{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-7b2f5cdf0b8faa0b", "name": "Possibly dead Python function: recognize", "shortDescription": {"text": "Possibly dead Python function: recognize"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-190cb7043f3f06a5", "name": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/pages/SuperadminSiteler.jsx:249", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/pages/SuperadminSiteler.jsx:249"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b8b1d77d2f222ccb", "name": "Stray `console.log` in TS/JS \u2014 database/seeds/02_bootstrap_superadmin.js:18", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 database/seeds/02_bootstrap_superadmin.js:18"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5281f01482f57d85", "name": "Stray `console.log` in TS/JS \u2014 database/seeds/02_dev_sample.js:5", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 database/seeds/02_dev_sample.js:5"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c970d51d9df7ea94", "name": "Stray `console.log` in TS/JS \u2014 database/seeds/01_bootstrap_admin.js:14", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 database/seeds/01_bootstrap_admin.js:14"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d59bb1c8675e5abb", "name": "Stray `console.log` in TS/JS \u2014 backend/globalSetup.js:8", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/globalSetup.js:8"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4f9419e4a1b7f900", "name": "Stray `console.log` in TS/JS \u2014 backend/src/server.js:121", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/server.js:121"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b6895d40970705b6", "name": "Stray `console.log` in TS/JS \u2014 backend/src/sentry.js:6", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/sentry.js:6"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e4100ef0dcf82228", "name": "Stray `console.log` in TS/JS \u2014 backend/src/jobs/bildirimRetry.js:9", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/jobs/bildirimRetry.js:9"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d7a84e7e7a63350e", "name": "Stray `console.log` in TS/JS \u2014 backend/src/jobs/emailRaporu.js:319", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/jobs/emailRaporu.js:319"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3f05424c7140d049", "name": "Stray `console.log` in TS/JS \u2014 backend/src/jobs/subscriptionLifecycle.js:145", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/jobs/subscriptionLifecycle.js:145"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0af0ae5e236cafd2", "name": "Stray `console.log` in TS/JS \u2014 backend/src/jobs/ocrSaglik.js:29", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/jobs/ocrSaglik.js:29"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa08d8701000aa44", "name": "Stray `console.log` in TS/JS \u2014 backend/src/jobs/dataRetention.js:67", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/jobs/dataRetention.js:67"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ccfaaa77998eb6e4", "name": "Stray `console.log` in TS/JS \u2014 backend/src/jobs/fotoTemizle.js:41", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/jobs/fotoTemizle.js:41"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cf5fe785694e9b63", "name": "Stray `console.log` in TS/JS \u2014 backend/src/jobs/parasutSync.js:49", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/jobs/parasutSync.js:49"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8998f893ee581d9e", "name": "Stray `console.log` in TS/JS \u2014 backend/src/jobs/zehirliOgrenmeTemizle.js:62", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/jobs/zehirliOgrenmeTemizle.js:62"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a919fd0553b1fd22", "name": "Privileged port 465 in use", "shortDescription": {"text": "Privileged port 465 in use"}, "fullDescription": {"text": "Port 465 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d63da3583b14afc0", "name": "Dockerfile runs as root: Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8987d6d1c30c7202", "name": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-44c97952c1791b8a", "name": "Dockerfile runs as root: backend/python_ocr/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: backend/python_ocr/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-30c14430eb696327", "name": "Docker base image is tag-pinned but not digest-pinned: python:3.11-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.11-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a399389f5f17b106", "name": "Runtime dotenv file present in repo: frontend/.env.production", "shortDescription": {"text": "Runtime dotenv file present in repo: frontend/.env.production"}, "fullDescription": {"text": "`frontend/.env.production` looks like a runtime dotenv file. No high-confidence secret value was matched, but runtime dotenv files often drift into live credentials. Move real values to a secret manager and keep only `.env.example` style templates in source control."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e3596be396d7b610", "name": "Runtime dotenv file present in repo: frontend/.env.check", "shortDescription": {"text": "Runtime dotenv file present in repo: frontend/.env.check"}, "fullDescription": {"text": "`frontend/.env.check` looks like a runtime dotenv file. It contains secret-looking assignments for VERCEL_OIDC_TOKEN. Move real values to a secret manager and keep only `.env.example` style templates in source control."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-9bdfceab7af8082d", "name": "Possible secret in backend/knexfile.js", "shortDescription": {"text": "Possible secret in backend/knexfile.js"}, "fullDescription": {"text": "Detected pattern matching password_literal. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 29 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 48 placeholder/mock markers across 22 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-715fdb10f9c85b74", "name": "Agent instruction/config may expose a secret: claude.md", "shortDescription": {"text": "Agent instruction/config may expose a secret: claude.md"}, "fullDescription": {"text": "Agent-facing files are routinely pasted into LLM/tool contexts. Move literal tokens, keys, and passwords into a secret manager or document them as placeholders only."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cbb5857940ba0dc2", "name": "Agent instruction/config may expose a secret: AGENTS.md", "shortDescription": {"text": "Agent instruction/config may expose a secret: AGENTS.md"}, "fullDescription": {"text": "Agent-facing files are routinely pasted into LLM/tool contexts. Move literal tokens, keys, and passwords into a secret manager or document them as placeholders only."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e725d2ab884fbd49", "name": "Multiple root agent instruction files without precedence", "shortDescription": {"text": "Multiple root agent instruction files without precedence"}, "fullDescription": {"text": "The repo has multiple top-level AI-coder instruction files. Without precedence rules, different agents may follow different policies."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e93b0351d7e2f33a", "name": "Commented-code block (5 lines) in frontend/src/pages/Kontrol.jsx:138", "shortDescription": {"text": "Commented-code block (5 lines) in frontend/src/pages/Kontrol.jsx:138"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-97d08a181063dd11", "name": "Commented-code block (6 lines) in database/migrations/20260524000016_sites_and_users_multitenant.js:54", "shortDescription": {"text": "Commented-code block (6 lines) in database/migrations/20260524000016_sites_and_users_multitenant.js:54"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0bf99a4973bb50de", "name": "Commented-code block (6 lines) in backend/tests/routes/subscription.test.js:154", "shortDescription": {"text": "Commented-code block (6 lines) in backend/tests/routes/subscription.test.js:154"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c9ae83bf37044978", "name": "Commented-code block (5 lines) in backend/tests/routes/multi_tenant_isolation.test.js:495", "shortDescription": {"text": "Commented-code block (5 lines) in backend/tests/routes/multi_tenant_isolation.test.js:495"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d790de030fca2c25", "name": "Commented-code block (7 lines) in backend/python_ocr/app.py:92", "shortDescription": {"text": "Commented-code block (7 lines) in backend/python_ocr/app.py:92"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b0b72b4c6c5d183f", "name": "Commented-code block (6 lines) in backend/src/db.js:5", "shortDescription": {"text": "Commented-code block (6 lines) in backend/src/db.js:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6d46ca61a5bddf63", "name": "Commented-code block (6 lines) in backend/src/server.js:58", "shortDescription": {"text": "Commented-code block (6 lines) in backend/src/server.js:58"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1e6450da502308cf", "name": "Commented-code block (5 lines) in backend/src/utils/validators.js:30", "shortDescription": {"text": "Commented-code block (5 lines) in backend/src/utils/validators.js:30"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7de82e6748031e4e", "name": "Commented-code block (5 lines) in backend/src/routes/kontroller.js:90", "shortDescription": {"text": "Commented-code block (5 lines) in backend/src/routes/kontroller.js:90"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b85cfd8fe81f1cb2", "name": "`fetch()` without try/.catch or AbortSignal \u2014 backend/src/routes/kontroller.js:95", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/src/routes/kontroller.js:95"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6acfb8dbddc8c676", "name": "Commented-code block (8 lines) in backend/src/routes/analiz.js:304", "shortDescription": {"text": "Commented-code block (8 lines) in backend/src/routes/analiz.js:304"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b6f1dc5896018062", "name": "Commented-code block (6 lines) in backend/src/routes/raporlar.js:43", "shortDescription": {"text": "Commented-code block (6 lines) in backend/src/routes/raporlar.js:43"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3bcc81d177d2d51d", "name": "Commented-code block (7 lines) in backend/src/services/plateMatcher.js:23", "shortDescription": {"text": "Commented-code block (7 lines) in backend/src/services/plateMatcher.js:23"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9c4626f01779f274", "name": "Commented-code block (5 lines) in backend/src/services/billing/paytr.js:113", "shortDescription": {"text": "Commented-code block (5 lines) in backend/src/services/billing/paytr.js:113"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a85b6bda6e05c598", "name": "Commented-code block (7 lines) in backend/src/jobs/fotoTemizle.js:10", "shortDescription": {"text": "Commented-code block (7 lines) in backend/src/jobs/fotoTemizle.js:10"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-22deb1bd34bd8219", "name": "Commented-code block (5 lines) in backend/src/jobs/zehirliOgrenmeTemizle.js:12", "shortDescription": {"text": "Commented-code block (5 lines) in backend/src/jobs/zehirliOgrenmeTemizle.js:12"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d30f85c43b86dcf0", "name": "27 env vars used in code but missing from .env.example", "shortDescription": {"text": "27 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `CI`, `DATABASE_URL_TEST`, `EASYOCR_GPU`, `FOTO_FILE_KEEP_DAYS`, `LOG_LEVEL`, `MODE`, `OCR_ALERT_EMAIL`, `OCR_ALLOW_DIPLOMATIC` + 19 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-24166ecf98d230cb", "name": "Frontend route `/protected` has no Link/navigate to it \u2014 frontend/src/auth/ProtectedRoute.test.jsx", "shortDescription": {"text": "Frontend route `/protected` has no Link/navigate to it \u2014 frontend/src/auth/ProtectedRoute.test.jsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d7e8f70b7fe221f7", "name": "Frontend route `/admin` has no Link/navigate to it \u2014 frontend/src/auth/ProtectedRoute.test.jsx", "shortDescription": {"text": "Frontend route `/admin` has no Link/navigate to it \u2014 frontend/src/auth/ProtectedRoute.test.jsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fa03af7b1926fdea", "name": "FastAPI POST `ocr` without auth dependency \u2014 backend/python_ocr/app.py:732", "shortDescription": {"text": "FastAPI POST `ocr` without auth dependency \u2014 backend/python_ocr/app.py:732"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-341dbb4d736d7fa8", "name": "Unused endpoint: POST /ocr", "shortDescription": {"text": "Unused endpoint: POST /ocr"}, "fullDescription": {"text": "`backend/python_ocr/app.py` declares `POST /ocr` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8fdbacfe9430a6ed", "name": "Unused endpoint: POST /auth/login", "shortDescription": {"text": "Unused endpoint: POST /auth/login"}, "fullDescription": {"text": "`frontend/src/auth/AuthContext.jsx` declares `POST /auth/login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ac42422b23e45104", "name": "Unused endpoint: GET /auth/me", "shortDescription": {"text": "Unused endpoint: GET /auth/me"}, "fullDescription": {"text": "`frontend/src/auth/AuthContext.jsx` declares `GET /auth/me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-af8fd16928659aab", "name": "Unused endpoint: POST /araclar", "shortDescription": {"text": "Unused endpoint: POST /araclar"}, "fullDescription": {"text": "`frontend/src/components/PlakaListesi.jsx` declares `POST /araclar` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a824eacb4355a304", "name": "Unused endpoint: GET /raporlar/schedules", "shortDescription": {"text": "Unused endpoint: GET /raporlar/schedules"}, "fullDescription": {"text": "`frontend/src/components/EmailSchedulesPanel.jsx` declares `GET /raporlar/schedules` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3915ef5be56ec257", "name": "Unused endpoint: POST /raporlar/schedules", "shortDescription": {"text": "Unused endpoint: POST /raporlar/schedules"}, "fullDescription": {"text": "`frontend/src/components/EmailSchedulesPanel.jsx` declares `POST /raporlar/schedules` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-82010a9e875c07ab", "name": "Unused endpoint: GET /ocr-stats/summary", "shortDescription": {"text": "Unused endpoint: GET /ocr-stats/summary"}, "fullDescription": {"text": "`frontend/src/pages/OcrIstatistik.jsx` declares `GET /ocr-stats/summary` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-64ab8b563721232e", "name": "Unused endpoint: POST /kontroller/analiz-et", "shortDescription": {"text": "Unused endpoint: POST /kontroller/analiz-et"}, "fullDescription": {"text": "`frontend/src/pages/AksamKontrolu.jsx` declares `POST /kontroller/analiz-et` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-55a7b89f8393978d", "name": "Unused endpoint: POST /bildirimler/gonder", "shortDescription": {"text": "Unused endpoint: POST /bildirimler/gonder"}, "fullDescription": {"text": "`frontend/src/pages/AksamKontrolu.jsx` declares `POST /bildirimler/gonder` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1c00499ebd3fa4f5", "name": "Unused endpoint: POST /bildirimler/toplu-gonder", "shortDescription": {"text": "Unused endpoint: POST /bildirimler/toplu-gonder"}, "fullDescription": {"text": "`frontend/src/pages/AksamKontrolu.jsx` declares `POST /bildirimler/toplu-gonder` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c6ce4b07040f6ff5", "name": "Unused endpoint: GET /kontroller/gece-cetelesi", "shortDescription": {"text": "Unused endpoint: GET /kontroller/gece-cetelesi"}, "fullDescription": {"text": "`frontend/src/pages/AksamKontrolu.jsx` declares `GET /kontroller/gece-cetelesi` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7f4afeba77f0d303", "name": "Unused endpoint: GET /kontroller/gece-cetelesi?yenile=1", "shortDescription": {"text": "Unused endpoint: GET /kontroller/gece-cetelesi?yenile=1"}, "fullDescription": {"text": "`frontend/src/pages/AksamKontrolu.jsx` declares `GET /kontroller/gece-cetelesi?yenile=1` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2623971938f397ce", "name": "Unused endpoint: GET /audit-log", "shortDescription": {"text": "Unused endpoint: GET /audit-log"}, "fullDescription": {"text": "`frontend/src/pages/AuditLog.jsx` declares `GET /audit-log` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-39c756a88b9dfe58", "name": "Unused endpoint: GET /site/subscription", "shortDescription": {"text": "Unused endpoint: GET /site/subscription"}, "fullDescription": {"text": "`frontend/src/pages/Abonelik.jsx` declares `GET /site/subscription` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-11dc94c995288c1f", "name": "Unused endpoint: POST /site/subscription", "shortDescription": {"text": "Unused endpoint: POST /site/subscription"}, "fullDescription": {"text": "`frontend/src/pages/Abonelik.jsx` declares `POST /site/subscription` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0e6edfde8eddc76d", "name": "Unused endpoint: PATCH /site/subscription/plan", "shortDescription": {"text": "Unused endpoint: PATCH /site/subscription/plan"}, "fullDescription": {"text": "`frontend/src/pages/Abonelik.jsx` declares `PATCH /site/subscription/plan` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-40ad42875ec01ce2", "name": "Unused endpoint: POST /site/subscription/cancel", "shortDescription": {"text": "Unused endpoint: POST /site/subscription/cancel"}, "fullDescription": {"text": "`frontend/src/pages/Abonelik.jsx` declares `POST /site/subscription/cancel` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-24086d9824d1b225", "name": "Unused endpoint: POST /site/subscription/reactivate", "shortDescription": {"text": "Unused endpoint: POST /site/subscription/reactivate"}, "fullDescription": {"text": "`frontend/src/pages/Abonelik.jsx` declares `POST /site/subscription/reactivate` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-81ed685117223f1a", "name": "Unused endpoint: GET /araclar", "shortDescription": {"text": "Unused endpoint: GET /araclar"}, "fullDescription": {"text": "`frontend/src/pages/AracListesi.jsx` declares `GET /araclar` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c27fb2a8724cdb49", "name": "Unused endpoint: GET /kontroller", "shortDescription": {"text": "Unused endpoint: GET /kontroller"}, "fullDescription": {"text": "`frontend/src/pages/Kontrol.jsx` declares `GET /kontroller` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9c9a55c1fd9e1792", "name": "Unused endpoint: POST /kontroller/foto-upload", "shortDescription": {"text": "Unused endpoint: POST /kontroller/foto-upload"}, "fullDescription": {"text": "`frontend/src/pages/Kontrol.jsx` declares `POST /kontroller/foto-upload` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e2c7b53fc34af9e9", "name": "Unused endpoint: POST /kontroller/manuel", "shortDescription": {"text": "Unused endpoint: POST /kontroller/manuel"}, "fullDescription": {"text": "`frontend/src/pages/Kontrol.jsx` declares `POST /kontroller/manuel` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ca97db76659b4e55", "name": "Unused endpoint: POST /sites", "shortDescription": {"text": "Unused endpoint: POST /sites"}, "fullDescription": {"text": "`frontend/src/pages/SuperadminSiteler.jsx` declares `POST /sites` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-23a4558b5fb325e7", "name": "Unused endpoint: GET /sites", "shortDescription": {"text": "Unused endpoint: GET /sites"}, "fullDescription": {"text": "`frontend/src/pages/SuperadminSiteler.jsx` declares `GET /sites` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e20e1d6e517da8db", "name": "Unused endpoint: GET /daireler", "shortDescription": {"text": "Unused endpoint: GET /daireler"}, "fullDescription": {"text": "`frontend/src/pages/Daireler.jsx` declares `GET /daireler` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-25fce5fd75e5f5b8", "name": "Unused endpoint: POST /daireler", "shortDescription": {"text": "Unused endpoint: POST /daireler"}, "fullDescription": {"text": "`frontend/src/pages/Daireler.jsx` declares `POST /daireler` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fff8be0c598ffb71", "name": "Unused endpoint: POST /daireler/bulk-import", "shortDescription": {"text": "Unused endpoint: POST /daireler/bulk-import"}, "fullDescription": {"text": "`frontend/src/pages/Daireler.jsx` declares `POST /daireler/bulk-import` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e997bb511b8a9907", "name": "Unused endpoint: GET /kontroller/ihlaller", "shortDescription": {"text": "Unused endpoint: GET /kontroller/ihlaller"}, "fullDescription": {"text": "`frontend/src/pages/Raporlar.jsx` declares `GET /kontroller/ihlaller` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-921b5d99e33e087a", "name": "Unused endpoint: GET /kontroller/ihlaller/ozet", "shortDescription": {"text": "Unused endpoint: GET /kontroller/ihlaller/ozet"}, "fullDescription": {"text": "`frontend/src/pages/Raporlar.jsx` declares `GET /kontroller/ihlaller/ozet` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fc981a1b6b8f4195", "name": "Unused endpoint: GET /bildirimler", "shortDescription": {"text": "Unused endpoint: GET /bildirimler"}, "fullDescription": {"text": "`frontend/src/pages/Raporlar.jsx` declares `GET /bildirimler` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8f7d653eb8581b19", "name": "Unused endpoint: GET /raporlar/dashboard", "shortDescription": {"text": "Unused endpoint: GET /raporlar/dashboard"}, "fullDescription": {"text": "`frontend/src/pages/Raporlar.jsx` declares `GET /raporlar/dashboard` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e66af13bbd149a30", "name": "Unused endpoint: GET /site-usage", "shortDescription": {"text": "Unused endpoint: GET /site-usage"}, "fullDescription": {"text": "`frontend/src/pages/Home.jsx` declares `GET /site-usage` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e96a6c9af5274e56", "name": "Unused endpoint: GET /misafir-araclar", "shortDescription": {"text": "Unused endpoint: GET /misafir-araclar"}, "fullDescription": {"text": "`frontend/src/pages/MisafirAraclar.jsx` declares `GET /misafir-araclar` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bd13b86135c80cdf", "name": "Unused endpoint: POST /misafir-araclar", "shortDescription": {"text": "Unused endpoint: POST /misafir-araclar"}, "fullDescription": {"text": "`frontend/src/pages/MisafirAraclar.jsx` declares `POST /misafir-araclar` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-915ff7fe2aa36e20", "name": "Unused endpoint: POST /auth/sifre-degistir", "shortDescription": {"text": "Unused endpoint: POST /auth/sifre-degistir"}, "fullDescription": {"text": "`frontend/src/pages/SifreDegistir.jsx` declares `POST /auth/sifre-degistir` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-543c8b1e781d1b7d", "name": "Unused endpoint: GET /auth/kullanicilar", "shortDescription": {"text": "Unused endpoint: GET /auth/kullanicilar"}, "fullDescription": {"text": "`frontend/src/pages/Kullanicilar.jsx` declares `GET /auth/kullanicilar` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8292c0931391749a", "name": "Unused endpoint: POST /auth/register", "shortDescription": {"text": "Unused endpoint: POST /auth/register"}, "fullDescription": {"text": "`frontend/src/pages/Kullanicilar.jsx` declares `POST /auth/register` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea33026b7f5fb06d", "name": "Unused endpoint: POST /auth/sifre-sifirla", "shortDescription": {"text": "Unused endpoint: POST /auth/sifre-sifirla"}, "fullDescription": {"text": "`frontend/src/pages/Kullanicilar.jsx` declares `POST /auth/sifre-sifirla` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-203ec659ed8ada77", "name": "Unused endpoint: USE /api/webhooks", "shortDescription": {"text": "Unused endpoint: USE /api/webhooks"}, "fullDescription": {"text": "`backend/src/server.js` declares `USE /api/webhooks` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dde3adb27bf7eebe", "name": "Unused endpoint: USE /api", "shortDescription": {"text": "Unused endpoint: USE /api"}, "fullDescription": {"text": "`backend/src/server.js` declares `USE /api` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8f5614c18a2feac7", "name": "Unused endpoint: GET /api", "shortDescription": {"text": "Unused endpoint: GET /api"}, "fullDescription": {"text": "`backend/src/server.js` declares `GET /api` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6eb452fbfb454d20", "name": "Unused endpoint: USE /api/auth", "shortDescription": {"text": "Unused endpoint: USE /api/auth"}, "fullDescription": {"text": "`backend/src/server.js` declares `USE /api/auth` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6534c9b49c0fec46", "name": "Unused endpoint: USE /api/daireler", "shortDescription": {"text": "Unused endpoint: USE /api/daireler"}, "fullDescription": {"text": "`backend/src/server.js` declares `USE /api/daireler` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-19ca63f7e077a0bb", "name": "Unused endpoint: USE /api/araclar", "shortDescription": {"text": "Unused endpoint: USE /api/araclar"}, "fullDescription": {"text": "`backend/src/server.js` declares `USE /api/araclar` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7e0f5a5193ea65e8", "name": "Unused endpoint: USE /api/misafir-araclar", "shortDescription": {"text": "Unused endpoint: USE /api/misafir-araclar"}, "fullDescription": {"text": "`backend/src/server.js` declares `USE /api/misafir-araclar` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-952018e7021c4afb", "name": "Unused endpoint: USE /api/audit-log", "shortDescription": {"text": "Unused endpoint: USE /api/audit-log"}, "fullDescription": {"text": "`backend/src/server.js` declares `USE /api/audit-log` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1c2859756391482d", "name": "Unused endpoint: USE /api/kontroller", "shortDescription": {"text": "Unused endpoint: USE /api/kontroller"}, "fullDescription": {"text": "`backend/src/server.js` declares `USE /api/kontroller` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c567bd73a69ffec9", "name": "Unused endpoint: USE /api/bildirimler", "shortDescription": {"text": "Unused endpoint: USE /api/bildirimler"}, "fullDescription": {"text": "`backend/src/server.js` declares `USE /api/bildirimler` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1aadfd9ecc9c0298", "name": "Unused endpoint: USE /api/ocr-stats", "shortDescription": {"text": "Unused endpoint: USE /api/ocr-stats"}, "fullDescription": {"text": "`backend/src/server.js` declares `USE /api/ocr-stats` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4c6fcb9d6bfeb851", "name": "Unused endpoint: USE /api/sites", "shortDescription": {"text": "Unused endpoint: USE /api/sites"}, "fullDescription": {"text": "`backend/src/server.js` declares `USE /api/sites` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/17945"}, "properties": {"repository": "recepyasar79/partrack2", "repoUrl": "https://github.com/recepyasar79/partrack2", "branch": "main"}, "results": [{"ruleId": "scanner-7b2f5cdf0b8faa0b", "level": "note", "message": {"text": "Possibly dead Python function: recognize"}, "properties": {"repobilityId": "7a185546e73115fd", "scanner": "scanner-primary", "fingerprint": "7b2f5cdf0b8faa0b", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/python_ocr/app.py:558"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-190cb7043f3f06a5", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/pages/SuperadminSiteler.jsx:249"}, "properties": {"repobilityId": "136d804f2bfda02d", "scanner": "scanner-primary", "fingerprint": "190cb7043f3f06a5", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-b8b1d77d2f222ccb", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 database/seeds/02_bootstrap_superadmin.js:18"}, "properties": {"repobilityId": "6c65a3f33957937c", "scanner": "scanner-primary", "fingerprint": "b8b1d77d2f222ccb", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5281f01482f57d85", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 database/seeds/02_dev_sample.js:5"}, "properties": {"repobilityId": "97b03a8406279e64", "scanner": "scanner-primary", "fingerprint": "5281f01482f57d85", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c970d51d9df7ea94", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 database/seeds/01_bootstrap_admin.js:14"}, "properties": {"repobilityId": "5f5a6bb869f33f10", "scanner": "scanner-primary", "fingerprint": "c970d51d9df7ea94", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d59bb1c8675e5abb", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/globalSetup.js:8"}, "properties": {"repobilityId": "94ba686066a07d26", "scanner": "scanner-primary", "fingerprint": "d59bb1c8675e5abb", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4f9419e4a1b7f900", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/server.js:121"}, "properties": {"repobilityId": "d7f22f465aadd584", "scanner": "scanner-primary", "fingerprint": "4f9419e4a1b7f900", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b6895d40970705b6", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/sentry.js:6"}, "properties": {"repobilityId": "db50f28ef8702e9c", "scanner": "scanner-primary", "fingerprint": "b6895d40970705b6", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e4100ef0dcf82228", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/jobs/bildirimRetry.js:9"}, "properties": {"repobilityId": "4bd5ac13ad19934b", "scanner": "scanner-primary", "fingerprint": "e4100ef0dcf82228", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d7a84e7e7a63350e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/jobs/emailRaporu.js:319"}, "properties": {"repobilityId": "57cb95f3b32d3965", "scanner": "scanner-primary", "fingerprint": "d7a84e7e7a63350e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3f05424c7140d049", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/jobs/subscriptionLifecycle.js:145"}, "properties": {"repobilityId": "fa80c9a7168ea6ac", "scanner": "scanner-primary", "fingerprint": "3f05424c7140d049", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0af0ae5e236cafd2", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/jobs/ocrSaglik.js:29"}, "properties": {"repobilityId": "d74b1c5f177383f9", "scanner": "scanner-primary", "fingerprint": "0af0ae5e236cafd2", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-aa08d8701000aa44", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/jobs/dataRetention.js:67"}, "properties": {"repobilityId": "d55f70156c3e781f", "scanner": "scanner-primary", "fingerprint": "aa08d8701000aa44", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ccfaaa77998eb6e4", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/jobs/fotoTemizle.js:41"}, "properties": {"repobilityId": "6ac1a86f00174c01", "scanner": "scanner-primary", "fingerprint": "ccfaaa77998eb6e4", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-cf5fe785694e9b63", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/jobs/parasutSync.js:49"}, "properties": {"repobilityId": "8a7ab353dd2d851f", "scanner": "scanner-primary", "fingerprint": "cf5fe785694e9b63", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8998f893ee581d9e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/jobs/zehirliOgrenmeTemizle.js:62"}, "properties": {"repobilityId": "02ef64af28c25609", "scanner": "scanner-primary", "fingerprint": "8998f893ee581d9e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a919fd0553b1fd22", "level": "warning", "message": {"text": "Privileged port 465 in use"}, "properties": {"repobilityId": "bcd1f06b60a2b6bc", "scanner": "scanner-primary", "fingerprint": "a919fd0553b1fd22", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/tests/mailer.test.js"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d63da3583b14afc0", "level": "warning", "message": {"text": "Dockerfile runs as root: Dockerfile"}, "properties": {"repobilityId": "a2ed1bd120e507db", "scanner": "scanner-primary", "fingerprint": "d63da3583b14afc0", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-8987d6d1c30c7202", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine"}, "properties": {"repobilityId": "068fbf45727eac17", "scanner": "scanner-primary", "fingerprint": "8987d6d1c30c7202", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-44c97952c1791b8a", "level": "warning", "message": {"text": "Dockerfile runs as root: backend/python_ocr/Dockerfile"}, "properties": {"repobilityId": "39a6a8ae32d51747", "scanner": "scanner-primary", "fingerprint": "44c97952c1791b8a", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-30c14430eb696327", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.11-slim"}, "properties": {"repobilityId": "ee986d64ae7a32e2", "scanner": "scanner-primary", "fingerprint": "30c14430eb696327", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/python_ocr/Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-a399389f5f17b106", "level": "error", "message": {"text": "Runtime dotenv file present in repo: frontend/.env.production"}, "properties": {"repobilityId": "f727d22a89e309c5", "scanner": "scanner-primary", "fingerprint": "a399389f5f17b106", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["secrets", "config", "env-file", "runtime-env"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/.env.production"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e3596be396d7b610", "level": "error", "message": {"text": "Runtime dotenv file present in repo: frontend/.env.check"}, "properties": {"repobilityId": "d388f2f50062b0b5", "scanner": "scanner-primary", "fingerprint": "e3596be396d7b610", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets", "config", "env-file", "runtime-env", "env_file_with_secret"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/.env.check"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9bdfceab7af8082d", "level": "error", "message": {"text": "Possible secret in backend/knexfile.js"}, "properties": {"repobilityId": "d4fd7a2c4a69211a", "scanner": "scanner-primary", "fingerprint": "9bdfceab7af8082d", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/knexfile.js"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "1d6a06ef2df1ae70", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "9a0bf13c35ae8bd5", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "c4d08f3f8d49d11a", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "563dabe3e3a30f90", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "1df2f50cb7fd1893", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "fb5e33ac0306aa3c", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "354bf6c70b73622d", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-715fdb10f9c85b74", "level": "error", "message": {"text": "Agent instruction/config may expose a secret: claude.md"}, "properties": {"repobilityId": "c351897f3969c518", "scanner": "scanner-primary", "fingerprint": "715fdb10f9c85b74", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["agent-instructions", "secrets", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "claude.md"}, "region": {"startLine": 395}}}]}, {"ruleId": "scanner-cbb5857940ba0dc2", "level": "error", "message": {"text": "Agent instruction/config may expose a secret: AGENTS.md"}, "properties": {"repobilityId": "e12c7213d5eadf3e", "scanner": "scanner-primary", "fingerprint": "cbb5857940ba0dc2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["agent-instructions", "secrets", "agents_md"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "AGENTS.md"}, "region": {"startLine": 207}}}]}, {"ruleId": "scanner-e725d2ab884fbd49", "level": "note", "message": {"text": "Multiple root agent instruction files without precedence"}, "properties": {"repobilityId": "1953db6c89508d22", "scanner": "scanner-primary", "fingerprint": "e725d2ab884fbd49", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["agent-instructions", "governance"]}}, {"ruleId": "scanner-e93b0351d7e2f33a", "level": "none", "message": {"text": "Commented-code block (5 lines) in frontend/src/pages/Kontrol.jsx:138"}, "properties": {"repobilityId": "c8662e08cbebe6ce", "scanner": "scanner-primary", "fingerprint": "e93b0351d7e2f33a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-97d08a181063dd11", "level": "none", "message": {"text": "Commented-code block (6 lines) in database/migrations/20260524000016_sites_and_users_multitenant.js:54"}, "properties": {"repobilityId": "468f1c3de666918f", "scanner": "scanner-primary", "fingerprint": "97d08a181063dd11", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0bf99a4973bb50de", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend/tests/routes/subscription.test.js:154"}, "properties": {"repobilityId": "5a63ae3b6c06e976", "scanner": "scanner-primary", "fingerprint": "0bf99a4973bb50de", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c9ae83bf37044978", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/tests/routes/multi_tenant_isolation.test.js:495"}, "properties": {"repobilityId": "9ae0b4d81ec58611", "scanner": "scanner-primary", "fingerprint": "c9ae83bf37044978", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d790de030fca2c25", "level": "none", "message": {"text": "Commented-code block (7 lines) in backend/python_ocr/app.py:92"}, "properties": {"repobilityId": "e94772a03d3d7269", "scanner": "scanner-primary", "fingerprint": "d790de030fca2c25", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b0b72b4c6c5d183f", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend/src/db.js:5"}, "properties": {"repobilityId": "2794de83b3179d14", "scanner": "scanner-primary", "fingerprint": "b0b72b4c6c5d183f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6d46ca61a5bddf63", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend/src/server.js:58"}, "properties": {"repobilityId": "b50c64e3183ee627", "scanner": "scanner-primary", "fingerprint": "6d46ca61a5bddf63", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1e6450da502308cf", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/src/utils/validators.js:30"}, "properties": {"repobilityId": "80d2c2846604194a", "scanner": "scanner-primary", "fingerprint": "1e6450da502308cf", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7de82e6748031e4e", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/src/routes/kontroller.js:90"}, "properties": {"repobilityId": "b3bd34afdc0873b9", "scanner": "scanner-primary", "fingerprint": "7de82e6748031e4e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b85cfd8fe81f1cb2", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/src/routes/kontroller.js:95"}, "properties": {"repobilityId": "369ffc5c7d3edbd4", "scanner": "scanner-primary", "fingerprint": "b85cfd8fe81f1cb2", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-6acfb8dbddc8c676", "level": "none", "message": {"text": "Commented-code block (8 lines) in backend/src/routes/analiz.js:304"}, "properties": {"repobilityId": "d8c1c953943c9d73", "scanner": "scanner-primary", "fingerprint": "6acfb8dbddc8c676", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b6f1dc5896018062", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend/src/routes/raporlar.js:43"}, "properties": {"repobilityId": "cb598e099f877e46", "scanner": "scanner-primary", "fingerprint": "b6f1dc5896018062", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3bcc81d177d2d51d", "level": "none", "message": {"text": "Commented-code block (7 lines) in backend/src/services/plateMatcher.js:23"}, "properties": {"repobilityId": "77d011b9e652f48f", "scanner": "scanner-primary", "fingerprint": "3bcc81d177d2d51d", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-9c4626f01779f274", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/src/services/billing/paytr.js:113"}, "properties": {"repobilityId": "dcb66c09942d89d1", "scanner": "scanner-primary", "fingerprint": "9c4626f01779f274", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a85b6bda6e05c598", "level": "none", "message": {"text": "Commented-code block (7 lines) in backend/src/jobs/fotoTemizle.js:10"}, "properties": {"repobilityId": "f61cf488e370f755", "scanner": "scanner-primary", "fingerprint": "a85b6bda6e05c598", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-22deb1bd34bd8219", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/src/jobs/zehirliOgrenmeTemizle.js:12"}, "properties": {"repobilityId": "e5871f448ef8e134", "scanner": "scanner-primary", "fingerprint": "22deb1bd34bd8219", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d30f85c43b86dcf0", "level": "note", "message": {"text": "27 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "4816db1c74a26e4a", "scanner": "scanner-primary", "fingerprint": "d30f85c43b86dcf0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-24166ecf98d230cb", "level": "warning", "message": {"text": "Frontend route `/protected` has no Link/navigate to it \u2014 frontend/src/auth/ProtectedRoute.test.jsx"}, "properties": {"repobilityId": "5a3877fa80dd88cf", "scanner": "scanner-primary", "fingerprint": "24166ecf98d230cb", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-d7e8f70b7fe221f7", "level": "warning", "message": {"text": "Frontend route `/admin` has no Link/navigate to it \u2014 frontend/src/auth/ProtectedRoute.test.jsx"}, "properties": {"repobilityId": "e9b29475bd1beef7", "scanner": "scanner-primary", "fingerprint": "d7e8f70b7fe221f7", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-fa03af7b1926fdea", "level": "error", "message": {"text": "FastAPI POST `ocr` without auth dependency \u2014 backend/python_ocr/app.py:732"}, "properties": {"repobilityId": "1c595ff9619a607e", "scanner": "scanner-primary", "fingerprint": "fa03af7b1926fdea", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/python_ocr/app.py"}, "region": {"startLine": 732}}}]}, {"ruleId": "scanner-341dbb4d736d7fa8", "level": "note", "message": {"text": "Unused endpoint: POST /ocr"}, "properties": {"repobilityId": "beb3138aec842d5f", "scanner": "scanner-primary", "fingerprint": "341dbb4d736d7fa8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8fdbacfe9430a6ed", "level": "note", "message": {"text": "Unused endpoint: POST /auth/login"}, "properties": {"repobilityId": "6703e455f51b6127", "scanner": "scanner-primary", "fingerprint": "8fdbacfe9430a6ed", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ac42422b23e45104", "level": "note", "message": {"text": "Unused endpoint: GET /auth/me"}, "properties": {"repobilityId": "86eeea79abf05fc7", "scanner": "scanner-primary", "fingerprint": "ac42422b23e45104", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-af8fd16928659aab", "level": "note", "message": {"text": "Unused endpoint: POST /araclar"}, "properties": {"repobilityId": "9f8833e8b03bc617", "scanner": "scanner-primary", "fingerprint": "af8fd16928659aab", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a824eacb4355a304", "level": "note", "message": {"text": "Unused endpoint: GET /raporlar/schedules"}, "properties": {"repobilityId": "ac017601d0aef977", "scanner": "scanner-primary", "fingerprint": "a824eacb4355a304", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3915ef5be56ec257", "level": "note", "message": {"text": "Unused endpoint: POST /raporlar/schedules"}, "properties": {"repobilityId": "ecb4654356fde9c3", "scanner": "scanner-primary", "fingerprint": "3915ef5be56ec257", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-82010a9e875c07ab", "level": "note", "message": {"text": "Unused endpoint: GET /ocr-stats/summary"}, "properties": {"repobilityId": "d3cfc7520c04547d", "scanner": "scanner-primary", "fingerprint": "82010a9e875c07ab", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-64ab8b563721232e", "level": "note", "message": {"text": "Unused endpoint: POST /kontroller/analiz-et"}, "properties": {"repobilityId": "803e17b20f689899", "scanner": "scanner-primary", "fingerprint": "64ab8b563721232e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-55a7b89f8393978d", "level": "note", "message": {"text": "Unused endpoint: POST /bildirimler/gonder"}, "properties": {"repobilityId": "5fc7f1f0534291fa", "scanner": "scanner-primary", "fingerprint": "55a7b89f8393978d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1c00499ebd3fa4f5", "level": "note", "message": {"text": "Unused endpoint: POST /bildirimler/toplu-gonder"}, "properties": {"repobilityId": "2fb7db4687f1d1f2", "scanner": "scanner-primary", "fingerprint": "1c00499ebd3fa4f5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c6ce4b07040f6ff5", "level": "note", "message": {"text": "Unused endpoint: GET /kontroller/gece-cetelesi"}, "properties": {"repobilityId": "a50c3b43bdb9b77b", "scanner": "scanner-primary", "fingerprint": "c6ce4b07040f6ff5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7f4afeba77f0d303", "level": "note", "message": {"text": "Unused endpoint: GET /kontroller/gece-cetelesi?yenile=1"}, "properties": {"repobilityId": "366e35294714d06b", "scanner": "scanner-primary", "fingerprint": "7f4afeba77f0d303", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2623971938f397ce", "level": "note", "message": {"text": "Unused endpoint: GET /audit-log"}, "properties": {"repobilityId": "55b8789ded9404b3", "scanner": "scanner-primary", "fingerprint": "2623971938f397ce", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-39c756a88b9dfe58", "level": "note", "message": {"text": "Unused endpoint: GET /site/subscription"}, "properties": {"repobilityId": "65618bf0623eda1a", "scanner": "scanner-primary", "fingerprint": "39c756a88b9dfe58", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-11dc94c995288c1f", "level": "note", "message": {"text": "Unused endpoint: POST /site/subscription"}, "properties": {"repobilityId": "a21b5acf0dcff1c3", "scanner": "scanner-primary", "fingerprint": "11dc94c995288c1f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0e6edfde8eddc76d", "level": "note", "message": {"text": "Unused endpoint: PATCH /site/subscription/plan"}, "properties": {"repobilityId": "4d233bf465b5fe03", "scanner": "scanner-primary", "fingerprint": "0e6edfde8eddc76d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-40ad42875ec01ce2", "level": "note", "message": {"text": "Unused endpoint: POST /site/subscription/cancel"}, "properties": {"repobilityId": "696bbc681cc2cb70", "scanner": "scanner-primary", "fingerprint": "40ad42875ec01ce2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-24086d9824d1b225", "level": "note", "message": {"text": "Unused endpoint: POST /site/subscription/reactivate"}, "properties": {"repobilityId": "092c745e017c4168", "scanner": "scanner-primary", "fingerprint": "24086d9824d1b225", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-81ed685117223f1a", "level": "note", "message": {"text": "Unused endpoint: GET /araclar"}, "properties": {"repobilityId": "59ebc82d12172772", "scanner": "scanner-primary", "fingerprint": "81ed685117223f1a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c27fb2a8724cdb49", "level": "note", "message": {"text": "Unused endpoint: GET /kontroller"}, "properties": {"repobilityId": "5e4ff02725a5b9c9", "scanner": "scanner-primary", "fingerprint": "c27fb2a8724cdb49", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9c9a55c1fd9e1792", "level": "note", "message": {"text": "Unused endpoint: POST /kontroller/foto-upload"}, "properties": {"repobilityId": "9bfa5740ad20aaa1", "scanner": "scanner-primary", "fingerprint": "9c9a55c1fd9e1792", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e2c7b53fc34af9e9", "level": "note", "message": {"text": "Unused endpoint: POST /kontroller/manuel"}, "properties": {"repobilityId": "cc86fff29e7fd704", "scanner": "scanner-primary", "fingerprint": "e2c7b53fc34af9e9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ca97db76659b4e55", "level": "note", "message": {"text": "Unused endpoint: POST /sites"}, "properties": {"repobilityId": "e8d30b4a7e78e20d", "scanner": "scanner-primary", "fingerprint": "ca97db76659b4e55", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-23a4558b5fb325e7", "level": "note", "message": {"text": "Unused endpoint: GET /sites"}, "properties": {"repobilityId": "9b24f60ceb8db5b2", "scanner": "scanner-primary", "fingerprint": "23a4558b5fb325e7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e20e1d6e517da8db", "level": "note", "message": {"text": "Unused endpoint: GET /daireler"}, "properties": {"repobilityId": "876bef08af98c465", "scanner": "scanner-primary", "fingerprint": "e20e1d6e517da8db", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-25fce5fd75e5f5b8", "level": "note", "message": {"text": "Unused endpoint: POST /daireler"}, "properties": {"repobilityId": "f0438c873c26f78b", "scanner": "scanner-primary", "fingerprint": "25fce5fd75e5f5b8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fff8be0c598ffb71", "level": "note", "message": {"text": "Unused endpoint: POST /daireler/bulk-import"}, "properties": {"repobilityId": "b87ff4c7edbf1a13", "scanner": "scanner-primary", "fingerprint": "fff8be0c598ffb71", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e997bb511b8a9907", "level": "note", "message": {"text": "Unused endpoint: GET /kontroller/ihlaller"}, "properties": {"repobilityId": "6a2a3de6a1130404", "scanner": "scanner-primary", "fingerprint": "e997bb511b8a9907", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-921b5d99e33e087a", "level": "note", "message": {"text": "Unused endpoint: GET /kontroller/ihlaller/ozet"}, "properties": {"repobilityId": "2429155f8917f271", "scanner": "scanner-primary", "fingerprint": "921b5d99e33e087a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fc981a1b6b8f4195", "level": "note", "message": {"text": "Unused endpoint: GET /bildirimler"}, "properties": {"repobilityId": "74e89b66a8df4527", "scanner": "scanner-primary", "fingerprint": "fc981a1b6b8f4195", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8f7d653eb8581b19", "level": "note", "message": {"text": "Unused endpoint: GET /raporlar/dashboard"}, "properties": {"repobilityId": "3016ce339d51ef64", "scanner": "scanner-primary", "fingerprint": "8f7d653eb8581b19", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e66af13bbd149a30", "level": "note", "message": {"text": "Unused endpoint: GET /site-usage"}, "properties": {"repobilityId": "daada170d379572d", "scanner": "scanner-primary", "fingerprint": "e66af13bbd149a30", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e96a6c9af5274e56", "level": "note", "message": {"text": "Unused endpoint: GET /misafir-araclar"}, "properties": {"repobilityId": "d8edc37f99de8934", "scanner": "scanner-primary", "fingerprint": "e96a6c9af5274e56", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bd13b86135c80cdf", "level": "note", "message": {"text": "Unused endpoint: POST /misafir-araclar"}, "properties": {"repobilityId": "13b1f2e330a2d26e", "scanner": "scanner-primary", "fingerprint": "bd13b86135c80cdf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-915ff7fe2aa36e20", "level": "note", "message": {"text": "Unused endpoint: POST /auth/sifre-degistir"}, "properties": {"repobilityId": "8c43ce7438acefc9", "scanner": "scanner-primary", "fingerprint": "915ff7fe2aa36e20", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-543c8b1e781d1b7d", "level": "note", "message": {"text": "Unused endpoint: GET /auth/kullanicilar"}, "properties": {"repobilityId": "9ac00466e4ff8b3d", "scanner": "scanner-primary", "fingerprint": "543c8b1e781d1b7d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8292c0931391749a", "level": "note", "message": {"text": "Unused endpoint: POST /auth/register"}, "properties": {"repobilityId": "4bb7a4047f8e670b", "scanner": "scanner-primary", "fingerprint": "8292c0931391749a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ea33026b7f5fb06d", "level": "note", "message": {"text": "Unused endpoint: POST /auth/sifre-sifirla"}, "properties": {"repobilityId": "38cacce08957610a", "scanner": "scanner-primary", "fingerprint": "ea33026b7f5fb06d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-203ec659ed8ada77", "level": "note", "message": {"text": "Unused endpoint: USE /api/webhooks"}, "properties": {"repobilityId": "2620030e7d256aec", "scanner": "scanner-primary", "fingerprint": "203ec659ed8ada77", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dde3adb27bf7eebe", "level": "note", "message": {"text": "Unused endpoint: USE /api"}, "properties": {"repobilityId": "fd5809094cc7576a", "scanner": "scanner-primary", "fingerprint": "dde3adb27bf7eebe", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8f5614c18a2feac7", "level": "note", "message": {"text": "Unused endpoint: GET /api"}, "properties": {"repobilityId": "3ef5bc1224db0433", "scanner": "scanner-primary", "fingerprint": "8f5614c18a2feac7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6eb452fbfb454d20", "level": "note", "message": {"text": "Unused endpoint: USE /api/auth"}, "properties": {"repobilityId": "cfb6b95509c67b14", "scanner": "scanner-primary", "fingerprint": "6eb452fbfb454d20", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6534c9b49c0fec46", "level": "note", "message": {"text": "Unused endpoint: USE /api/daireler"}, "properties": {"repobilityId": "70aa2f6c651a641b", "scanner": "scanner-primary", "fingerprint": "6534c9b49c0fec46", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-19ca63f7e077a0bb", "level": "note", "message": {"text": "Unused endpoint: USE /api/araclar"}, "properties": {"repobilityId": "d9c20cb26ad3b9c1", "scanner": "scanner-primary", "fingerprint": "19ca63f7e077a0bb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7e0f5a5193ea65e8", "level": "note", "message": {"text": "Unused endpoint: USE /api/misafir-araclar"}, "properties": {"repobilityId": "0abf0499d2e8e544", "scanner": "scanner-primary", "fingerprint": "7e0f5a5193ea65e8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-952018e7021c4afb", "level": "note", "message": {"text": "Unused endpoint: USE /api/audit-log"}, "properties": {"repobilityId": "cc1c58af6e2de373", "scanner": "scanner-primary", "fingerprint": "952018e7021c4afb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1c2859756391482d", "level": "note", "message": {"text": "Unused endpoint: USE /api/kontroller"}, "properties": {"repobilityId": "b361e6732342b189", "scanner": "scanner-primary", "fingerprint": "1c2859756391482d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c567bd73a69ffec9", "level": "note", "message": {"text": "Unused endpoint: USE /api/bildirimler"}, "properties": {"repobilityId": "7738ee859fd2bc29", "scanner": "scanner-primary", "fingerprint": "c567bd73a69ffec9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1aadfd9ecc9c0298", "level": "note", "message": {"text": "Unused endpoint: USE /api/ocr-stats"}, "properties": {"repobilityId": "8ef6ac694031bece", "scanner": "scanner-primary", "fingerprint": "1aadfd9ecc9c0298", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4c6fcb9d6bfeb851", "level": "note", "message": {"text": "Unused endpoint: USE /api/sites"}, "properties": {"repobilityId": "4222ed29c23e4be7", "scanner": "scanner-primary", "fingerprint": "4c6fcb9d6bfeb851", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}