{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-10685e04204f9020", "name": "Stray `console.log` in TS/JS \u2014 supabase/functions/generate-photo/index.ts:172", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/generate-photo/index.ts:172"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-48ba0b80425435ff", "name": "Stray `console.log` in TS/JS \u2014 supabase/functions/validate-code/index.ts:74", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/validate-code/index.ts:74"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-794d3ff19e5120bd", "name": "Stray `console.log` in TS/JS \u2014 supabase/functions/create-payment/index.ts:120", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/create-payment/index.ts:120"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fdb52899ed6a3c76", "name": "Stray `console.log` in TS/JS \u2014 supabase/functions/generate-one/index.ts:71", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/generate-one/index.ts:71"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fb900ef9683b7300", "name": "Stray `console.log` in TS/JS \u2014 supabase/functions/cleanup-orders/index.ts:44", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/cleanup-orders/index.ts:44"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c2fb84261f862d56", "name": "Stray `console.log` in TS/JS \u2014 supabase/functions/yookassa-webhook/index.ts:16", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/yookassa-webhook/index.ts:16"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7ecadca98cd5acd8", "name": "Stray `console.log` in TS/JS \u2014 supabase/functions/retry-generation/index.ts:162", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/retry-generation/index.ts:162"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ed7fb25ff0bde61b", "name": "Stray `console.log` in TS/JS \u2014 supabase/functions/check-order/index.ts:66", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/check-order/index.ts:66"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-abcc648360925060", "name": "Stray `console.log` in TS/JS \u2014 supabase/functions/auto-refund-order/index.ts:63", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/auto-refund-order/index.ts:63"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7faadbc60f0aad31", "name": "Stray `console.log` in TS/JS \u2014 server/index.ts:107", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 server/index.ts:107"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-001e8af1acc548dd", "name": "Stray `console.log` in TS/JS \u2014 server/routes/generation.ts:207", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 server/routes/generation.ts:207"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f355287afc1048a8", "name": "Stray `console.log` in TS/JS \u2014 server/routes/payment.ts:130", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 server/routes/payment.ts:130"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ae439af18d14b522", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/ReferralBlock.tsx:53", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/ReferralBlock.tsx:53"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0051bbd46061f50c", "name": "Icon-only button without accessible name \u2014 src/components/ProfileOverlay.tsx:39", "shortDescription": {"text": "Icon-only button without accessible name \u2014 src/components/ProfileOverlay.tsx:39"}, "fullDescription": {"text": "A `<button>` whose only child is a single glyph or symbol needs `title=` or `aria-label=` so screen readers (and tooltips on hover) work.\n\nWhy: P3 in CHECKLIST.md \u2014 icon-only buttons skipped a title.\nRule id: fq.button.no-label"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-33fd1514286a79f7", "name": "Stray `console.log` in TS/JS \u2014 src/components/screens/ResultsScreen.tsx:261", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/components/screens/ResultsScreen.tsx:261"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8680be5aeb67a939", "name": "Insecure pattern 'node_child_process' in scripts/smoke_test.mjs:15", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/smoke_test.mjs:15"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a2d1066bd3e296c9", "name": "Insecure pattern 'cors_wildcard' in supabase/functions/generate-photo/index.ts:6", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/generate-photo/index.ts:6"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-952e4c7a10f62caf", "name": "Insecure pattern 'cors_wildcard' in supabase/functions/pay-with-credits/index.ts:21", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/pay-with-credits/index.ts:21"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ec74ce9e33b2346e", "name": "Insecure pattern 'cors_wildcard' in supabase/functions/find-recent-order/index.ts:5", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/find-recent-order/index.ts:5"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-84657c25cc4a4eec", "name": "Insecure pattern 'cors_wildcard' in supabase/functions/create-payment/index.ts:6", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/create-payment/index.ts:6"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-62461dc692f00fbf", "name": "Insecure pattern 'cors_wildcard' in supabase/functions/generate-one/index.ts:5", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/generate-one/index.ts:5"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1de80831b5836074", "name": "Insecure pattern 'cors_wildcard' in supabase/functions/get-balance/index.ts:5", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/get-balance/index.ts:5"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-332df7f570dc71de", "name": "Insecure pattern 'cors_wildcard' in supabase/functions/cleanup-orders/index.ts:5", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/cleanup-orders/index.ts:5"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8b9fa4a4ee036a9a", "name": "Insecure pattern 'cors_wildcard' in supabase/functions/yookassa-webhook/index.ts:5", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/yookassa-webhook/index.ts:5"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b2c48bff5917a154", "name": "Insecure pattern 'cors_wildcard' in supabase/functions/retry-generation/index.ts:5", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/retry-generation/index.ts:5"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cef28752c722392a", "name": "Insecure pattern 'cors_wildcard' in supabase/functions/check-order/index.ts:6", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/check-order/index.ts:6"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f317682a7ebd1cd5", "name": "Insecure pattern 'cors_wildcard' in supabase/functions/auto-refund-order/index.ts:5", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/auto-refund-order/index.ts:5"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d6eaa089bb46c9f4", "name": "Very large file: server/services/prompts.ts (1879 lines)", "shortDescription": {"text": "Very large file: server/services/prompts.ts (1879 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "2 test file(s) for 62 source file(s) (ratio 0.03). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 135 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 12 placeholder/mock markers across 5 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license, ci. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bea357a6497a2d5d", "name": "Agent authority lacks a verifier contract: CLAUDE.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: CLAUDE.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-85f1414f7d154d1b", "name": "Commented-code block (5 lines) in supabase/functions/find-recent-order/index.ts:9", "shortDescription": {"text": "Commented-code block (5 lines) in supabase/functions/find-recent-order/index.ts:9"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d39f039f7e31a809", "name": "Commented-code block (5 lines) in supabase/functions/create-payment/index.ts:80", "shortDescription": {"text": "Commented-code block (5 lines) in supabase/functions/create-payment/index.ts:80"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3707daf2112caa24", "name": "`fetch()` without try/.catch or AbortSignal \u2014 supabase/functions/create-payment/index.ts:114", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 supabase/functions/create-payment/index.ts:114"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0b562ed361da2840", "name": "`fetch()` without try/.catch or AbortSignal \u2014 supabase/functions/cleanup-orders/index.ts:72", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 supabase/functions/cleanup-orders/index.ts:72"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c94bd0d1c38bd1a5", "name": "`fetch()` without try/.catch or AbortSignal \u2014 supabase/functions/check-order/index.ts:123", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 supabase/functions/check-order/index.ts:123"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-76a41db619a56003", "name": "Commented-code block (10 lines) in supabase/functions/auto-refund-order/index.ts:9", "shortDescription": {"text": "Commented-code block (10 lines) in supabase/functions/auto-refund-order/index.ts:9"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0d47da381366229d", "name": "`fetch()` without try/.catch or AbortSignal \u2014 supabase/functions/auto-refund-order/index.ts:220", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 supabase/functions/auto-refund-order/index.ts:220"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ee1feae688fd4db5", "name": "Commented-code block (6 lines) in server/featureFlags.ts:23", "shortDescription": {"text": "Commented-code block (6 lines) in server/featureFlags.ts:23"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3e51603ec5308b24", "name": "Commented-code block (5 lines) in server/routes/generation.ts:211", "shortDescription": {"text": "Commented-code block (5 lines) in server/routes/generation.ts:211"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a1e42fccb5480a55", "name": "Commented-code block (7 lines) in server/routes/payment.ts:350", "shortDescription": {"text": "Commented-code block (7 lines) in server/routes/payment.ts:350"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-973dabc1b8d241fe", "name": "Commented-code block (6 lines) in server/routes/order.ts:51", "shortDescription": {"text": "Commented-code block (6 lines) in server/routes/order.ts:51"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6a124a7a1fbb8716", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/services/replicate.ts:82", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/services/replicate.ts:82"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ec6681e98b31eca0", "name": "Commented-code block (7 lines) in server/services/pairPrompts.ts:3", "shortDescription": {"text": "Commented-code block (7 lines) in server/services/pairPrompts.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0f0b4fa7842e15e5", "name": "Commented-code block (5 lines) in server/services/prompts.ts:682", "shortDescription": {"text": "Commented-code block (5 lines) in server/services/prompts.ts:682"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cc989a747dfa74b3", "name": "Commented-code block (6 lines) in server/services/orderCredit.ts:7", "shortDescription": {"text": "Commented-code block (6 lines) in server/services/orderCredit.ts:7"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e6941f05c799501b", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/services/yookassa.ts:86", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/services/yookassa.ts:86"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-29305817b0651247", "name": "Commented-code block (5 lines) in server/services/openrouter.ts:51", "shortDescription": {"text": "Commented-code block (5 lines) in server/services/openrouter.ts:51"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c79b03a27eeb8b4c", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/services/openrouter.ts:120", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/services/openrouter.ts:120"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f501a6e1814e98f0", "name": "Commented-code block (9 lines) in server/services/referrals.ts:3", "shortDescription": {"text": "Commented-code block (9 lines) in server/services/referrals.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2c410d67495f6afc", "name": "Commented-code block (5 lines) in server/db/pool.ts:9", "shortDescription": {"text": "Commented-code block (5 lines) in server/db/pool.ts:9"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cd5ecba8e029fb1c", "name": "Commented-code block (5 lines) in src/App.tsx:133", "shortDescription": {"text": "Commented-code block (5 lines) in src/App.tsx:133"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5126c61537eb0dc4", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/components/screens/ResultsScreen.tsx:53", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/components/screens/ResultsScreen.tsx:53"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b4a216d20f38f390", "name": "Commented-code block (7 lines) in src/components/screens/StudioScreen.tsx:334", "shortDescription": {"text": "Commented-code block (7 lines) in src/components/screens/StudioScreen.tsx:334"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-252f199396cfcb08", "name": "Commented-code block (5 lines) in src/lib/constants.ts:182", "shortDescription": {"text": "Commented-code block (5 lines) in src/lib/constants.ts:182"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-697bcc654a18dc81", "name": "Commented-code block (5 lines) in src/services/referrals.ts:3", "shortDescription": {"text": "Commented-code block (5 lines) in src/services/referrals.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-35375b22a4a064ee", "name": "Commented-code block (5 lines) in src/services/styles.ts:9", "shortDescription": {"text": "Commented-code block (5 lines) in src/services/styles.ts:9"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cc0f9d8e41b33b0e", "name": "11 env vars used in code but missing from .env.example", "shortDescription": {"text": "11 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `CLUB_DISCOUNT_PERCENT`, `DAILY_GENERATION_LIMIT`, `DIAGNOSTIC_TOKEN`, `FREE_ARCHIVE_TTL_MINUTES`, `PHOTO_TEMP_DIR`, `PHOTO_TTL_MINUTES`, `REPLICATE_ADAPTER`, `REPLICATE_API_TOKEN` + 3 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7c290b8a4b9dc251", "name": "Dangling fetch: GET https://api.yookassa.ru/v3/payments/${existingPending.payment_id} (supabase/functions/create-payment", "shortDescription": {"text": "Dangling fetch: GET https://api.yookassa.ru/v3/payments/${existingPending.payment_id} (supabase/functions/create-payment/index.ts:114)"}, "fullDescription": {"text": "`supabase/functions/create-payment/index.ts:114` calls `GET https://api.yookassa.ru/v3/payments/${existingPending.payment_id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.yookassa.ru/v3/payments/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d13a240247596136", "name": "Dangling fetch: POST https://ai.gateway.lovable.dev/v1/chat/completions (supabase/functions/create-payment/index.ts:180)", "shortDescription": {"text": "Dangling fetch: POST https://ai.gateway.lovable.dev/v1/chat/completions (supabase/functions/create-payment/index.ts:180)"}, "fullDescription": {"text": "`supabase/functions/create-payment/index.ts:180` calls `POST https://ai.gateway.lovable.dev/v1/chat/completions` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/ai.gateway.lovable.dev/v1/chat/completions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d65aba03b2faa02f", "name": "Dangling fetch: POST https://api.yookassa.ru/v3/payments (supabase/functions/create-payment/index.ts:325)", "shortDescription": {"text": "Dangling fetch: POST https://api.yookassa.ru/v3/payments (supabase/functions/create-payment/index.ts:325)"}, "fullDescription": {"text": "`supabase/functions/create-payment/index.ts:325` calls `POST https://api.yookassa.ru/v3/payments` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.yookassa.ru/v3/payments`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ed86e1c29111279b", "name": "Dangling fetch: POST https://ai.gateway.lovable.dev/v1/chat/completions (supabase/functions/retry-generation/index.ts:41", "shortDescription": {"text": "Dangling fetch: POST https://ai.gateway.lovable.dev/v1/chat/completions (supabase/functions/retry-generation/index.ts:41)"}, "fullDescription": {"text": "`supabase/functions/retry-generation/index.ts:41` calls `POST https://ai.gateway.lovable.dev/v1/chat/completions` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/ai.gateway.lovable.dev/v1/chat/completions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fe8cec095f7af836", "name": "Dangling fetch: GET https://api.yookassa.ru/v3/payments/${order.payment_id} (supabase/functions/check-order/index.ts:108", "shortDescription": {"text": "Dangling fetch: GET https://api.yookassa.ru/v3/payments/${order.payment_id} (supabase/functions/check-order/index.ts:108)"}, "fullDescription": {"text": "`supabase/functions/check-order/index.ts:108` calls `GET https://api.yookassa.ru/v3/payments/${order.payment_id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.yookassa.ru/v3/payments/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-22fd48c2225b8c79", "name": "Dangling fetch: POST https://api.yookassa.ru/v3/refunds (supabase/functions/auto-refund-order/index.ts:220)", "shortDescription": {"text": "Dangling fetch: POST https://api.yookassa.ru/v3/refunds (supabase/functions/auto-refund-order/index.ts:220)"}, "fullDescription": {"text": "`supabase/functions/auto-refund-order/index.ts:220` calls `POST https://api.yookassa.ru/v3/refunds` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.yookassa.ru/v3/refunds`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-82090de52c734935", "name": "Dangling fetch: POST /api/payment/create (src/services/api.ts:77)", "shortDescription": {"text": "Dangling fetch: POST /api/payment/create (src/services/api.ts:77)"}, "fullDescription": {"text": "`src/services/api.ts:77` calls `POST /api/payment/create` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/payment/create`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-de6d5a6842f6b908", "name": "Dangling fetch: GET /api/order/check?order_id=${encodeURIComponent(orderId)} (src/services/api.ts:100)", "shortDescription": {"text": "Dangling fetch: GET /api/order/check?order_id=${encodeURIComponent(orderId)} (src/services/api.ts:100)"}, "fullDescription": {"text": "`src/services/api.ts:100` calls `GET /api/order/check?order_id=${encodeURIComponent(orderId)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/order/check`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ee53bade285ff2b7", "name": "Dangling fetch: GET /api/order/find-recent?customer_key=${encodeURIComponent(customerKey)} (src/services/api.ts:121)", "shortDescription": {"text": "Dangling fetch: GET /api/order/find-recent?customer_key=${encodeURIComponent(customerKey)} (src/services/api.ts:121)"}, "fullDescription": {"text": "`src/services/api.ts:121` calls `GET /api/order/find-recent?customer_key=${encodeURIComponent(customerKey)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/order/find-recent`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dbf49e834ebba39a", "name": "Dangling fetch: GET /api/balance?customer_key=${encodeURIComponent(customerKey)} (src/services/api.ts:131)", "shortDescription": {"text": "Dangling fetch: GET /api/balance?customer_key=${encodeURIComponent(customerKey)} (src/services/api.ts:131)"}, "fullDescription": {"text": "`src/services/api.ts:131` calls `GET /api/balance?customer_key=${encodeURIComponent(customerKey)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/balance`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ae8d24ce7ad7fdb9", "name": "Dangling fetch: POST /api/generation/single (src/services/api.ts:187)", "shortDescription": {"text": "Dangling fetch: POST /api/generation/single (src/services/api.ts:187)"}, "fullDescription": {"text": "`src/services/api.ts:187` calls `POST /api/generation/single` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/generation/single`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-68aac0653b26e1b7", "name": "Dangling fetch: POST /api/generation/pair (src/services/api.ts:213)", "shortDescription": {"text": "Dangling fetch: POST /api/generation/pair (src/services/api.ts:213)"}, "fullDescription": {"text": "`src/services/api.ts:213` calls `POST /api/generation/pair` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/generation/pair`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4756b4c4da7d2088", "name": "Unused endpoint: GET /api/health", "shortDescription": {"text": "Unused endpoint: GET /api/health"}, "fullDescription": {"text": "`server/index.ts` declares `GET /api/health` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7aa4b2518cbbbfa2", "name": "Unused endpoint: GET /api/config", "shortDescription": {"text": "Unused endpoint: GET /api/config"}, "fullDescription": {"text": "`server/index.ts` declares `GET /api/config` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aafda6d33fa25f40", "name": "Unused endpoint: USE /api/payment/create", "shortDescription": {"text": "Unused endpoint: USE /api/payment/create"}, "fullDescription": {"text": "`server/index.ts` declares `USE /api/payment/create` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-79247397c9d05e77", "name": "Unused endpoint: USE /api/payment", "shortDescription": {"text": "Unused endpoint: USE /api/payment"}, "fullDescription": {"text": "`server/index.ts` declares `USE /api/payment` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b74acf3521abf598", "name": "Unused endpoint: USE /api/balance", "shortDescription": {"text": "Unused endpoint: USE /api/balance"}, "fullDescription": {"text": "`server/index.ts` declares `USE /api/balance` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-477eee27476efd83", "name": "Unused endpoint: USE /api/order", "shortDescription": {"text": "Unused endpoint: USE /api/order"}, "fullDescription": {"text": "`server/index.ts` declares `USE /api/order` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-00d2f0293753841f", "name": "Unused endpoint: USE /api/credits", "shortDescription": {"text": "Unused endpoint: USE /api/credits"}, "fullDescription": {"text": "`server/index.ts` declares `USE /api/credits` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6a3460d428c799fa", "name": "Unused endpoint: USE /api/photos", "shortDescription": {"text": "Unused endpoint: USE /api/photos"}, "fullDescription": {"text": "`server/index.ts` declares `USE /api/photos` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1ff52e40b771206a", "name": "Unused endpoint: USE /api/generation", "shortDescription": {"text": "Unused endpoint: USE /api/generation"}, "fullDescription": {"text": "`server/index.ts` declares `USE /api/generation` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b486ac2e740761dd", "name": "Unused endpoint: USE /api/styles", "shortDescription": {"text": "Unused endpoint: USE /api/styles"}, "fullDescription": {"text": "`server/index.ts` declares `USE /api/styles` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-30873d2a5b3f5f7f", "name": "Unused endpoint: USE /api/referrals", "shortDescription": {"text": "Unused endpoint: USE /api/referrals"}, "fullDescription": {"text": "`server/index.ts` declares `USE /api/referrals` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ce02a65ce2ebdf43", "name": "Unused endpoint: POST /debit", "shortDescription": {"text": "Unused endpoint: POST /debit"}, "fullDescription": {"text": "`server/routes/credits.ts` declares `POST /debit` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`server/routes/balance.ts` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-caaf263bf1b5febe", "name": "Unused endpoint: POST /single", "shortDescription": {"text": "Unused endpoint: POST /single"}, "fullDescription": {"text": "`server/routes/generation.ts` declares `POST /single` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e343c1fa58c93a21", "name": "Unused endpoint: POST /pair", "shortDescription": {"text": "Unused endpoint: POST /pair"}, "fullDescription": {"text": "`server/routes/generation.ts` declares `POST /pair` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3115613eb674a56a", "name": "Unused endpoint: GET /diagnostic", "shortDescription": {"text": "Unused endpoint: GET /diagnostic"}, "fullDescription": {"text": "`server/routes/payment.ts` declares `GET /diagnostic` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-599114e2a4d7d26d", "name": "Unused endpoint: POST /create", "shortDescription": {"text": "Unused endpoint: POST /create"}, "fullDescription": {"text": "`server/routes/payment.ts` declares `POST /create` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6236b283b79811b8", "name": "Unused endpoint: POST /upload", "shortDescription": {"text": "Unused endpoint: POST /upload"}, "fullDescription": {"text": "`server/routes/photos.ts` declares `POST /upload` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b707af78bb95724c", "name": "Unused endpoint: GET /:filename", "shortDescription": {"text": "Unused endpoint: GET /:filename"}, "fullDescription": {"text": "`server/routes/photos.ts` declares `GET /:filename` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3f452b0ac7643615", "name": "Unused endpoint: GET /download/:filename", "shortDescription": {"text": "Unused endpoint: GET /download/:filename"}, "fullDescription": {"text": "`server/routes/photos.ts` declares `GET /download/:filename` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd1dc91abf32142d", "name": "Unused endpoint: GET /me", "shortDescription": {"text": "Unused endpoint: GET /me"}, "fullDescription": {"text": "`server/routes/referrals.ts` declares `GET /me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4f5d79195606d3fb", "name": "Unused endpoint: POST /track", "shortDescription": {"text": "Unused endpoint: POST /track"}, "fullDescription": {"text": "`server/routes/referrals.ts` declares `POST /track` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e5f899fff8e655a2", "name": "Unused endpoint: GET /check", "shortDescription": {"text": "Unused endpoint: GET /check"}, "fullDescription": {"text": "`server/routes/order.ts` declares `GET /check` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e03f080c6c0c08c8", "name": "Unused endpoint: GET /find-recent", "shortDescription": {"text": "Unused endpoint: GET /find-recent"}, "fullDescription": {"text": "`server/routes/order.ts` declares `GET /find-recent` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/22445"}, "properties": {"repository": "vsarypova071-glitch/Photo-Transformation-Studio", "repoUrl": "https://github.com/vsarypova071-glitch/Photo-Transformation-Studio", "branch": "main"}, "results": [{"ruleId": "scanner-10685e04204f9020", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/generate-photo/index.ts:172"}, "properties": {"repobilityId": "d7ab45f7eb855823", "scanner": "scanner-primary", "fingerprint": "10685e04204f9020", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-48ba0b80425435ff", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/validate-code/index.ts:74"}, "properties": {"repobilityId": "712cb991d981a43e", "scanner": "scanner-primary", "fingerprint": "48ba0b80425435ff", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-794d3ff19e5120bd", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/create-payment/index.ts:120"}, "properties": {"repobilityId": "b055cc7fb8f67cb0", "scanner": "scanner-primary", "fingerprint": "794d3ff19e5120bd", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-fdb52899ed6a3c76", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/generate-one/index.ts:71"}, "properties": {"repobilityId": "59e3a2b0f692401b", "scanner": "scanner-primary", "fingerprint": "fdb52899ed6a3c76", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-fb900ef9683b7300", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/cleanup-orders/index.ts:44"}, "properties": {"repobilityId": "3ef438d8fb57fe80", "scanner": "scanner-primary", "fingerprint": "fb900ef9683b7300", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c2fb84261f862d56", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/yookassa-webhook/index.ts:16"}, "properties": {"repobilityId": "373c80653db66cac", "scanner": "scanner-primary", "fingerprint": "c2fb84261f862d56", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7ecadca98cd5acd8", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/retry-generation/index.ts:162"}, "properties": {"repobilityId": "609936ca1c977851", "scanner": "scanner-primary", "fingerprint": "7ecadca98cd5acd8", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ed7fb25ff0bde61b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/check-order/index.ts:66"}, "properties": {"repobilityId": "4ec1cfae1434b558", "scanner": "scanner-primary", "fingerprint": "ed7fb25ff0bde61b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-abcc648360925060", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/auto-refund-order/index.ts:63"}, "properties": {"repobilityId": "820442b0540dedb2", "scanner": "scanner-primary", "fingerprint": "abcc648360925060", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7faadbc60f0aad31", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 server/index.ts:107"}, "properties": {"repobilityId": "b4961a877930fd2f", "scanner": "scanner-primary", "fingerprint": "7faadbc60f0aad31", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-001e8af1acc548dd", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 server/routes/generation.ts:207"}, "properties": {"repobilityId": "8929281e6ea40d0c", "scanner": "scanner-primary", "fingerprint": "001e8af1acc548dd", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f355287afc1048a8", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 server/routes/payment.ts:130"}, "properties": {"repobilityId": "d5dd6d2a96ab9289", "scanner": "scanner-primary", "fingerprint": "f355287afc1048a8", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ae439af18d14b522", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/ReferralBlock.tsx:53"}, "properties": {"repobilityId": "edec586c79cf9f76", "scanner": "scanner-primary", "fingerprint": "ae439af18d14b522", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-0051bbd46061f50c", "level": "note", "message": {"text": "Icon-only button without accessible name \u2014 src/components/ProfileOverlay.tsx:39"}, "properties": {"repobilityId": "86bdd216d2eca472", "scanner": "scanner-primary", "fingerprint": "0051bbd46061f50c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.button.no-label"]}}, {"ruleId": "scanner-33fd1514286a79f7", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/components/screens/ResultsScreen.tsx:261"}, "properties": {"repobilityId": "9f7dd68bcf6ffdeb", "scanner": "scanner-primary", "fingerprint": "33fd1514286a79f7", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8680be5aeb67a939", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/smoke_test.mjs:15"}, "properties": {"repobilityId": "b3b0fc3cebe73720", "scanner": "scanner-primary", "fingerprint": "8680be5aeb67a939", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/smoke_test.mjs"}, "region": {"startLine": 15}}}]}, {"ruleId": "scanner-a2d1066bd3e296c9", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/generate-photo/index.ts:6"}, "properties": {"repobilityId": "2efa80e81b3fbcd4", "scanner": "scanner-primary", "fingerprint": "a2d1066bd3e296c9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "supabase/functions/generate-photo/index.ts"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-952e4c7a10f62caf", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/pay-with-credits/index.ts:21"}, "properties": {"repobilityId": "082828f663deba81", "scanner": "scanner-primary", "fingerprint": "952e4c7a10f62caf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "supabase/functions/pay-with-credits/index.ts"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-ec74ce9e33b2346e", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/find-recent-order/index.ts:5"}, "properties": {"repobilityId": "f2e9b7d22d4ff8ec", "scanner": "scanner-primary", "fingerprint": "ec74ce9e33b2346e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "supabase/functions/find-recent-order/index.ts"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-84657c25cc4a4eec", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/create-payment/index.ts:6"}, "properties": {"repobilityId": "68918927164bc93e", "scanner": "scanner-primary", "fingerprint": "84657c25cc4a4eec", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "supabase/functions/create-payment/index.ts"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-62461dc692f00fbf", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/generate-one/index.ts:5"}, "properties": {"repobilityId": "53decee400b1b967", "scanner": "scanner-primary", "fingerprint": "62461dc692f00fbf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "supabase/functions/generate-one/index.ts"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-1de80831b5836074", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/get-balance/index.ts:5"}, "properties": {"repobilityId": "1af4bfc89aee6f9c", "scanner": "scanner-primary", "fingerprint": "1de80831b5836074", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "supabase/functions/get-balance/index.ts"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-332df7f570dc71de", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/cleanup-orders/index.ts:5"}, "properties": {"repobilityId": "93f89102abb3012c", "scanner": "scanner-primary", "fingerprint": "332df7f570dc71de", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "supabase/functions/cleanup-orders/index.ts"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-8b9fa4a4ee036a9a", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/yookassa-webhook/index.ts:5"}, "properties": {"repobilityId": "02a5d3b63aff37d6", "scanner": "scanner-primary", "fingerprint": "8b9fa4a4ee036a9a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "supabase/functions/yookassa-webhook/index.ts"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-b2c48bff5917a154", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/retry-generation/index.ts:5"}, "properties": {"repobilityId": "edbafe8f9fa90b5a", "scanner": "scanner-primary", "fingerprint": "b2c48bff5917a154", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "supabase/functions/retry-generation/index.ts"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-cef28752c722392a", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/check-order/index.ts:6"}, "properties": {"repobilityId": "df2dad4c0b2eea84", "scanner": "scanner-primary", "fingerprint": "cef28752c722392a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "supabase/functions/check-order/index.ts"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-f317682a7ebd1cd5", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/auto-refund-order/index.ts:5"}, "properties": {"repobilityId": "9b36e356a7753aa6", "scanner": "scanner-primary", "fingerprint": "f317682a7ebd1cd5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "supabase/functions/auto-refund-order/index.ts"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-d6eaa089bb46c9f4", "level": "note", "message": {"text": "Very large file: server/services/prompts.ts (1879 lines)"}, "properties": {"repobilityId": "98a80039c5770b3a", "scanner": "scanner-primary", "fingerprint": "d6eaa089bb46c9f4", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "e46c9169188a4c9a", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "0322d39347f43b16", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "722d044044986ef7", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "15a9bf5c4361c211", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "87ffbe6fe972b4f4", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "016df5de478dc1dc", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "49911e42ca721173", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "2ba633fe52fb7299", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-bea357a6497a2d5d", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: CLAUDE.md"}, "properties": {"repobilityId": "aae72df3934829ac", "scanner": "scanner-primary", "fingerprint": "bea357a6497a2d5d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "CLAUDE.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-85f1414f7d154d1b", "level": "none", "message": {"text": "Commented-code block (5 lines) in supabase/functions/find-recent-order/index.ts:9"}, "properties": {"repobilityId": "90d4b81d114d96f9", "scanner": "scanner-primary", "fingerprint": "85f1414f7d154d1b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d39f039f7e31a809", "level": "none", "message": {"text": "Commented-code block (5 lines) in supabase/functions/create-payment/index.ts:80"}, "properties": {"repobilityId": "7c8a7c9d6b919277", "scanner": "scanner-primary", "fingerprint": "d39f039f7e31a809", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3707daf2112caa24", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 supabase/functions/create-payment/index.ts:114"}, "properties": {"repobilityId": "d0947cf16c168a1c", "scanner": "scanner-primary", "fingerprint": "3707daf2112caa24", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-0b562ed361da2840", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 supabase/functions/cleanup-orders/index.ts:72"}, "properties": {"repobilityId": "1cbc9df56a67a683", "scanner": "scanner-primary", "fingerprint": "0b562ed361da2840", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-c94bd0d1c38bd1a5", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 supabase/functions/check-order/index.ts:123"}, "properties": {"repobilityId": "2937656442cdd360", "scanner": "scanner-primary", "fingerprint": "c94bd0d1c38bd1a5", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-76a41db619a56003", "level": "none", "message": {"text": "Commented-code block (10 lines) in supabase/functions/auto-refund-order/index.ts:9"}, "properties": {"repobilityId": "33f99e4343a12f48", "scanner": "scanner-primary", "fingerprint": "76a41db619a56003", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0d47da381366229d", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 supabase/functions/auto-refund-order/index.ts:220"}, "properties": {"repobilityId": "b5bee0f3969e9ca7", "scanner": "scanner-primary", "fingerprint": "0d47da381366229d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-ee1feae688fd4db5", "level": "none", "message": {"text": "Commented-code block (6 lines) in server/featureFlags.ts:23"}, "properties": {"repobilityId": "decd8cf22598a36f", "scanner": "scanner-primary", "fingerprint": "ee1feae688fd4db5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3e51603ec5308b24", "level": "none", "message": {"text": "Commented-code block (5 lines) in server/routes/generation.ts:211"}, "properties": {"repobilityId": "5660d1fafc1427da", "scanner": "scanner-primary", "fingerprint": "3e51603ec5308b24", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a1e42fccb5480a55", "level": "none", "message": {"text": "Commented-code block (7 lines) in server/routes/payment.ts:350"}, "properties": {"repobilityId": "dbeaec375ec89570", "scanner": "scanner-primary", "fingerprint": "a1e42fccb5480a55", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-973dabc1b8d241fe", "level": "none", "message": {"text": "Commented-code block (6 lines) in server/routes/order.ts:51"}, "properties": {"repobilityId": "545fb9097bc65140", "scanner": "scanner-primary", "fingerprint": "973dabc1b8d241fe", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6a124a7a1fbb8716", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/services/replicate.ts:82"}, "properties": {"repobilityId": "67b57db6c70d6b4f", "scanner": "scanner-primary", "fingerprint": "6a124a7a1fbb8716", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-ec6681e98b31eca0", "level": "none", "message": {"text": "Commented-code block (7 lines) in server/services/pairPrompts.ts:3"}, "properties": {"repobilityId": "3550f0d2909f5e1e", "scanner": "scanner-primary", "fingerprint": "ec6681e98b31eca0", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0f0b4fa7842e15e5", "level": "none", "message": {"text": "Commented-code block (5 lines) in server/services/prompts.ts:682"}, "properties": {"repobilityId": "5082b80dd78b8df7", "scanner": "scanner-primary", "fingerprint": "0f0b4fa7842e15e5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-cc989a747dfa74b3", "level": "none", "message": {"text": "Commented-code block (6 lines) in server/services/orderCredit.ts:7"}, "properties": {"repobilityId": "0f13be2583849912", "scanner": "scanner-primary", "fingerprint": "cc989a747dfa74b3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e6941f05c799501b", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/services/yookassa.ts:86"}, "properties": {"repobilityId": "bda19bbc8310e0c2", "scanner": "scanner-primary", "fingerprint": "e6941f05c799501b", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-29305817b0651247", "level": "none", "message": {"text": "Commented-code block (5 lines) in server/services/openrouter.ts:51"}, "properties": {"repobilityId": "6196968fb79852ff", "scanner": "scanner-primary", "fingerprint": "29305817b0651247", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c79b03a27eeb8b4c", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/services/openrouter.ts:120"}, "properties": {"repobilityId": "e237f504e39a0f8a", "scanner": "scanner-primary", "fingerprint": "c79b03a27eeb8b4c", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-f501a6e1814e98f0", "level": "none", "message": {"text": "Commented-code block (9 lines) in server/services/referrals.ts:3"}, "properties": {"repobilityId": "1093bd826bcaad83", "scanner": "scanner-primary", "fingerprint": "f501a6e1814e98f0", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2c410d67495f6afc", "level": "none", "message": {"text": "Commented-code block (5 lines) in server/db/pool.ts:9"}, "properties": {"repobilityId": "df628f2b1846e538", "scanner": "scanner-primary", "fingerprint": "2c410d67495f6afc", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-cd5ecba8e029fb1c", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/App.tsx:133"}, "properties": {"repobilityId": "d4389f8a1f56b507", "scanner": "scanner-primary", "fingerprint": "cd5ecba8e029fb1c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5126c61537eb0dc4", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/components/screens/ResultsScreen.tsx:53"}, "properties": {"repobilityId": "db5863c66052756b", "scanner": "scanner-primary", "fingerprint": "5126c61537eb0dc4", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-b4a216d20f38f390", "level": "none", "message": {"text": "Commented-code block (7 lines) in src/components/screens/StudioScreen.tsx:334"}, "properties": {"repobilityId": "d631fe7bf61ce9fc", "scanner": "scanner-primary", "fingerprint": "b4a216d20f38f390", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-252f199396cfcb08", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/lib/constants.ts:182"}, "properties": {"repobilityId": "7841dda593e9bd82", "scanner": "scanner-primary", "fingerprint": "252f199396cfcb08", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-697bcc654a18dc81", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/services/referrals.ts:3"}, "properties": {"repobilityId": "529c1b504baf6f3b", "scanner": "scanner-primary", "fingerprint": "697bcc654a18dc81", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-35375b22a4a064ee", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/services/styles.ts:9"}, "properties": {"repobilityId": "c5aeda9f97fd5c61", "scanner": "scanner-primary", "fingerprint": "35375b22a4a064ee", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-cc0f9d8e41b33b0e", "level": "note", "message": {"text": "11 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "c82cd8cd626c3599", "scanner": "scanner-primary", "fingerprint": "cc0f9d8e41b33b0e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-7c290b8a4b9dc251", "level": "error", "message": {"text": "Dangling fetch: GET https://api.yookassa.ru/v3/payments/${existingPending.payment_id} (supabase/functions/create-payment/index.ts:114)"}, "properties": {"repobilityId": "8e075c907ff609b2", "scanner": "scanner-primary", "fingerprint": "7c290b8a4b9dc251", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-d13a240247596136", "level": "error", "message": {"text": "Dangling fetch: POST https://ai.gateway.lovable.dev/v1/chat/completions (supabase/functions/create-payment/index.ts:180)"}, "properties": {"repobilityId": "69e0742d86630293", "scanner": "scanner-primary", "fingerprint": "d13a240247596136", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-d65aba03b2faa02f", "level": "error", "message": {"text": "Dangling fetch: POST https://api.yookassa.ru/v3/payments (supabase/functions/create-payment/index.ts:325)"}, "properties": {"repobilityId": "6d5a82eacafb9e29", "scanner": "scanner-primary", "fingerprint": "d65aba03b2faa02f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-ed86e1c29111279b", "level": "error", "message": {"text": "Dangling fetch: POST https://ai.gateway.lovable.dev/v1/chat/completions (supabase/functions/retry-generation/index.ts:41)"}, "properties": {"repobilityId": "10e9b11f338b571e", "scanner": "scanner-primary", "fingerprint": "ed86e1c29111279b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-fe8cec095f7af836", "level": "error", "message": {"text": "Dangling fetch: GET https://api.yookassa.ru/v3/payments/${order.payment_id} (supabase/functions/check-order/index.ts:108)"}, "properties": {"repobilityId": "810c23fb28bb6ba9", "scanner": "scanner-primary", "fingerprint": "fe8cec095f7af836", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-22fd48c2225b8c79", "level": "error", "message": {"text": "Dangling fetch: POST https://api.yookassa.ru/v3/refunds (supabase/functions/auto-refund-order/index.ts:220)"}, "properties": {"repobilityId": "024c5be22b188e6c", "scanner": "scanner-primary", "fingerprint": "22fd48c2225b8c79", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-82090de52c734935", "level": "error", "message": {"text": "Dangling fetch: POST /api/payment/create (src/services/api.ts:77)"}, "properties": {"repobilityId": "e91424ae4c0f2587", "scanner": "scanner-primary", "fingerprint": "82090de52c734935", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-de6d5a6842f6b908", "level": "error", "message": {"text": "Dangling fetch: GET /api/order/check?order_id=${encodeURIComponent(orderId)} (src/services/api.ts:100)"}, "properties": {"repobilityId": "f88a6bfda287ed9b", "scanner": "scanner-primary", "fingerprint": "de6d5a6842f6b908", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-ee53bade285ff2b7", "level": "error", "message": {"text": "Dangling fetch: GET /api/order/find-recent?customer_key=${encodeURIComponent(customerKey)} (src/services/api.ts:121)"}, "properties": {"repobilityId": "e6e72bf72c887b56", "scanner": "scanner-primary", "fingerprint": "ee53bade285ff2b7", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-dbf49e834ebba39a", "level": "error", "message": {"text": "Dangling fetch: GET /api/balance?customer_key=${encodeURIComponent(customerKey)} (src/services/api.ts:131)"}, "properties": {"repobilityId": "3474691e7ef80105", "scanner": "scanner-primary", "fingerprint": "dbf49e834ebba39a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-ae8d24ce7ad7fdb9", "level": "error", "message": {"text": "Dangling fetch: POST /api/generation/single (src/services/api.ts:187)"}, "properties": {"repobilityId": "2a2b41e4f45231dd", "scanner": "scanner-primary", "fingerprint": "ae8d24ce7ad7fdb9", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-68aac0653b26e1b7", "level": "error", "message": {"text": "Dangling fetch: POST /api/generation/pair (src/services/api.ts:213)"}, "properties": {"repobilityId": "0851bdddfc5193ef", "scanner": "scanner-primary", "fingerprint": "68aac0653b26e1b7", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-4756b4c4da7d2088", "level": "note", "message": {"text": "Unused endpoint: GET /api/health"}, "properties": {"repobilityId": "779ee59986e3e7ae", "scanner": "scanner-primary", "fingerprint": "4756b4c4da7d2088", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7aa4b2518cbbbfa2", "level": "note", "message": {"text": "Unused endpoint: GET /api/config"}, "properties": {"repobilityId": "91120b4ac1906ae2", "scanner": "scanner-primary", "fingerprint": "7aa4b2518cbbbfa2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-aafda6d33fa25f40", "level": "note", "message": {"text": "Unused endpoint: USE /api/payment/create"}, "properties": {"repobilityId": "0e2a229fdc87c880", "scanner": "scanner-primary", "fingerprint": "aafda6d33fa25f40", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-79247397c9d05e77", "level": "note", "message": {"text": "Unused endpoint: USE /api/payment"}, "properties": {"repobilityId": "d3aeadafd72265de", "scanner": "scanner-primary", "fingerprint": "79247397c9d05e77", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b74acf3521abf598", "level": "note", "message": {"text": "Unused endpoint: USE /api/balance"}, "properties": {"repobilityId": "187ddb192cd54f1c", "scanner": "scanner-primary", "fingerprint": "b74acf3521abf598", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-477eee27476efd83", "level": "note", "message": {"text": "Unused endpoint: USE /api/order"}, "properties": {"repobilityId": "e63ccc23e8616e31", "scanner": "scanner-primary", "fingerprint": "477eee27476efd83", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-00d2f0293753841f", "level": "note", "message": {"text": "Unused endpoint: USE /api/credits"}, "properties": {"repobilityId": "1fd5040833158761", "scanner": "scanner-primary", "fingerprint": "00d2f0293753841f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6a3460d428c799fa", "level": "note", "message": {"text": "Unused endpoint: USE /api/photos"}, "properties": {"repobilityId": "8db9c3292358c9d7", "scanner": "scanner-primary", "fingerprint": "6a3460d428c799fa", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1ff52e40b771206a", "level": "note", "message": {"text": "Unused endpoint: USE /api/generation"}, "properties": {"repobilityId": "a5967d3d9896cd5d", "scanner": "scanner-primary", "fingerprint": "1ff52e40b771206a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b486ac2e740761dd", "level": "note", "message": {"text": "Unused endpoint: USE /api/styles"}, "properties": {"repobilityId": "42efa4d55d15c68a", "scanner": "scanner-primary", "fingerprint": "b486ac2e740761dd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-30873d2a5b3f5f7f", "level": "note", "message": {"text": "Unused endpoint: USE /api/referrals"}, "properties": {"repobilityId": "8d4c18d41fa83f16", "scanner": "scanner-primary", "fingerprint": "30873d2a5b3f5f7f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ce02a65ce2ebdf43", "level": "note", "message": {"text": "Unused endpoint: POST /debit"}, "properties": {"repobilityId": "54a0ecb9e548ae11", "scanner": "scanner-primary", "fingerprint": "ce02a65ce2ebdf43", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "4b40f79bd421426c", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-caaf263bf1b5febe", "level": "note", "message": {"text": "Unused endpoint: POST /single"}, "properties": {"repobilityId": "8edea0701ada4a29", "scanner": "scanner-primary", "fingerprint": "caaf263bf1b5febe", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e343c1fa58c93a21", "level": "note", "message": {"text": "Unused endpoint: POST /pair"}, "properties": {"repobilityId": "dc9c32799956bfd2", "scanner": "scanner-primary", "fingerprint": "e343c1fa58c93a21", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3115613eb674a56a", "level": "note", "message": {"text": "Unused endpoint: GET /diagnostic"}, "properties": {"repobilityId": "47cfcf438029e90d", "scanner": "scanner-primary", "fingerprint": "3115613eb674a56a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-599114e2a4d7d26d", "level": "note", "message": {"text": "Unused endpoint: POST /create"}, "properties": {"repobilityId": "7bcff1a4fc1777d6", "scanner": "scanner-primary", "fingerprint": "599114e2a4d7d26d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6236b283b79811b8", "level": "note", "message": {"text": "Unused endpoint: POST /upload"}, "properties": {"repobilityId": "4d30175d64b7804c", "scanner": "scanner-primary", "fingerprint": "6236b283b79811b8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b707af78bb95724c", "level": "note", "message": {"text": "Unused endpoint: GET /:filename"}, "properties": {"repobilityId": "ee084ee1d77d31ed", "scanner": "scanner-primary", "fingerprint": "b707af78bb95724c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3f452b0ac7643615", "level": "note", "message": {"text": "Unused endpoint: GET /download/:filename"}, "properties": {"repobilityId": "619ed8fdb6f1d440", "scanner": "scanner-primary", "fingerprint": "3f452b0ac7643615", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd1dc91abf32142d", "level": "note", "message": {"text": "Unused endpoint: GET /me"}, "properties": {"repobilityId": "5c645ce0309ea02c", "scanner": "scanner-primary", "fingerprint": "fd1dc91abf32142d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4f5d79195606d3fb", "level": "note", "message": {"text": "Unused endpoint: POST /track"}, "properties": {"repobilityId": "a3af326864862f06", "scanner": "scanner-primary", "fingerprint": "4f5d79195606d3fb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e5f899fff8e655a2", "level": "note", "message": {"text": "Unused endpoint: GET /check"}, "properties": {"repobilityId": "5bca5af7333d439e", "scanner": "scanner-primary", "fingerprint": "e5f899fff8e655a2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e03f080c6c0c08c8", "level": "note", "message": {"text": "Unused endpoint: GET /find-recent"}, "properties": {"repobilityId": "a564f8813962a51e", "scanner": "scanner-primary", "fingerprint": "e03f080c6c0c08c8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}