{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-7e57de1cb8cb12c5", "name": "Possibly dead Python function: display_vulnerability", "shortDescription": {"text": "Possibly dead Python function: display_vulnerability"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e65541c8a53b3cda", "name": "Possibly dead Python function: cleanup_on_exit", "shortDescription": {"text": "Possibly dead Python function: cleanup_on_exit"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-73fa47c10c52002c", "name": "Possibly dead Python function: update_status", "shortDescription": {"text": "Possibly dead Python function: update_status"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-459d2b6eea18bc03", "name": "Possibly dead Python function: compose", "shortDescription": {"text": "Possibly dead Python function: compose"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f9c464518c1f8b58", "name": "Possibly dead Python function: cleanup_on_exit", "shortDescription": {"text": "Possibly dead Python function: cleanup_on_exit"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0e1967e18d6c6d27", "name": "Possibly dead Python function: watch_show_splash", "shortDescription": {"text": "Possibly dead Python function: watch_show_splash"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7babe04d22999e7f", "name": "Possibly dead Python function: watch_selected_agent_id", "shortDescription": {"text": "Possibly dead Python function: watch_selected_agent_id"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0ba479a2c90b82bc", "name": "Possibly dead Python function: scan_target", "shortDescription": {"text": "Possibly dead Python function: scan_target"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72980f43a32a7af0", "name": "Possibly dead Python function: action_toggle_help", "shortDescription": {"text": "Possibly dead Python function: action_toggle_help"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9051bbb40b23d069", "name": "Possibly dead Python function: action_request_quit", "shortDescription": {"text": "Possibly dead Python function: action_request_quit"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-655745c7cdffcea8", "name": "Possibly dead Python function: action_stop_selected_agent", "shortDescription": {"text": "Possibly dead Python function: action_stop_selected_agent"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cd9206978538006f", "name": "Possibly dead Python function: action_open_viewer", "shortDescription": {"text": "Possibly dead Python function: action_open_viewer"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e6e74db3138d14d3", "name": "Possibly dead Python function: register_tool_renderer", "shortDescription": {"text": "Possibly dead Python function: register_tool_renderer"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3e08b00fa2418572", "name": "Possibly dead Python function: log_message", "shortDescription": {"text": "Possibly dead Python function: log_message"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0c05fe4e65f73f04", "name": "Possibly dead Python function: do_GET", "shortDescription": {"text": "Possibly dead Python function: do_GET"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-54f616f1ca554440", "name": "Possibly dead Python function: do_POST", "shortDescription": {"text": "Possibly dead Python function: do_POST"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2795c72de3104042", "name": "Possibly dead Python function: draw", "shortDescription": {"text": "Possibly dead Python function: draw"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0f47a2893463b7e4", "name": "Possibly dead Python function: invoke", "shortDescription": {"text": "Possibly dead Python function: invoke"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6aa126efcfc6c738", "name": "Possibly dead Python function: approve", "shortDescription": {"text": "Possibly dead Python function: approve"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a2c292da16f8321d", "name": "Possibly dead Python function: configure", "shortDescription": {"text": "Possibly dead Python function: configure"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bead75b0f9233e05", "name": "No API endpoints detected", "shortDescription": {"text": "No API endpoints detected"}, "fullDescription": {"text": "The scanner did not find FastAPI/Flask/Express/NestJS/GraphQL/gRPC routes. If this repo exposes APIs, the framework may be unsupported."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e87575d4513eb23f", "name": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/App.tsx:433", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/App.tsx:433"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-e755dfcbb6d79371", "name": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/PastRunsView.tsx:154", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/PastRunsView.tsx:154"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-e2e3349dd5f02e73", "name": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/Sidebar.tsx:204", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/Sidebar.tsx:204"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-0a4dc6ab2a1a1cc3", "name": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/live/ScanPromptComposer.", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/live/ScanPromptComposer.tsx:154"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-0fe763307856cf4a", "name": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/live/AgentTranscript.tsx", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/live/AgentTranscript.tsx:221"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-2af1d9a84b0c26fb", "name": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/live/AgentDetailModal.ts", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/live/AgentDetailModal.tsx:134"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-52f80d75c4f25551", "name": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/live/tool-renderers/Prox", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/live/tool-renderers/ProxyRenderer.tsx:60"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-59f394f9013ea757", "name": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/live/tool-renderers/Brow", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/live/tool-renderers/BrowserRenderer.tsx:103"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-a565bc4ff1b1bfd9", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 strix/viewer/frontend/src/components/live/tool-renderers/ToolCard.", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 strix/viewer/frontend/src/components/live/tool-renderers/ToolCard.tsx:91"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-ac192f4099711b27", "name": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/live/tool-renderers/Agen", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/live/tool-renderers/AgentCommsRenderer.tsx:62"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-2a70baea79d3c3f1", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 strix/viewer/frontend/src/components/vulnerability/MdCodeBlock.tsx", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 strix/viewer/frontend/src/components/vulnerability/MdCodeBlock.tsx:98"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-f1d1b9e3421b8043", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 strix/viewer/frontend/src/components/vulnerability/PocBlock.tsx:66", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 strix/viewer/frontend/src/components/vulnerability/PocBlock.tsx:66"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-f56ca8b5cd9bfeb6", "name": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/vulnerability/IssueSideb", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/vulnerability/IssueSidebar.tsx:186"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-4febc3151adfb61e", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 strix/viewer/frontend/src/components/vulnerability/CodeDiffBlock.t", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 strix/viewer/frontend/src/components/vulnerability/CodeDiffBlock.tsx:105"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-1754019b26bcc718", "name": "Debug `console.log` remains in browser-facing code \u2014 strix/viewer/static/assets/index-BNKUksp9.js:427", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 strix/viewer/static/assets/index-BNKUksp9.js:427"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-5bec99d8f3499094", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 strix/viewer/static/assets/index-BNKUksp9.js:49", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 strix/viewer/static/assets/index-BNKUksp9.js:49"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-7d113c51e14a7684", "name": "dynamic urllib use detected \u2014 strix/interface/utils.py:1058", "shortDescription": {"text": "dynamic urllib use detected \u2014 strix/interface/utils.py:1058"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A01:2017 - Injection\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-4cfb8e65d0489137", "name": "dynamic urllib use detected \u2014 strix/telemetry/posthog.py:45", "shortDescription": {"text": "dynamic urllib use detected \u2014 strix/telemetry/posthog.py:45"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A01:2017 - Injection\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-dc365bb545ea1176", "name": "dynamic urllib use detected \u2014 strix/telemetry/scarf.py:46", "shortDescription": {"text": "dynamic urllib use detected \u2014 strix/telemetry/scarf.py:46"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A01:2017 - Injection\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-b11fc2fec1bd9815", "name": "dynamic urllib use detected \u2014 strix/tools/proxy/caido_api.py:82", "shortDescription": {"text": "dynamic urllib use detected \u2014 strix/tools/proxy/caido_api.py:82"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A01:2017 - Injection\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-9d7c405454297fbd", "name": "dynamic urllib use detected \u2014 strix/viewer/auth.py:158", "shortDescription": {"text": "dynamic urllib use detected \u2014 strix/viewer/auth.py:158"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A01:2017 - Injection\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-00e35e68bc564750", "name": "react dangerouslysetinnerhtml \u2014 strix/viewer/frontend/src/components/vulnerability/PocBlock.tsx:67", "shortDescription": {"text": "react dangerouslysetinnerhtml \u2014 strix/viewer/frontend/src/components/vulnerability/PocBlock.tsx:67"}, "fullDescription": {"text": "Detection of dangerouslySetInnerHTML from non-constant definition. This can inadvertently expose users to cross-site scripting (XSS) attacks if this comes from user-provided input. If you have to use dangerouslySetInnerHTML, consider using a sanitization library such as DOMPurify to sanitize your HTML.\n\nRule: typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-641e71734508028f", "name": "DS-0001: ':latest' tag used \u2014 containers/Dockerfile", "shortDescription": {"text": "DS-0001: ':latest' tag used \u2014 containers/Dockerfile"}, "fullDescription": {"text": "':latest' tag used\n\nSpecify a tag in the 'FROM' statement for image 'kalilinux/kali-rolling'\n\nRule: DS-0001\nSeverity: MEDIUM\nTarget: containers/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fe581c047bf007ed", "name": "DS-0014: RUN using 'wget' and 'curl' \u2014 containers/Dockerfile", "shortDescription": {"text": "DS-0014: RUN using 'wget' and 'curl' \u2014 containers/Dockerfile"}, "fullDescription": {"text": "RUN using 'wget' and 'curl'\n\nShouldn't use both curl and wget\n\nRule: DS-0014\nSeverity: LOW\nTarget: containers/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d208366609dd3350", "name": "DS-0026: No HEALTHCHECK defined \u2014 containers/Dockerfile", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 containers/Dockerfile"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: containers/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-265cef33778fac1c", "name": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 containers/Dockerfile", "shortDescription": {"text": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 containers/Dockerfile"}, "fullDescription": {"text": "'apt-get' missing '--no-install-recommends'\n\n'--no-install-recommends' flag is missed: 'apt-get install -y wapiti'\n\nRule: DS-0029\nSeverity: HIGH\nTarget: containers/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-311cf2f918064d9b", "name": "Dockerfile runs as root: containers/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: containers/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-83e01070fe5ce7b2", "name": "Docker base image uses a mutable or implicit tag: kalilinux/kali-rolling:latest", "shortDescription": {"text": "Docker base image uses a mutable or implicit tag: kalilinux/kali-rolling:latest"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5a86918e2ce640b0", "name": "Dockerfile pipes a remote installer into a shell", "shortDescription": {"text": "Dockerfile pipes a remote installer into a shell"}, "fullDescription": {"text": "Executing downloaded code during image build gives the remote endpoint build-time code execution. Prefer pinned packages or verify downloaded installers by checksum/signature."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5768d198a3e76dc0", "name": "Insecure pattern 'dangerous_innerhtml' in strix/viewer/frontend/src/components/live/tool-renderers/ToolCard.tsx:91", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in strix/viewer/frontend/src/components/live/tool-renderers/ToolCard.tsx:91"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-3c7a21602b90127d", "name": "Insecure pattern 'dangerous_innerhtml' in strix/viewer/frontend/src/components/vulnerability/MdCodeBlock.tsx:98", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in strix/viewer/frontend/src/components/vulnerability/MdCodeBlock.tsx:98"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-a6b70bf15ad2379d", "name": "Insecure pattern 'dangerous_innerhtml' in strix/viewer/frontend/src/components/vulnerability/PocBlock.tsx:66", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in strix/viewer/frontend/src/components/vulnerability/PocBlock.tsx:66"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-2ccb9f177157db4d", "name": "Insecure pattern 'dangerous_innerhtml' in strix/viewer/frontend/src/components/vulnerability/CodeDiffBlock.tsx:105", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in strix/viewer/frontend/src/components/vulnerability/CodeDiffBlock.tsx:105"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-ceff21cb4db471c8", "name": "Possible secret in strix/telemetry/posthog.py", "shortDescription": {"text": "Possible secret in strix/telemetry/posthog.py"}, "fullDescription": {"text": "Detected 1 occurrence(s) matching generic_api_key. Rotate real credentials and move them to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.72}}, {"id": "scanner-45923e6067b64ebf", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-33b23e9b127e38d5", "name": "Very large file: strix/interface/utils.py (1580 lines)", "shortDescription": {"text": "Very large file: strix/interface/utils.py (1580 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9dc62ee4a221c055", "name": "Very large file: strix/interface/tui/app.py (2027 lines)", "shortDescription": {"text": "Very large file: strix/interface/tui/app.py (2027 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea3b5e389d8c9c0f", "name": "Low test-to-source ratio", "shortDescription": {"text": "Low test-to-source ratio"}, "fullDescription": {"text": "33 tests / 147 src (ratio 0.22)."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 13 placeholder/mock markers across 7 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9d625ab8e2133fdf", "name": "Blocking `time.sleep(...)` inside `async def run_cli` \u2014 strix/interface/cli.py:166", "shortDescription": {"text": "Blocking `time.sleep(...)` inside `async def run_cli` \u2014 strix/interface/cli.py:166"}, "fullDescription": {"text": "Sync I/O inside an async function blocks the event loop. While `time.sleep(...)` is running, *all* other coroutines on this loop are paused \u2014 silent throughput collapse under concurrency. Use the async equivalent (`httpx.AsyncClient`, `asyncio.sleep`, `aiofiles`) or wrap with `await asyncio.to_thread(...)`."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2ecc02befcc7377d", "name": "Network/subprocess call without timeout or try/except \u2014 strix/interface/utils.py:517", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 strix/interface/utils.py:517"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-5a0b7da586a72ef6", "name": "Legacy-named symbol `node_to_copy` in strix/interface/tui/app.py:1576", "shortDescription": {"text": "Legacy-named symbol `node_to_copy` in strix/interface/tui/app.py:1576"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ac2949fcd4b3f5d8", "name": "Legacy-named symbol `highlighted_old` in strix/interface/tui/renderers/filesystem_renderer.py:152", "shortDescription": {"text": "Legacy-named symbol `highlighted_old` in strix/interface/tui/renderers/filesystem_renderer.py:152"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fcae0136c65466d2", "name": "Stub function `render` (body is just `pass`/`return`) \u2014 strix/interface/tui/renderers/base_renderer.py:13", "shortDescription": {"text": "Stub function `render` (body is just `pass`/`return`) \u2014 strix/interface/tui/renderers/base_renderer.py:13"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-78a91bb011ab0469", "name": "Fire-and-forget `fetch()` has no rejection handler \u2014 strix/viewer/frontend/src/lib/cta.ts:32", "shortDescription": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 strix/viewer/frontend/src/lib/cta.ts:32"}, "fullDescription": {"text": "This fetch result is neither awaited, returned, assigned, nor followed by `.catch(...)`. A network failure can therefore become an unhandled promise rejection. Await/return the promise or attach an explicit rejection handler."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-3a75c6a6b9719d20", "name": "Legacy-named symbol `unstable_legacy` in strix/viewer/static/assets/index-BNKUksp9.js:48", "shortDescription": {"text": "Legacy-named symbol `unstable_legacy` in strix/viewer/static/assets/index-BNKUksp9.js:48"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-08cb73e1a87ad250", "name": "Legacy-named symbol `_link_or_copy` in strix/runtime/local_dir_staging.py:62", "shortDescription": {"text": "Legacy-named symbol `_link_or_copy` in strix/runtime/local_dir_staging.py:62"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6a48232c0fc1fdb5", "name": "Vulnerable dependency vite 6.0.0: GHSA-356w-63v5-8wf4", "shortDescription": {"text": "Vulnerable dependency vite 6.0.0: GHSA-356w-63v5-8wf4"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `6.0.0` (declared in `strix/viewer/frontend/package.json`) is affected by GHSA-356w-63v5-8wf4 (aka CVE-2025-32395).\nNote: `6.0.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nVite has an `server.fs.deny` bypass with an invalid `request-target`\n\nAliases: CVE-2025-32395\nAdvisory: https://osv.dev/vulnerability/GHSA-356w-63v5-8wf4\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-e1ba231af868820b", "name": "Vulnerable dependency vite 6.0.0: GHSA-4r4m-qw57-chr8", "shortDescription": {"text": "Vulnerable dependency vite 6.0.0: GHSA-4r4m-qw57-chr8"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `6.0.0` (declared in `strix/viewer/frontend/package.json`) is affected by GHSA-4r4m-qw57-chr8 (aka CVE-2025-31125).\nNote: `6.0.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nVite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query\n\nAliases: CVE-2025-31125\nAdvisory: https://osv.dev/vulnerability/GHSA-4r4m-qw57-chr8\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-1550b3006ee36582", "name": "Vulnerable dependency vite 6.0.0: GHSA-4w7w-66w2-5vf9", "shortDescription": {"text": "Vulnerable dependency vite 6.0.0: GHSA-4w7w-66w2-5vf9"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `6.0.0` (declared in `strix/viewer/frontend/package.json`) is affected by GHSA-4w7w-66w2-5vf9 (aka CVE-2026-39365).\nNote: `6.0.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nVite Vulnerable to Path Traversal in Optimized Deps `.map` Handling\n\nAliases: CVE-2026-39365\nAdvisory: https://osv.dev/vulnerability/GHSA-4w7w-66w2-5vf9\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-a6485df16313a77d", "name": "Vulnerable dependency vite 6.0.0: GHSA-859w-5945-r5v3", "shortDescription": {"text": "Vulnerable dependency vite 6.0.0: GHSA-859w-5945-r5v3"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `6.0.0` (declared in `strix/viewer/frontend/package.json`) is affected by GHSA-859w-5945-r5v3 (aka CVE-2025-46565).\nNote: `6.0.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nVite's server.fs.deny bypassed with /. for files under project root\n\nAliases: CVE-2025-46565\nAdvisory: https://osv.dev/vulnerability/GHSA-859w-5945-r5v3\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-8add7cc999e8f67b", "name": "Vulnerable dependency vite 6.0.0: GHSA-93m4-6634-74q7", "shortDescription": {"text": "Vulnerable dependency vite 6.0.0: GHSA-93m4-6634-74q7"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `6.0.0` (declared in `strix/viewer/frontend/package.json`) is affected by GHSA-93m4-6634-74q7 (aka CVE-2025-62522).\nNote: `6.0.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nvite allows server.fs.deny bypass via backslash on Windows\n\nAliases: CVE-2025-62522\nAdvisory: https://osv.dev/vulnerability/GHSA-93m4-6634-74q7\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-49a46573f1105343", "name": "Vulnerable dependency vite 6.0.0: GHSA-fx2h-pf6j-xcff", "shortDescription": {"text": "Vulnerable dependency vite 6.0.0: GHSA-fx2h-pf6j-xcff"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `6.0.0` (declared in `strix/viewer/frontend/package.json`) is affected by GHSA-fx2h-pf6j-xcff (aka CVE-2026-53571).\nNote: `6.0.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nvite: `server.fs.deny` bypass on Windows alternate paths\n\nAliases: CVE-2026-53571\nAdvisory: https://osv.dev/vulnerability/GHSA-fx2h-pf6j-xcff\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.7}}, {"id": "scanner-f3d2ae215921fdf8", "name": "Vulnerable dependency vite 6.0.0: GHSA-g4jq-h2w9-997c", "shortDescription": {"text": "Vulnerable dependency vite 6.0.0: GHSA-g4jq-h2w9-997c"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `6.0.0` (declared in `strix/viewer/frontend/package.json`) is affected by GHSA-g4jq-h2w9-997c (aka CVE-2025-58751).\nNote: `6.0.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nVite middleware may serve files starting with the same name with the public directory\n\nAliases: CVE-2025-58751\nAdvisory: https://osv.dev/vulnerability/GHSA-g4jq-h2w9-997c\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.7}}, {"id": "scanner-21eb3e3971924e98", "name": "Vulnerable dependency vite 6.0.0: GHSA-jqfw-vq24-v9c3", "shortDescription": {"text": "Vulnerable dependency vite 6.0.0: GHSA-jqfw-vq24-v9c3"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `6.0.0` (declared in `strix/viewer/frontend/package.json`) is affected by GHSA-jqfw-vq24-v9c3 (aka CVE-2025-58752).\nNote: `6.0.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nVite's `server.fs` settings were not applied to HTML files\n\nAliases: CVE-2025-58752\nAdvisory: https://osv.dev/vulnerability/GHSA-jqfw-vq24-v9c3\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.7}}, {"id": "scanner-d457aeaca320f760", "name": "Vulnerable dependency vite 6.0.0: GHSA-p9ff-h696-f583", "shortDescription": {"text": "Vulnerable dependency vite 6.0.0: GHSA-p9ff-h696-f583"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `6.0.0` (declared in `strix/viewer/frontend/package.json`) is affected by GHSA-p9ff-h696-f583 (aka CVE-2026-39363).\nNote: `6.0.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nVite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket\n\nAliases: CVE-2026-39363\nAdvisory: https://osv.dev/vulnerability/GHSA-p9ff-h696-f583\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.7}}, {"id": "scanner-763d6437504797cc", "name": "Vulnerable dependency vite 6.0.0: GHSA-v6wh-96g9-6wx3", "shortDescription": {"text": "Vulnerable dependency vite 6.0.0: GHSA-v6wh-96g9-6wx3"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `6.0.0` (declared in `strix/viewer/frontend/package.json`) is affected by GHSA-v6wh-96g9-6wx3 (aka CVE-2026-53632).\nNote: `6.0.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nlaunch-editor: NTLMv2 hash disclosure via UNC path handling on Windows\n\nAliases: CVE-2026-53632\nAdvisory: https://osv.dev/vulnerability/GHSA-v6wh-96g9-6wx3\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-8eaf087d0fa38f77", "name": "Vulnerable dependency vite 6.0.0: GHSA-vg6x-rcgg-rjx6", "shortDescription": {"text": "Vulnerable dependency vite 6.0.0: GHSA-vg6x-rcgg-rjx6"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `6.0.0` (declared in `strix/viewer/frontend/package.json`) is affected by GHSA-vg6x-rcgg-rjx6 (aka CVE-2025-24010).\nNote: `6.0.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nWebsites were able to send any requests to the development server and read the response in vite\n\nAliases: CVE-2025-24010\nAdvisory: https://osv.dev/vulnerability/GHSA-vg6x-rcgg-rjx6\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-eefee982b0a9f9fb", "name": "Vulnerable dependency vite 6.0.0: GHSA-x574-m823-4x7w", "shortDescription": {"text": "Vulnerable dependency vite 6.0.0: GHSA-x574-m823-4x7w"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `6.0.0` (declared in `strix/viewer/frontend/package.json`) is affected by GHSA-x574-m823-4x7w (aka CVE-2025-30208).\nNote: `6.0.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nVite bypasses server.fs.deny when using ?raw??\n\nAliases: CVE-2025-30208\nAdvisory: https://osv.dev/vulnerability/GHSA-x574-m823-4x7w\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-dc7fd80b0529d9b5", "name": "Vulnerable dependency vite 6.0.0: GHSA-xcj6-pq6g-qj4x", "shortDescription": {"text": "Vulnerable dependency vite 6.0.0: GHSA-xcj6-pq6g-qj4x"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `6.0.0` (declared in `strix/viewer/frontend/package.json`) is affected by GHSA-xcj6-pq6g-qj4x (aka CVE-2025-31486).\nNote: `6.0.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nVite allows server.fs.deny to be bypassed with .svg or relative paths\n\nAliases: CVE-2025-31486\nAdvisory: https://osv.dev/vulnerability/GHSA-xcj6-pq6g-qj4x\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-02beaef6201fc578", "name": "Vulnerable dependency setuptools 82.0.1: GHSA-h35f-9h28-mq5c", "shortDescription": {"text": "Vulnerable dependency setuptools 82.0.1: GHSA-h35f-9h28-mq5c"}, "fullDescription": {"text": "OSV.dev reports `setuptools` at version `82.0.1` (resolved in `uv.lock`) is affected by GHSA-h35f-9h28-mq5c (aka CVE-2026-59890).\nNote: `setuptools` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nsetuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+\n\nAliases: BIT-setuptools-2026-59890, CVE-2026-59890, GHSA-h35f-9h28-mq5c, PYSEC-2026-3447\nAdvisory: https://osv.dev/vulnerability/GHSA-h35f-9h28-mq5c\nFix: upgrade `setuptools` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-5e039c3fe7436cb8", "name": "Dependency @dagrejs/dagre is a major version behind", "shortDescription": {"text": "Dependency @dagrejs/dagre is a major version behind"}, "fullDescription": {"text": "`@dagrejs/dagre` is pinned at `2.0.4` in `strix/viewer/frontend/package.json` while the latest release on the npm registry is `3.0.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@dagrejs/dagre` to `3.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-ba689014da0e3a24", "name": "Dependency diff is a major version behind", "shortDescription": {"text": "Dependency diff is a major version behind"}, "fullDescription": {"text": "`diff` is pinned at `8.0.3` in `strix/viewer/frontend/package.json` while the latest release on the npm registry is `9.0.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `diff` to `9.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-5cfa59782845124c", "name": "Dependency lucide-react is a major version behind", "shortDescription": {"text": "Dependency lucide-react is a major version behind"}, "fullDescription": {"text": "`lucide-react` is pinned at `0.563.0` in `strix/viewer/frontend/package.json` while the latest release on the npm registry is `1.26.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `lucide-react` to `1.26.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}]}}, "automationDetails": {"id": "repobility/30774"}, "properties": {"repository": "usestrix/strix", "repoUrl": "https://github.com/usestrix/strix", "branch": "main"}, "results": [{"ruleId": "scanner-7e57de1cb8cb12c5", "level": "note", "message": {"text": "Possibly dead Python function: display_vulnerability"}, "properties": {"repobilityId": "acf32191730d6852", "scanner": "scanner-primary", "fingerprint": "7e57de1cb8cb12c5", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/interface/cli.py:104"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e65541c8a53b3cda", "level": "note", "message": {"text": "Possibly dead Python function: cleanup_on_exit"}, "properties": {"repobilityId": "77b077ab267c95d1", "scanner": "scanner-primary", "fingerprint": "e65541c8a53b3cda", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/interface/cli.py:122"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-73fa47c10c52002c", "level": "note", "message": {"text": "Possibly dead Python function: update_status"}, "properties": {"repobilityId": "cfc1d5263b9a362e", "scanner": "scanner-primary", "fingerprint": "73fa47c10c52002c", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/interface/cli.py:162"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-459d2b6eea18bc03", "level": "note", "message": {"text": "Possibly dead Python function: compose"}, "properties": {"repobilityId": "e8baae2c9d6dad8b", "scanner": "scanner-primary", "fingerprint": "459d2b6eea18bc03", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/interface/tui/app.py:853"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f9c464518c1f8b58", "level": "note", "message": {"text": "Possibly dead Python function: cleanup_on_exit"}, "properties": {"repobilityId": "77b077ab267c95d1", "scanner": "scanner-primary", "fingerprint": "f9c464518c1f8b58", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/interface/tui/app.py:839"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0e1967e18d6c6d27", "level": "note", "message": {"text": "Possibly dead Python function: watch_show_splash"}, "properties": {"repobilityId": "2c0cfe40b8295804", "scanner": "scanner-primary", "fingerprint": "0e1967e18d6c6d27", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/interface/tui/app.py:857"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7babe04d22999e7f", "level": "note", "message": {"text": "Possibly dead Python function: watch_selected_agent_id"}, "properties": {"repobilityId": "e746a38d005de57e", "scanner": "scanner-primary", "fingerprint": "7babe04d22999e7f", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/interface/tui/app.py:1444"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0ba479a2c90b82bc", "level": "note", "message": {"text": "Possibly dead Python function: scan_target"}, "properties": {"repobilityId": "9cc82adbf30366b5", "scanner": "scanner-primary", "fingerprint": "0ba479a2c90b82bc", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/interface/tui/app.py:1457"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-72980f43a32a7af0", "level": "note", "message": {"text": "Possibly dead Python function: action_toggle_help"}, "properties": {"repobilityId": "1e1acccd54ccbeff", "scanner": "scanner-primary", "fingerprint": "72980f43a32a7af0", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/interface/tui/app.py:1726"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9051bbb40b23d069", "level": "note", "message": {"text": "Possibly dead Python function: action_request_quit"}, "properties": {"repobilityId": "30dca5c372b82b6e", "scanner": "scanner-primary", "fingerprint": "9051bbb40b23d069", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/interface/tui/app.py:1744"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-655745c7cdffcea8", "level": "note", "message": {"text": "Possibly dead Python function: action_stop_selected_agent"}, "properties": {"repobilityId": "291ffcb315a5db0c", "scanner": "scanner-primary", "fingerprint": "655745c7cdffcea8", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/interface/tui/app.py:1760"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cd9206978538006f", "level": "note", "message": {"text": "Possibly dead Python function: action_open_viewer"}, "properties": {"repobilityId": "2977e0d44df23b8c", "scanner": "scanner-primary", "fingerprint": "cd9206978538006f", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/interface/tui/app.py:1835"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e6e74db3138d14d3", "level": "note", "message": {"text": "Possibly dead Python function: register_tool_renderer"}, "properties": {"repobilityId": "7699f50d819b7b14", "scanner": "scanner-primary", "fingerprint": "e6e74db3138d14d3", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/interface/tui/renderers/registry.py:24"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3e08b00fa2418572", "level": "note", "message": {"text": "Possibly dead Python function: log_message"}, "properties": {"repobilityId": "965f3150b4af5b2e", "scanner": "scanner-primary", "fingerprint": "3e08b00fa2418572", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/server.py:144"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0c05fe4e65f73f04", "level": "note", "message": {"text": "Possibly dead Python function: do_GET"}, "properties": {"repobilityId": "2d943bb45e4f13bd", "scanner": "scanner-primary", "fingerprint": "0c05fe4e65f73f04", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/server.py:147"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-54f616f1ca554440", "level": "note", "message": {"text": "Possibly dead Python function: do_POST"}, "properties": {"repobilityId": "53357410ca9379a9", "scanner": "scanner-primary", "fingerprint": "54f616f1ca554440", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/server.py:164"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2795c72de3104042", "level": "note", "message": {"text": "Possibly dead Python function: draw"}, "properties": {"repobilityId": "53ecb21dcbad2db9", "scanner": "scanner-primary", "fingerprint": "2795c72de3104042", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/report_pdf.py:117"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0f47a2893463b7e4", "level": "note", "message": {"text": "Possibly dead Python function: invoke"}, "properties": {"repobilityId": "a0f6754c12b3a2c8", "scanner": "scanner-primary", "fingerprint": "0f47a2893463b7e4", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/agents/factory.py:238"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6aa126efcfc6c738", "level": "note", "message": {"text": "Possibly dead Python function: approve"}, "properties": {"repobilityId": "7f1cade6e1afe280", "scanner": "scanner-primary", "fingerprint": "6aa126efcfc6c738", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/agents/factory.py:139"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a2c292da16f8321d", "level": "note", "message": {"text": "Possibly dead Python function: configure"}, "properties": {"repobilityId": "c0dbafc76b7d83b8", "scanner": "scanner-primary", "fingerprint": "a2c292da16f8321d", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/agents/factory.py:270"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bead75b0f9233e05", "level": "none", "message": {"text": "No API endpoints detected"}, "properties": {"repobilityId": "0f8bb852027c38f8", "scanner": "scanner-primary", "fingerprint": "bead75b0f9233e05", "layer": "api", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-e87575d4513eb23f", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/App.tsx:433"}, "properties": {"repobilityId": "63223386e01b3094", "scanner": "scanner-primary", "fingerprint": "e87575d4513eb23f", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/src/App.tsx"}, "region": {"startLine": 433}}}]}, {"ruleId": "scanner-e755dfcbb6d79371", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/PastRunsView.tsx:154"}, "properties": {"repobilityId": "8fb0720cc9aba245", "scanner": "scanner-primary", "fingerprint": "e755dfcbb6d79371", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/src/components/PastRunsView.tsx"}, "region": {"startLine": 154}}}]}, {"ruleId": "scanner-e2e3349dd5f02e73", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/Sidebar.tsx:204"}, "properties": {"repobilityId": "ba5c44b63bee78cc", "scanner": "scanner-primary", "fingerprint": "e2e3349dd5f02e73", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/src/components/Sidebar.tsx"}, "region": {"startLine": 204}}}]}, {"ruleId": "scanner-0a4dc6ab2a1a1cc3", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/live/ScanPromptComposer.tsx:154"}, "properties": {"repobilityId": "f7a43763c2773087", "scanner": "scanner-primary", "fingerprint": "0a4dc6ab2a1a1cc3", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/src/components/live/ScanPromptComposer.tsx"}, "region": {"startLine": 154}}}]}, {"ruleId": "scanner-0fe763307856cf4a", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/live/AgentTranscript.tsx:221"}, "properties": {"repobilityId": "fe7ccafba314eef6", "scanner": "scanner-primary", "fingerprint": "0fe763307856cf4a", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/src/components/live/AgentTranscript.tsx"}, "region": {"startLine": 221}}}]}, {"ruleId": "scanner-2af1d9a84b0c26fb", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/live/AgentDetailModal.tsx:134"}, "properties": {"repobilityId": "2ea289424c1c4381", "scanner": "scanner-primary", "fingerprint": "2af1d9a84b0c26fb", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/src/components/live/AgentDetailModal.tsx"}, "region": {"startLine": 134}}}]}, {"ruleId": "scanner-52f80d75c4f25551", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/live/tool-renderers/ProxyRenderer.tsx:60"}, "properties": {"repobilityId": "017227927e2f6a6b", "scanner": "scanner-primary", "fingerprint": "52f80d75c4f25551", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/src/components/live/tool-renderers/ProxyRenderer.tsx"}, "region": {"startLine": 60}}}]}, {"ruleId": "scanner-59f394f9013ea757", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/live/tool-renderers/BrowserRenderer.tsx:103"}, "properties": {"repobilityId": "4abcb68c66e25caf", "scanner": "scanner-primary", "fingerprint": "59f394f9013ea757", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/src/components/live/tool-renderers/BrowserRenderer.tsx"}, "region": {"startLine": 103}}}]}, {"ruleId": "scanner-a565bc4ff1b1bfd9", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 strix/viewer/frontend/src/components/live/tool-renderers/ToolCard.tsx:91"}, "properties": {"repobilityId": "aa0eb76414af8352", "scanner": "scanner-primary", "fingerprint": "a565bc4ff1b1bfd9", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/src/components/live/tool-renderers/ToolCard.tsx"}, "region": {"startLine": 91}}}]}, {"ruleId": "scanner-ac192f4099711b27", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/live/tool-renderers/AgentCommsRenderer.tsx:62"}, "properties": {"repobilityId": "53c4c3db19043ed7", "scanner": "scanner-primary", "fingerprint": "ac192f4099711b27", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/src/components/live/tool-renderers/AgentCommsRenderer.tsx"}, "region": {"startLine": 62}}}]}, {"ruleId": "scanner-2a70baea79d3c3f1", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 strix/viewer/frontend/src/components/vulnerability/MdCodeBlock.tsx:98"}, "properties": {"repobilityId": "272eb02bfed60149", "scanner": "scanner-primary", "fingerprint": "2a70baea79d3c3f1", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/src/components/vulnerability/MdCodeBlock.tsx"}, "region": {"startLine": 98}}}]}, {"ruleId": "scanner-f1d1b9e3421b8043", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 strix/viewer/frontend/src/components/vulnerability/PocBlock.tsx:66"}, "properties": {"repobilityId": "6dfe28e153948a0d", "scanner": "scanner-primary", "fingerprint": "f1d1b9e3421b8043", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/src/components/vulnerability/PocBlock.tsx"}, "region": {"startLine": 66}}}]}, {"ruleId": "scanner-f56ca8b5cd9bfeb6", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 strix/viewer/frontend/src/components/vulnerability/IssueSidebar.tsx:186"}, "properties": {"repobilityId": "c84599815dbc0bc7", "scanner": "scanner-primary", "fingerprint": "f56ca8b5cd9bfeb6", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/src/components/vulnerability/IssueSidebar.tsx"}, "region": {"startLine": 186}}}]}, {"ruleId": "scanner-4febc3151adfb61e", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 strix/viewer/frontend/src/components/vulnerability/CodeDiffBlock.tsx:105"}, "properties": {"repobilityId": "cad9bd3e7ee7b0d1", "scanner": "scanner-primary", "fingerprint": "4febc3151adfb61e", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/src/components/vulnerability/CodeDiffBlock.tsx"}, "region": {"startLine": 105}}}]}, {"ruleId": "scanner-1754019b26bcc718", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 strix/viewer/static/assets/index-BNKUksp9.js:427"}, "properties": {"repobilityId": "a4721da2f0b0d583", "scanner": "scanner-primary", "fingerprint": "1754019b26bcc718", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/static/assets/index-BNKUksp9.js"}, "region": {"startLine": 427}}}]}, {"ruleId": "scanner-5bec99d8f3499094", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 strix/viewer/static/assets/index-BNKUksp9.js:49"}, "properties": {"repobilityId": "6f7fa0de2238764e", "scanner": "scanner-primary", "fingerprint": "5bec99d8f3499094", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/static/assets/index-BNKUksp9.js"}, "region": {"startLine": 49}}}]}, {"ruleId": "scanner-7d113c51e14a7684", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 strix/interface/utils.py:1058"}, "properties": {"repobilityId": "01d07e2925c48d11", "scanner": "scanner-primary", "fingerprint": "7d113c51e14a7684", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/interface/utils.py"}, "region": {"startLine": 1058}}}]}, {"ruleId": "scanner-4cfb8e65d0489137", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 strix/telemetry/posthog.py:45"}, "properties": {"repobilityId": "ce11943a5da7b3c7", "scanner": "scanner-primary", "fingerprint": "4cfb8e65d0489137", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/telemetry/posthog.py"}, "region": {"startLine": 45}}}]}, {"ruleId": "scanner-dc365bb545ea1176", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 strix/telemetry/scarf.py:46"}, "properties": {"repobilityId": "694862178a8a3f61", "scanner": "scanner-primary", "fingerprint": "dc365bb545ea1176", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/telemetry/scarf.py"}, "region": {"startLine": 46}}}]}, {"ruleId": "scanner-b11fc2fec1bd9815", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 strix/tools/proxy/caido_api.py:82"}, "properties": {"repobilityId": "6c888504608a1434", "scanner": "scanner-primary", "fingerprint": "b11fc2fec1bd9815", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/tools/proxy/caido_api.py"}, "region": {"startLine": 82}}}]}, {"ruleId": "scanner-9d7c405454297fbd", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 strix/viewer/auth.py:158"}, "properties": {"repobilityId": "200a140ce685cb12", "scanner": "scanner-primary", "fingerprint": "9d7c405454297fbd", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/auth.py"}, "region": {"startLine": 158}}}]}, {"ruleId": "scanner-00e35e68bc564750", "level": "warning", "message": {"text": "react dangerouslysetinnerhtml \u2014 strix/viewer/frontend/src/components/vulnerability/PocBlock.tsx:67"}, "properties": {"repobilityId": "db4f6f46240a4688", "scanner": "scanner-primary", "fingerprint": "00e35e68bc564750", "layer": "security", "severity": "medium", "confidence": 0.7, "tags": ["semgrep", "security", "react"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/src/components/vulnerability/PocBlock.tsx"}, "region": {"startLine": 67}}}]}, {"ruleId": "scanner-641e71734508028f", "level": "warning", "message": {"text": "DS-0001: ':latest' tag used \u2014 containers/Dockerfile"}, "properties": {"repobilityId": "22d9f38e774f42a3", "scanner": "scanner-primary", "fingerprint": "641e71734508028f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-fe581c047bf007ed", "level": "note", "message": {"text": "DS-0014: RUN using 'wget' and 'curl' \u2014 containers/Dockerfile"}, "properties": {"repobilityId": "f597dd747fd12f82", "scanner": "scanner-primary", "fingerprint": "fe581c047bf007ed", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-d208366609dd3350", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 containers/Dockerfile"}, "properties": {"repobilityId": "827e1540360c2d63", "scanner": "scanner-primary", "fingerprint": "d208366609dd3350", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-265cef33778fac1c", "level": "error", "message": {"text": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 containers/Dockerfile"}, "properties": {"repobilityId": "0e437f0e7898fc5f", "scanner": "scanner-primary", "fingerprint": "265cef33778fac1c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-311cf2f918064d9b", "level": "warning", "message": {"text": "Dockerfile runs as root: containers/Dockerfile"}, "properties": {"repobilityId": "0f334707f3ff6c93", "scanner": "scanner-primary", "fingerprint": "311cf2f918064d9b", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-83e01070fe5ce7b2", "level": "warning", "message": {"text": "Docker base image uses a mutable or implicit tag: kalilinux/kali-rolling:latest"}, "properties": {"repobilityId": "cb75d61cb2b9252c", "scanner": "scanner-primary", "fingerprint": "83e01070fe5ce7b2", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "containers/Dockerfile"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-5a86918e2ce640b0", "level": "error", "message": {"text": "Dockerfile pipes a remote installer into a shell"}, "properties": {"repobilityId": "09eff1e928f2cc44", "scanner": "scanner-primary", "fingerprint": "5a86918e2ce640b0", "layer": "hardware", "severity": "high", "confidence": 1.0, "tags": ["supply-chain", "docker", "remote-installer"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "containers/Dockerfile"}, "region": {"startLine": 85}}}]}, {"ruleId": "scanner-5768d198a3e76dc0", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in strix/viewer/frontend/src/components/live/tool-renderers/ToolCard.tsx:91"}, "properties": {"repobilityId": "591524d68a3c091f", "scanner": "scanner-primary", "fingerprint": "5768d198a3e76dc0", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/src/components/live/tool-renderers/ToolCard.tsx"}, "region": {"startLine": 91}}}]}, {"ruleId": "scanner-3c7a21602b90127d", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in strix/viewer/frontend/src/components/vulnerability/MdCodeBlock.tsx:98"}, "properties": {"repobilityId": "bca21a23d26feabe", "scanner": "scanner-primary", "fingerprint": "3c7a21602b90127d", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/src/components/vulnerability/MdCodeBlock.tsx"}, "region": {"startLine": 98}}}]}, {"ruleId": "scanner-a6b70bf15ad2379d", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in strix/viewer/frontend/src/components/vulnerability/PocBlock.tsx:66"}, "properties": {"repobilityId": "c643decd114d1575", "scanner": "scanner-primary", "fingerprint": "a6b70bf15ad2379d", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/src/components/vulnerability/PocBlock.tsx"}, "region": {"startLine": 66}}}]}, {"ruleId": "scanner-2ccb9f177157db4d", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in strix/viewer/frontend/src/components/vulnerability/CodeDiffBlock.tsx:105"}, "properties": {"repobilityId": "9fac9e0fe182f35e", "scanner": "scanner-primary", "fingerprint": "2ccb9f177157db4d", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/src/components/vulnerability/CodeDiffBlock.tsx"}, "region": {"startLine": 105}}}]}, {"ruleId": "scanner-ceff21cb4db471c8", "level": "error", "message": {"text": "Possible secret in strix/telemetry/posthog.py"}, "properties": {"repobilityId": "5bbcfab5eabcb3d7", "scanner": "scanner-primary", "fingerprint": "ceff21cb4db471c8", "layer": "security", "severity": "high", "confidence": 0.72, "tags": ["secrets", "generic_api_key"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/telemetry/posthog.py"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-45923e6067b64ebf", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "2819ce8606628b67", "scanner": "scanner-primary", "fingerprint": "45923e6067b64ebf", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/build-release.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-33b23e9b127e38d5", "level": "note", "message": {"text": "Very large file: strix/interface/utils.py (1580 lines)"}, "properties": {"repobilityId": "679ddaffb7253059", "scanner": "scanner-primary", "fingerprint": "33b23e9b127e38d5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-9dc62ee4a221c055", "level": "note", "message": {"text": "Very large file: strix/interface/tui/app.py (2027 lines)"}, "properties": {"repobilityId": "bff234138248a13f", "scanner": "scanner-primary", "fingerprint": "9dc62ee4a221c055", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ea3b5e389d8c9c0f", "level": "note", "message": {"text": "Low test-to-source ratio"}, "properties": {"repobilityId": "ef7b2552cc00a375", "scanner": "scanner-primary", "fingerprint": "ea3b5e389d8c9c0f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["tests"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "bf2d557bd30f80b4", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "6f697199524c05fd", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-9d625ab8e2133fdf", "level": "error", "message": {"text": "Blocking `time.sleep(...)` inside `async def run_cli` \u2014 strix/interface/cli.py:166"}, "properties": {"repobilityId": "e5ea5a9a8e8fc655", "scanner": "scanner-primary", "fingerprint": "9d625ab8e2133fdf", "layer": "quality", "severity": "high", "confidence": 1.0, "tags": ["integrity", "sync-io-in-async", "performance"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/interface/cli.py"}, "region": {"startLine": 166}}}]}, {"ruleId": "scanner-2ecc02befcc7377d", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 strix/interface/utils.py:517"}, "properties": {"repobilityId": "f9f2f10bc243e8ca", "scanner": "scanner-primary", "fingerprint": "2ecc02befcc7377d", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/interface/utils.py"}, "region": {"startLine": 517}}}]}, {"ruleId": "scanner-5a0b7da586a72ef6", "level": "note", "message": {"text": "Legacy-named symbol `node_to_copy` in strix/interface/tui/app.py:1576"}, "properties": {"repobilityId": "2af4ce396f141f51", "scanner": "scanner-primary", "fingerprint": "5a0b7da586a72ef6", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-ac2949fcd4b3f5d8", "level": "note", "message": {"text": "Legacy-named symbol `highlighted_old` in strix/interface/tui/renderers/filesystem_renderer.py:152"}, "properties": {"repobilityId": "930f930481528711", "scanner": "scanner-primary", "fingerprint": "ac2949fcd4b3f5d8", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-fcae0136c65466d2", "level": "note", "message": {"text": "Stub function `render` (body is just `pass`/`return`) \u2014 strix/interface/tui/renderers/base_renderer.py:13"}, "properties": {"repobilityId": "14754c30dbceef3c", "scanner": "scanner-primary", "fingerprint": "fcae0136c65466d2", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-78a91bb011ab0469", "level": "warning", "message": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 strix/viewer/frontend/src/lib/cta.ts:32"}, "properties": {"repobilityId": "d367240e5e3b7b83", "scanner": "scanner-primary", "fingerprint": "78a91bb011ab0469", "layer": "quality", "severity": "medium", "confidence": 0.9, "tags": ["integrity", "fragile-runtime", "robustness", "unhandled-promise"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/src/lib/cta.ts"}, "region": {"startLine": 32}}}]}, {"ruleId": "scanner-3a75c6a6b9719d20", "level": "note", "message": {"text": "Legacy-named symbol `unstable_legacy` in strix/viewer/static/assets/index-BNKUksp9.js:48"}, "properties": {"repobilityId": "d24b1293361e16b1", "scanner": "scanner-primary", "fingerprint": "3a75c6a6b9719d20", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-08cb73e1a87ad250", "level": "note", "message": {"text": "Legacy-named symbol `_link_or_copy` in strix/runtime/local_dir_staging.py:62"}, "properties": {"repobilityId": "fa645c83fe04f978", "scanner": "scanner-primary", "fingerprint": "08cb73e1a87ad250", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-6a48232c0fc1fdb5", "level": "warning", "message": {"text": "Vulnerable dependency vite 6.0.0: GHSA-356w-63v5-8wf4"}, "properties": {"repobilityId": "b63aaa172400cf88", "scanner": "scanner-primary", "fingerprint": "6a48232c0fc1fdb5", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-356w-63v5-8wf4", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e1ba231af868820b", "level": "warning", "message": {"text": "Vulnerable dependency vite 6.0.0: GHSA-4r4m-qw57-chr8"}, "properties": {"repobilityId": "909c3f0ab6049fd5", "scanner": "scanner-primary", "fingerprint": "e1ba231af868820b", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-4r4m-qw57-chr8", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1550b3006ee36582", "level": "warning", "message": {"text": "Vulnerable dependency vite 6.0.0: GHSA-4w7w-66w2-5vf9"}, "properties": {"repobilityId": "36033e745539c358", "scanner": "scanner-primary", "fingerprint": "1550b3006ee36582", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-4w7w-66w2-5vf9", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a6485df16313a77d", "level": "warning", "message": {"text": "Vulnerable dependency vite 6.0.0: GHSA-859w-5945-r5v3"}, "properties": {"repobilityId": "03601b771efefe46", "scanner": "scanner-primary", "fingerprint": "a6485df16313a77d", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-859w-5945-r5v3", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8add7cc999e8f67b", "level": "warning", "message": {"text": "Vulnerable dependency vite 6.0.0: GHSA-93m4-6634-74q7"}, "properties": {"repobilityId": "09894c9157a5fbb4", "scanner": "scanner-primary", "fingerprint": "8add7cc999e8f67b", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-93m4-6634-74q7", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-49a46573f1105343", "level": "error", "message": {"text": "Vulnerable dependency vite 6.0.0: GHSA-fx2h-pf6j-xcff"}, "properties": {"repobilityId": "46a2c0e18c6bcb75", "scanner": "scanner-primary", "fingerprint": "49a46573f1105343", "layer": "dependencies", "severity": "high", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-fx2h-pf6j-xcff", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f3d2ae215921fdf8", "level": "note", "message": {"text": "Vulnerable dependency vite 6.0.0: GHSA-g4jq-h2w9-997c"}, "properties": {"repobilityId": "af6c39d56f8e0b4b", "scanner": "scanner-primary", "fingerprint": "f3d2ae215921fdf8", "layer": "dependencies", "severity": "low", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-g4jq-h2w9-997c", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-21eb3e3971924e98", "level": "note", "message": {"text": "Vulnerable dependency vite 6.0.0: GHSA-jqfw-vq24-v9c3"}, "properties": {"repobilityId": "b011dc6dc84caefe", "scanner": "scanner-primary", "fingerprint": "21eb3e3971924e98", "layer": "dependencies", "severity": "low", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-jqfw-vq24-v9c3", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d457aeaca320f760", "level": "error", "message": {"text": "Vulnerable dependency vite 6.0.0: GHSA-p9ff-h696-f583"}, "properties": {"repobilityId": "0f6a510b35fb4a5b", "scanner": "scanner-primary", "fingerprint": "d457aeaca320f760", "layer": "dependencies", "severity": "high", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-p9ff-h696-f583", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-763d6437504797cc", "level": "warning", "message": {"text": "Vulnerable dependency vite 6.0.0: GHSA-v6wh-96g9-6wx3"}, "properties": {"repobilityId": "45b56ada30bc112c", "scanner": "scanner-primary", "fingerprint": "763d6437504797cc", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-v6wh-96g9-6wx3", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8eaf087d0fa38f77", "level": "warning", "message": {"text": "Vulnerable dependency vite 6.0.0: GHSA-vg6x-rcgg-rjx6"}, "properties": {"repobilityId": "d2a38d407b1b42a0", "scanner": "scanner-primary", "fingerprint": "8eaf087d0fa38f77", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-vg6x-rcgg-rjx6", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-eefee982b0a9f9fb", "level": "warning", "message": {"text": "Vulnerable dependency vite 6.0.0: GHSA-x574-m823-4x7w"}, "properties": {"repobilityId": "69816d5baa36f021", "scanner": "scanner-primary", "fingerprint": "eefee982b0a9f9fb", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-x574-m823-4x7w", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dc7fd80b0529d9b5", "level": "warning", "message": {"text": "Vulnerable dependency vite 6.0.0: GHSA-xcj6-pq6g-qj4x"}, "properties": {"repobilityId": "1fb99e93ead97de1", "scanner": "scanner-primary", "fingerprint": "dc7fd80b0529d9b5", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-xcj6-pq6g-qj4x", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-02beaef6201fc578", "level": "warning", "message": {"text": "Vulnerable dependency setuptools 82.0.1: GHSA-h35f-9h28-mq5c"}, "properties": {"repobilityId": "36330ba4f14508b6", "scanner": "scanner-primary", "fingerprint": "02beaef6201fc578", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-h35f-9h28-mq5c", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5e039c3fe7436cb8", "level": "note", "message": {"text": "Dependency @dagrejs/dagre is a major version behind"}, "properties": {"repobilityId": "d411f5a460199520", "scanner": "scanner-primary", "fingerprint": "5e039c3fe7436cb8", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ba689014da0e3a24", "level": "note", "message": {"text": "Dependency diff is a major version behind"}, "properties": {"repobilityId": "1c631226c966216f", "scanner": "scanner-primary", "fingerprint": "ba689014da0e3a24", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5cfa59782845124c", "level": "note", "message": {"text": "Dependency lucide-react is a major version behind"}, "properties": {"repobilityId": "b87d2c594b20378b", "scanner": "scanner-primary", "fingerprint": "5cfa59782845124c", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "strix/viewer/frontend/package.json"}, "region": {"startLine": 1}}}]}]}]}