner-primary", "fingerprint": "dde3adb27bf7eebe", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5c1545494ab6166c", "level": "note", "message": {"text": "Unused endpoint: GET /api/me"}, "properties": {"repobilityId": "6accb3ac40897f1a", "scanner": "scanner-primary", "fingerprint": "5c1545494ab6166c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-70583fbeefb962c2", "level": "note", "message": {"text": "Unused endpoint: USE /api/contacts"}, "properties": {"repobilityId": "d399974e50f36243", "scanner": "scanner-primary", "fingerprint": "70583fbeefb962c2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-53cfbec65b30b169", "level": "note", "message": {"text": "Unused endpoint: USE /api/tags"}, "properties": {"repobilityId": "2b7b79785e2849d6", "scanner": "scanner-primary", "fingerprint": "53cfbec65b30b169", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1b6c609850c719b2", "level": "note", "message": {"text": "Unused endpoint: USE /api/notes"}, "properties": {"repobilityId": "d61f06a110837937", "scanner": "scanner-primary", "fingerprint": "1b6c609850c719b2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd9601980cbe25bc", "level": "note", "message": {"text": "Unused endpoint: USE /api/imports"}, "properties": {"repobilityId": "5d499266ec51563a", "scanner": "scanner-primary", "fingerprint": "fd9601980cbe25bc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-316c43db307befc3", "level": "note", "message": {"text": "Unused endpoint: USE /api/ai"}, "properties": {"repobilityId": "ca62d98f3dd97386", "scanner": "scanner-primary", "fingerprint": "316c43db307befc3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bb789cf847f59e24", "level": "note", "message": {"text": "Unused endpoint: USE /api/companies"}, "properties": {"repobilityId": "d38dc3ad0b63131a", "scanner": "scanner-primary", "fingerprint": "bb789cf847f59e24", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7acee280a96329f0", "level": "note", "message": {"text": "Unused endpoint: USE /api/reminders"}, "properties": {"repobilityId": "b9a3b9985971909d", "scanner": "scanner-primary", "fingerprint": "7acee280a96329f0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-72b1fad5c9a5616e", "level": "note", "message": {"text": "Unused endpoint: USE /api/voice"}, "properties": {"repobilityId": "a722108c9f2fb434", "scanner": "scanner-primary", "fingerprint": "72b1fad5c9a5616e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-54b22f7e03a52a84", "level": "note", "message": {"text": "Unused endpoint: USE /api/inbox"}, "properties": {"repobilityId": "4d824d0f481ca5ef", "scanner": "scanner-primary", "fingerprint": "54b22f7e03a52a84", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-94ddd00dc84af41d", "level": "note", "message": {"text": "Unused endpoint: USE /api/email"}, "properties": {"repobilityId": "a25d2c4de177a956", "scanner": "scanner-primary", "fingerprint": "94ddd00dc84af41d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cbc2069b0ad4e4ce", "level": "note", "message": {"text": "Unused endpoint: USE /api/beeper"}, "properties": {"repobilityId": "76b7cec5e41a87d8", "scanner": "scanner-primary", "fingerprint": "cbc2069b0ad4e4ce", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6aa456b28221a743", "level": "note", "message": {"text": "Unused endpoint: USE /api/sequences"}, "properties": {"repobilityId": "c05dbbe0c17b845d", "scanner": "scanner-primary", "fingerprint": "6aa456b28221a743", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0ab055a45f0b96b6", "level": "note", "message": {"text": "Unused endpoint: USE /api/pipeline"}, "properties": {"repobilityId": "a1a999e91244a0ec", "scanner": "scanner-primary", "fingerprint": "0ab055a45f0b96b6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9b90090379f5d72c", "level": "note", "message": {"text": "Unused endpoint: USE /api/telegram-bot"}, "properties": {"repobilityId": "26934de014605342", "scanner": "scanner-primary", "fingerprint": "9b90090379f5d72c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "872489017a5a5525", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cd8dc4599ec52a08", "level": "note", "message": {"text": "Unused endpoint: GET /stats"}, "properties": {"repobilityId": "4ad4e5dfc55a2370", "scanner": "scanner-primary", "fingerprint": "cd8dc4599ec52a08", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ca5756175765b49d", "level": "note", "message": {"text": "Unused endpoint: GET /:id"}, "properties": {"repobilityId": "1f7219e60f02ec6f", "scanner": "scanner-primary", "fingerprint": "ca5756175765b49d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a009b1a56794f45", "level": "note", "message": {"text": "Unused endpoint: POST /"}, "properties": {"repobilityId": "0fb7bf1cdae8fa26", "scanner": "scanner-primary", "fingerprint": "7a009b1a56794f45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5fbc954f63526821", "level": "note", "message": {"text": "Unused endpoint: PATCH /:id"}, "properties": {"repobilityId": "ec0868d1c081adaa", "scanner": "scanner-primary", "fingerprint": "5fbc954f63526821", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a61c112b611f4bb", "level": "note", "message": {"text": "Unused endpoint: DELETE /:id"}, "properties": {"repobilityId": "8683c5a9a30b75c7", "scanner": "scanner-primary", "fingerprint": "7a61c112b611f4bb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-666fb422429d5f1e", "level": "note", "message": {"text": "Unused endpoint: POST /:id/merge"}, "properties": {"repobilityId": "d07f6b6840945312", "scanner": "scanner-primary", "fingerprint": "666fb422429d5f1e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-20ad983b98baf21d", "level": "note", "message": {"text": "Unused endpoint: POST /:id/enrich"}, "properties": {"repobilityId": "e49cb84974de2390", "scanner": "scanner-primary", "fingerprint": "20ad983b98baf21d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a7436bbd633834b4", "level": "note", "message": {"text": "Unused endpoint: GET /enrich-job/:jobId"}, "properties": {"repobilityId": "4db739036d5efe50", "scanner": "scanner-primary", "fingerprint": "a7436bbd633834b4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b1c6b43f820b8518", "level": "note", "message": {"text": "Unused endpoint: POST /bulk-delete"}, "properties": {"repobilityId": "d94519edf463367d", "scanner": "scanner-primary", "fingerprint": "b1c6b43f820b8518", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-99c5d4958fd78940", "level": "note", "message": {"text": "Unused endpoint: POST /bulk-tag"}, "properties": {"repobilityId": "e9a36e24e34c6a9b", "scanner": "scanner-primary", "fingerprint": "99c5d4958fd78940", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4ff50bd4f79c87a3", "level": "note", "message": {"text": "Unused endpoint: POST /:id/platforms"}, "properties": {"repobilityId": "82796b5c2efd8edb", "scanner": "scanner-primary", "fingerprint": "4ff50bd4f79c87a3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1c5d5c2e67a0552e", "level": "note", "message": {"text": "Unused endpoint: PUT /:id/platforms/:pid"}, "properties": {"repobilityId": "3b532ed0baf2aea9", "scanner": "scanner-primary", "fingerprint": "1c5d5c2e67a0552e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-119b8328aa3c3e5c", "level": "note", "message": {"text": "Unused endpoint: DELETE /:id/platforms/:pid"}, "properties": {"repobilityId": "7c3e9b0537448d60", "scanner": "scanner-primary", "fingerprint": "119b8328aa3c3e5c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a5428e9d1b816731", "level": "note", "message": {"text": "Unused endpoint: GET /username"}, "properties": {"repobilityId": "57da24aaeab52847", "scanner": "scanner-primary", "fingerprint": "a5428e9d1b816731", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-76818c29a282da00", "level": "note", "message": {"text": "Unused endpoint: POST /generate-token"}, "properties": {"repobilityId": "fa2eb68983447208", "scanner": "scanner-primary", "fingerprint": "76818c29a282da00", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3295d44f7b6283c3", "level": "note", "message": {"text": "Unused endpoint: POST /unlink"}, "properties": {"repobilityId": "98ea9b28ec7374dc", "scanner": "scanner-primary", "fingerprint": "3295d44f7b6283c3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f7c2d12ac97167d8", "level": "note", "message": {"text": "Unused endpoint: GET /contacts/:id/timeline"}, "properties": {"repobilityId": "b419261141d2dbfc", "scanner": "scanner-primary", "fingerprint": "f7c2d12ac97167d8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f2fa3b5d85e1d74d", "level": "note", "message": {"text": "Unused endpoint: GET /connect-url"}, "properties": {"repobilityId": "55f3d851d9315e54", "scanner": "scanner-primary", "fingerprint": "f2fa3b5d85e1d74d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-612648bbd62b68ab", "level": "note", "message": {"text": "Unused endpoint: DELETE /disconnect"}, "properties": {"repobilityId": "a7e44784791206e8", "scanner": "scanner-primary", "fingerprint": "612648bbd62b68ab", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fa413208496243a5", "level": "note", "message": {"text": "Unused endpoint: POST /sync"}, "properties": {"repobilityId": "47a290e9ed083b37", "scanner": "scanner-primary", "fingerprint": "fa413208496243a5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a2de4317039c9a7f", "level": "note", "message": {"text": "Unused endpoint: GET /threads"}, "properties": {"repobilityId": "05e99f642be4545d", "scanner": "scanner-primary", "fingerprint": "a2de4317039c9a7f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cdfb578618cf2542", "level": "note", "message": {"text": "Unused endpoint: GET /callback"}, "properties": {"repobilityId": "6813ab5a3408c1cb", "scanner": "scanner-primary", "fingerprint": "cdfb578618cf2542", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-43269e4e79c2e69e", "level": "note", "message": {"text": "Unused endpoint: GET /events"}, "properties": {"repobilityId": "4548185a33c91ec5", "scanner": "scanner-primary", "fingerprint": "43269e4e79c2e69e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6f0fc82742855439", "level": "note", "message": {"text": "Unused endpoint: GET /conversations"}, "properties": {"repobilityId": "ee511cfdc434bcbc", "scanner": "scanner-primary", "fingerprint": "6f0fc82742855439", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3e59d3824648f87d", "level": "note", "message": {"text": "Unused endpoint: GET /thread"}, "properties": {"repobilityId": "c6ca2660d110c851", "scanner": "scanner-primary", "fingerprint": "3e59d3824648f87d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}