{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-d165a5b500790c33", "name": "Stray `console.log` in TS/JS \u2014 scripts/test-exceljs-error.ts:8", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-exceljs-error.ts:8"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c73b24a9d809db67", "name": "Stray `console.log` in TS/JS \u2014 scripts/test-rut-multi.ts:14", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-rut-multi.ts:14"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fa05bb775d214985", "name": "Stray `console.log` in TS/JS \u2014 scripts/test-rut.ts:10", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-rut.ts:10"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f15260e5733bfb27", "name": "Stray `console.log` in TS/JS \u2014 scripts/test-dian-session-invalidation.ts:22", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-dian-session-invalidation.ts:22"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-186f168ad7be8c07", "name": "Stray `console.log` in TS/JS \u2014 scripts/build-excel-from-rows.ts:35", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/build-excel-from-rows.ts:35"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0ac6af230baccfce", "name": "Stray `console.log` in TS/JS \u2014 scripts/test-dian-stress.ts:43", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-dian-stress.ts:43"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-75c6f26157c0d8fb", "name": "Stray `console.log` in TS/JS \u2014 scripts/test-dian-massdl.ts:20", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-dian-massdl.ts:20"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa8ad788794ad1b9", "name": "Stray `console.log` in TS/JS \u2014 scripts/test-empty-excel.ts:1", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-empty-excel.ts:1"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b021654aeb7f8295", "name": "Stray `console.log` in TS/JS \u2014 scripts/migrateSqliteToMongo.ts:81", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/migrateSqliteToMongo.ts:81"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d7a76e1a73a17599", "name": "Stray `console.log` in TS/JS \u2014 scripts/test-rut-xvfb.ts:8", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-rut-xvfb.ts:8"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2b2711d1936e0331", "name": "Stray `console.log` in TS/JS \u2014 scripts/migrate-siigo-ownership.ts:24", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/migrate-siigo-ownership.ts:24"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5872d596100ecd2d", "name": "Stray `console.log` in TS/JS \u2014 scripts/test-dian-3cufes.ts:24", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-dian-3cufes.ts:24"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8c253fbecbd670f6", "name": "Stray `console.log` in TS/JS \u2014 src/index.ts:100", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/index.ts:100"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5297ed881fe3ad54", "name": "Stray `console.log` in TS/JS \u2014 src/middleware/requireIntegrationAuth.ts:52", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/middleware/requireIntegrationAuth.ts:52"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-419989ce5d205a2b", "name": "Stray `console.log` in TS/JS \u2014 src/routes/dianMassDownload.ts:424", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/routes/dianMassDownload.ts:424"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-86c8285930ee83aa", "name": "Stray `console.log` in TS/JS \u2014 src/routes/causation.ts:80", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/routes/causation.ts:80"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-84826d1c4290be74", "name": "Stray `console.log` in TS/JS \u2014 src/routes/googleAuth.ts:227", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/routes/googleAuth.ts:227"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d078310284638773", "name": "Stray `console.log` in TS/JS \u2014 src/routes/dianExcel.ts:147", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/routes/dianExcel.ts:147"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-267623cf7dc6feee", "name": "Stray `console.log` in TS/JS \u2014 src/routes/dianCufeDownload.ts:515", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/routes/dianCufeDownload.ts:515"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7c885120785fb583", "name": "Stray `console.log` in TS/JS \u2014 src/routes/dian.ts:125", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/routes/dian.ts:125"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-70eea9c97a76f6ff", "name": "Stray `console.log` in TS/JS \u2014 src/routes/siigo.ts:1165", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/routes/siigo.ts:1165"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aba40baad1592835", "name": "Stray `console.log` in TS/JS \u2014 src/services/siigoService.ts:233", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/services/siigoService.ts:233"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8a795a0722309aab", "name": "Stray `console.log` in TS/JS \u2014 src/services/googleDrive.ts:61", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/services/googleDrive.ts:61"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-949c0a970b9819fd", "name": "Stray `console.log` in TS/JS \u2014 src/services/causationInputService.ts:104", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/services/causationInputService.ts:104"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-761c90f88d0dbeba", "name": "Stray `console.log` in TS/JS \u2014 src/services/xmlParser.ts:71", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/services/xmlParser.ts:71"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3abf70f7446e29cf", "name": "Stray `console.log` in TS/JS \u2014 src/services/siigoCompaniesService.ts:285", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/services/siigoCompaniesService.ts:285"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4a501bd4cabab6f2", "name": "Stray `console.log` in TS/JS \u2014 src/services/dianScraper.ts:193", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/services/dianScraper.ts:193"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-402f05a1cd8b4086", "name": "Stray `console.log` in TS/JS \u2014 src/services/database.ts:812", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/services/database.ts:812"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-de7201adfe395b35", "name": "Stray `console.log` in TS/JS \u2014 src/services/siigoAccountingService.ts:113", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/services/siigoAccountingService.ts:113"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a35c6a00f751880f", "name": "Docker base image is tag-pinned but not digest-pinned: node:20-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-77a464701f01cedf", "name": "Possible secret in README.md", "shortDescription": {"text": "Possible secret in README.md"}, "fullDescription": {"text": "Detected pattern matching private_key. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-9c209b7d3d74088c", "name": "Insecure pattern 'private_key_in_repo' in README.md:109", "shortDescription": {"text": "Insecure pattern 'private_key_in_repo' in README.md:109"}, "fullDescription": {"text": "Found a known-risky pattern (private_key_in_repo). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-1359d17c80883477", "name": "Insecure pattern 'node_child_process' in scripts/installPuppeteer.mjs:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/installPuppeteer.mjs:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1d8544ee21650f15", "name": "Insecure pattern 'node_child_process' in src/index.ts:7", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/index.ts:7"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8890a1642f1a4977", "name": "Insecure pattern 'cors_wildcard' in src/routes/rutConsulta.ts:230", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in src/routes/rutConsulta.ts:230"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cb639d9a10a47b23", "name": "package.json defines install-time lifecycle scripts", "shortDescription": {"text": "package.json defines install-time lifecycle scripts"}, "fullDescription": {"text": "preinstall/install/postinstall/prepare scripts execute during dependency installation. Review them carefully for network calls, obfuscation, shell execution, or credential access."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ee15057109e7166d", "name": "Very large file: src/routes/siigo.ts (1757 lines)", "shortDescription": {"text": "Very large file: src/routes/siigo.ts (1757 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-68cc1643cec6b1b8", "name": "Very large file: src/services/dianScraper.ts (3028 lines)", "shortDescription": {"text": "Very large file: src/services/dianScraper.ts (3028 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea3b5e389d8c9c0f", "name": "Low test-to-source ratio", "shortDescription": {"text": "Low test-to-source ratio"}, "fullDescription": {"text": "14 tests / 73 src (ratio 0.19)."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 248 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-974e0927fc27f5ce", "name": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/test-rut-multi.ts:16", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/test-rut-multi.ts:16"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b56625c78586eedd", "name": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/test-rut.ts:35", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/test-rut.ts:35"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3ecfad328a3d6c3c", "name": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/test-xml.mjs:69", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/test-xml.mjs:69"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4a89ab756b793667", "name": "Commented-code block (5 lines) in src/index.ts:107", "shortDescription": {"text": "Commented-code block (5 lines) in src/index.ts:107"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-009f93a76f1e8836", "name": "Commented-code block (5 lines) in src/routes/dianCufeDownload.ts:408", "shortDescription": {"text": "Commented-code block (5 lines) in src/routes/dianCufeDownload.ts:408"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1debfa983a5dd28a", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/siigoService.ts:199", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/siigoService.ts:199"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-09f75de9229cc603", "name": "Legacy-named symbol `tooOld` in src/services/rutConsultaService.ts:152", "shortDescription": {"text": "Legacy-named symbol `tooOld` in src/services/rutConsultaService.ts:152"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6d0115285d509215", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/rutConsultaService.ts:35", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/rutConsultaService.ts:35"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-018487b6eeb01700", "name": "Commented-code block (6 lines) in src/services/dianScraper.ts:72", "shortDescription": {"text": "Commented-code block (6 lines) in src/services/dianScraper.ts:72"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8bb8a44df581d67e", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/dianScraper.ts:1868", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/dianScraper.ts:1868"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c974e01ea0113a33", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/siigoSuggestionsService.ts:302", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/siigoSuggestionsService.ts:302"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1870dbe394562110", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/bookmarkletTemplate.ts:64", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/bookmarkletTemplate.ts:64"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6adfe3d30ee9355f", "name": "40 env vars used in code but missing from .env.example", "shortDescription": {"text": "40 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `ADMIN_NITS`, `BROWSER_MAX_HOLD_MS`, `BROWSER_SWEEP_INTERVAL_MS`, `DEMO_INVITE_TTL_DAYS`, `DEMO_TRIAL_HOURS`, `DEMO_TRIAL_LIMIT`, `DIAN_CUFE_COMPLETION_SWEEPS`, `DIAN_CUFE_RECYCLE_EVERY` + 32 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-deba949b5fe6f339", "name": "Dangling fetch: POST https://api.capsolver.com/createTask (scripts/test-rut-multi.ts:16)", "shortDescription": {"text": "Dangling fetch: POST https://api.capsolver.com/createTask (scripts/test-rut-multi.ts:16)"}, "fullDescription": {"text": "`scripts/test-rut-multi.ts:16` calls `POST https://api.capsolver.com/createTask` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.capsolver.com/createtask`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e87c846e02793bcd", "name": "Dangling fetch: POST https://api.capsolver.com/getTaskResult (scripts/test-rut-multi.ts:29)", "shortDescription": {"text": "Dangling fetch: POST https://api.capsolver.com/getTaskResult (scripts/test-rut-multi.ts:29)"}, "fullDescription": {"text": "`scripts/test-rut-multi.ts:29` calls `POST https://api.capsolver.com/getTaskResult` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.capsolver.com/gettaskresult`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-41e28b1e28593e8e", "name": "Dangling fetch: POST https://api.capsolver.com/createTask (scripts/test-rut.ts:18)", "shortDescription": {"text": "Dangling fetch: POST https://api.capsolver.com/createTask (scripts/test-rut.ts:18)"}, "fullDescription": {"text": "`scripts/test-rut.ts:18` calls `POST https://api.capsolver.com/createTask` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.capsolver.com/createtask`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-994c045937648faf", "name": "Dangling fetch: POST https://api.capsolver.com/getTaskResult (scripts/test-rut.ts:35)", "shortDescription": {"text": "Dangling fetch: POST https://api.capsolver.com/getTaskResult (scripts/test-rut.ts:35)"}, "fullDescription": {"text": "`scripts/test-rut.ts:35` calls `POST https://api.capsolver.com/getTaskResult` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.capsolver.com/gettaskresult`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-76a243c9eaaf9ce7", "name": "Dangling fetch: GET /v1/vouchers (src/services/siigoService.ts:456)", "shortDescription": {"text": "Dangling fetch: GET /v1/vouchers (src/services/siigoService.ts:456)"}, "fullDescription": {"text": "`src/services/siigoService.ts:456` calls `GET /v1/vouchers` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/vouchers`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-39252aa67bbc916f", "name": "Dangling fetch: GET /v1/journals (src/services/siigoService.ts:461)", "shortDescription": {"text": "Dangling fetch: GET /v1/journals (src/services/siigoService.ts:461)"}, "fullDescription": {"text": "`src/services/siigoService.ts:461` calls `GET /v1/journals` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/journals`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-26b2c0024a60b864", "name": "Dangling fetch: POST /v1/credit-notes (src/services/siigoService.ts:547)", "shortDescription": {"text": "Dangling fetch: POST /v1/credit-notes (src/services/siigoService.ts:547)"}, "fullDescription": {"text": "`src/services/siigoService.ts:547` calls `POST /v1/credit-notes` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/credit-notes`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3d09b70d8979bf1c", "name": "Dangling fetch: POST /v1/journals (src/services/siigoService.ts:557)", "shortDescription": {"text": "Dangling fetch: POST /v1/journals (src/services/siigoService.ts:557)"}, "fullDescription": {"text": "`src/services/siigoService.ts:557` calls `POST /v1/journals` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/journals`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-91bb6877b117e67d", "name": "Dangling fetch: POST https://api.capsolver.com/createTask (src/services/rutConsultaService.ts:14)", "shortDescription": {"text": "Dangling fetch: POST https://api.capsolver.com/createTask (src/services/rutConsultaService.ts:14)"}, "fullDescription": {"text": "`src/services/rutConsultaService.ts:14` calls `POST https://api.capsolver.com/createTask` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.capsolver.com/createtask`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dbf2c2866614fd88", "name": "Dangling fetch: POST https://api.capsolver.com/getTaskResult (src/services/rutConsultaService.ts:35)", "shortDescription": {"text": "Dangling fetch: POST https://api.capsolver.com/getTaskResult (src/services/rutConsultaService.ts:35)"}, "fullDescription": {"text": "`src/services/rutConsultaService.ts:35` calls `POST https://api.capsolver.com/getTaskResult` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.capsolver.com/gettaskresult`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c4379632dcb1b8b1", "name": "Dangling fetch: POST /v1/test-balance-report-by-thirdparty (src/services/siigoSuggestionsService.ts:300)", "shortDescription": {"text": "Dangling fetch: POST /v1/test-balance-report-by-thirdparty (src/services/siigoSuggestionsService.ts:300)"}, "fullDescription": {"text": "`src/services/siigoSuggestionsService.ts:300` calls `POST /v1/test-balance-report-by-thirdparty` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/test-balance-report-by-thirdparty`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b28d92215a503990", "name": "Unused endpoint: USE /auth", "shortDescription": {"text": "Unused endpoint: USE /auth"}, "fullDescription": {"text": "`src/index.ts` declares `USE /auth` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a1d1c53a33cd39a3", "name": "Unused endpoint: USE /auth/google", "shortDescription": {"text": "Unused endpoint: USE /auth/google"}, "fullDescription": {"text": "`src/index.ts` declares `USE /auth/google` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ab58e8f7d4755a17", "name": "Unused endpoint: USE /portal-status", "shortDescription": {"text": "Unused endpoint: USE /portal-status"}, "fullDescription": {"text": "`src/index.ts` declares `USE /portal-status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b2d8849fb6b1ac47", "name": "Unused endpoint: USE /admin", "shortDescription": {"text": "Unused endpoint: USE /admin"}, "fullDescription": {"text": "`src/index.ts` declares `USE /admin` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e5fa0167867e1351", "name": "Unused endpoint: USE /dian", "shortDescription": {"text": "Unused endpoint: USE /dian"}, "fullDescription": {"text": "`src/index.ts` declares `USE /dian` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ed8ef2a9dea4e05", "name": "Unused endpoint: USE /dian-excel", "shortDescription": {"text": "Unused endpoint: USE /dian-excel"}, "fullDescription": {"text": "`src/index.ts` declares `USE /dian-excel` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0673a848962af705", "name": "Unused endpoint: USE /dian-third-parties", "shortDescription": {"text": "Unused endpoint: USE /dian-third-parties"}, "fullDescription": {"text": "`src/index.ts` declares `USE /dian-third-parties` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-86c296db9fc103b1", "name": "Unused endpoint: USE /dian-cufe", "shortDescription": {"text": "Unused endpoint: USE /dian-cufe"}, "fullDescription": {"text": "`src/index.ts` declares `USE /dian-cufe` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dfd1292396da5059", "name": "Unused endpoint: USE /dian-mass-download", "shortDescription": {"text": "Unused endpoint: USE /dian-mass-download"}, "fullDescription": {"text": "`src/index.ts` declares `USE /dian-mass-download` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d718b3520b8e853c", "name": "Unused endpoint: USE /integrations/siigo", "shortDescription": {"text": "Unused endpoint: USE /integrations/siigo"}, "fullDescription": {"text": "`src/index.ts` declares `USE /integrations/siigo` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-86e312764c06162a", "name": "Unused endpoint: USE /causation", "shortDescription": {"text": "Unused endpoint: USE /causation"}, "fullDescription": {"text": "`src/index.ts` declares `USE /causation` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b19480c187b352f3", "name": "Unused endpoint: USE /conciliacion", "shortDescription": {"text": "Unused endpoint: USE /conciliacion"}, "fullDescription": {"text": "`src/index.ts` declares `USE /conciliacion` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-677bb3f3ad6beaac", "name": "Unused endpoint: USE /caja-erp", "shortDescription": {"text": "Unused endpoint: USE /caja-erp"}, "fullDescription": {"text": "`src/index.ts` declares `USE /caja-erp` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`src/index.ts` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fca11d494725d7c3", "name": "Unused endpoint: POST /analyze", "shortDescription": {"text": "Unused endpoint: POST /analyze"}, "fullDescription": {"text": "`src/routes/conciliacion.ts` declares `POST /analyze` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-581797447c054d7b", "name": "Unused endpoint: POST /reconcile", "shortDescription": {"text": "Unused endpoint: POST /reconcile"}, "fullDescription": {"text": "`src/routes/conciliacion.ts` declares `POST /reconcile` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7028d9c853d87627", "name": "Unused endpoint: POST /export", "shortDescription": {"text": "Unused endpoint: POST /export"}, "fullDescription": {"text": "`src/routes/conciliacion.ts` declares `POST /export` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa2a58e374c0f7c9", "name": "Unused endpoint: GET /job-status/:jobId", "shortDescription": {"text": "Unused endpoint: GET /job-status/:jobId"}, "fullDescription": {"text": "`src/routes/dianMassDownload.ts` declares `GET /job-status/:jobId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7076c80fb2226378", "name": "Unused endpoint: GET /job-download/:jobId", "shortDescription": {"text": "Unused endpoint: GET /job-download/:jobId"}, "fullDescription": {"text": "`src/routes/dianMassDownload.ts` declares `GET /job-download/:jobId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-78063faf7233f3fc", "name": "Unused endpoint: POST /job-cancel/:jobId", "shortDescription": {"text": "Unused endpoint: POST /job-cancel/:jobId"}, "fullDescription": {"text": "`src/routes/dianMassDownload.ts` declares `POST /job-cancel/:jobId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a13a7e97aeacf55f", "name": "Unused endpoint: POST /start", "shortDescription": {"text": "Unused endpoint: POST /start"}, "fullDescription": {"text": "`src/routes/dianMassDownload.ts` declares `POST /start` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-618721b912bad1c2", "name": "Unused endpoint: POST /login", "shortDescription": {"text": "Unused endpoint: POST /login"}, "fullDescription": {"text": "`src/routes/auth.ts` declares `POST /login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-304b6f2b403d93f7", "name": "Unused endpoint: POST /register", "shortDescription": {"text": "Unused endpoint: POST /register"}, "fullDescription": {"text": "`src/routes/auth.ts` declares `POST /register` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0bf5c69465cb5483", "name": "Unused endpoint: GET /demo-invites/:token", "shortDescription": {"text": "Unused endpoint: GET /demo-invites/:token"}, "fullDescription": {"text": "`src/routes/auth.ts` declares `GET /demo-invites/:token` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-252326a8e232b70f", "name": "Unused endpoint: POST /demo/register", "shortDescription": {"text": "Unused endpoint: POST /demo/register"}, "fullDescription": {"text": "`src/routes/auth.ts` declares `POST /demo/register` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-99fc36db98c134ce", "name": "Unused endpoint: POST /logout", "shortDescription": {"text": "Unused endpoint: POST /logout"}, "fullDescription": {"text": "`src/routes/auth.ts` declares `POST /logout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a34e686ab26b7733", "name": "Unused endpoint: POST /admin/create-user", "shortDescription": {"text": "Unused endpoint: POST /admin/create-user"}, "fullDescription": {"text": "`src/routes/auth.ts` declares `POST /admin/create-user` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd1dc91abf32142d", "name": "Unused endpoint: GET /me", "shortDescription": {"text": "Unused endpoint: GET /me"}, "fullDescription": {"text": "`src/routes/auth.ts` declares `GET /me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e738bbb5b457b24b", "name": "Unused endpoint: GET /kanban", "shortDescription": {"text": "Unused endpoint: GET /kanban"}, "fullDescription": {"text": "`src/routes/auth.ts` declares `GET /kanban` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1dee6097d92f76ad", "name": "Unused endpoint: PUT /kanban", "shortDescription": {"text": "Unused endpoint: PUT /kanban"}, "fullDescription": {"text": "`src/routes/auth.ts` declares `PUT /kanban` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4fe9bb486644f008", "name": "Unused endpoint: POST /change-password", "shortDescription": {"text": "Unused endpoint: POST /change-password"}, "fullDescription": {"text": "`src/routes/auth.ts` declares `POST /change-password` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-21792688fabb1a87", "name": "Unused endpoint: POST /test-openai-file", "shortDescription": {"text": "Unused endpoint: POST /test-openai-file"}, "fullDescription": {"text": "`src/routes/causation.ts` declares `POST /test-openai-file` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ad8ce37bb46294de", "name": "Unused endpoint: POST /build", "shortDescription": {"text": "Unused endpoint: POST /build"}, "fullDescription": {"text": "`src/routes/causation.ts` declares `POST /build` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d345fa90f5de3745", "name": "Unused endpoint: GET /authorize", "shortDescription": {"text": "Unused endpoint: GET /authorize"}, "fullDescription": {"text": "`src/routes/googleAuth.ts` declares `GET /authorize` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c330a85f2b3723e2", "name": "Unused endpoint: POST /authorize-url", "shortDescription": {"text": "Unused endpoint: POST /authorize-url"}, "fullDescription": {"text": "`src/routes/googleAuth.ts` declares `POST /authorize-url` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cdfb578618cf2542", "name": "Unused endpoint: GET /callback", "shortDescription": {"text": "Unused endpoint: GET /callback"}, "fullDescription": {"text": "`src/routes/googleAuth.ts` declares `GET /callback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-540ebf4772ccf420", "name": "Unused endpoint: POST /disconnect", "shortDescription": {"text": "Unused endpoint: POST /disconnect"}, "fullDescription": {"text": "`src/routes/googleAuth.ts` declares `POST /disconnect` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fa4d04d3d9445e38", "name": "Unused endpoint: POST /select", "shortDescription": {"text": "Unused endpoint: POST /select"}, "fullDescription": {"text": "`src/routes/googleAuth.ts` declares `POST /select` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-970eb92d6ec2bfaa", "name": "Unused endpoint: POST /generate", "shortDescription": {"text": "Unused endpoint: POST /generate"}, "fullDescription": {"text": "`src/routes/dianExcel.ts` declares `POST /generate` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cd064d46b37a617a", "name": "Unused endpoint: GET /download/:jobId", "shortDescription": {"text": "Unused endpoint: GET /download/:jobId"}, "fullDescription": {"text": "`src/routes/dianExcel.ts` declares `GET /download/:jobId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-21c06842a0c4334b", "name": "Unused endpoint: GET /download-files/:jobId", "shortDescription": {"text": "Unused endpoint: GET /download-files/:jobId"}, "fullDescription": {"text": "`src/routes/dianExcel.ts` declares `GET /download-files/:jobId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-adec5374797f4ae7", "name": "Unused endpoint: POST /consultar", "shortDescription": {"text": "Unused endpoint: POST /consultar"}, "fullDescription": {"text": "`src/routes/rutConsulta.ts` declares `POST /consultar` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-90631dcf4fb49f54", "name": "Unused endpoint: POST /bulk", "shortDescription": {"text": "Unused endpoint: POST /bulk"}, "fullDescription": {"text": "`src/routes/rutConsulta.ts` declares `POST /bulk` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-70256c5efade35d2", "name": "Unused endpoint: GET /bulk-status/:jobId", "shortDescription": {"text": "Unused endpoint: GET /bulk-status/:jobId"}, "fullDescription": {"text": "`src/routes/rutConsulta.ts` declares `GET /bulk-status/:jobId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ab94f4c23984996b", "name": "Unused endpoint: GET /validar/:nit", "shortDescription": {"text": "Unused endpoint: GET /validar/:nit"}, "fullDescription": {"text": "`src/routes/rutConsulta.ts` declares `GET /validar/:nit` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b38efdd655f6ccd8", "name": "Unused endpoint: POST /browser-job", "shortDescription": {"text": "Unused endpoint: POST /browser-job"}, "fullDescription": {"text": "`src/routes/rutConsulta.ts` declares `POST /browser-job` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-45a95efa75cfa1b6", "name": "Unused endpoint: GET /browser-job/:jobId/status", "shortDescription": {"text": "Unused endpoint: GET /browser-job/:jobId/status"}, "fullDescription": {"text": "`src/routes/rutConsulta.ts` declares `GET /browser-job/:jobId/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-862ca1beb2ad0757", "name": "Unused endpoint: GET /bookmarklet.js", "shortDescription": {"text": "Unused endpoint: GET /bookmarklet.js"}, "fullDescription": {"text": "`src/routes/rutConsulta.ts` declares `GET /bookmarklet.js` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f901b4788a1eae72", "name": "Unused endpoint: OPTIONS /browser-job/:jobId/pending", "shortDescription": {"text": "Unused endpoint: OPTIONS /browser-job/:jobId/pending"}, "fullDescription": {"text": "`src/routes/rutConsulta.ts` declares `OPTIONS /browser-job/:jobId/pending` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-974329c2e6f5a3ee", "name": "Unused endpoint: GET /browser-job/:jobId/pending", "shortDescription": {"text": "Unused endpoint: GET /browser-job/:jobId/pending"}, "fullDescription": {"text": "`src/routes/rutConsulta.ts` declares `GET /browser-job/:jobId/pending` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/19216"}, "properties": {"repository": "Selachon/ContaGO-API", "repoUrl": "https://github.com/Selachon/ContaGO-API", "branch": "main"}, "results": [{"ruleId": "scanner-d165a5b500790c33", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-exceljs-error.ts:8"}, "properties": {"repobilityId": "0215e697a9f29b63", "scanner": "scanner-primary", "fingerprint": "d165a5b500790c33", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c73b24a9d809db67", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-rut-multi.ts:14"}, "properties": {"repobilityId": "148bd353f6fe577d", "scanner": "scanner-primary", "fingerprint": "c73b24a9d809db67", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-fa05bb775d214985", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-rut.ts:10"}, "properties": {"repobilityId": "e1de17055d99a266", "scanner": "scanner-primary", "fingerprint": "fa05bb775d214985", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f15260e5733bfb27", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-dian-session-invalidation.ts:22"}, "properties": {"repobilityId": "2ba01ba7076a87d5", "scanner": "scanner-primary", "fingerprint": "f15260e5733bfb27", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-186f168ad7be8c07", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/build-excel-from-rows.ts:35"}, "properties": {"repobilityId": "97cf6ace624eb2a7", "scanner": "scanner-primary", "fingerprint": "186f168ad7be8c07", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0ac6af230baccfce", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-dian-stress.ts:43"}, "properties": {"repobilityId": "ecf4fd0a38eca9f0", "scanner": "scanner-primary", "fingerprint": "0ac6af230baccfce", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-75c6f26157c0d8fb", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-dian-massdl.ts:20"}, "properties": {"repobilityId": "fc1daadc2ef64929", "scanner": "scanner-primary", "fingerprint": "75c6f26157c0d8fb", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-aa8ad788794ad1b9", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-empty-excel.ts:1"}, "properties": {"repobilityId": "b3bc9282198dbadb", "scanner": "scanner-primary", "fingerprint": "aa8ad788794ad1b9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b021654aeb7f8295", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/migrateSqliteToMongo.ts:81"}, "properties": {"repobilityId": "e24e1a963579775d", "scanner": "scanner-primary", "fingerprint": "b021654aeb7f8295", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d7a76e1a73a17599", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-rut-xvfb.ts:8"}, "properties": {"repobilityId": "06d7e95817a06c00", "scanner": "scanner-primary", "fingerprint": "d7a76e1a73a17599", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2b2711d1936e0331", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/migrate-siigo-ownership.ts:24"}, "properties": {"repobilityId": "3321fec12720e682", "scanner": "scanner-primary", "fingerprint": "2b2711d1936e0331", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5872d596100ecd2d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-dian-3cufes.ts:24"}, "properties": {"repobilityId": "50610e816c007e76", "scanner": "scanner-primary", "fingerprint": "5872d596100ecd2d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8c253fbecbd670f6", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/index.ts:100"}, "properties": {"repobilityId": "867f5b4f120dafeb", "scanner": "scanner-primary", "fingerprint": "8c253fbecbd670f6", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5297ed881fe3ad54", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/middleware/requireIntegrationAuth.ts:52"}, "properties": {"repobilityId": "3dd7f4f9868f7ce4", "scanner": "scanner-primary", "fingerprint": "5297ed881fe3ad54", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-419989ce5d205a2b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/routes/dianMassDownload.ts:424"}, "properties": {"repobilityId": "8a3a9e1d8bab96bd", "scanner": "scanner-primary", "fingerprint": "419989ce5d205a2b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-86c8285930ee83aa", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/routes/causation.ts:80"}, "properties": {"repobilityId": "fe5374abb24314bc", "scanner": "scanner-primary", "fingerprint": "86c8285930ee83aa", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-84826d1c4290be74", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/routes/googleAuth.ts:227"}, "properties": {"repobilityId": "4131830d0ba72b7d", "scanner": "scanner-primary", "fingerprint": "84826d1c4290be74", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d078310284638773", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/routes/dianExcel.ts:147"}, "properties": {"repobilityId": "98fa459c7e2a7e02", "scanner": "scanner-primary", "fingerprint": "d078310284638773", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-267623cf7dc6feee", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/routes/dianCufeDownload.ts:515"}, "properties": {"repobilityId": "8cf8eac9e853f56f", "scanner": "scanner-primary", "fingerprint": "267623cf7dc6feee", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7c885120785fb583", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/routes/dian.ts:125"}, "properties": {"repobilityId": "fc833b2b0edb7bc6", "scanner": "scanner-primary", "fingerprint": "7c885120785fb583", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-70eea9c97a76f6ff", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/routes/siigo.ts:1165"}, "properties": {"repobilityId": "eddac1f173b4bd11", "scanner": "scanner-primary", "fingerprint": "70eea9c97a76f6ff", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-aba40baad1592835", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/services/siigoService.ts:233"}, "properties": {"repobilityId": "757c0ef3cd6fd7a2", "scanner": "scanner-primary", "fingerprint": "aba40baad1592835", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8a795a0722309aab", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/services/googleDrive.ts:61"}, "properties": {"repobilityId": "c200df8535baf758", "scanner": "scanner-primary", "fingerprint": "8a795a0722309aab", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-949c0a970b9819fd", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/services/causationInputService.ts:104"}, "properties": {"repobilityId": "f82e52cebfa54fcd", "scanner": "scanner-primary", "fingerprint": "949c0a970b9819fd", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-761c90f88d0dbeba", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/services/xmlParser.ts:71"}, "properties": {"repobilityId": "1dddaec44f7289c6", "scanner": "scanner-primary", "fingerprint": "761c90f88d0dbeba", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3abf70f7446e29cf", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/services/siigoCompaniesService.ts:285"}, "properties": {"repobilityId": "d5c3d396a056b657", "scanner": "scanner-primary", "fingerprint": "3abf70f7446e29cf", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4a501bd4cabab6f2", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/services/dianScraper.ts:193"}, "properties": {"repobilityId": "d023e0787cbff57c", "scanner": "scanner-primary", "fingerprint": "4a501bd4cabab6f2", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-402f05a1cd8b4086", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/services/database.ts:812"}, "properties": {"repobilityId": "6043017156aee307", "scanner": "scanner-primary", "fingerprint": "402f05a1cd8b4086", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-de7201adfe395b35", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/services/siigoAccountingService.ts:113"}, "properties": {"repobilityId": "91e34175b9300700", "scanner": "scanner-primary", "fingerprint": "de7201adfe395b35", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a35c6a00f751880f", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-slim"}, "properties": {"repobilityId": "2493e5de73cf9890", "scanner": "scanner-primary", "fingerprint": "a35c6a00f751880f", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-a35c6a00f751880f", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-slim"}, "properties": {"repobilityId": "5b39201d440a091e", "scanner": "scanner-primary", "fingerprint": "a35c6a00f751880f", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-77a464701f01cedf", "level": "error", "message": {"text": "Possible secret in README.md"}, "properties": {"repobilityId": "7e8d0f40ced2565c", "scanner": "scanner-primary", "fingerprint": "77a464701f01cedf", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "README.md"}, "region": {"startLine": 109}}}]}, {"ruleId": "scanner-9c209b7d3d74088c", "level": "error", "message": {"text": "Insecure pattern 'private_key_in_repo' in README.md:109"}, "properties": {"repobilityId": "9f3cd7a09905263d", "scanner": "scanner-primary", "fingerprint": "9c209b7d3d74088c", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["owasp", "private_key_in_repo"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "README.md"}, "region": {"startLine": 109}}}]}, {"ruleId": "scanner-1359d17c80883477", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/installPuppeteer.mjs:1"}, "properties": {"repobilityId": "e5e44f862cfde311", "scanner": "scanner-primary", "fingerprint": "1359d17c80883477", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/installPuppeteer.mjs"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1d8544ee21650f15", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/index.ts:7"}, "properties": {"repobilityId": "4deb876426214aa4", "scanner": "scanner-primary", "fingerprint": "1d8544ee21650f15", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/index.ts"}, "region": {"startLine": 7}}}]}, {"ruleId": "scanner-8890a1642f1a4977", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in src/routes/rutConsulta.ts:230"}, "properties": {"repobilityId": "6954205f2c780123", "scanner": "scanner-primary", "fingerprint": "8890a1642f1a4977", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/rutConsulta.ts"}, "region": {"startLine": 230}}}]}, {"ruleId": "scanner-cb639d9a10a47b23", "level": "note", "message": {"text": "package.json defines install-time lifecycle scripts"}, "properties": {"repobilityId": "edeab51902066991", "scanner": "scanner-primary", "fingerprint": "cb639d9a10a47b23", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "npm", "install-scripts"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-ee15057109e7166d", "level": "note", "message": {"text": "Very large file: src/routes/siigo.ts (1757 lines)"}, "properties": {"repobilityId": "750e1c8942a6f98b", "scanner": "scanner-primary", "fingerprint": "ee15057109e7166d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-68cc1643cec6b1b8", "level": "note", "message": {"text": "Very large file: src/services/dianScraper.ts (3028 lines)"}, "properties": {"repobilityId": "e8f209f36287b689", "scanner": "scanner-primary", "fingerprint": "68cc1643cec6b1b8", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ea3b5e389d8c9c0f", "level": "note", "message": {"text": "Low test-to-source ratio"}, "properties": {"repobilityId": "ef7b2552cc00a375", "scanner": "scanner-primary", "fingerprint": "ea3b5e389d8c9c0f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["tests"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "dfdc5eebfcdd0b87", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "d61543a728b6ef0d", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "310d599457a90871", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "b3e81223b0865a0b", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "04051808f9db367a", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "23e5ae0179cee7ce", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-974e0927fc27f5ce", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/test-rut-multi.ts:16"}, "properties": {"repobilityId": "fd1c6ab0d5f14b19", "scanner": "scanner-primary", "fingerprint": "974e0927fc27f5ce", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-b56625c78586eedd", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/test-rut.ts:35"}, "properties": {"repobilityId": "89275509b787199f", "scanner": "scanner-primary", "fingerprint": "b56625c78586eedd", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-3ecfad328a3d6c3c", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/test-xml.mjs:69"}, "properties": {"repobilityId": "d6f2bd826eabd123", "scanner": "scanner-primary", "fingerprint": "3ecfad328a3d6c3c", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-4a89ab756b793667", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/index.ts:107"}, "properties": {"repobilityId": "c3d8c22537e51b57", "scanner": "scanner-primary", "fingerprint": "4a89ab756b793667", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-009f93a76f1e8836", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/routes/dianCufeDownload.ts:408"}, "properties": {"repobilityId": "e081d329fc4a9fc4", "scanner": "scanner-primary", "fingerprint": "009f93a76f1e8836", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1debfa983a5dd28a", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/siigoService.ts:199"}, "properties": {"repobilityId": "1b1dc48baaa69df7", "scanner": "scanner-primary", "fingerprint": "1debfa983a5dd28a", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-09f75de9229cc603", "level": "note", "message": {"text": "Legacy-named symbol `tooOld` in src/services/rutConsultaService.ts:152"}, "properties": {"repobilityId": "656a58f8703ec236", "scanner": "scanner-primary", "fingerprint": "09f75de9229cc603", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-6d0115285d509215", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/rutConsultaService.ts:35"}, "properties": {"repobilityId": "f4f9751777866fe2", "scanner": "scanner-primary", "fingerprint": "6d0115285d509215", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-018487b6eeb01700", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/services/dianScraper.ts:72"}, "properties": {"repobilityId": "89eb27124fb082d4", "scanner": "scanner-primary", "fingerprint": "018487b6eeb01700", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8bb8a44df581d67e", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/dianScraper.ts:1868"}, "properties": {"repobilityId": "d1dcd883cd6134d9", "scanner": "scanner-primary", "fingerprint": "8bb8a44df581d67e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-c974e01ea0113a33", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/siigoSuggestionsService.ts:302"}, "properties": {"repobilityId": "cf90c652c18183dc", "scanner": "scanner-primary", "fingerprint": "c974e01ea0113a33", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-1870dbe394562110", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/bookmarkletTemplate.ts:64"}, "properties": {"repobilityId": "3b237b35ca02cccb", "scanner": "scanner-primary", "fingerprint": "1870dbe394562110", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-6adfe3d30ee9355f", "level": "note", "message": {"text": "40 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "a58f987b7fee95b4", "scanner": "scanner-primary", "fingerprint": "6adfe3d30ee9355f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-deba949b5fe6f339", "level": "error", "message": {"text": "Dangling fetch: POST https://api.capsolver.com/createTask (scripts/test-rut-multi.ts:16)"}, "properties": {"repobilityId": "43b76f24d93f418b", "scanner": "scanner-primary", "fingerprint": "deba949b5fe6f339", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-e87c846e02793bcd", "level": "error", "message": {"text": "Dangling fetch: POST https://api.capsolver.com/getTaskResult (scripts/test-rut-multi.ts:29)"}, "properties": {"repobilityId": "d1210ab8dc5c2b19", "scanner": "scanner-primary", "fingerprint": "e87c846e02793bcd", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-41e28b1e28593e8e", "level": "error", "message": {"text": "Dangling fetch: POST https://api.capsolver.com/createTask (scripts/test-rut.ts:18)"}, "properties": {"repobilityId": "8171eaf42a498c20", "scanner": "scanner-primary", "fingerprint": "41e28b1e28593e8e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-994c045937648faf", "level": "error", "message": {"text": "Dangling fetch: POST https://api.capsolver.com/getTaskResult (scripts/test-rut.ts:35)"}, "properties": {"repobilityId": "400e1bb232de02a5", "scanner": "scanner-primary", "fingerprint": "994c045937648faf", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-76a243c9eaaf9ce7", "level": "error", "message": {"text": "Dangling fetch: GET /v1/vouchers (src/services/siigoService.ts:456)"}, "properties": {"repobilityId": "77d5f5a4375eefcb", "scanner": "scanner-primary", "fingerprint": "76a243c9eaaf9ce7", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-39252aa67bbc916f", "level": "error", "message": {"text": "Dangling fetch: GET /v1/journals (src/services/siigoService.ts:461)"}, "properties": {"repobilityId": "21c6aa95f598b0b8", "scanner": "scanner-primary", "fingerprint": "39252aa67bbc916f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-26b2c0024a60b864", "level": "error", "message": {"text": "Dangling fetch: POST /v1/credit-notes (src/services/siigoService.ts:547)"}, "properties": {"repobilityId": "e2ff802c6af4da64", "scanner": "scanner-primary", "fingerprint": "26b2c0024a60b864", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-3d09b70d8979bf1c", "level": "error", "message": {"text": "Dangling fetch: POST /v1/journals (src/services/siigoService.ts:557)"}, "properties": {"repobilityId": "be1671403b73f8e7", "scanner": "scanner-primary", "fingerprint": "3d09b70d8979bf1c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-91bb6877b117e67d", "level": "error", "message": {"text": "Dangling fetch: POST https://api.capsolver.com/createTask (src/services/rutConsultaService.ts:14)"}, "properties": {"repobilityId": "70d11c9500217456", "scanner": "scanner-primary", "fingerprint": "91bb6877b117e67d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-dbf2c2866614fd88", "level": "error", "message": {"text": "Dangling fetch: POST https://api.capsolver.com/getTaskResult (src/services/rutConsultaService.ts:35)"}, "properties": {"repobilityId": "72f03e7fef164347", "scanner": "scanner-primary", "fingerprint": "dbf2c2866614fd88", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-c4379632dcb1b8b1", "level": "error", "message": {"text": "Dangling fetch: POST /v1/test-balance-report-by-thirdparty (src/services/siigoSuggestionsService.ts:300)"}, "properties": {"repobilityId": "13914dc1758cbd7a", "scanner": "scanner-primary", "fingerprint": "c4379632dcb1b8b1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-b28d92215a503990", "level": "note", "message": {"text": "Unused endpoint: USE /auth"}, "properties": {"repobilityId": "76e9796925726655", "scanner": "scanner-primary", "fingerprint": "b28d92215a503990", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a1d1c53a33cd39a3", "level": "note", "message": {"text": "Unused endpoint: USE /auth/google"}, "properties": {"repobilityId": "a1fbf4d8933bfc6a", "scanner": "scanner-primary", "fingerprint": "a1d1c53a33cd39a3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ab58e8f7d4755a17", "level": "note", "message": {"text": "Unused endpoint: USE /portal-status"}, "properties": {"repobilityId": "49985f322d8b8d2c", "scanner": "scanner-primary", "fingerprint": "ab58e8f7d4755a17", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b2d8849fb6b1ac47", "level": "note", "message": {"text": "Unused endpoint: USE /admin"}, "properties": {"repobilityId": "7855f43f7d9739c3", "scanner": "scanner-primary", "fingerprint": "b2d8849fb6b1ac47", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e5fa0167867e1351", "level": "note", "message": {"text": "Unused endpoint: USE /dian"}, "properties": {"repobilityId": "7a0396c3aef2c4a6", "scanner": "scanner-primary", "fingerprint": "e5fa0167867e1351", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3ed8ef2a9dea4e05", "level": "note", "message": {"text": "Unused endpoint: USE /dian-excel"}, "properties": {"repobilityId": "b0bce2483589c4d5", "scanner": "scanner-primary", "fingerprint": "3ed8ef2a9dea4e05", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0673a848962af705", "level": "note", "message": {"text": "Unused endpoint: USE /dian-third-parties"}, "properties": {"repobilityId": "3cf5c20ba21d2011", "scanner": "scanner-primary", "fingerprint": "0673a848962af705", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-86c296db9fc103b1", "level": "note", "message": {"text": "Unused endpoint: USE /dian-cufe"}, "properties": {"repobilityId": "5a4fdec951a7cbca", "scanner": "scanner-primary", "fingerprint": "86c296db9fc103b1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dfd1292396da5059", "level": "note", "message": {"text": "Unused endpoint: USE /dian-mass-download"}, "properties": {"repobilityId": "f254bd52b971e769", "scanner": "scanner-primary", "fingerprint": "dfd1292396da5059", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d718b3520b8e853c", "level": "note", "message": {"text": "Unused endpoint: USE /integrations/siigo"}, "properties": {"repobilityId": "a734a43365fb3f01", "scanner": "scanner-primary", "fingerprint": "d718b3520b8e853c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-86e312764c06162a", "level": "note", "message": {"text": "Unused endpoint: USE /causation"}, "properties": {"repobilityId": "fd8cf03229aff001", "scanner": "scanner-primary", "fingerprint": "86e312764c06162a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b19480c187b352f3", "level": "note", "message": {"text": "Unused endpoint: USE /conciliacion"}, "properties": {"repobilityId": "1aa7eddc835c3685", "scanner": "scanner-primary", "fingerprint": "b19480c187b352f3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-677bb3f3ad6beaac", "level": "note", "message": {"text": "Unused endpoint: USE /caja-erp"}, "properties": {"repobilityId": "a19a419b88af80a5", "scanner": "scanner-primary", "fingerprint": "677bb3f3ad6beaac", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "1d5a1a5881aabadf", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fca11d494725d7c3", "level": "note", "message": {"text": "Unused endpoint: POST /analyze"}, "properties": {"repobilityId": "b469fc7106da2356", "scanner": "scanner-primary", "fingerprint": "fca11d494725d7c3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-581797447c054d7b", "level": "note", "message": {"text": "Unused endpoint: POST /reconcile"}, "properties": {"repobilityId": "7c7a6f84d937eeaa", "scanner": "scanner-primary", "fingerprint": "581797447c054d7b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7028d9c853d87627", "level": "note", "message": {"text": "Unused endpoint: POST /export"}, "properties": {"repobilityId": "7e29fafa7afbed70", "scanner": "scanner-primary", "fingerprint": "7028d9c853d87627", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-aa2a58e374c0f7c9", "level": "note", "message": {"text": "Unused endpoint: GET /job-status/:jobId"}, "properties": {"repobilityId": "7b5ccf027dfaad40", "scanner": "scanner-primary", "fingerprint": "aa2a58e374c0f7c9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7076c80fb2226378", "level": "note", "message": {"text": "Unused endpoint: GET /job-download/:jobId"}, "properties": {"repobilityId": "673a21925c4f373b", "scanner": "scanner-primary", "fingerprint": "7076c80fb2226378", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-78063faf7233f3fc", "level": "note", "message": {"text": "Unused endpoint: POST /job-cancel/:jobId"}, "properties": {"repobilityId": "c3a7b83e70805fe8", "scanner": "scanner-primary", "fingerprint": "78063faf7233f3fc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a13a7e97aeacf55f", "level": "note", "message": {"text": "Unused endpoint: POST /start"}, "properties": {"repobilityId": "6bcbf2cf24f77a1b", "scanner": "scanner-primary", "fingerprint": "a13a7e97aeacf55f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-618721b912bad1c2", "level": "note", "message": {"text": "Unused endpoint: POST /login"}, "properties": {"repobilityId": "99af822a4b4c46ce", "scanner": "scanner-primary", "fingerprint": "618721b912bad1c2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-304b6f2b403d93f7", "level": "note", "message": {"text": "Unused endpoint: POST /register"}, "properties": {"repobilityId": "19581a08e78df03e", "scanner": "scanner-primary", "fingerprint": "304b6f2b403d93f7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0bf5c69465cb5483", "level": "note", "message": {"text": "Unused endpoint: GET /demo-invites/:token"}, "properties": {"repobilityId": "7675f454efeede17", "scanner": "scanner-primary", "fingerprint": "0bf5c69465cb5483", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-252326a8e232b70f", "level": "note", "message": {"text": "Unused endpoint: POST /demo/register"}, "properties": {"repobilityId": "b7ec61b96590777d", "scanner": "scanner-primary", "fingerprint": "252326a8e232b70f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-99fc36db98c134ce", "level": "note", "message": {"text": "Unused endpoint: POST /logout"}, "properties": {"repobilityId": "c0752dd0ec544c62", "scanner": "scanner-primary", "fingerprint": "99fc36db98c134ce", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a34e686ab26b7733", "level": "note", "message": {"text": "Unused endpoint: POST /admin/create-user"}, "properties": {"repobilityId": "df45da8d8e444bf7", "scanner": "scanner-primary", "fingerprint": "a34e686ab26b7733", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd1dc91abf32142d", "level": "note", "message": {"text": "Unused endpoint: GET /me"}, "properties": {"repobilityId": "a85c0f183d978189", "scanner": "scanner-primary", "fingerprint": "fd1dc91abf32142d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e738bbb5b457b24b", "level": "note", "message": {"text": "Unused endpoint: GET /kanban"}, "properties": {"repobilityId": "a92a70ec62918192", "scanner": "scanner-primary", "fingerprint": "e738bbb5b457b24b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1dee6097d92f76ad", "level": "note", "message": {"text": "Unused endpoint: PUT /kanban"}, "properties": {"repobilityId": "fa0e356947fe8fe9", "scanner": "scanner-primary", "fingerprint": "1dee6097d92f76ad", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4fe9bb486644f008", "level": "note", "message": {"text": "Unused endpoint: POST /change-password"}, "properties": {"repobilityId": "bfd7d593015dcfa5", "scanner": "scanner-primary", "fingerprint": "4fe9bb486644f008", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-21792688fabb1a87", "level": "note", "message": {"text": "Unused endpoint: POST /test-openai-file"}, "properties": {"repobilityId": "eccda94c046b4e94", "scanner": "scanner-primary", "fingerprint": "21792688fabb1a87", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ad8ce37bb46294de", "level": "note", "message": {"text": "Unused endpoint: POST /build"}, "properties": {"repobilityId": "fba169232e56b19b", "scanner": "scanner-primary", "fingerprint": "ad8ce37bb46294de", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d345fa90f5de3745", "level": "note", "message": {"text": "Unused endpoint: GET /authorize"}, "properties": {"repobilityId": "7f3de83d744554ac", "scanner": "scanner-primary", "fingerprint": "d345fa90f5de3745", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c330a85f2b3723e2", "level": "note", "message": {"text": "Unused endpoint: POST /authorize-url"}, "properties": {"repobilityId": "6cae001c289b0933", "scanner": "scanner-primary", "fingerprint": "c330a85f2b3723e2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cdfb578618cf2542", "level": "note", "message": {"text": "Unused endpoint: GET /callback"}, "properties": {"repobilityId": "9e216473dfab9f4f", "scanner": "scanner-primary", "fingerprint": "cdfb578618cf2542", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-540ebf4772ccf420", "level": "note", "message": {"text": "Unused endpoint: POST /disconnect"}, "properties": {"repobilityId": "a51da76eaf217278", "scanner": "scanner-primary", "fingerprint": "540ebf4772ccf420", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fa4d04d3d9445e38", "level": "note", "message": {"text": "Unused endpoint: POST /select"}, "properties": {"repobilityId": "89a1302a063948fc", "scanner": "scanner-primary", "fingerprint": "fa4d04d3d9445e38", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-970eb92d6ec2bfaa", "level": "note", "message": {"text": "Unused endpoint: POST /generate"}, "properties": {"repobilityId": "a9a6e0951b002349", "scanner": "scanner-primary", "fingerprint": "970eb92d6ec2bfaa", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cd064d46b37a617a", "level": "note", "message": {"text": "Unused endpoint: GET /download/:jobId"}, "properties": {"repobilityId": "0c0b88a31801d910", "scanner": "scanner-primary", "fingerprint": "cd064d46b37a617a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-21c06842a0c4334b", "level": "note", "message": {"text": "Unused endpoint: GET /download-files/:jobId"}, "properties": {"repobilityId": "f6a1e66e239d1e5f", "scanner": "scanner-primary", "fingerprint": "21c06842a0c4334b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-adec5374797f4ae7", "level": "note", "message": {"text": "Unused endpoint: POST /consultar"}, "properties": {"repobilityId": "f0db6800bcc36582", "scanner": "scanner-primary", "fingerprint": "adec5374797f4ae7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-90631dcf4fb49f54", "level": "note", "message": {"text": "Unused endpoint: POST /bulk"}, "properties": {"repobilityId": "49cbb891f4f44e34", "scanner": "scanner-primary", "fingerprint": "90631dcf4fb49f54", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-70256c5efade35d2", "level": "note", "message": {"text": "Unused endpoint: GET /bulk-status/:jobId"}, "properties": {"repobilityId": "a7cd7746cbdf6c72", "scanner": "scanner-primary", "fingerprint": "70256c5efade35d2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ab94f4c23984996b", "level": "note", "message": {"text": "Unused endpoint: GET /validar/:nit"}, "properties": {"repobilityId": "9670e0138ea15774", "scanner": "scanner-primary", "fingerprint": "ab94f4c23984996b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b38efdd655f6ccd8", "level": "note", "message": {"text": "Unused endpoint: POST /browser-job"}, "properties": {"repobilityId": "b574552efb1febf4", "scanner": "scanner-primary", "fingerprint": "b38efdd655f6ccd8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-45a95efa75cfa1b6", "level": "note", "message": {"text": "Unused endpoint: GET /browser-job/:jobId/status"}, "properties": {"repobilityId": "a5ce604cab302fb7", "scanner": "scanner-primary", "fingerprint": "45a95efa75cfa1b6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-862ca1beb2ad0757", "level": "note", "message": {"text": "Unused endpoint: GET /bookmarklet.js"}, "properties": {"repobilityId": "bfab3e79e4e6a5ff", "scanner": "scanner-primary", "fingerprint": "862ca1beb2ad0757", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f901b4788a1eae72", "level": "note", "message": {"text": "Unused endpoint: OPTIONS /browser-job/:jobId/pending"}, "properties": {"repobilityId": "80972237700b17c7", "scanner": "scanner-primary", "fingerprint": "f901b4788a1eae72", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-974329c2e6f5a3ee", "level": "note", "message": {"text": "Unused endpoint: GET /browser-job/:jobId/pending"}, "properties": {"repobilityId": "1eaf4c970240d93c", "scanner": "scanner-primary", "fingerprint": "974329c2e6f5a3ee", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}