{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-56340619a18d260b", "name": "Stray `console.log` in TS/JS \u2014 backend/autopub.js:138", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/autopub.js:138"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0710009c872fc892", "name": "Stray `console.log` in TS/JS \u2014 backend/migrate.js:118", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrate.js:118"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-39ed0ccfedc92fd0", "name": "Stray `console.log` in TS/JS \u2014 backend/youtube-videos.js:142", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/youtube-videos.js:142"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-507be11eec983006", "name": "Stray `console.log` in TS/JS \u2014 backend/startup-validator.js:112", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/startup-validator.js:112"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f87aca58daeb41c5", "name": "Stray `console.log` in TS/JS \u2014 backend/monitor.js:224", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/monitor.js:224"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5b6b1b7da7ba44d2", "name": "Stray `console.log` in TS/JS \u2014 backend/telegram.js:646", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/telegram.js:646"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3df0717b81a86207", "name": "Stray `console.log` in TS/JS \u2014 backend/server.js:21", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/server.js:21"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-70ab0911e4a4ef3e", "name": "Stray `console.log` in TS/JS \u2014 backend/scrapers/headless-content.js:184", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/scrapers/headless-content.js:184"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f77358da31644ced", "name": "Stray `console.log` in TS/JS \u2014 backend/scrapers/full-content.js:249", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/scrapers/full-content.js:249"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d1a2772621fddbed", "name": "Stray `console.log` in TS/JS \u2014 backend/connectors/wordpress.js:80", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/connectors/wordpress.js:80"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eb372675c7b8f868", "name": "Stray `console.log` in TS/JS \u2014 backend/connectors/whatsapp.js:55", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/connectors/whatsapp.js:55"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ad7a6a76cf50ea9e", "name": "Stray `console.log` in TS/JS \u2014 backend/utils/card-generator.js:392", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/utils/card-generator.js:392"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c61c7d835abc36ba", "name": "Stray `console.log` in TS/JS \u2014 backend/routes/admin.js:265", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/routes/admin.js:265"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-21fbd4d9e93f8d14", "name": "Stray `console.log` in TS/JS \u2014 backend/routes/publish.js:75", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/routes/publish.js:75"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1870546bd99afd3c", "name": "Stray `console.log` in TS/JS \u2014 backend/routes/drafts.js:22", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/routes/drafts.js:22"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b4e45b7d0ee64a79", "name": "Stray `console.log` in TS/JS \u2014 backend/db/setup.js:27", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/db/setup.js:27"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2fa0a9e0aff3316a", "name": "Stray `console.log` in TS/JS \u2014 backend/db/diagnostico-imagens.js:93", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/db/diagnostico-imagens.js:93"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8e6bd461bbb8b505", "name": "Stray `console.log` in TS/JS \u2014 backend/db/diagnostico-deep.js:17", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/db/diagnostico-deep.js:17"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ac5b848b21ae768b", "name": "Stray `console.log` in TS/JS \u2014 backend/db/seed.js:15", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/db/seed.js:15"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-33062f66588ab6e0", "name": "Stray `console.log` in TS/JS \u2014 backend/db/fix-images.js:23", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/db/fix-images.js:23"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c265f938b71f61de", "name": "Stray `console.log` in TS/JS \u2014 backend/db/inspect-govrs-alers.js:15", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/db/inspect-govrs-alers.js:15"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1f1385f2b04b6cf5", "name": "Insecure pattern 'direct_innerhtml_assignment' in index.html:1986", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in index.html:1986"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9d8d908f0355d360", "name": "Insecure pattern 'cors_wildcard' in cloudflare-worker-sc-proxy.js:20", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in cloudflare-worker-sc-proxy.js:20"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bbd972b8f521f67f", "name": "Insecure pattern 'local_storage_auth_token' in frontend/subscriber/login.html:255", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in frontend/subscriber/login.html:255"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4a52240cff6884f2", "name": "Insecure pattern 'direct_innerhtml_assignment' in frontend/subscriber/index.html:1115", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in frontend/subscriber/index.html:1115"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bf19a391ab5eafc0", "name": "Insecure pattern 'direct_innerhtml_assignment' in frontend/subscriber/admin.html:2559", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in frontend/subscriber/admin.html:2559"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f393285bb8e1aea5", "name": "Insecure pattern 'insert_adjacent_html' in frontend/subscriber/admin.html:3590", "shortDescription": {"text": "Insecure pattern 'insert_adjacent_html' in frontend/subscriber/admin.html:3590"}, "fullDescription": {"text": "Found a known-risky pattern (insert_adjacent_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6d45b74f6677a7ec", "name": "Insecure pattern 'direct_innerhtml_assignment' in frontend/subscriber/coluna.html:192", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in frontend/subscriber/coluna.html:192"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-90fcb44d9b461505", "name": "Possible secret in .claude/settings.local.json", "shortDescription": {"text": "Possible secret in .claude/settings.local.json"}, "fullDescription": {"text": "Detected pattern matching password_literal. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-df142b7be32c2bf0", "name": "Insecure pattern 'node_child_process' in backend/monitor.js:31", "shortDescription": {"text": "Insecure pattern 'node_child_process' in backend/monitor.js:31"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6f1484849c8457d8", "name": "Insecure pattern 'cors_wildcard' in backend/routes/image-proxy.js:65", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in backend/routes/image-proxy.js:65"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-28c4a04bd807da0c", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "appleboy/ssh-action@v1.0.3 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7f2ad7d9bd07fa21", "name": "Very large file: backend/server.js (1722 lines)", "shortDescription": {"text": "Very large file: backend/server.js (1722 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-25a166cb7f7ea9c1", "name": "Very large file: backend/routes/admin.js (1292 lines)", "shortDescription": {"text": "Very large file: backend/routes/admin.js (1292 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "0 test file(s) for 53 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 171 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9d79c4077342a7d0", "name": "Runtime service client appears to use placeholder configuration", "shortDescription": {"text": "Runtime service client appears to use placeholder configuration"}, "fullDescription": {"text": "A runtime source file appears to wire Supabase/Firebase/AI/payment-style clients to placeholder URLs, keys, or fallback values. In the Fable corpus this often means the UI/API shape is present while the backend service is not actually configured."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-11825279136b53a3", "name": "CI is configured but no tests are detected", "shortDescription": {"text": "CI is configured but no tests are detected"}, "fullDescription": {"text": "A CI pipeline exists, but the scan found no test files to gate. Opus labeled this generated-code pattern as config theater: release machinery exists, but it has little behavioral signal."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, tests. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license, tests. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ecb0d2c55ed6875d", "name": "Agent authority lacks a verifier contract: .claude/settings.local.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/settings.local.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2a0f59a9864856b8", "name": "`fetch()` without try/.catch or AbortSignal \u2014 cloudflare-worker-sc-proxy.js:16", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 cloudflare-worker-sc-proxy.js:16"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b30c5a65d32a13b2", "name": "Commented-code block (6 lines) in backend/telegram.js:47", "shortDescription": {"text": "Commented-code block (6 lines) in backend/telegram.js:47"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0824c033ca6b60ae", "name": "Commented-code block (7 lines) in backend/server.js:1047", "shortDescription": {"text": "Commented-code block (7 lines) in backend/server.js:1047"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bbef0d55a8571350", "name": "Commented-code block (5 lines) in backend/connectors/hashtags.js:7", "shortDescription": {"text": "Commented-code block (5 lines) in backend/connectors/hashtags.js:7"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-fe999cfc1ab754e0", "name": "`fetch()` without try/.catch or AbortSignal \u2014 backend/connectors/blogger.js:7", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/connectors/blogger.js:7"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cc4f7e2e85950661", "name": "Commented-code block (7 lines) in backend/connectors/facebook.js:17", "shortDescription": {"text": "Commented-code block (7 lines) in backend/connectors/facebook.js:17"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-72967d777ce66a6e", "name": "Commented-code block (5 lines) in backend/connectors/wordpress.js:173", "shortDescription": {"text": "Commented-code block (5 lines) in backend/connectors/wordpress.js:173"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-69713650f15d76a6", "name": "`fetch()` without try/.catch or AbortSignal \u2014 backend/db/diagnostico-deep.js:10", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/db/diagnostico-deep.js:10"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b0b5e7cb1208a7cd", "name": "13 env vars used in code but missing from .env.example", "shortDescription": {"text": "13 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `ADMIN_PASSWORD`, `CF_PROXY_TOKEN`, `CF_PROXY_URL`, `EVOLUTION_API_KEY`, `EVOLUTION_API_URL`, `GOOGLE_CLIENT_ID`, `GOOGLE_CLIENT_SECRET`, `MONITOR_BOT_TOKEN` + 5 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-32b3d353a2a39830", "name": "Dangling fetch: POST https://api.deepseek.com/chat/completions (backend/autopub.js:50)", "shortDescription": {"text": "Dangling fetch: POST https://api.deepseek.com/chat/completions (backend/autopub.js:50)"}, "fullDescription": {"text": "`backend/autopub.js:50` calls `POST https://api.deepseek.com/chat/completions` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/api.deepseek.com/chat/completions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e2193352bdfb800b", "name": "Dangling fetch: POST https://api.openai.com/v1/audio/transcriptions (backend/telegram.js:191)", "shortDescription": {"text": "Dangling fetch: POST https://api.openai.com/v1/audio/transcriptions (backend/telegram.js:191)"}, "fullDescription": {"text": "`backend/telegram.js:191` calls `POST https://api.openai.com/v1/audio/transcriptions` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/api.openai.com/v1/audio/transcriptions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c56c78404e8e8784", "name": "Dangling fetch: POST https://api.deepseek.com/chat/completions (backend/telegram.js:204)", "shortDescription": {"text": "Dangling fetch: POST https://api.deepseek.com/chat/completions (backend/telegram.js:204)"}, "fullDescription": {"text": "`backend/telegram.js:204` calls `POST https://api.deepseek.com/chat/completions` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/api.deepseek.com/chat/completions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-70a511ba29eb42ae", "name": "Dangling fetch: POST https://api.deepseek.com/chat/completions (backend/connectors/hashtags.js:88)", "shortDescription": {"text": "Dangling fetch: POST https://api.deepseek.com/chat/completions (backend/connectors/hashtags.js:88)"}, "fullDescription": {"text": "`backend/connectors/hashtags.js:88` calls `POST https://api.deepseek.com/chat/completions` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/api.deepseek.com/chat/completions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7003d4557b69e213", "name": "Dangling fetch: POST https://oauth2.googleapis.com/token (backend/connectors/blogger.js:7)", "shortDescription": {"text": "Dangling fetch: POST https://oauth2.googleapis.com/token (backend/connectors/blogger.js:7)"}, "fullDescription": {"text": "`backend/connectors/blogger.js:7` calls `POST https://oauth2.googleapis.com/token` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/oauth2.googleapis.com/token`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fb32badbb7ccf987", "name": "Dangling fetch: POST https://www.googleapis.com/blogger/v3/blogs/${site.blogger_blog_id}/posts/ (backend/connectors/blog", "shortDescription": {"text": "Dangling fetch: POST https://www.googleapis.com/blogger/v3/blogs/${site.blogger_blog_id}/posts/ (backend/connectors/blogger.js:47)"}, "fullDescription": {"text": "`backend/connectors/blogger.js:47` calls `POST https://www.googleapis.com/blogger/v3/blogs/${site.blogger_blog_id}/posts/` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/www.googleapis.com/blogger/v3/blogs/<p>/posts`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-12daf4eaf8baf060", "name": "Dangling fetch: POST https://api.telegram.org/bot${token}/sendMessage (backend/utils/telegram-notify.js:36)", "shortDescription": {"text": "Dangling fetch: POST https://api.telegram.org/bot${token}/sendMessage (backend/utils/telegram-notify.js:36)"}, "fullDescription": {"text": "`backend/utils/telegram-notify.js:36` calls `POST https://api.telegram.org/bot${token}/sendMessage` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/api.telegram.org/bot/<p>/sendmessage`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b598094bc0b768fa", "name": "Dangling fetch: POST https://api.deepseek.com/chat/completions (backend/utils/source-detector.js:104)", "shortDescription": {"text": "Dangling fetch: POST https://api.deepseek.com/chat/completions (backend/utils/source-detector.js:104)"}, "fullDescription": {"text": "`backend/utils/source-detector.js:104` calls `POST https://api.deepseek.com/chat/completions` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/api.deepseek.com/chat/completions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-de68d700735e3351", "name": "Dangling fetch: GET https://graph.facebook.com/v20.0/act_${accountId} (backend/routes/admin.js:1016)", "shortDescription": {"text": "Dangling fetch: GET https://graph.facebook.com/v20.0/act_${accountId} (backend/routes/admin.js:1016)"}, "fullDescription": {"text": "`backend/routes/admin.js:1016` calls `GET https://graph.facebook.com/v20.0/act_${accountId}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/graph.facebook.com/v20.0/act_/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-70b6338d59dbb483", "name": "Dangling fetch: POST https://api.deepseek.com/chat/completions (backend/routes/admin.js:1091)", "shortDescription": {"text": "Dangling fetch: POST https://api.deepseek.com/chat/completions (backend/routes/admin.js:1091)"}, "fullDescription": {"text": "`backend/routes/admin.js:1091` calls `POST https://api.deepseek.com/chat/completions` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/api.deepseek.com/chat/completions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-91bd27dcd804109b", "name": "Dangling fetch: POST https://api.deepseek.com/chat/completions (backend/routes/ia.js:79)", "shortDescription": {"text": "Dangling fetch: POST https://api.deepseek.com/chat/completions (backend/routes/ia.js:79)"}, "fullDescription": {"text": "`backend/routes/ia.js:79` calls `POST https://api.deepseek.com/chat/completions` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/api.deepseek.com/chat/completions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-45fdf66d5b3bc917", "name": "Dangling fetch: POST https://api.deepseek.com/chat/completions (backend/routes/ia.js:147)", "shortDescription": {"text": "Dangling fetch: POST https://api.deepseek.com/chat/completions (backend/routes/ia.js:147)"}, "fullDescription": {"text": "`backend/routes/ia.js:147` calls `POST https://api.deepseek.com/chat/completions` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/api.deepseek.com/chat/completions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-885b9aeb8421455d", "name": "Dangling fetch: POST https://api.deepseek.com/chat/completions (backend/routes/ia.js:190)", "shortDescription": {"text": "Dangling fetch: POST https://api.deepseek.com/chat/completions (backend/routes/ia.js:190)"}, "fullDescription": {"text": "`backend/routes/ia.js:190` calls `POST https://api.deepseek.com/chat/completions` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/api.deepseek.com/chat/completions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f9ea876ff3178b7e", "name": "Dangling fetch: GET https://sombrio.sc.gov.br/2026/04/16/parceria-entre-o-citi-e-alunos-sombrienses-produz-bolsas-ecolog", "shortDescription": {"text": "Dangling fetch: GET https://sombrio.sc.gov.br/2026/04/16/parceria-entre-o-citi-e-alunos-sombrienses-produz-bolsas-ecologicamente-corretas/ (backend/db/diagnostico-deep.js:18)"}, "fullDescription": {"text": "`backend/db/diagnostico-deep.js:18` calls `GET https://sombrio.sc.gov.br/2026/04/16/parceria-entre-o-citi-e-alunos-sombrienses-produz-bolsas-ecologicamente-corretas/` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/sombrio.sc.gov.br/<p>/<p>/<p>/parceria-entre-o-citi-e-alunos-sombrienses-produz-bolsas-ecologicamente-corretas`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-82311b522606f487", "name": "Dangling fetch: GET https://www.capaodacanoa.rs.gov.br/noticia/view/874/segunda-edicao-da-feira-de-pascoa-sabor-e-tradic", "shortDescription": {"text": "Dangling fetch: GET https://www.capaodacanoa.rs.gov.br/noticia/view/874/segunda-edicao-da-feira-de-pascoa-sabor-e-tradicao-supera-expectativas-e-movimenta-capao-da-canoa (backend/db/diagnostico-deep.js:26)"}, "fullDescription": {"text": "`backend/db/diagnostico-deep.js:26` calls `GET https://www.capaodacanoa.rs.gov.br/noticia/view/874/segunda-edicao-da-feira-de-pascoa-sabor-e-tradicao-supera-expectativas-e-movimenta-capao-da-canoa` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/www.capaodacanoa.rs.gov.br/noticia/view/<p>/segunda-edicao-da-feira-de-pascoa-sabor-e-tradicao-supera-expectativas-e-movimenta-capao-da-canoa`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cbc6913bf8818eb7", "name": "Dangling fetch: GET https://ww4.al.rs.gov.br/noticia/343265 (backend/db/diagnostico-deep.js:52)", "shortDescription": {"text": "Dangling fetch: GET https://ww4.al.rs.gov.br/noticia/343265 (backend/db/diagnostico-deep.js:52)"}, "fullDescription": {"text": "`backend/db/diagnostico-deep.js:52` calls `GET https://ww4.al.rs.gov.br/noticia/343265` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/ww4.al.rs.gov.br/noticia/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`backend/server.js` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4523275038ad5934", "name": "Unused endpoint: GET /api/preview/:token", "shortDescription": {"text": "Unused endpoint: GET /api/preview/:token"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/preview/:token` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1bc898b3b7565990", "name": "Unused endpoint: USE /uploads", "shortDescription": {"text": "Unused endpoint: USE /uploads"}, "fullDescription": {"text": "`backend/server.js` declares `USE /uploads` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-84bd4c31da0619b1", "name": "Unused endpoint: USE /api/uploads", "shortDescription": {"text": "Unused endpoint: USE /api/uploads"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/uploads` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dde3adb27bf7eebe", "name": "Unused endpoint: USE /api", "shortDescription": {"text": "Unused endpoint: USE /api"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6eb452fbfb454d20", "name": "Unused endpoint: USE /api/auth", "shortDescription": {"text": "Unused endpoint: USE /api/auth"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/auth` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-07c4bba00fd83bc9", "name": "Unused endpoint: USE /api/articles", "shortDescription": {"text": "Unused endpoint: USE /api/articles"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/articles` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5979f2f5be25c70b", "name": "Unused endpoint: USE /api/publish", "shortDescription": {"text": "Unused endpoint: USE /api/publish"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/publish` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4c6fcb9d6bfeb851", "name": "Unused endpoint: USE /api/sites", "shortDescription": {"text": "Unused endpoint: USE /api/sites"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/sites` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-375cbbc5a3cc2d4a", "name": "Unused endpoint: USE /api/drafts", "shortDescription": {"text": "Unused endpoint: USE /api/drafts"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/drafts` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c3f095befe80f027", "name": "Unused endpoint: USE /api/publications", "shortDescription": {"text": "Unused endpoint: USE /api/publications"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/publications` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d3038f43cdd12233", "name": "Unused endpoint: USE /api/subscriber/sources", "shortDescription": {"text": "Unused endpoint: USE /api/subscriber/sources"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/subscriber/sources` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5e1951ffed949c70", "name": "Unused endpoint: USE /api/subscriber", "shortDescription": {"text": "Unused endpoint: USE /api/subscriber"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/subscriber` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e1ae3aeb68b3c3c1", "name": "Unused endpoint: USE /api/ia", "shortDescription": {"text": "Unused endpoint: USE /api/ia"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/ia` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-379b09f9de636500", "name": "Unused endpoint: GET /api/settings", "shortDescription": {"text": "Unused endpoint: GET /api/settings"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-16e94a53f296ada6", "name": "Unused endpoint: USE /api/contato", "shortDescription": {"text": "Unused endpoint: USE /api/contato"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/contato` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8316edd4aabd9834", "name": "Unused endpoint: USE /api/proxy-image", "shortDescription": {"text": "Unused endpoint: USE /api/proxy-image"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/proxy-image` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1fef85ca80065d2f", "name": "Unused endpoint: USE /api/admin/sites-catalog", "shortDescription": {"text": "Unused endpoint: USE /api/admin/sites-catalog"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/admin/sites-catalog` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b72ae661584b27a8", "name": "Unused endpoint: USE /api/admin/whatsapp", "shortDescription": {"text": "Unused endpoint: USE /api/admin/whatsapp"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/admin/whatsapp` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d9e69da016ad7528", "name": "Unused endpoint: USE /api/admin/youtube", "shortDescription": {"text": "Unused endpoint: USE /api/admin/youtube"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/admin/youtube` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1ec35b081427a3d4", "name": "Unused endpoint: USE /api/colunista", "shortDescription": {"text": "Unused endpoint: USE /api/colunista"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/colunista` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-58ba43d81b84919f", "name": "Unused endpoint: USE /api/plugin", "shortDescription": {"text": "Unused endpoint: USE /api/plugin"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/plugin` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-acfcb211f61ac2dc", "name": "Unused endpoint: USE /api/admin/plugin", "shortDescription": {"text": "Unused endpoint: USE /api/admin/plugin"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/admin/plugin` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa4bac17ad96cfe0", "name": "Unused endpoint: GET /api/admin/card-templates", "shortDescription": {"text": "Unused endpoint: GET /api/admin/card-templates"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/admin/card-templates` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0b889f3e42be0cac", "name": "Unused endpoint: GET /api/admin/fontes-saude", "shortDescription": {"text": "Unused endpoint: GET /api/admin/fontes-saude"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/admin/fontes-saude` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3add7d22af0e0830", "name": "Unused endpoint: POST /api/admin/card-templates", "shortDescription": {"text": "Unused endpoint: POST /api/admin/card-templates"}, "fullDescription": {"text": "`backend/server.js` declares `POST /api/admin/card-templates` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-93993223f7b2434f", "name": "Unused endpoint: DELETE /api/admin/card-templates/:slug", "shortDescription": {"text": "Unused endpoint: DELETE /api/admin/card-templates/:slug"}, "fullDescription": {"text": "`backend/server.js` declares `DELETE /api/admin/card-templates/:slug` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9d4e2fe59b84a714", "name": "Unused endpoint: GET /api/admin/card-templates/:slug/layout", "shortDescription": {"text": "Unused endpoint: GET /api/admin/card-templates/:slug/layout"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/admin/card-templates/:slug/layout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4d15ed579d038aaf", "name": "Unused endpoint: POST /api/admin/card-templates/:slug/preview", "shortDescription": {"text": "Unused endpoint: POST /api/admin/card-templates/:slug/preview"}, "fullDescription": {"text": "`backend/server.js` declares `POST /api/admin/card-templates/:slug/preview` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8d2b757a35dd5417", "name": "Unused endpoint: PUT /api/admin/card-templates/:slug/layout", "shortDescription": {"text": "Unused endpoint: PUT /api/admin/card-templates/:slug/layout"}, "fullDescription": {"text": "`backend/server.js` declares `PUT /api/admin/card-templates/:slug/layout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d93a530ce10d47d9", "name": "Unused endpoint: USE /api/admin", "shortDescription": {"text": "Unused endpoint: USE /api/admin"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/admin` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a4560acf8a1da0ab", "name": "Unused endpoint: GET /api/test-card", "shortDescription": {"text": "Unused endpoint: GET /api/test-card"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/test-card` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4756b4c4da7d2088", "name": "Unused endpoint: GET /api/health", "shortDescription": {"text": "Unused endpoint: GET /api/health"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/health` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-83b35a5a43f6f471", "name": "Unused endpoint: GET /api/sources", "shortDescription": {"text": "Unused endpoint: GET /api/sources"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/sources` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-41376dc246cd5de8", "name": "Unused endpoint: GET /api/feeds", "shortDescription": {"text": "Unused endpoint: GET /api/feeds"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/feeds` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b68be2fdcdcae72b", "name": "Unused endpoint: GET /api/article", "shortDescription": {"text": "Unused endpoint: GET /api/article"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/article` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7aa4b2518cbbbfa2", "name": "Unused endpoint: GET /api/config", "shortDescription": {"text": "Unused endpoint: GET /api/config"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/config` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-64b8e6b11d60cba5", "name": "Unused endpoint: GET /api/refresh", "shortDescription": {"text": "Unused endpoint: GET /api/refresh"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/refresh` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9620e016518f2af0", "name": "Unused endpoint: GET /wp-json/wp/v2/posts?per_page=1", "shortDescription": {"text": "Unused endpoint: GET /wp-json/wp/v2/posts?per_page=1"}, "fullDescription": {"text": "`backend/connectors/wordpress.js` declares `GET /wp-json/wp/v2/posts?per_page=1` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8aad19992e2c81dc", "name": "Unused endpoint: POST /wp-json/wp/v2/tags", "shortDescription": {"text": "Unused endpoint: POST /wp-json/wp/v2/tags"}, "fullDescription": {"text": "`backend/connectors/wordpress.js` declares `POST /wp-json/wp/v2/tags` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0c862d17a13ebf74", "name": "Unused endpoint: POST /wp-json/wp/v2/posts", "shortDescription": {"text": "Unused endpoint: POST /wp-json/wp/v2/posts"}, "fullDescription": {"text": "`backend/connectors/wordpress.js` declares `POST /wp-json/wp/v2/posts` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a009b1a56794f45", "name": "Unused endpoint: POST /", "shortDescription": {"text": "Unused endpoint: POST /"}, "fullDescription": {"text": "`backend/routes/contato.js` declares `POST /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cd8dc4599ec52a08", "name": "Unused endpoint: GET /stats", "shortDescription": {"text": "Unused endpoint: GET /stats"}, "fullDescription": {"text": "`backend/routes/admin.js` declares `GET /stats` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9617aa24fd377881", "name": "Unused endpoint: GET /sources", "shortDescription": {"text": "Unused endpoint: GET /sources"}, "fullDescription": {"text": "`backend/routes/admin.js` declares `GET /sources` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cdd4d5073491a3a4", "name": "Unused endpoint: PATCH /sources/:slug/toggle", "shortDescription": {"text": "Unused endpoint: PATCH /sources/:slug/toggle"}, "fullDescription": {"text": "`backend/routes/admin.js` declares `PATCH /sources/:slug/toggle` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-59a514f2e6c659e5", "name": "Unused endpoint: PATCH /sources/:slug/refresh", "shortDescription": {"text": "Unused endpoint: PATCH /sources/:slug/refresh"}, "fullDescription": {"text": "`backend/routes/admin.js` declares `PATCH /sources/:slug/refresh` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5467e682054ad3ed", "name": "Unused endpoint: POST /sources", "shortDescription": {"text": "Unused endpoint: POST /sources"}, "fullDescription": {"text": "`backend/routes/admin.js` declares `POST /sources` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-acbfbd41d78c4717", "name": "Unused endpoint: PUT /sources/:slug", "shortDescription": {"text": "Unused endpoint: PUT /sources/:slug"}, "fullDescription": {"text": "`backend/routes/admin.js` declares `PUT /sources/:slug` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-25e034373a8ea4de", "name": "Unused endpoint: POST /sources/analyze", "shortDescription": {"text": "Unused endpoint: POST /sources/analyze"}, "fullDescription": {"text": "`backend/routes/admin.js` declares `POST /sources/analyze` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5530389f33ab2875", "name": "Unused endpoint: POST /sources/test-scraping", "shortDescription": {"text": "Unused endpoint: POST /sources/test-scraping"}, "fullDescription": {"text": "`backend/routes/admin.js` declares `POST /sources/test-scraping` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/22765"}, "properties": {"repository": "wilsonglopes/newsxmnews", "repoUrl": "https://github.com/wilsonglopes/newsxmnews", "branch": "main"}, "results": [{"ruleId": "scanner-56340619a18d260b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/autopub.js:138"}, "properties": {"repobilityId": "8f3172ae3274d58d", "scanner": "scanner-primary", "fingerprint": "56340619a18d260b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0710009c872fc892", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/migrate.js:118"}, "properties": {"repobilityId": "2770a9ba3db61437", "scanner": "scanner-primary", "fingerprint": "0710009c872fc892", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-39ed0ccfedc92fd0", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/youtube-videos.js:142"}, "properties": {"repobilityId": "fc6883a5b3d53ef5", "scanner": "scanner-primary", "fingerprint": "39ed0ccfedc92fd0", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-507be11eec983006", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/startup-validator.js:112"}, "properties": {"repobilityId": "e6bb434d379b08c3", "scanner": "scanner-primary", "fingerprint": "507be11eec983006", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f87aca58daeb41c5", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/monitor.js:224"}, "properties": {"repobilityId": "19761ef62ce308df", "scanner": "scanner-primary", "fingerprint": "f87aca58daeb41c5", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5b6b1b7da7ba44d2", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/telegram.js:646"}, "properties": {"repobilityId": "ae5af069abac253d", "scanner": "scanner-primary", "fingerprint": "5b6b1b7da7ba44d2", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3df0717b81a86207", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/server.js:21"}, "properties": {"repobilityId": "ec6c625862fd9ddc", "scanner": "scanner-primary", "fingerprint": "3df0717b81a86207", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-70ab0911e4a4ef3e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/scrapers/headless-content.js:184"}, "properties": {"repobilityId": "483457d85164edac", "scanner": "scanner-primary", "fingerprint": "70ab0911e4a4ef3e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f77358da31644ced", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/scrapers/full-content.js:249"}, "properties": {"repobilityId": "17ed0b15fa2f8e93", "scanner": "scanner-primary", "fingerprint": "f77358da31644ced", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d1a2772621fddbed", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/connectors/wordpress.js:80"}, "properties": {"repobilityId": "08fcc43f07da9120", "scanner": "scanner-primary", "fingerprint": "d1a2772621fddbed", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-eb372675c7b8f868", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/connectors/whatsapp.js:55"}, "properties": {"repobilityId": "79f5fd5001b01e6e", "scanner": "scanner-primary", "fingerprint": "eb372675c7b8f868", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ad7a6a76cf50ea9e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/utils/card-generator.js:392"}, "properties": {"repobilityId": "770d6d3d9c140cb3", "scanner": "scanner-primary", "fingerprint": "ad7a6a76cf50ea9e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c61c7d835abc36ba", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/routes/admin.js:265"}, "properties": {"repobilityId": "8e2e41373bd6f6cb", "scanner": "scanner-primary", "fingerprint": "c61c7d835abc36ba", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-21fbd4d9e93f8d14", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/routes/publish.js:75"}, "properties": {"repobilityId": "92c7a4308ae7cb8b", "scanner": "scanner-primary", "fingerprint": "21fbd4d9e93f8d14", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-1870546bd99afd3c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/routes/drafts.js:22"}, "properties": {"repobilityId": "599340f08efb305b", "scanner": "scanner-primary", "fingerprint": "1870546bd99afd3c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b4e45b7d0ee64a79", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/db/setup.js:27"}, "properties": {"repobilityId": "c8c379eff940c40c", "scanner": "scanner-primary", "fingerprint": "b4e45b7d0ee64a79", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2fa0a9e0aff3316a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/db/diagnostico-imagens.js:93"}, "properties": {"repobilityId": "1d318b4b48fc11f2", "scanner": "scanner-primary", "fingerprint": "2fa0a9e0aff3316a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8e6bd461bbb8b505", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/db/diagnostico-deep.js:17"}, "properties": {"repobilityId": "d9726bf4c32e522e", "scanner": "scanner-primary", "fingerprint": "8e6bd461bbb8b505", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ac5b848b21ae768b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/db/seed.js:15"}, "properties": {"repobilityId": "e56654f0f9e543a7", "scanner": "scanner-primary", "fingerprint": "ac5b848b21ae768b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-33062f66588ab6e0", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/db/fix-images.js:23"}, "properties": {"repobilityId": "4c9c416a28d47d92", "scanner": "scanner-primary", "fingerprint": "33062f66588ab6e0", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c265f938b71f61de", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/db/inspect-govrs-alers.js:15"}, "properties": {"repobilityId": "d5c63f2e3f58c79c", "scanner": "scanner-primary", "fingerprint": "c265f938b71f61de", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-1f1385f2b04b6cf5", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in index.html:1986"}, "properties": {"repobilityId": "f91708437a3a5445", "scanner": "scanner-primary", "fingerprint": "1f1385f2b04b6cf5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "index.html"}, "region": {"startLine": 1986}}}]}, {"ruleId": "scanner-9d8d908f0355d360", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in cloudflare-worker-sc-proxy.js:20"}, "properties": {"repobilityId": "0d3a53f0c1eb08ec", "scanner": "scanner-primary", "fingerprint": "9d8d908f0355d360", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "cloudflare-worker-sc-proxy.js"}, "region": {"startLine": 20}}}]}, {"ruleId": "scanner-bbd972b8f521f67f", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in frontend/subscriber/login.html:255"}, "properties": {"repobilityId": "5b402cd1045bfa52", "scanner": "scanner-primary", "fingerprint": "bbd972b8f521f67f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/subscriber/login.html"}, "region": {"startLine": 255}}}]}, {"ruleId": "scanner-4a52240cff6884f2", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in frontend/subscriber/index.html:1115"}, "properties": {"repobilityId": "0da197f4d34d1665", "scanner": "scanner-primary", "fingerprint": "4a52240cff6884f2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/subscriber/index.html"}, "region": {"startLine": 1115}}}]}, {"ruleId": "scanner-bf19a391ab5eafc0", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in frontend/subscriber/admin.html:2559"}, "properties": {"repobilityId": "4e87c94c3f9915f1", "scanner": "scanner-primary", "fingerprint": "bf19a391ab5eafc0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/subscriber/admin.html"}, "region": {"startLine": 2559}}}]}, {"ruleId": "scanner-f393285bb8e1aea5", "level": "warning", "message": {"text": "Insecure pattern 'insert_adjacent_html' in frontend/subscriber/admin.html:3590"}, "properties": {"repobilityId": "b4822a48b986b63c", "scanner": "scanner-primary", "fingerprint": "f393285bb8e1aea5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "insert_adjacent_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/subscriber/admin.html"}, "region": {"startLine": 3590}}}]}, {"ruleId": "scanner-6d45b74f6677a7ec", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in frontend/subscriber/coluna.html:192"}, "properties": {"repobilityId": "18ddcc631a0eef12", "scanner": "scanner-primary", "fingerprint": "6d45b74f6677a7ec", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/subscriber/coluna.html"}, "region": {"startLine": 192}}}]}, {"ruleId": "scanner-90fcb44d9b461505", "level": "error", "message": {"text": "Possible secret in .claude/settings.local.json"}, "properties": {"repobilityId": "31609f8f1b78960c", "scanner": "scanner-primary", "fingerprint": "90fcb44d9b461505", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/settings.local.json"}, "region": {"startLine": 155}}}]}, {"ruleId": "scanner-df142b7be32c2bf0", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in backend/monitor.js:31"}, "properties": {"repobilityId": "296603eee8be8351", "scanner": "scanner-primary", "fingerprint": "df142b7be32c2bf0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/monitor.js"}, "region": {"startLine": 31}}}]}, {"ruleId": "scanner-6f1484849c8457d8", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in backend/routes/image-proxy.js:65"}, "properties": {"repobilityId": "46b9a95fcea12d45", "scanner": "scanner-primary", "fingerprint": "6f1484849c8457d8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routes/image-proxy.js"}, "region": {"startLine": 65}}}]}, {"ruleId": "scanner-28c4a04bd807da0c", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "0bc463708914950e", "scanner": "scanner-primary", "fingerprint": "28c4a04bd807da0c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy.yml"}, "region": {"startLine": 13}}}]}, {"ruleId": "scanner-7f2ad7d9bd07fa21", "level": "note", "message": {"text": "Very large file: backend/server.js (1722 lines)"}, "properties": {"repobilityId": "2c4c2b5f4015f25d", "scanner": "scanner-primary", "fingerprint": "7f2ad7d9bd07fa21", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-25a166cb7f7ea9c1", "level": "note", "message": {"text": "Very large file: backend/routes/admin.js (1292 lines)"}, "properties": {"repobilityId": "6fe7a27a63e068fd", "scanner": "scanner-primary", "fingerprint": "25a166cb7f7ea9c1", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "1549cfd4a77031c2", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "8f6bf3a0a8d5c4b6", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-9d79c4077342a7d0", "level": "warning", "message": {"text": "Runtime service client appears to use placeholder configuration"}, "properties": {"repobilityId": "f844057a064c18b8", "scanner": "scanner-primary", "fingerprint": "9d79c4077342a7d0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "runtime-config", "service-client", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "7d047f6e48087729", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-11825279136b53a3", "level": "warning", "message": {"text": "CI is configured but no tests are detected"}, "properties": {"repobilityId": "882eb961e61a204e", "scanner": "scanner-primary", "fingerprint": "11825279136b53a3", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "ci", "config-theater", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "7e70511bdf20e996", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "213e02e5138e3bd1", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "84ed073735b55ccc", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "604bc5c789bbd525", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-ecb0d2c55ed6875d", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/settings.local.json"}, "properties": {"repobilityId": "d8bae33a6d517bf0", "scanner": "scanner-primary", "fingerprint": "ecb0d2c55ed6875d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/settings.local.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2a0f59a9864856b8", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 cloudflare-worker-sc-proxy.js:16"}, "properties": {"repobilityId": "8601c4132e6f5631", "scanner": "scanner-primary", "fingerprint": "2a0f59a9864856b8", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-b30c5a65d32a13b2", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend/telegram.js:47"}, "properties": {"repobilityId": "0c31c608b33699da", "scanner": "scanner-primary", "fingerprint": "b30c5a65d32a13b2", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0824c033ca6b60ae", "level": "none", "message": {"text": "Commented-code block (7 lines) in backend/server.js:1047"}, "properties": {"repobilityId": "7e8ca4b853e84106", "scanner": "scanner-primary", "fingerprint": "0824c033ca6b60ae", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-bbef0d55a8571350", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/connectors/hashtags.js:7"}, "properties": {"repobilityId": "74eed7d8d125c3a6", "scanner": "scanner-primary", "fingerprint": "bbef0d55a8571350", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-fe999cfc1ab754e0", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/connectors/blogger.js:7"}, "properties": {"repobilityId": "620ce550147ddedd", "scanner": "scanner-primary", "fingerprint": "fe999cfc1ab754e0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-cc4f7e2e85950661", "level": "none", "message": {"text": "Commented-code block (7 lines) in backend/connectors/facebook.js:17"}, "properties": {"repobilityId": "1e66f1079224008d", "scanner": "scanner-primary", "fingerprint": "cc4f7e2e85950661", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-72967d777ce66a6e", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/connectors/wordpress.js:173"}, "properties": {"repobilityId": "2590c463edfa740c", "scanner": "scanner-primary", "fingerprint": "72967d777ce66a6e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-69713650f15d76a6", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/db/diagnostico-deep.js:10"}, "properties": {"repobilityId": "fc3fd819857215c0", "scanner": "scanner-primary", "fingerprint": "69713650f15d76a6", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-b0b5e7cb1208a7cd", "level": "note", "message": {"text": "13 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "2737b8666c1f7eeb", "scanner": "scanner-primary", "fingerprint": "b0b5e7cb1208a7cd", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-32b3d353a2a39830", "level": "error", "message": {"text": "Dangling fetch: POST https://api.deepseek.com/chat/completions (backend/autopub.js:50)"}, "properties": {"repobilityId": "c327e86cf4d7cd00", "scanner": "scanner-primary", "fingerprint": "32b3d353a2a39830", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-e2193352bdfb800b", "level": "error", "message": {"text": "Dangling fetch: POST https://api.openai.com/v1/audio/transcriptions (backend/telegram.js:191)"}, "properties": {"repobilityId": "509fb68ab61fd3f2", "scanner": "scanner-primary", "fingerprint": "e2193352bdfb800b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-c56c78404e8e8784", "level": "error", "message": {"text": "Dangling fetch: POST https://api.deepseek.com/chat/completions (backend/telegram.js:204)"}, "properties": {"repobilityId": "770e8b9f206fd97e", "scanner": "scanner-primary", "fingerprint": "c56c78404e8e8784", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-70a511ba29eb42ae", "level": "error", "message": {"text": "Dangling fetch: POST https://api.deepseek.com/chat/completions (backend/connectors/hashtags.js:88)"}, "properties": {"repobilityId": "a932ef1b8b6198ec", "scanner": "scanner-primary", "fingerprint": "70a511ba29eb42ae", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-7003d4557b69e213", "level": "error", "message": {"text": "Dangling fetch: POST https://oauth2.googleapis.com/token (backend/connectors/blogger.js:7)"}, "properties": {"repobilityId": "e26bb6818da839b2", "scanner": "scanner-primary", "fingerprint": "7003d4557b69e213", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-fb32badbb7ccf987", "level": "error", "message": {"text": "Dangling fetch: POST https://www.googleapis.com/blogger/v3/blogs/${site.blogger_blog_id}/posts/ (backend/connectors/blogger.js:47)"}, "properties": {"repobilityId": "67fc9ed61ebb7632", "scanner": "scanner-primary", "fingerprint": "fb32badbb7ccf987", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-12daf4eaf8baf060", "level": "error", "message": {"text": "Dangling fetch: POST https://api.telegram.org/bot${token}/sendMessage (backend/utils/telegram-notify.js:36)"}, "properties": {"repobilityId": "3c153e67c0b5e5eb", "scanner": "scanner-primary", "fingerprint": "12daf4eaf8baf060", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-b598094bc0b768fa", "level": "error", "message": {"text": "Dangling fetch: POST https://api.deepseek.com/chat/completions (backend/utils/source-detector.js:104)"}, "properties": {"repobilityId": "6b37b152630fb2ce", "scanner": "scanner-primary", "fingerprint": "b598094bc0b768fa", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-de68d700735e3351", "level": "error", "message": {"text": "Dangling fetch: GET https://graph.facebook.com/v20.0/act_${accountId} (backend/routes/admin.js:1016)"}, "properties": {"repobilityId": "0a825edcbfe2dcca", "scanner": "scanner-primary", "fingerprint": "de68d700735e3351", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-70b6338d59dbb483", "level": "error", "message": {"text": "Dangling fetch: POST https://api.deepseek.com/chat/completions (backend/routes/admin.js:1091)"}, "properties": {"repobilityId": "b0c4049afba8a26d", "scanner": "scanner-primary", "fingerprint": "70b6338d59dbb483", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-91bd27dcd804109b", "level": "error", "message": {"text": "Dangling fetch: POST https://api.deepseek.com/chat/completions (backend/routes/ia.js:79)"}, "properties": {"repobilityId": "5455177dc989abd1", "scanner": "scanner-primary", "fingerprint": "91bd27dcd804109b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-45fdf66d5b3bc917", "level": "error", "message": {"text": "Dangling fetch: POST https://api.deepseek.com/chat/completions (backend/routes/ia.js:147)"}, "properties": {"repobilityId": "492184182b19e64e", "scanner": "scanner-primary", "fingerprint": "45fdf66d5b3bc917", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-885b9aeb8421455d", "level": "error", "message": {"text": "Dangling fetch: POST https://api.deepseek.com/chat/completions (backend/routes/ia.js:190)"}, "properties": {"repobilityId": "656bb18ab2f96eca", "scanner": "scanner-primary", "fingerprint": "885b9aeb8421455d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-f9ea876ff3178b7e", "level": "error", "message": {"text": "Dangling fetch: GET https://sombrio.sc.gov.br/2026/04/16/parceria-entre-o-citi-e-alunos-sombrienses-produz-bolsas-ecologicamente-corretas/ (backend/db/diagnostico-deep.js:18)"}, "properties": {"repobilityId": "96671e8a91dde18c", "scanner": "scanner-primary", "fingerprint": "f9ea876ff3178b7e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-82311b522606f487", "level": "error", "message": {"text": "Dangling fetch: GET https://www.capaodacanoa.rs.gov.br/noticia/view/874/segunda-edicao-da-feira-de-pascoa-sabor-e-tradicao-supera-expectativas-e-movimenta-capao-da-canoa (backend/db/diagnostico-deep.js:26)"}, "properties": {"repobilityId": "60f40098d1b2cbfe", "scanner": "scanner-primary", "fingerprint": "82311b522606f487", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-cbc6913bf8818eb7", "level": "error", "message": {"text": "Dangling fetch: GET https://ww4.al.rs.gov.br/noticia/343265 (backend/db/diagnostico-deep.js:52)"}, "properties": {"repobilityId": "e1be6bd35ee20eac", "scanner": "scanner-primary", "fingerprint": "cbc6913bf8818eb7", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "7d4772f7c52bce64", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4523275038ad5934", "level": "note", "message": {"text": "Unused endpoint: GET /api/preview/:token"}, "properties": {"repobilityId": "c12dd722f62a16fa", "scanner": "scanner-primary", "fingerprint": "4523275038ad5934", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1bc898b3b7565990", "level": "note", "message": {"text": "Unused endpoint: USE /uploads"}, "properties": {"repobilityId": "d2c9d1907a1121fd", "scanner": "scanner-primary", "fingerprint": "1bc898b3b7565990", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-84bd4c31da0619b1", "level": "note", "message": {"text": "Unused endpoint: USE /api/uploads"}, "properties": {"repobilityId": "a06b21db33c60e94", "scanner": "scanner-primary", "fingerprint": "84bd4c31da0619b1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dde3adb27bf7eebe", "level": "note", "message": {"text": "Unused endpoint: USE /api"}, "properties": {"repobilityId": "e7ff5964127d9924", "scanner": "scanner-primary", "fingerprint": "dde3adb27bf7eebe", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6eb452fbfb454d20", "level": "note", "message": {"text": "Unused endpoint: USE /api/auth"}, "properties": {"repobilityId": "0a5793afc5ea0a13", "scanner": "scanner-primary", "fingerprint": "6eb452fbfb454d20", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-07c4bba00fd83bc9", "level": "note", "message": {"text": "Unused endpoint: USE /api/articles"}, "properties": {"repobilityId": "9ad79062b6360bf4", "scanner": "scanner-primary", "fingerprint": "07c4bba00fd83bc9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5979f2f5be25c70b", "level": "note", "message": {"text": "Unused endpoint: USE /api/publish"}, "properties": {"repobilityId": "0e97e71b33fd6819", "scanner": "scanner-primary", "fingerprint": "5979f2f5be25c70b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4c6fcb9d6bfeb851", "level": "note", "message": {"text": "Unused endpoint: USE /api/sites"}, "properties": {"repobilityId": "ea35542b7e9c6ef8", "scanner": "scanner-primary", "fingerprint": "4c6fcb9d6bfeb851", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-375cbbc5a3cc2d4a", "level": "note", "message": {"text": "Unused endpoint: USE /api/drafts"}, "properties": {"repobilityId": "a874ced8c8cbd8e5", "scanner": "scanner-primary", "fingerprint": "375cbbc5a3cc2d4a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c3f095befe80f027", "level": "note", "message": {"text": "Unused endpoint: USE /api/publications"}, "properties": {"repobilityId": "048708ae04da2693", "scanner": "scanner-primary", "fingerprint": "c3f095befe80f027", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d3038f43cdd12233", "level": "note", "message": {"text": "Unused endpoint: USE /api/subscriber/sources"}, "properties": {"repobilityId": "9b249bb41bbcbeb9", "scanner": "scanner-primary", "fingerprint": "d3038f43cdd12233", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5e1951ffed949c70", "level": "note", "message": {"text": "Unused endpoint: USE /api/subscriber"}, "properties": {"repobilityId": "5e8f11b1bacd4214", "scanner": "scanner-primary", "fingerprint": "5e1951ffed949c70", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e1ae3aeb68b3c3c1", "level": "note", "message": {"text": "Unused endpoint: USE /api/ia"}, "properties": {"repobilityId": "c0352ccdc22ec94e", "scanner": "scanner-primary", "fingerprint": "e1ae3aeb68b3c3c1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-379b09f9de636500", "level": "note", "message": {"text": "Unused endpoint: GET /api/settings"}, "properties": {"repobilityId": "12b4f6f7f445b476", "scanner": "scanner-primary", "fingerprint": "379b09f9de636500", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-16e94a53f296ada6", "level": "note", "message": {"text": "Unused endpoint: USE /api/contato"}, "properties": {"repobilityId": "816beb71dd297665", "scanner": "scanner-primary", "fingerprint": "16e94a53f296ada6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8316edd4aabd9834", "level": "note", "message": {"text": "Unused endpoint: USE /api/proxy-image"}, "properties": {"repobilityId": "5a5fb7a93234db8e", "scanner": "scanner-primary", "fingerprint": "8316edd4aabd9834", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1fef85ca80065d2f", "level": "note", "message": {"text": "Unused endpoint: USE /api/admin/sites-catalog"}, "properties": {"repobilityId": "09646a47a9a40cc0", "scanner": "scanner-primary", "fingerprint": "1fef85ca80065d2f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b72ae661584b27a8", "level": "note", "message": {"text": "Unused endpoint: USE /api/admin/whatsapp"}, "properties": {"repobilityId": "58240c65680b4d29", "scanner": "scanner-primary", "fingerprint": "b72ae661584b27a8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d9e69da016ad7528", "level": "note", "message": {"text": "Unused endpoint: USE /api/admin/youtube"}, "properties": {"repobilityId": "802ecb983448a99b", "scanner": "scanner-primary", "fingerprint": "d9e69da016ad7528", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1ec35b081427a3d4", "level": "note", "message": {"text": "Unused endpoint: USE /api/colunista"}, "properties": {"repobilityId": "81c6a4d0dee78650", "scanner": "scanner-primary", "fingerprint": "1ec35b081427a3d4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-58ba43d81b84919f", "level": "note", "message": {"text": "Unused endpoint: USE /api/plugin"}, "properties": {"repobilityId": "658372b063f7e109", "scanner": "scanner-primary", "fingerprint": "58ba43d81b84919f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-acfcb211f61ac2dc", "level": "note", "message": {"text": "Unused endpoint: USE /api/admin/plugin"}, "properties": {"repobilityId": "fb02a17bec87f7de", "scanner": "scanner-primary", "fingerprint": "acfcb211f61ac2dc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-aa4bac17ad96cfe0", "level": "note", "message": {"text": "Unused endpoint: GET /api/admin/card-templates"}, "properties": {"repobilityId": "4352f47c415710e2", "scanner": "scanner-primary", "fingerprint": "aa4bac17ad96cfe0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0b889f3e42be0cac", "level": "note", "message": {"text": "Unused endpoint: GET /api/admin/fontes-saude"}, "properties": {"repobilityId": "2d6f4acdd87f9de9", "scanner": "scanner-primary", "fingerprint": "0b889f3e42be0cac", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3add7d22af0e0830", "level": "note", "message": {"text": "Unused endpoint: POST /api/admin/card-templates"}, "properties": {"repobilityId": "2b0ed21b106dc7b0", "scanner": "scanner-primary", "fingerprint": "3add7d22af0e0830", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-93993223f7b2434f", "level": "note", "message": {"text": "Unused endpoint: DELETE /api/admin/card-templates/:slug"}, "properties": {"repobilityId": "998a4f52e1d8fc54", "scanner": "scanner-primary", "fingerprint": "93993223f7b2434f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9d4e2fe59b84a714", "level": "note", "message": {"text": "Unused endpoint: GET /api/admin/card-templates/:slug/layout"}, "properties": {"repobilityId": "c14de9a8f8024133", "scanner": "scanner-primary", "fingerprint": "9d4e2fe59b84a714", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4d15ed579d038aaf", "level": "note", "message": {"text": "Unused endpoint: POST /api/admin/card-templates/:slug/preview"}, "properties": {"repobilityId": "48f851f10774d65e", "scanner": "scanner-primary", "fingerprint": "4d15ed579d038aaf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8d2b757a35dd5417", "level": "note", "message": {"text": "Unused endpoint: PUT /api/admin/card-templates/:slug/layout"}, "properties": {"repobilityId": "352be05fe805535a", "scanner": "scanner-primary", "fingerprint": "8d2b757a35dd5417", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d93a530ce10d47d9", "level": "note", "message": {"text": "Unused endpoint: USE /api/admin"}, "properties": {"repobilityId": "a46d89dae1e3a2d4", "scanner": "scanner-primary", "fingerprint": "d93a530ce10d47d9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a4560acf8a1da0ab", "level": "note", "message": {"text": "Unused endpoint: GET /api/test-card"}, "properties": {"repobilityId": "1e3a7c0bc746e113", "scanner": "scanner-primary", "fingerprint": "a4560acf8a1da0ab", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4756b4c4da7d2088", "level": "note", "message": {"text": "Unused endpoint: GET /api/health"}, "properties": {"repobilityId": "1e5295e69c6e06d8", "scanner": "scanner-primary", "fingerprint": "4756b4c4da7d2088", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-83b35a5a43f6f471", "level": "note", "message": {"text": "Unused endpoint: GET /api/sources"}, "properties": {"repobilityId": "c311a91c4739fb79", "scanner": "scanner-primary", "fingerprint": "83b35a5a43f6f471", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-41376dc246cd5de8", "level": "note", "message": {"text": "Unused endpoint: GET /api/feeds"}, "properties": {"repobilityId": "449c347e0b9772ed", "scanner": "scanner-primary", "fingerprint": "41376dc246cd5de8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b68be2fdcdcae72b", "level": "note", "message": {"text": "Unused endpoint: GET /api/article"}, "properties": {"repobilityId": "4c9b7e2069abbda1", "scanner": "scanner-primary", "fingerprint": "b68be2fdcdcae72b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7aa4b2518cbbbfa2", "level": "note", "message": {"text": "Unused endpoint: GET /api/config"}, "properties": {"repobilityId": "34ed507c527a48e1", "scanner": "scanner-primary", "fingerprint": "7aa4b2518cbbbfa2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-64b8e6b11d60cba5", "level": "note", "message": {"text": "Unused endpoint: GET /api/refresh"}, "properties": {"repobilityId": "f971cc425f3e1950", "scanner": "scanner-primary", "fingerprint": "64b8e6b11d60cba5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9620e016518f2af0", "level": "note", "message": {"text": "Unused endpoint: GET /wp-json/wp/v2/posts?per_page=1"}, "properties": {"repobilityId": "343b8c3853bd792b", "scanner": "scanner-primary", "fingerprint": "9620e016518f2af0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8aad19992e2c81dc", "level": "note", "message": {"text": "Unused endpoint: POST /wp-json/wp/v2/tags"}, "properties": {"repobilityId": "3c2660d56bd81a76", "scanner": "scanner-primary", "fingerprint": "8aad19992e2c81dc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0c862d17a13ebf74", "level": "note", "message": {"text": "Unused endpoint: POST /wp-json/wp/v2/posts"}, "properties": {"repobilityId": "b0627f6bb6d6f4be", "scanner": "scanner-primary", "fingerprint": "0c862d17a13ebf74", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a009b1a56794f45", "level": "note", "message": {"text": "Unused endpoint: POST /"}, "properties": {"repobilityId": "59f56287d7b7e625", "scanner": "scanner-primary", "fingerprint": "7a009b1a56794f45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cd8dc4599ec52a08", "level": "note", "message": {"text": "Unused endpoint: GET /stats"}, "properties": {"repobilityId": "741214f3a034df5c", "scanner": "scanner-primary", "fingerprint": "cd8dc4599ec52a08", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9617aa24fd377881", "level": "note", "message": {"text": "Unused endpoint: GET /sources"}, "properties": {"repobilityId": "ad73ec561d85c61c", "scanner": "scanner-primary", "fingerprint": "9617aa24fd377881", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cdd4d5073491a3a4", "level": "note", "message": {"text": "Unused endpoint: PATCH /sources/:slug/toggle"}, "properties": {"repobilityId": "63baea1465298942", "scanner": "scanner-primary", "fingerprint": "cdd4d5073491a3a4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-59a514f2e6c659e5", "level": "note", "message": {"text": "Unused endpoint: PATCH /sources/:slug/refresh"}, "properties": {"repobilityId": "a8d303c966ecb1e6", "scanner": "scanner-primary", "fingerprint": "59a514f2e6c659e5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5467e682054ad3ed", "level": "note", "message": {"text": "Unused endpoint: POST /sources"}, "properties": {"repobilityId": "ea77381c7481d2a9", "scanner": "scanner-primary", "fingerprint": "5467e682054ad3ed", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-acbfbd41d78c4717", "level": "note", "message": {"text": "Unused endpoint: PUT /sources/:slug"}, "properties": {"repobilityId": "b3adefbbf45b2308", "scanner": "scanner-primary", "fingerprint": "acbfbd41d78c4717", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-25e034373a8ea4de", "level": "note", "message": {"text": "Unused endpoint: POST /sources/analyze"}, "properties": {"repobilityId": "9510c75925361eec", "scanner": "scanner-primary", "fingerprint": "25e034373a8ea4de", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5530389f33ab2875", "level": "note", "message": {"text": "Unused endpoint: POST /sources/test-scraping"}, "properties": {"repobilityId": "7cc445be2392f324", "scanner": "scanner-primary", "fingerprint": "5530389f33ab2875", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}