{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-0cd88c1c85a503b9", "name": "Possibly dead Python function: reply_content", "shortDescription": {"text": "Possibly dead Python function: reply_content"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea12aa0cfd3c1510", "name": "Possibly dead Python function: deco", "shortDescription": {"text": "Possibly dead Python function: deco"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-09b480445bd13e21", "name": "Possibly dead Python function: call", "shortDescription": {"text": "Possibly dead Python function: call"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-df3f157dc99bb62b", "name": "Possibly dead Python function: gid_match", "shortDescription": {"text": "Possibly dead Python function: gid_match"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f3e3fd31da81d590", "name": "Possibly dead Python function: cid_match", "shortDescription": {"text": "Possibly dead Python function: cid_match"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c75762b227827387", "name": "Possibly dead Python function: api_delete_user_address", "shortDescription": {"text": "Possibly dead Python function: api_delete_user_address"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-564ee8b0e80e9d86", "name": "Possibly dead Python function: api_set_profile_address", "shortDescription": {"text": "Possibly dead Python function: api_set_profile_address"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ec423cf92878d93", "name": "Possibly dead Python function: api_update_chat_item", "shortDescription": {"text": "Possibly dead Python function: api_update_chat_item"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3c51fb05bb56f86f", "name": "Possibly dead Python function: api_delete_chat_items", "shortDescription": {"text": "Possibly dead Python function: api_delete_chat_items"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d2432d04919befe8", "name": "Possibly dead Python function: api_delete_member_chat_item", "shortDescription": {"text": "Possibly dead Python function: api_delete_member_chat_item"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dc10cda14db71548", "name": "Possibly dead Python function: api_chat_item_reaction", "shortDescription": {"text": "Possibly dead Python function: api_chat_item_reaction"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fff773a395c4a6eb", "name": "Possibly dead Python function: api_receive_file", "shortDescription": {"text": "Possibly dead Python function: api_receive_file"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-86ba40c9ad8a9c4c", "name": "Possibly dead Python function: api_cancel_file", "shortDescription": {"text": "Possibly dead Python function: api_cancel_file"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b04079d60d34327b", "name": "Possibly dead Python function: api_add_member", "shortDescription": {"text": "Possibly dead Python function: api_add_member"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b81ff5fd8826dcc0", "name": "Possibly dead Python function: api_join_group", "shortDescription": {"text": "Possibly dead Python function: api_join_group"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ab545d20375f95b8", "name": "Possibly dead Python function: api_accept_member", "shortDescription": {"text": "Possibly dead Python function: api_accept_member"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-62ff60a141e6f5f7", "name": "Possibly dead Python function: api_set_members_role", "shortDescription": {"text": "Possibly dead Python function: api_set_members_role"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bc32e244ed4cfcfd", "name": "Possibly dead Python function: api_block_members_for_all", "shortDescription": {"text": "Possibly dead Python function: api_block_members_for_all"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7220904896fc56ca", "name": "Possibly dead Python function: api_remove_members", "shortDescription": {"text": "Possibly dead Python function: api_remove_members"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0be1de5dcb203c0b", "name": "Possibly dead Python function: api_leave_group", "shortDescription": {"text": "Possibly dead Python function: api_leave_group"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1191be3873132f2c", "name": "Possibly dead Python function: api_list_members", "shortDescription": {"text": "Possibly dead Python function: api_list_members"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c2f6565ff6ee4373", "name": "Possibly dead Python function: api_new_group", "shortDescription": {"text": "Possibly dead Python function: api_new_group"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5311072e2d457e5e", "name": "Possibly dead Python function: api_update_group_profile", "shortDescription": {"text": "Possibly dead Python function: api_update_group_profile"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-944181e2c412fd0d", "name": "Possibly dead Python function: api_create_group_link", "shortDescription": {"text": "Possibly dead Python function: api_create_group_link"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d13f309c205bea48", "name": "Possibly dead Python function: api_set_group_link_member_role", "shortDescription": {"text": "Possibly dead Python function: api_set_group_link_member_role"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a0dc68b5d4f1c95", "name": "Possibly dead Python function: api_delete_group_link", "shortDescription": {"text": "Possibly dead Python function: api_delete_group_link"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-939e67eccb03724d", "name": "Possibly dead Python function: api_get_group_link_str", "shortDescription": {"text": "Possibly dead Python function: api_get_group_link_str"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dca602673e331320", "name": "Possibly dead Python function: api_create_link", "shortDescription": {"text": "Possibly dead Python function: api_create_link"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b5510156d72735ab", "name": "Possibly dead Python function: api_connect", "shortDescription": {"text": "Possibly dead Python function: api_connect"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5c7ee34fd044469a", "name": "Possibly dead Python function: api_accept_contact_request", "shortDescription": {"text": "Possibly dead Python function: api_accept_contact_request"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f9c28be7c1fe0d89", "name": "TODO/FIXME marker in shipping code \u2014 apps/multiplatform/common/src/commonMain/resources/assets/www/call.js:1144", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 apps/multiplatform/common/src/commonMain/resources/assets/www/call.js:1144"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-326992887a10f4fc", "name": "Debug `console.log` remains in browser-facing code \u2014 apps/multiplatform/common/src/commonMain/resources/assets/www/call.", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 apps/multiplatform/common/src/commonMain/resources/assets/www/call.js:30"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-34bc175cda3e7974", "name": "Debug `console.log` remains in browser-facing code \u2014 apps/multiplatform/common/src/commonMain/resources/assets/www/deskt", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 apps/multiplatform/common/src/commonMain/resources/assets/www/desktop/ui.js:8"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-10c8bf995ee4f49e", "name": "Debug `console.log` remains in browser-facing code \u2014 website/src/js/contact.js:11", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 website/src/js/contact.js:11"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-2f7737315ee6c076", "name": "Debug `console.log` remains in browser-facing code \u2014 website/src/js/design3.js:77", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 website/src/js/design3.js:77"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-7a9a1597ab25b677", "name": "Debug `console.log` remains in browser-facing code \u2014 website/src/js/directory.js:309", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 website/src/js/directory.js:309"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-7168835c14006656", "name": "Debug `console.log` remains in browser-facing code \u2014 website/src/js/animation2.js:3", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 website/src/js/animation2.js:3"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-20a216ff8a60b744", "name": "Debug `console.log` remains in browser-facing code \u2014 website/src/js/docs.js:51", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 website/src/js/docs.js:51"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-3ab81bca85fdfced", "name": "TODO/FIXME marker in shipping code \u2014 website/src/js/animation.js:70", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 website/src/js/animation.js:70"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-ee762c55b2668d55", "name": "TODO/FIXME marker in shipping code \u2014 website/src/call/call.js:480", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 website/src/call/call.js:480"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-1c58187104e1fdd0", "name": "Debug `console.log` remains in browser-facing code \u2014 website/src/call/call.js:16", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 website/src/call/call.js:16"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-c55c904fcc6bbbff", "name": "Debug `console.log` remains in browser-facing code \u2014 website/src/call/ui.js:76", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 website/src/call/ui.js:76"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-f79b068ffbb6f531", "name": "Debug `console.log` remains in browser-facing code \u2014 packages/simplex-chat-webrtc/src/ui.js:76", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 packages/simplex-chat-webrtc/src/ui.js:76"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-0f199007329f3cc8", "name": "TODO/FIXME marker in shipping code \u2014 packages/simplex-chat-webrtc/src/call.ts:1457", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 packages/simplex-chat-webrtc/src/call.ts:1457"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-61aff3a2912d74ff", "name": "Debug `console.log` remains in browser-facing code \u2014 packages/simplex-chat-webrtc/src/call.ts:238", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 packages/simplex-chat-webrtc/src/call.ts:238"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-3539c0f81270c39e", "name": "Debug `console.log` remains in browser-facing code \u2014 packages/simplex-chat-webrtc/src/desktop/ui.ts:9", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 packages/simplex-chat-webrtc/src/desktop/ui.ts:9"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-7dd0e4b3bc41e934", "name": "TODO/FIXME marker in shipping code \u2014 packages/simplex-chat-client/typescript/src/client.ts:63", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 packages/simplex-chat-client/typescript/src/client.ts:63"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-ac45240a8d19a4da", "name": "dynamic urllib use detected \u2014 packages/simplex-chat-python/src/simplex_chat/_native.py:102", "shortDescription": {"text": "dynamic urllib use detected \u2014 packages/simplex-chat-python/src/simplex_chat/_native.py:102"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A01:2017 - Injection\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-803e7afa5090eecb", "name": "template unescaped with safe \u2014 website/src/_includes/contact_page.html:11", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/contact_page.html:11"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-524a132ccdf911c6", "name": "template unescaped with safe \u2014 website/src/_includes/footer.html:13", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/footer.html:13"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-880385a0303c7d20", "name": "template unescaped with safe \u2014 website/src/_includes/hero.html:11", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/hero.html:11"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-fda1c9fd87840e32", "name": "unquoted attribute var \u2014 website/src/_includes/layouts/article.html:5", "shortDescription": {"text": "unquoted attribute var \u2014 website/src/_includes/layouts/article.html:5"}, "fullDescription": {"text": "Detected a unquoted template variable as an attribute. If unquoted, a malicious actor could inject custom JavaScript handlers. To fix this, add quotes around the template expression, like this: \"{{ expr }}\".\n\nRule: generic.html-templates.security.unquoted-attribute-var.unquoted-attribute-var\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-54264229cc352f3d", "name": "template unescaped with safe \u2014 website/src/_includes/layouts/article.html:44", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/layouts/article.html:44"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-2022dacf64fa7387", "name": "unquoted attribute var \u2014 website/src/_includes/layouts/doc.html:6", "shortDescription": {"text": "unquoted attribute var \u2014 website/src/_includes/layouts/doc.html:6"}, "fullDescription": {"text": "Detected a unquoted template variable as an attribute. If unquoted, a malicious actor could inject custom JavaScript handlers. To fix this, add quotes around the template expression, like this: \"{{ expr }}\".\n\nRule: generic.html-templates.security.unquoted-attribute-var.unquoted-attribute-var\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-4ff9e7edaa69340f", "name": "var in href \u2014 website/src/_includes/layouts/doc.html:54", "shortDescription": {"text": "var in href \u2014 website/src/_includes/layouts/doc.html:54"}, "fullDescription": {"text": "Detected a template variable used in an anchor tag with the 'href' attribute. This allows a malicious actor to input the 'javascript:' URI and is subject to cross- site scripting (XSS) attacks. If using Flask, use 'url_for()' to safely generate a URL. If using Django, use the 'url' filter to safely generate a URL. If using Mustache, use a URL encoding library, or prepend a slash '/' to the variable for relative links (`href=\"/{{link}}\"`). You may also consider setting the Content Security Policy (CSP) header.\n\nRule: generic.html-templates.security.var-in-href.var-in-href\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-41c6aeddafee7856", "name": "template unescaped with safe \u2014 website/src/_includes/layouts/doc.html:77", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/layouts/doc.html:77"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-ad26c68d40d12a7e", "name": "unquoted attribute var \u2014 website/src/_includes/layouts/jobs.html:5", "shortDescription": {"text": "unquoted attribute var \u2014 website/src/_includes/layouts/jobs.html:5"}, "fullDescription": {"text": "Detected a unquoted template variable as an attribute. If unquoted, a malicious actor could inject custom JavaScript handlers. To fix this, add quotes around the template expression, like this: \"{{ expr }}\".\n\nRule: generic.html-templates.security.unquoted-attribute-var.unquoted-attribute-var\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-a6516173ffd33c67", "name": "template unescaped with safe \u2014 website/src/_includes/layouts/jobs.html:32", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/layouts/jobs.html:32"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-40616225e4c27deb", "name": "unquoted attribute var \u2014 website/src/_includes/layouts/main.html:5", "shortDescription": {"text": "unquoted attribute var \u2014 website/src/_includes/layouts/main.html:5"}, "fullDescription": {"text": "Detected a unquoted template variable as an attribute. If unquoted, a malicious actor could inject custom JavaScript handlers. To fix this, add quotes around the template expression, like this: \"{{ expr }}\".\n\nRule: generic.html-templates.security.unquoted-attribute-var.unquoted-attribute-var\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-a681fa38c28a497a", "name": "template unescaped with safe \u2014 website/src/_includes/layouts/main.html:43", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/layouts/main.html:43"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-25b6ec26dd243c79", "name": "unquoted attribute var \u2014 website/src/_includes/layouts/privacy.html:5", "shortDescription": {"text": "unquoted attribute var \u2014 website/src/_includes/layouts/privacy.html:5"}, "fullDescription": {"text": "Detected a unquoted template variable as an attribute. If unquoted, a malicious actor could inject custom JavaScript handlers. To fix this, add quotes around the template expression, like this: \"{{ expr }}\".\n\nRule: generic.html-templates.security.unquoted-attribute-var.unquoted-attribute-var\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-aa6a1cfd415cc5a5", "name": "template unescaped with safe \u2014 website/src/_includes/layouts/privacy.html:39", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/layouts/privacy.html:39"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-2fe28436323440bb", "name": "var in href \u2014 website/src/_includes/layouts/redirect.html:19", "shortDescription": {"text": "var in href \u2014 website/src/_includes/layouts/redirect.html:19"}, "fullDescription": {"text": "Detected a template variable used in an anchor tag with the 'href' attribute. This allows a malicious actor to input the 'javascript:' URI and is subject to cross- site scripting (XSS) attacks. If using Flask, use 'url_for()' to safely generate a URL. If using Django, use the 'url' filter to safely generate a URL. If using Mustache, use a URL encoding library, or prepend a slash '/' to the variable for relative links (`href=\"/{{link}}\"`). You may also consider setting the Content Security Policy (CSP) header.\n\nRule: generic.html-templates.security.var-in-href.var-in-href\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-1db67d6415723a92", "name": "unquoted attribute var \u2014 website/src/_includes/layouts/token.html:5", "shortDescription": {"text": "unquoted attribute var \u2014 website/src/_includes/layouts/token.html:5"}, "fullDescription": {"text": "Detected a unquoted template variable as an attribute. If unquoted, a malicious actor could inject custom JavaScript handlers. To fix this, add quotes around the template expression, like this: \"{{ expr }}\".\n\nRule: generic.html-templates.security.unquoted-attribute-var.unquoted-attribute-var\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-669e0db0f9a5bad7", "name": "template unescaped with safe \u2014 website/src/_includes/layouts/token.html:222", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/layouts/token.html:222"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-679d42f2be28c50e", "name": "template unescaped with safe \u2014 website/src/_includes/navbar.html:17", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/navbar.html:17"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-09e1c9aabb0d5300", "name": "var in href \u2014 website/src/_includes/navbar.html:51", "shortDescription": {"text": "var in href \u2014 website/src/_includes/navbar.html:51"}, "fullDescription": {"text": "Detected a template variable used in an anchor tag with the 'href' attribute. This allows a malicious actor to input the 'javascript:' URI and is subject to cross- site scripting (XSS) attacks. If using Flask, use 'url_for()' to safely generate a URL. If using Django, use the 'url' filter to safely generate a URL. If using Mustache, use a URL encoding library, or prepend a slash '/' to the variable for relative links (`href=\"/{{link}}\"`). You may also consider setting the Content Security Policy (CSP) header.\n\nRule: generic.html-templates.security.var-in-href.var-in-href\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-455218701d4a64f7", "name": "unquoted attribute var \u2014 website/src/_includes/navbar.html:51", "shortDescription": {"text": "unquoted attribute var \u2014 website/src/_includes/navbar.html:51"}, "fullDescription": {"text": "Detected a unquoted template variable as an attribute. If unquoted, a malicious actor could inject custom JavaScript handlers. To fix this, add quotes around the template expression, like this: \"{{ expr }}\".\n\nRule: generic.html-templates.security.unquoted-attribute-var.unquoted-attribute-var\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-2ba7adae1d88c981", "name": "template unescaped with safe \u2014 website/src/_includes/overlay_content/file/protocol.html:2", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/overlay_content/file/protocol.html:2"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-d595e5f59f6d1126", "name": "template unescaped with safe \u2014 website/src/_includes/overlay_content/hero/card_1.html:2", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/overlay_content/hero/card_1.html:2"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-de23e5a8764cb4d8", "name": "template unescaped with safe \u2014 website/src/_includes/overlay_content/hero/card_2.html:2", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/overlay_content/hero/card_2.html:2"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-58fd472b56e5ddd4", "name": "template unescaped with safe \u2014 website/src/_includes/overlay_content/hero/card_3.html:2", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/overlay_content/hero/card_3.html:2"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-5397af6b19c25859", "name": "template unescaped with safe \u2014 website/src/_includes/overlay_content/simplex_network/card_1.html:2", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/overlay_content/simplex_network/card_1.html:2"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-872b6e94bc0bbab6", "name": "template unescaped with safe \u2014 website/src/_includes/overlay_content/why_privacy_matters/card_1.html:2", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/overlay_content/why_privacy_matters/card_1.html:2"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-c266ea0318816140", "name": "template unescaped with safe \u2014 website/src/_includes/overlay_content/why_privacy_matters/card_2.html:2", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/overlay_content/why_privacy_matters/card_2.html:2"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-0d331472217fd235", "name": "template unescaped with safe \u2014 website/src/_includes/overlay_content/why_privacy_matters/card_3.html:2", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/overlay_content/why_privacy_matters/card_3.html:2"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-197998140b62735b", "name": "template unescaped with safe \u2014 website/src/_includes/overlay_content/why_simplex_is_unique/card_1.html:2", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/overlay_content/why_simplex_is_unique/card_1.html:2"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-6ca3b41b76999e9d", "name": "template unescaped with safe \u2014 website/src/_includes/overlay_content/why_simplex_is_unique/card_2.html:2", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/overlay_content/why_simplex_is_unique/card_2.html:2"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-448805d117b20476", "name": "template unescaped with safe \u2014 website/src/_includes/overlay_content/why_simplex_is_unique/card_3.html:2", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/overlay_content/why_simplex_is_unique/card_3.html:2"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-95a11fc1e06e1012", "name": "template unescaped with safe \u2014 website/src/_includes/overlay_content/why_simplex_is_unique/card_4.html:2", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/overlay_content/why_simplex_is_unique/card_4.html:2"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-3e75d75f3e7c9946", "name": "template unescaped with safe \u2014 website/src/_includes/sections/join_simplex.html:6", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/sections/join_simplex.html:6"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-36e5312f43a63cd5", "name": "unquoted attribute var \u2014 website/src/_includes/sections/join_simplex.html:20", "shortDescription": {"text": "unquoted attribute var \u2014 website/src/_includes/sections/join_simplex.html:20"}, "fullDescription": {"text": "Detected a unquoted template variable as an attribute. If unquoted, a malicious actor could inject custom JavaScript handlers. To fix this, add quotes around the template expression, like this: \"{{ expr }}\".\n\nRule: generic.html-templates.security.unquoted-attribute-var.unquoted-attribute-var\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-cd8ed9e29dc92cfd", "name": "template unescaped with safe \u2014 website/src/_includes/sections/simplex_unique.html:3", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/sections/simplex_unique.html:3"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-d76edf2a1a807712", "name": "template unescaped with safe \u2014 website/src/_includes/sections/simplex_unique/card_1.html:2", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/sections/simplex_unique/card_1.html:2"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-63cbf95516bd8e13", "name": "template unescaped with safe \u2014 website/src/_includes/sections/simplex_unique/card_2.html:2", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/sections/simplex_unique/card_2.html:2"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-2cd6907783562f5c", "name": "template unescaped with safe \u2014 website/src/_includes/sections/simplex_unique/card_3.html:2", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/sections/simplex_unique/card_3.html:2"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-6374787b8ea18884", "name": "template unescaped with safe \u2014 website/src/_includes/sections/simplex_unique/card_4.html:2", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/sections/simplex_unique/card_4.html:2"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-7374226dbcceb8d2", "name": "template unescaped with safe \u2014 website/src/_includes/simplex_explained.html:28", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/_includes/simplex_explained.html:28"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-3f98a05f965fdace", "name": "var in href \u2014 website/src/blog.html:76", "shortDescription": {"text": "var in href \u2014 website/src/blog.html:76"}, "fullDescription": {"text": "Detected a template variable used in an anchor tag with the 'href' attribute. This allows a malicious actor to input the 'javascript:' URI and is subject to cross- site scripting (XSS) attacks. If using Flask, use 'url_for()' to safely generate a URL. If using Django, use the 'url' filter to safely generate a URL. If using Mustache, use a URL encoding library, or prepend a slash '/' to the variable for relative links (`href=\"/{{link}}\"`). You may also consider setting the Content Security Policy (CSP) header.\n\nRule: generic.html-templates.security.var-in-href.var-in-href\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-e89fe1b0a4a2f577", "name": "template unescaped with safe \u2014 website/src/blog.html:76", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/blog.html:76"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-c60abd48cef265bb", "name": "template unescaped with safe \u2014 website/src/fdroid.html:21", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/fdroid.html:21"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-e4afe4742cc2e118", "name": "template unescaped with safe \u2014 website/src/file.html:187", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/file.html:187"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-86e239994cbd8dc5", "name": "unquoted attribute var \u2014 website/src/index.html:12", "shortDescription": {"text": "unquoted attribute var \u2014 website/src/index.html:12"}, "fullDescription": {"text": "Detected a unquoted template variable as an attribute. If unquoted, a malicious actor could inject custom JavaScript handlers. To fix this, add quotes around the template expression, like this: \"{{ expr }}\".\n\nRule: generic.html-templates.security.unquoted-attribute-var.unquoted-attribute-var\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-77997e855effa5d2", "name": "template unescaped with safe \u2014 website/src/index.html:100", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/index.html:100"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-d209195850b933fa", "name": "var in href \u2014 website/src/index.html:117", "shortDescription": {"text": "var in href \u2014 website/src/index.html:117"}, "fullDescription": {"text": "Detected a template variable used in an anchor tag with the 'href' attribute. This allows a malicious actor to input the 'javascript:' URI and is subject to cross- site scripting (XSS) attacks. If using Flask, use 'url_for()' to safely generate a URL. If using Django, use the 'url' filter to safely generate a URL. If using Mustache, use a URL encoding library, or prepend a slash '/' to the variable for relative links (`href=\"/{{link}}\"`). You may also consider setting the Content Security Policy (CSP) header.\n\nRule: generic.html-templates.security.var-in-href.var-in-href\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-3b896f7335595212", "name": "template unescaped with safe \u2014 website/src/links.html:236", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/links.html:236"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-cac6225d3d7bf291", "name": "var in href \u2014 website/src/links.html:295", "shortDescription": {"text": "var in href \u2014 website/src/links.html:295"}, "fullDescription": {"text": "Detected a template variable used in an anchor tag with the 'href' attribute. This allows a malicious actor to input the 'javascript:' URI and is subject to cross- site scripting (XSS) attacks. If using Flask, use 'url_for()' to safely generate a URL. If using Django, use the 'url' filter to safely generate a URL. If using Mustache, use a URL encoding library, or prepend a slash '/' to the variable for relative links (`href=\"/{{link}}\"`). You may also consider setting the Content Security Policy (CSP) header.\n\nRule: generic.html-templates.security.var-in-href.var-in-href\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-2812bc3318bd1721", "name": "template unescaped with safe \u2014 website/src/messaging.html:21", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/messaging.html:21"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-e8bdf265f92e6e28", "name": "template unescaped with safe \u2014 website/src/old.html:14", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/old.html:14"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-d1cf6cfa52e23d69", "name": "template unescaped with safe \u2014 website/src/why.html:15", "shortDescription": {"text": "template unescaped with safe \u2014 website/src/why.html:15"}, "fullDescription": {"text": "Detected a segment of a Flask template where autoescaping is explicitly disabled with '| safe' filter. This allows rendering of raw HTML in this segment. Ensure no user data is rendered here, otherwise this is a cross-site scripting (XSS) vulnerability.\n\nRule: python.flask.security.xss.audit.template-unescaped-with-safe.template-unescaped-with-safe\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-3a3527e70129fb18", "name": "DS-0002: Image user should not be 'root' \u2014 Dockerfile", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 Dockerfile"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3c4041c454cda88e", "name": "DS-0026: No HEALTHCHECK defined \u2014 Dockerfile", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 Dockerfile"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a4b9283354e8accd", "name": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 Dockerfile", "shortDescription": {"text": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 Dockerfile"}, "fullDescription": {"text": "'apt-get' missing '--no-install-recommends'\n\n'--no-install-recommends' flag is missed: 'apt-get update && apt-get install -y curl git build-essential libgmp3-dev zlib1g-dev llvm-12 llvm-12-dev libnuma-dev libssl-dev'\n\nRule: DS-0029\nSeverity: HIGH\nTarget: Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9212dfb5585dffa6", "name": "DS-0026: No HEALTHCHECK defined \u2014 Dockerfile.build", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 Dockerfile.build"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: Dockerfile.build"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-36e3fde2a5facb6d", "name": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 Dockerfile.build", "shortDescription": {"text": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 Dockerfile.build"}, "fullDescription": {"text": "'apt-get' missing '--no-install-recommends'\n\n'--no-install-recommends' flag is missed: 'apt-get update &&     apt-get install -y curl                        libpq-dev                        git                        strip-nondeterminism                        sqlite3                        libsqlite3-dev                        build-essential                        libgmp3-dev                        zlib1g-dev                        llvm                        cmake                        llvm-dev                        libnuma-dev       \n\nRule: DS-0029\nSeverity: HIGH\nTarget: Dockerfile.build"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dc83e44bf55910b6", "name": "Privileged port 256 in use", "shortDescription": {"text": "Privileged port 256 in use"}, "fullDescription": {"text": "Port 256 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f01032220206384d", "name": "Privileged port 98 in use", "shortDescription": {"text": "Privileged port 98 in use"}, "fullDescription": {"text": "Port 98 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ae8cc70ffc7d7022", "name": "Privileged port 70 in use", "shortDescription": {"text": "Privileged port 70 in use"}, "fullDescription": {"text": "Port 70 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-05cb8b58b94b41f7", "name": "Privileged port 14 in use", "shortDescription": {"text": "Privileged port 14 in use"}, "fullDescription": {"text": "Port 14 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6a0dd1c78bdd0436", "name": "Privileged port 77 in use", "shortDescription": {"text": "Privileged port 77 in use"}, "fullDescription": {"text": "Port 77 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d63da3583b14afc0", "name": "Dockerfile runs as root: Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b7396bc6b618acbd", "name": "Docker base image is tag-pinned but not digest-pinned: ubuntu:${TAG}", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: ubuntu:${TAG}"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e2f1cddf8cbe14d3", "name": "Dockerfile pipes a remote installer into a shell", "shortDescription": {"text": "Dockerfile pipes a remote installer into a shell"}, "fullDescription": {"text": "Executing downloaded code during image build gives the remote endpoint build-time code execution. Prefer pinned packages or verify downloaded installers by checksum/signature."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "high", "confidence": 1.0}}, {"id": "scanner-54fd559fd5a28a50", "name": "Insecure pattern 'direct_innerhtml_assignment' in apps/multiplatform/common/src/commonMain/resources/assets/www/desktop/", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in apps/multiplatform/common/src/commonMain/resources/assets/www/desktop/ui.js:89"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-acb101d9b72dc9c5", "name": "Insecure pattern 'direct_innerhtml_assignment' in website/.eleventy.js:136", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in website/.eleventy.js:136"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-ad7e4e7ef1bcea81", "name": "Insecure pattern 'direct_innerhtml_assignment' in website/src/js/prism.min.js:3", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in website/src/js/prism.min.js:3"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-3d3d816fa27b2fac", "name": "Insecure pattern 'direct_innerhtml_assignment' in website/src/js/swiper-bundle.min.js:13", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in website/src/js/swiper-bundle.min.js:13"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-b9272c04c5a18d5e", "name": "Insecure pattern 'direct_innerhtml_assignment' in website/src/js/docs.js:6", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in website/src/js/docs.js:6"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-ad1a9928348d53cd", "name": "Insecure pattern 'insert_adjacent_html' in website/src/js/demo.js:61", "shortDescription": {"text": "Insecure pattern 'insert_adjacent_html' in website/src/js/demo.js:61"}, "fullDescription": {"text": "Found a known-risky pattern (insert_adjacent_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-dac2c9a8e67947f8", "name": "Insecure pattern 'insert_adjacent_html' in website/src/js/index.js:61", "shortDescription": {"text": "Insecure pattern 'insert_adjacent_html' in website/src/js/index.js:61"}, "fullDescription": {"text": "Found a known-risky pattern (insert_adjacent_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-1853d72c598b2255", "name": "Insecure pattern 'direct_innerhtml_assignment' in packages/simplex-chat-webrtc/src/desktop/ui.ts:108", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in packages/simplex-chat-webrtc/src/desktop/ui.ts:108"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8ecdc3efdd4aa236", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "cla-assistant/github-action@v2.3.0 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2fdcc3aac10df7e9", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-73b22d23d303a3a0", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/setup-node@v1 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8200d745dafb1795", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v3 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6ba9bfab5f283202", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v3 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-361c9c3d725df6cc", "name": "package.json defines install-time lifecycle scripts", "shortDescription": {"text": "package.json defines install-time lifecycle scripts"}, "fullDescription": {"text": "preinstall/install/postinstall/prepare scripts execute during dependency installation. Review them carefully for network calls, obfuscation, shell execution, or credential access."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-349a56cdc52f291a", "name": "Very large file: apps/multiplatform/common/src/commonMain/resources/assets/www/call.js (1505 lines)", "shortDescription": {"text": "Very large file: apps/multiplatform/common/src/commonMain/resources/assets/www/call.js (1505 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72f2376383857ca3", "name": "Very large file: apps/simplex-support-bot/bot.test.ts (2706 lines)", "shortDescription": {"text": "Very large file: apps/simplex-support-bot/bot.test.ts (2706 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-826d16b77e3bb3d0", "name": "Very large file: packages/simplex-chat-python/src/simplex_chat/types/_types.py (3562 lines)", "shortDescription": {"text": "Very large file: packages/simplex-chat-python/src/simplex_chat/types/_types.py (3562 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-005811cee59e8bf5", "name": "Very large file: packages/simplex-chat-webrtc/src/call.ts (1872 lines)", "shortDescription": {"text": "Very large file: packages/simplex-chat-webrtc/src/call.ts (1872 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-babf804452f97582", "name": "Very large file: packages/simplex-chat-client/types/typescript/src/types.ts (5070 lines)", "shortDescription": {"text": "Very large file: packages/simplex-chat-client/types/typescript/src/types.ts (5070 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea3b5e389d8c9c0f", "name": "Low test-to-source ratio", "shortDescription": {"text": "Low test-to-source ratio"}, "fullDescription": {"text": "17 tests / 78 src (ratio 0.22)."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0075309a6605cbd9", "name": "Node manifest has dependencies but no lockfile: website/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: website/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9d0ad3de1b0a95bd", "name": "Node manifest has dependencies but no lockfile: packages/simplex-chat-nodejs/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/simplex-chat-nodejs/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-666a05be2dfb94bd", "name": "Node manifest has dependencies but no lockfile: packages/simplex-chat-webrtc/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/simplex-chat-webrtc/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-405514940086b49f", "name": "Node manifest has dependencies but no lockfile: packages/simplex-chat-client/types/typescript/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/simplex-chat-client/types/typescript/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9459e1bdf08e40de", "name": "Node manifest has dependencies but no lockfile: packages/simplex-chat-client/typescript/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/simplex-chat-client/typescript/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 232 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-55be46ce63e4f882", "name": "Commented-code block (5 lines) in apps/multiplatform/common/src/commonMain/resources/assets/www/call.js:394", "shortDescription": {"text": "Commented-code block (5 lines) in apps/multiplatform/common/src/commonMain/resources/assets/www/call.js:394"}, "fullDescription": {"text": "3 of 5 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-fa3baf4c5a0300a4", "name": "Legacy-named symbol `simplex_v1` in apps/simplex-support-bot/src/config.ts:63", "shortDescription": {"text": "Legacy-named symbol `simplex_v1` in apps/simplex-support-bot/src/config.ts:63"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-05cbfb7271f1d203", "name": "Legacy-named symbol `isOld` in website/customize_docs_frontmatter.js:78", "shortDescription": {"text": "Legacy-named symbol `isOld` in website/customize_docs_frontmatter.js:78"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7c07ecd85796a5a0", "name": "Legacy-named symbol `content_copy` in website/src/js/contact.js:41", "shortDescription": {"text": "Legacy-named symbol `content_copy` in website/src/js/contact.js:41"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2bca68ea7ee5db3e", "name": "Commented-code block (6 lines) in website/src/js/directory.js:376", "shortDescription": {"text": "Commented-code block (6 lines) in website/src/js/directory.js:376"}, "fullDescription": {"text": "6 of 6 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-2ab7256b01f63ddd", "name": "Commented-code block (10 lines) in website/src/js/animation2.js:4", "shortDescription": {"text": "Commented-code block (10 lines) in website/src/js/animation2.js:4"}, "fullDescription": {"text": "5 of 10 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-6deb31ec89b62598", "name": "Legacy-named symbol `content_copy` in website/src/js/index.js:361", "shortDescription": {"text": "Legacy-named symbol `content_copy` in website/src/js/index.js:361"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f6b52c5f2fff9616", "name": "Commented-code block (10 lines) in website/src/js/animation.js:43", "shortDescription": {"text": "Commented-code block (10 lines) in website/src/js/animation.js:43"}, "fullDescription": {"text": "9 of 10 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-add249c786702e9c", "name": "Commented-code block (5 lines) in website/src/call/call.js:479", "shortDescription": {"text": "Commented-code block (5 lines) in website/src/call/call.js:479"}, "fullDescription": {"text": "4 of 5 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-1fd1f68279cf930a", "name": "Commented-code block (6 lines) in website/src/call/ui.js:19", "shortDescription": {"text": "Commented-code block (6 lines) in website/src/call/ui.js:19"}, "fullDescription": {"text": "5 of 6 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-9a63a91057d181f7", "name": "Legacy-named symbol `simplex_v1` in packages/simplex-chat-nodejs/src/api.ts:77", "shortDescription": {"text": "Legacy-named symbol `simplex_v1` in packages/simplex-chat-nodejs/src/api.ts:77"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-525a0c763e747a5a", "name": "Legacy-named symbol `from_buffer_copy` in packages/simplex-chat-python/src/simplex_chat/_native.py:188", "shortDescription": {"text": "Legacy-named symbol `from_buffer_copy` in packages/simplex-chat-python/src/simplex_chat/_native.py:188"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fff6cca32dffa01f", "name": "Legacy-named symbol `expiredOld` in packages/simplex-chat-python/src/simplex_chat/types/_types.py:152", "shortDescription": {"text": "Legacy-named symbol `expiredOld` in packages/simplex-chat-python/src/simplex_chat/types/_types.py:152"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7509df1178fc87ff", "name": "Commented-code block (6 lines) in packages/simplex-chat-webrtc/src/ui.js:19", "shortDescription": {"text": "Commented-code block (6 lines) in packages/simplex-chat-webrtc/src/ui.js:19"}, "fullDescription": {"text": "5 of 6 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-73a37d69cb51830f", "name": "Commented-code block (5 lines) in packages/simplex-chat-webrtc/src/call.ts:686", "shortDescription": {"text": "Commented-code block (5 lines) in packages/simplex-chat-webrtc/src/call.ts:686"}, "fullDescription": {"text": "3 of 5 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-475dd4cdbb915027", "name": "Legacy-named symbol `ExpiredOld` in packages/simplex-chat-client/types/typescript/src/types.ts:205", "shortDescription": {"text": "Legacy-named symbol `ExpiredOld` in packages/simplex-chat-client/types/typescript/src/types.ts:205"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-165feafc550752d7", "name": "Vulnerable dependency vitest 1.6.1: GHSA-5xrq-8626-4rwp", "shortDescription": {"text": "Vulnerable dependency vitest 1.6.1: GHSA-5xrq-8626-4rwp"}, "fullDescription": {"text": "OSV.dev reports `vitest` at version `1.6.1` (resolved in `apps/simplex-support-bot/package-lock.json`) is affected by GHSA-5xrq-8626-4rwp (aka CVE-2026-47429).\n\nWhen Vitest UI server is listening, arbitrary file can be read and executed\n\nAliases: CVE-2026-47429\nAdvisory: https://osv.dev/vulnerability/GHSA-5xrq-8626-4rwp\nFix: upgrade `vitest` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-6998a30cc67c4017", "name": "Vulnerable dependency rollup 2.72.1: GHSA-gcx4-mw62-g8wm", "shortDescription": {"text": "Vulnerable dependency rollup 2.72.1: GHSA-gcx4-mw62-g8wm"}, "fullDescription": {"text": "OSV.dev reports `rollup` at version `2.72.1` (declared in `packages/simplex-chat-client/typescript/package.json`) is affected by GHSA-gcx4-mw62-g8wm (aka CVE-2024-47068).\nNote: `2.72.1` is the declared floor of a range \u2014 the installed version may be newer.\n\nDOM Clobbering Gadget found in rollup bundled scripts that leads to XSS\n\nAliases: CVE-2024-47068\nAdvisory: https://osv.dev/vulnerability/GHSA-gcx4-mw62-g8wm\nFix: upgrade `rollup` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.7}}, {"id": "scanner-6a28d5abb3a21338", "name": "Vulnerable dependency rollup 2.72.1: GHSA-mw96-cpmx-2vgc", "shortDescription": {"text": "Vulnerable dependency rollup 2.72.1: GHSA-mw96-cpmx-2vgc"}, "fullDescription": {"text": "OSV.dev reports `rollup` at version `2.72.1` (declared in `packages/simplex-chat-client/typescript/package.json`) is affected by GHSA-mw96-cpmx-2vgc (aka CVE-2026-27606).\nNote: `2.72.1` is the declared floor of a range \u2014 the installed version may be newer.\n\nRollup 4 has Arbitrary File Write via Path Traversal\n\nAliases: CVE-2026-27606\nAdvisory: https://osv.dev/vulnerability/GHSA-mw96-cpmx-2vgc\nFix: upgrade `rollup` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.7}}, {"id": "scanner-23f84f0d08cf9228", "name": "Vulnerable dependency fs 0.0.1-security: MAL-2025-21003", "shortDescription": {"text": "Vulnerable dependency fs 0.0.1-security: MAL-2025-21003"}, "fullDescription": {"text": "OSV.dev reports `fs` at version `0.0.1-security` (declared in `website/package.json`) is affected by MAL-2025-21003.\nNote: `0.0.1-security` is the declared floor of a range \u2014 the installed version may be newer.\n\nMalicious code in fs (npm)\n\nAdvisory: https://osv.dev/vulnerability/MAL-2025-21003\nFix: upgrade `fs` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-7d0af19f905d175c", "name": "Vulnerable dependency markdown-it 13.0.1: GHSA-38c4-r59v-3vqw", "shortDescription": {"text": "Vulnerable dependency markdown-it 13.0.1: GHSA-38c4-r59v-3vqw"}, "fullDescription": {"text": "OSV.dev reports `markdown-it` at version `13.0.1` (declared in `website/package.json`) is affected by GHSA-38c4-r59v-3vqw (aka CVE-2026-2327).\nNote: `13.0.1` is the declared floor of a range \u2014 the installed version may be newer.\n\nmarkdown-it is has a Regular Expression Denial of Service (ReDoS)\n\nAliases: CVE-2026-2327\nAdvisory: https://osv.dev/vulnerability/GHSA-38c4-r59v-3vqw\nFix: upgrade `markdown-it` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-5d534136b77c7084", "name": "Vulnerable dependency markdown-it 13.0.1: GHSA-6v5v-wf23-fmfq", "shortDescription": {"text": "Vulnerable dependency markdown-it 13.0.1: GHSA-6v5v-wf23-fmfq"}, "fullDescription": {"text": "OSV.dev reports `markdown-it` at version `13.0.1` (declared in `website/package.json`) is affected by GHSA-6v5v-wf23-fmfq (aka CVE-2026-48988).\nNote: `13.0.1` is the declared floor of a range \u2014 the installed version may be newer.\n\nmarkdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations\n\nAliases: CVE-2026-48988\nAdvisory: https://osv.dev/vulnerability/GHSA-6v5v-wf23-fmfq\nFix: upgrade `markdown-it` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-bce14173c06b5350", "name": "Vulnerable dependency fast-uri 2.1.0: GHSA-q3j6-qgpj-74h6", "shortDescription": {"text": "Vulnerable dependency fast-uri 2.1.0: GHSA-q3j6-qgpj-74h6"}, "fullDescription": {"text": "OSV.dev reports `fast-uri` at version `2.1.0` (declared in `website/package.json`) is affected by GHSA-q3j6-qgpj-74h6 (aka CVE-2026-6321).\nNote: `2.1.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nfast-uri vulnerable to path traversal via percent-encoded dot segments\n\nAliases: CVE-2026-6321\nAdvisory: https://osv.dev/vulnerability/GHSA-q3j6-qgpj-74h6\nFix: upgrade `fast-uri` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.7}}, {"id": "scanner-09feb9c813cefdf4", "name": "Vulnerable dependency fast-uri 2.1.0: GHSA-v39h-62p7-jpjc", "shortDescription": {"text": "Vulnerable dependency fast-uri 2.1.0: GHSA-v39h-62p7-jpjc"}, "fullDescription": {"text": "OSV.dev reports `fast-uri` at version `2.1.0` (declared in `website/package.json`) is affected by GHSA-v39h-62p7-jpjc (aka CVE-2026-6322).\nNote: `2.1.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nfast-uri vulnerable to host confusion via percent-encoded authority delimiters\n\nAliases: CVE-2026-6322\nAdvisory: https://osv.dev/vulnerability/GHSA-v39h-62p7-jpjc\nFix: upgrade `fast-uri` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.7}}, {"id": "scanner-4bd54199af779af6", "name": "Vulnerable dependency esbuild 0.21.5: GHSA-67mh-4wv8-2f99", "shortDescription": {"text": "Vulnerable dependency esbuild 0.21.5: GHSA-67mh-4wv8-2f99"}, "fullDescription": {"text": "OSV.dev reports `esbuild` at version `0.21.5` (resolved in `apps/simplex-support-bot/package-lock.json`) is affected by GHSA-67mh-4wv8-2f99.\nNote: `esbuild` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nesbuild enables any website to send any requests to the development server and read the response\n\nAdvisory: https://osv.dev/vulnerability/GHSA-67mh-4wv8-2f99\nFix: upgrade `esbuild` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-c33ad296124c932f", "name": "Vulnerable dependency postcss 8.5.10: GHSA-6g55-p6wh-862q", "shortDescription": {"text": "Vulnerable dependency postcss 8.5.10: GHSA-6g55-p6wh-862q"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.5.10` (resolved in `apps/simplex-support-bot/package-lock.json`) is affected by GHSA-6g55-p6wh-862q (aka CVE-2026-45623).\nNote: `postcss` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nPostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments\n\nAliases: CVE-2026-45623\nAdvisory: https://osv.dev/vulnerability/GHSA-6g55-p6wh-862q\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-0608f2d29b2565de", "name": "Vulnerable dependency vite 5.4.21: GHSA-4w7w-66w2-5vf9", "shortDescription": {"text": "Vulnerable dependency vite 5.4.21: GHSA-4w7w-66w2-5vf9"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `5.4.21` (resolved in `apps/simplex-support-bot/package-lock.json`) is affected by GHSA-4w7w-66w2-5vf9 (aka CVE-2026-39365).\nNote: `vite` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nVite Vulnerable to Path Traversal in Optimized Deps `.map` Handling\n\nAliases: CVE-2026-39365\nAdvisory: https://osv.dev/vulnerability/GHSA-4w7w-66w2-5vf9\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-f0b3454151599e5c", "name": "Vulnerable dependency vite 5.4.21: GHSA-fx2h-pf6j-xcff", "shortDescription": {"text": "Vulnerable dependency vite 5.4.21: GHSA-fx2h-pf6j-xcff"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `5.4.21` (resolved in `apps/simplex-support-bot/package-lock.json`) is affected by GHSA-fx2h-pf6j-xcff (aka CVE-2026-53571).\nNote: `vite` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nvite: `server.fs.deny` bypass on Windows alternate paths\n\nAliases: CVE-2026-53571\nAdvisory: https://osv.dev/vulnerability/GHSA-fx2h-pf6j-xcff\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-f9500129983dd770", "name": "Vulnerable dependency vite 5.4.21: GHSA-v6wh-96g9-6wx3", "shortDescription": {"text": "Vulnerable dependency vite 5.4.21: GHSA-v6wh-96g9-6wx3"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `5.4.21` (resolved in `apps/simplex-support-bot/package-lock.json`) is affected by GHSA-v6wh-96g9-6wx3 (aka CVE-2026-53632).\nNote: `vite` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nlaunch-editor: NTLMv2 hash disclosure via UNC path handling on Windows\n\nAliases: CVE-2026-53632\nAdvisory: https://osv.dev/vulnerability/GHSA-v6wh-96g9-6wx3\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-9faf81221a573ee8", "name": "Dependency commander is a major version behind", "shortDescription": {"text": "Dependency commander is a major version behind"}, "fullDescription": {"text": "`commander` is pinned at `14.0.3` in `apps/simplex-support-bot/package.json` while the latest release on the npm registry is `15.0.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `commander` to `15.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-f6b4a27d30e54c85", "name": "Dependency isomorphic-ws is a major version behind", "shortDescription": {"text": "Dependency isomorphic-ws is a major version behind"}, "fullDescription": {"text": "`isomorphic-ws` is pinned at `4.0.1` in `packages/simplex-chat-client/typescript/package.json` while the latest release on the npm registry is `5.0.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `isomorphic-ws` to `5.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-4f8e0d7871001fc2", "name": "Dependency jsdom is two or more major versions behind", "shortDescription": {"text": "Dependency jsdom is two or more major versions behind"}, "fullDescription": {"text": "`jsdom` is pinned at `22.1.0` in `website/package.json` while the latest release on the npm registry is `29.1.1` \u2014 7 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `jsdom` to `29.1.1`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-6767832726b8c642", "name": "Dependency markdown-it is a major version behind", "shortDescription": {"text": "Dependency markdown-it is a major version behind"}, "fullDescription": {"text": "`markdown-it` is pinned at `13.0.1` in `website/package.json` while the latest release on the npm registry is `14.3.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `markdown-it` to `14.3.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-2dc73caad484864f", "name": "Dependency typescript is two or more major versions behind", "shortDescription": {"text": "Dependency typescript is two or more major versions behind"}, "fullDescription": {"text": "`typescript` is pinned at `5.9.2` in `packages/simplex-chat-client/types/typescript/package.json` while the latest release on the npm registry is `7.0.2` \u2014 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `typescript` to `7.0.2`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}]}}, "automationDetails": {"id": "repobility/30759"}, "properties": {"repository": "simplex-chat/simplex-chat", "repoUrl": "https://github.com/simplex-chat/simplex-chat", "branch": "main"}, "results": [{"ruleId": "scanner-0cd88c1c85a503b9", "level": "note", "message": {"text": "Possibly dead Python function: reply_content"}, "properties": {"repobilityId": "8fd47513248db0e3", "scanner": "scanner-primary", "fingerprint": "0cd88c1c85a503b9", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/client.py:82"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ea12aa0cfd3c1510", "level": "note", "message": {"text": "Possibly dead Python function: deco"}, "properties": {"repobilityId": "11da05572c448654", "scanner": "scanner-primary", "fingerprint": "ea12aa0cfd3c1510", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/client.py:302"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-09b480445bd13e21", "level": "note", "message": {"text": "Possibly dead Python function: call"}, "properties": {"repobilityId": "cf6e1a33b1245f9d", "scanner": "scanner-primary", "fingerprint": "09b480445bd13e21", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/client.py:769"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-df3f157dc99bb62b", "level": "note", "message": {"text": "Possibly dead Python function: gid_match"}, "properties": {"repobilityId": "06de52da58a4ca21", "scanner": "scanner-primary", "fingerprint": "df3f157dc99bb62b", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/filters.py:34"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f3e3fd31da81d590", "level": "note", "message": {"text": "Possibly dead Python function: cid_match"}, "properties": {"repobilityId": "d8f17a9da0fcc5df", "scanner": "scanner-primary", "fingerprint": "f3e3fd31da81d590", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/filters.py:43"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c75762b227827387", "level": "note", "message": {"text": "Possibly dead Python function: api_delete_user_address"}, "properties": {"repobilityId": "05ce8d436e45dc6f", "scanner": "scanner-primary", "fingerprint": "c75762b227827387", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:133"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-564ee8b0e80e9d86", "level": "note", "message": {"text": "Possibly dead Python function: api_set_profile_address"}, "properties": {"repobilityId": "39beacb228277a87", "scanner": "scanner-primary", "fingerprint": "564ee8b0e80e9d86", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:154"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ec423cf92878d93", "level": "note", "message": {"text": "Possibly dead Python function: api_update_chat_item"}, "properties": {"repobilityId": "bc988680000e93e6", "scanner": "scanner-primary", "fingerprint": "3ec423cf92878d93", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:219"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3c51fb05bb56f86f", "level": "note", "message": {"text": "Possibly dead Python function: api_delete_chat_items"}, "properties": {"repobilityId": "69db200c930ac7b2", "scanner": "scanner-primary", "fingerprint": "3c51fb05bb56f86f", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:241"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d2432d04919befe8", "level": "note", "message": {"text": "Possibly dead Python function: api_delete_member_chat_item"}, "properties": {"repobilityId": "37bc37f94aa60623", "scanner": "scanner-primary", "fingerprint": "d2432d04919befe8", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:261"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dc10cda14db71548", "level": "note", "message": {"text": "Possibly dead Python function: api_chat_item_reaction"}, "properties": {"repobilityId": "086c4ebb0611944a", "scanner": "scanner-primary", "fingerprint": "dc10cda14db71548", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:273"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fff773a395c4a6eb", "level": "note", "message": {"text": "Possibly dead Python function: api_receive_file"}, "properties": {"repobilityId": "c0902bfcde573930", "scanner": "scanner-primary", "fingerprint": "fff773a395c4a6eb", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:299"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-86ba40c9ad8a9c4c", "level": "note", "message": {"text": "Possibly dead Python function: api_cancel_file"}, "properties": {"repobilityId": "298d45842a7d9ff1", "scanner": "scanner-primary", "fingerprint": "86ba40c9ad8a9c4c", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:307"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b04079d60d34327b", "level": "note", "message": {"text": "Possibly dead Python function: api_add_member"}, "properties": {"repobilityId": "4fa8e901f3ff0015", "scanner": "scanner-primary", "fingerprint": "b04079d60d34327b", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:316"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b81ff5fd8826dcc0", "level": "note", "message": {"text": "Possibly dead Python function: api_join_group"}, "properties": {"repobilityId": "2e951481e6878626", "scanner": "scanner-primary", "fingerprint": "b81ff5fd8826dcc0", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:328"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ab545d20375f95b8", "level": "note", "message": {"text": "Possibly dead Python function: api_accept_member"}, "properties": {"repobilityId": "8661f4dbe1b358de", "scanner": "scanner-primary", "fingerprint": "ab545d20375f95b8", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:334"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-62ff60a141e6f5f7", "level": "note", "message": {"text": "Possibly dead Python function: api_set_members_role"}, "properties": {"repobilityId": "7f0c5db2f1f2ba92", "scanner": "scanner-primary", "fingerprint": "62ff60a141e6f5f7", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:346"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bc32e244ed4cfcfd", "level": "note", "message": {"text": "Possibly dead Python function: api_block_members_for_all"}, "properties": {"repobilityId": "3c37b610a6d7b02b", "scanner": "scanner-primary", "fingerprint": "bc32e244ed4cfcfd", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:357"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7220904896fc56ca", "level": "note", "message": {"text": "Possibly dead Python function: api_remove_members"}, "properties": {"repobilityId": "34f3473a8160a0c9", "scanner": "scanner-primary", "fingerprint": "7220904896fc56ca", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:368"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0be1de5dcb203c0b", "level": "note", "message": {"text": "Possibly dead Python function: api_leave_group"}, "properties": {"repobilityId": "557d28e1f67cecf3", "scanner": "scanner-primary", "fingerprint": "0be1de5dcb203c0b", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:380"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1191be3873132f2c", "level": "note", "message": {"text": "Possibly dead Python function: api_list_members"}, "properties": {"repobilityId": "4f95cd060f0d55da", "scanner": "scanner-primary", "fingerprint": "1191be3873132f2c", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:386"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c2f6565ff6ee4373", "level": "note", "message": {"text": "Possibly dead Python function: api_new_group"}, "properties": {"repobilityId": "c2c88d9c0ad62ae3", "scanner": "scanner-primary", "fingerprint": "c2f6565ff6ee4373", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:392"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5311072e2d457e5e", "level": "note", "message": {"text": "Possibly dead Python function: api_update_group_profile"}, "properties": {"repobilityId": "290625bfee2c7b66", "scanner": "scanner-primary", "fingerprint": "5311072e2d457e5e", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:402"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-944181e2c412fd0d", "level": "note", "message": {"text": "Possibly dead Python function: api_create_group_link"}, "properties": {"repobilityId": "3999eab38d3ad670", "scanner": "scanner-primary", "fingerprint": "944181e2c412fd0d", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:418"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d13f309c205bea48", "level": "note", "message": {"text": "Possibly dead Python function: api_set_group_link_member_role"}, "properties": {"repobilityId": "60b584144cf77d78", "scanner": "scanner-primary", "fingerprint": "d13f309c205bea48", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:427"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7a0dc68b5d4f1c95", "level": "note", "message": {"text": "Possibly dead Python function: api_delete_group_link"}, "properties": {"repobilityId": "e423bd345d6d89ad", "scanner": "scanner-primary", "fingerprint": "7a0dc68b5d4f1c95", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:436"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-939e67eccb03724d", "level": "note", "message": {"text": "Possibly dead Python function: api_get_group_link_str"}, "properties": {"repobilityId": "3b0fac7a639a3a2a", "scanner": "scanner-primary", "fingerprint": "939e67eccb03724d", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:447"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dca602673e331320", "level": "note", "message": {"text": "Possibly dead Python function: api_create_link"}, "properties": {"repobilityId": "5c4cff35ca668610", "scanner": "scanner-primary", "fingerprint": "dca602673e331320", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:455"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b5510156d72735ab", "level": "note", "message": {"text": "Possibly dead Python function: api_connect"}, "properties": {"repobilityId": "5082d8959de9252c", "scanner": "scanner-primary", "fingerprint": "b5510156d72735ab", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:476"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5c7ee34fd044469a", "level": "note", "message": {"text": "Possibly dead Python function: api_accept_contact_request"}, "properties": {"repobilityId": "11692d2c2e217731", "scanner": "scanner-primary", "fingerprint": "5c7ee34fd044469a", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/api.py:503"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f9c28be7c1fe0d89", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 apps/multiplatform/common/src/commonMain/resources/assets/www/call.js:1144"}, "properties": {"repobilityId": "d65ab1ba5db209c5", "scanner": "scanner-primary", "fingerprint": "f9c28be7c1fe0d89", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/multiplatform/common/src/commonMain/resources/assets/www/call.js"}, "region": {"startLine": 1144}}}]}, {"ruleId": "scanner-326992887a10f4fc", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 apps/multiplatform/common/src/commonMain/resources/assets/www/call.js:30"}, "properties": {"repobilityId": "6542d2b6d8398326", "scanner": "scanner-primary", "fingerprint": "326992887a10f4fc", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/multiplatform/common/src/commonMain/resources/assets/www/call.js"}, "region": {"startLine": 30}}}]}, {"ruleId": "scanner-34bc175cda3e7974", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 apps/multiplatform/common/src/commonMain/resources/assets/www/desktop/ui.js:8"}, "properties": {"repobilityId": "f801395cd54062f4", "scanner": "scanner-primary", "fingerprint": "34bc175cda3e7974", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/multiplatform/common/src/commonMain/resources/assets/www/desktop/ui.js"}, "region": {"startLine": 8}}}]}, {"ruleId": "scanner-10c8bf995ee4f49e", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 website/src/js/contact.js:11"}, "properties": {"repobilityId": "ef5337d0cb1f1f35", "scanner": "scanner-primary", "fingerprint": "10c8bf995ee4f49e", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/js/contact.js"}, "region": {"startLine": 11}}}]}, {"ruleId": "scanner-2f7737315ee6c076", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 website/src/js/design3.js:77"}, "properties": {"repobilityId": "1ab694d0cc52da76", "scanner": "scanner-primary", "fingerprint": "2f7737315ee6c076", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/js/design3.js"}, "region": {"startLine": 77}}}]}, {"ruleId": "scanner-7a9a1597ab25b677", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 website/src/js/directory.js:309"}, "properties": {"repobilityId": "130554b001e7f925", "scanner": "scanner-primary", "fingerprint": "7a9a1597ab25b677", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/js/directory.js"}, "region": {"startLine": 309}}}]}, {"ruleId": "scanner-7168835c14006656", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 website/src/js/animation2.js:3"}, "properties": {"repobilityId": "8b65886c75dabf87", "scanner": "scanner-primary", "fingerprint": "7168835c14006656", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/js/animation2.js"}, "region": {"startLine": 3}}}]}, {"ruleId": "scanner-20a216ff8a60b744", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 website/src/js/docs.js:51"}, "properties": {"repobilityId": "b04832f9501e6f30", "scanner": "scanner-primary", "fingerprint": "20a216ff8a60b744", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/js/docs.js"}, "region": {"startLine": 51}}}]}, {"ruleId": "scanner-3ab81bca85fdfced", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 website/src/js/animation.js:70"}, "properties": {"repobilityId": "b3d28f62aabba445", "scanner": "scanner-primary", "fingerprint": "3ab81bca85fdfced", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/js/animation.js"}, "region": {"startLine": 70}}}]}, {"ruleId": "scanner-ee762c55b2668d55", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 website/src/call/call.js:480"}, "properties": {"repobilityId": "6b5b93642716334f", "scanner": "scanner-primary", "fingerprint": "ee762c55b2668d55", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/call/call.js"}, "region": {"startLine": 480}}}]}, {"ruleId": "scanner-1c58187104e1fdd0", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 website/src/call/call.js:16"}, "properties": {"repobilityId": "0c733926db5e999d", "scanner": "scanner-primary", "fingerprint": "1c58187104e1fdd0", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/call/call.js"}, "region": {"startLine": 16}}}]}, {"ruleId": "scanner-c55c904fcc6bbbff", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 website/src/call/ui.js:76"}, "properties": {"repobilityId": "2ff20c57eeeb624c", "scanner": "scanner-primary", "fingerprint": "c55c904fcc6bbbff", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/call/ui.js"}, "region": {"startLine": 76}}}]}, {"ruleId": "scanner-f79b068ffbb6f531", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 packages/simplex-chat-webrtc/src/ui.js:76"}, "properties": {"repobilityId": "cd563cf97a6838c6", "scanner": "scanner-primary", "fingerprint": "f79b068ffbb6f531", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-webrtc/src/ui.js"}, "region": {"startLine": 76}}}]}, {"ruleId": "scanner-0f199007329f3cc8", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 packages/simplex-chat-webrtc/src/call.ts:1457"}, "properties": {"repobilityId": "3bbb82d899f301b9", "scanner": "scanner-primary", "fingerprint": "0f199007329f3cc8", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-webrtc/src/call.ts"}, "region": {"startLine": 1457}}}]}, {"ruleId": "scanner-61aff3a2912d74ff", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 packages/simplex-chat-webrtc/src/call.ts:238"}, "properties": {"repobilityId": "e8667ce67e93964e", "scanner": "scanner-primary", "fingerprint": "61aff3a2912d74ff", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-webrtc/src/call.ts"}, "region": {"startLine": 238}}}]}, {"ruleId": "scanner-3539c0f81270c39e", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 packages/simplex-chat-webrtc/src/desktop/ui.ts:9"}, "properties": {"repobilityId": "888dc05872aa8c37", "scanner": "scanner-primary", "fingerprint": "3539c0f81270c39e", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-webrtc/src/desktop/ui.ts"}, "region": {"startLine": 9}}}]}, {"ruleId": "scanner-7dd0e4b3bc41e934", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 packages/simplex-chat-client/typescript/src/client.ts:63"}, "properties": {"repobilityId": "3b748c0ed9e12c7e", "scanner": "scanner-primary", "fingerprint": "7dd0e4b3bc41e934", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-client/typescript/src/client.ts"}, "region": {"startLine": 63}}}]}, {"ruleId": "scanner-ac45240a8d19a4da", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 packages/simplex-chat-python/src/simplex_chat/_native.py:102"}, "properties": {"repobilityId": "f5261171d2bb1103", "scanner": "scanner-primary", "fingerprint": "ac45240a8d19a4da", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-python/src/simplex_chat/_native.py"}, "region": {"startLine": 102}}}]}, {"ruleId": "scanner-803e7afa5090eecb", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/contact_page.html:11"}, "properties": {"repobilityId": "75ccd13becbaa946", "scanner": "scanner-primary", "fingerprint": "803e7afa5090eecb", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/contact_page.html"}, "region": {"startLine": 11}}}]}, {"ruleId": "scanner-524a132ccdf911c6", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/footer.html:13"}, "properties": {"repobilityId": "f8081a87cc12c9f8", "scanner": "scanner-primary", "fingerprint": "524a132ccdf911c6", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/footer.html"}, "region": {"startLine": 13}}}]}, {"ruleId": "scanner-880385a0303c7d20", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/hero.html:11"}, "properties": {"repobilityId": "fc5c3ce5c3e1d524", "scanner": "scanner-primary", "fingerprint": "880385a0303c7d20", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/hero.html"}, "region": {"startLine": 11}}}]}, {"ruleId": "scanner-fda1c9fd87840e32", "level": "warning", "message": {"text": "unquoted attribute var \u2014 website/src/_includes/layouts/article.html:5"}, "properties": {"repobilityId": "379c0bf997be9d9b", "scanner": "scanner-primary", "fingerprint": "fda1c9fd87840e32", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "html-templates"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/layouts/article.html"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-54264229cc352f3d", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/layouts/article.html:44"}, "properties": {"repobilityId": "92c1f1ff0af188d7", "scanner": "scanner-primary", "fingerprint": "54264229cc352f3d", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/layouts/article.html"}, "region": {"startLine": 44}}}]}, {"ruleId": "scanner-2022dacf64fa7387", "level": "warning", "message": {"text": "unquoted attribute var \u2014 website/src/_includes/layouts/doc.html:6"}, "properties": {"repobilityId": "9e4f987b45cba180", "scanner": "scanner-primary", "fingerprint": "2022dacf64fa7387", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "html-templates"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/layouts/doc.html"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-4ff9e7edaa69340f", "level": "warning", "message": {"text": "var in href \u2014 website/src/_includes/layouts/doc.html:54"}, "properties": {"repobilityId": "def69644a73b5b9e", "scanner": "scanner-primary", "fingerprint": "4ff9e7edaa69340f", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "html-templates"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/layouts/doc.html"}, "region": {"startLine": 54}}}]}, {"ruleId": "scanner-41c6aeddafee7856", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/layouts/doc.html:77"}, "properties": {"repobilityId": "e1c06ec14702928d", "scanner": "scanner-primary", "fingerprint": "41c6aeddafee7856", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/layouts/doc.html"}, "region": {"startLine": 77}}}]}, {"ruleId": "scanner-ad26c68d40d12a7e", "level": "warning", "message": {"text": "unquoted attribute var \u2014 website/src/_includes/layouts/jobs.html:5"}, "properties": {"repobilityId": "68dd8e407fa5769d", "scanner": "scanner-primary", "fingerprint": "ad26c68d40d12a7e", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "html-templates"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/layouts/jobs.html"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-a6516173ffd33c67", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/layouts/jobs.html:32"}, "properties": {"repobilityId": "44a337e28fff6c3c", "scanner": "scanner-primary", "fingerprint": "a6516173ffd33c67", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/layouts/jobs.html"}, "region": {"startLine": 32}}}]}, {"ruleId": "scanner-40616225e4c27deb", "level": "warning", "message": {"text": "unquoted attribute var \u2014 website/src/_includes/layouts/main.html:5"}, "properties": {"repobilityId": "e42722e8bd2400a4", "scanner": "scanner-primary", "fingerprint": "40616225e4c27deb", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "html-templates"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/layouts/main.html"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-a681fa38c28a497a", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/layouts/main.html:43"}, "properties": {"repobilityId": "12efb84475338b6c", "scanner": "scanner-primary", "fingerprint": "a681fa38c28a497a", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/layouts/main.html"}, "region": {"startLine": 43}}}]}, {"ruleId": "scanner-25b6ec26dd243c79", "level": "warning", "message": {"text": "unquoted attribute var \u2014 website/src/_includes/layouts/privacy.html:5"}, "properties": {"repobilityId": "77b1aab746ef14a7", "scanner": "scanner-primary", "fingerprint": "25b6ec26dd243c79", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "html-templates"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/layouts/privacy.html"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-aa6a1cfd415cc5a5", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/layouts/privacy.html:39"}, "properties": {"repobilityId": "b920d0ecf01433ee", "scanner": "scanner-primary", "fingerprint": "aa6a1cfd415cc5a5", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/layouts/privacy.html"}, "region": {"startLine": 39}}}]}, {"ruleId": "scanner-2fe28436323440bb", "level": "warning", "message": {"text": "var in href \u2014 website/src/_includes/layouts/redirect.html:19"}, "properties": {"repobilityId": "f1ed3a3d3725f533", "scanner": "scanner-primary", "fingerprint": "2fe28436323440bb", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "html-templates"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/layouts/redirect.html"}, "region": {"startLine": 19}}}]}, {"ruleId": "scanner-1db67d6415723a92", "level": "warning", "message": {"text": "unquoted attribute var \u2014 website/src/_includes/layouts/token.html:5"}, "properties": {"repobilityId": "01fbfd595dd51670", "scanner": "scanner-primary", "fingerprint": "1db67d6415723a92", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "html-templates"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/layouts/token.html"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-669e0db0f9a5bad7", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/layouts/token.html:222"}, "properties": {"repobilityId": "62c48531f5c71e93", "scanner": "scanner-primary", "fingerprint": "669e0db0f9a5bad7", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/layouts/token.html"}, "region": {"startLine": 222}}}]}, {"ruleId": "scanner-679d42f2be28c50e", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/navbar.html:17"}, "properties": {"repobilityId": "b8bd714c6ec44c42", "scanner": "scanner-primary", "fingerprint": "679d42f2be28c50e", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/navbar.html"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-09e1c9aabb0d5300", "level": "warning", "message": {"text": "var in href \u2014 website/src/_includes/navbar.html:51"}, "properties": {"repobilityId": "99e3de7976409d94", "scanner": "scanner-primary", "fingerprint": "09e1c9aabb0d5300", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "html-templates"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/navbar.html"}, "region": {"startLine": 51}}}]}, {"ruleId": "scanner-455218701d4a64f7", "level": "warning", "message": {"text": "unquoted attribute var \u2014 website/src/_includes/navbar.html:51"}, "properties": {"repobilityId": "1fff7b25ffe741c6", "scanner": "scanner-primary", "fingerprint": "455218701d4a64f7", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "html-templates"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/navbar.html"}, "region": {"startLine": 51}}}]}, {"ruleId": "scanner-2ba7adae1d88c981", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/overlay_content/file/protocol.html:2"}, "properties": {"repobilityId": "7c8495ff3821532b", "scanner": "scanner-primary", "fingerprint": "2ba7adae1d88c981", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/overlay_content/file/protocol.html"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-d595e5f59f6d1126", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/overlay_content/hero/card_1.html:2"}, "properties": {"repobilityId": "9748d34bc1e82c75", "scanner": "scanner-primary", "fingerprint": "d595e5f59f6d1126", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/overlay_content/hero/card_1.html"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-de23e5a8764cb4d8", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/overlay_content/hero/card_2.html:2"}, "properties": {"repobilityId": "a2c95fbf6f5df959", "scanner": "scanner-primary", "fingerprint": "de23e5a8764cb4d8", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/overlay_content/hero/card_2.html"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-58fd472b56e5ddd4", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/overlay_content/hero/card_3.html:2"}, "properties": {"repobilityId": "ef96b9c58bf13e9a", "scanner": "scanner-primary", "fingerprint": "58fd472b56e5ddd4", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/overlay_content/hero/card_3.html"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-5397af6b19c25859", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/overlay_content/simplex_network/card_1.html:2"}, "properties": {"repobilityId": "4bfb91b4671551d4", "scanner": "scanner-primary", "fingerprint": "5397af6b19c25859", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/overlay_content/simplex_network/card_1.html"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-872b6e94bc0bbab6", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/overlay_content/why_privacy_matters/card_1.html:2"}, "properties": {"repobilityId": "65f7c3dd2ceb6cf6", "scanner": "scanner-primary", "fingerprint": "872b6e94bc0bbab6", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/overlay_content/why_privacy_matters/card_1.html"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-c266ea0318816140", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/overlay_content/why_privacy_matters/card_2.html:2"}, "properties": {"repobilityId": "3f75f1eb14a780aa", "scanner": "scanner-primary", "fingerprint": "c266ea0318816140", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/overlay_content/why_privacy_matters/card_2.html"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-0d331472217fd235", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/overlay_content/why_privacy_matters/card_3.html:2"}, "properties": {"repobilityId": "a64bacc3af105e49", "scanner": "scanner-primary", "fingerprint": "0d331472217fd235", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/overlay_content/why_privacy_matters/card_3.html"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-197998140b62735b", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/overlay_content/why_simplex_is_unique/card_1.html:2"}, "properties": {"repobilityId": "8920a60133727095", "scanner": "scanner-primary", "fingerprint": "197998140b62735b", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/overlay_content/why_simplex_is_unique/card_1.html"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-6ca3b41b76999e9d", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/overlay_content/why_simplex_is_unique/card_2.html:2"}, "properties": {"repobilityId": "a47bf45f8603698c", "scanner": "scanner-primary", "fingerprint": "6ca3b41b76999e9d", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/overlay_content/why_simplex_is_unique/card_2.html"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-448805d117b20476", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/overlay_content/why_simplex_is_unique/card_3.html:2"}, "properties": {"repobilityId": "a65212dc89a3ad51", "scanner": "scanner-primary", "fingerprint": "448805d117b20476", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/overlay_content/why_simplex_is_unique/card_3.html"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-95a11fc1e06e1012", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/overlay_content/why_simplex_is_unique/card_4.html:2"}, "properties": {"repobilityId": "7a48bd09f85fd671", "scanner": "scanner-primary", "fingerprint": "95a11fc1e06e1012", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/overlay_content/why_simplex_is_unique/card_4.html"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-3e75d75f3e7c9946", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/sections/join_simplex.html:6"}, "properties": {"repobilityId": "9a45033cabbee765", "scanner": "scanner-primary", "fingerprint": "3e75d75f3e7c9946", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/sections/join_simplex.html"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-36e5312f43a63cd5", "level": "warning", "message": {"text": "unquoted attribute var \u2014 website/src/_includes/sections/join_simplex.html:20"}, "properties": {"repobilityId": "2541d4459d13efef", "scanner": "scanner-primary", "fingerprint": "36e5312f43a63cd5", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "html-templates"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/sections/join_simplex.html"}, "region": {"startLine": 20}}}]}, {"ruleId": "scanner-cd8ed9e29dc92cfd", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/sections/simplex_unique.html:3"}, "properties": {"repobilityId": "971108b0b184a6df", "scanner": "scanner-primary", "fingerprint": "cd8ed9e29dc92cfd", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/sections/simplex_unique.html"}, "region": {"startLine": 3}}}]}, {"ruleId": "scanner-d76edf2a1a807712", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/sections/simplex_unique/card_1.html:2"}, "properties": {"repobilityId": "1edf0647f29d5d74", "scanner": "scanner-primary", "fingerprint": "d76edf2a1a807712", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/sections/simplex_unique/card_1.html"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-63cbf95516bd8e13", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/sections/simplex_unique/card_2.html:2"}, "properties": {"repobilityId": "6c2af3ccc1ae5791", "scanner": "scanner-primary", "fingerprint": "63cbf95516bd8e13", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/sections/simplex_unique/card_2.html"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-2cd6907783562f5c", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/sections/simplex_unique/card_3.html:2"}, "properties": {"repobilityId": "b9184e53a250b617", "scanner": "scanner-primary", "fingerprint": "2cd6907783562f5c", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/sections/simplex_unique/card_3.html"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-6374787b8ea18884", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/sections/simplex_unique/card_4.html:2"}, "properties": {"repobilityId": "f185336152225508", "scanner": "scanner-primary", "fingerprint": "6374787b8ea18884", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/sections/simplex_unique/card_4.html"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-7374226dbcceb8d2", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/_includes/simplex_explained.html:28"}, "properties": {"repobilityId": "a58203772c721de4", "scanner": "scanner-primary", "fingerprint": "7374226dbcceb8d2", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/_includes/simplex_explained.html"}, "region": {"startLine": 28}}}]}, {"ruleId": "scanner-3f98a05f965fdace", "level": "warning", "message": {"text": "var in href \u2014 website/src/blog.html:76"}, "properties": {"repobilityId": "168c884fdf815d4e", "scanner": "scanner-primary", "fingerprint": "3f98a05f965fdace", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "html-templates"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/blog.html"}, "region": {"startLine": 76}}}]}, {"ruleId": "scanner-e89fe1b0a4a2f577", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/blog.html:76"}, "properties": {"repobilityId": "97ee1f2c1b7a89dc", "scanner": "scanner-primary", "fingerprint": "e89fe1b0a4a2f577", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/blog.html"}, "region": {"startLine": 76}}}]}, {"ruleId": "scanner-c60abd48cef265bb", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/fdroid.html:21"}, "properties": {"repobilityId": "a222e40ce9de1170", "scanner": "scanner-primary", "fingerprint": "c60abd48cef265bb", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/fdroid.html"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-e4afe4742cc2e118", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/file.html:187"}, "properties": {"repobilityId": "6f38960f566cf33a", "scanner": "scanner-primary", "fingerprint": "e4afe4742cc2e118", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/file.html"}, "region": {"startLine": 187}}}]}, {"ruleId": "scanner-86e239994cbd8dc5", "level": "warning", "message": {"text": "unquoted attribute var \u2014 website/src/index.html:12"}, "properties": {"repobilityId": "15c377487461870d", "scanner": "scanner-primary", "fingerprint": "86e239994cbd8dc5", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "html-templates"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/index.html"}, "region": {"startLine": 12}}}]}, {"ruleId": "scanner-77997e855effa5d2", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/index.html:100"}, "properties": {"repobilityId": "28b30bd79278b939", "scanner": "scanner-primary", "fingerprint": "77997e855effa5d2", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/index.html"}, "region": {"startLine": 100}}}]}, {"ruleId": "scanner-d209195850b933fa", "level": "warning", "message": {"text": "var in href \u2014 website/src/index.html:117"}, "properties": {"repobilityId": "2aa07c369faf9ee2", "scanner": "scanner-primary", "fingerprint": "d209195850b933fa", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "html-templates"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/index.html"}, "region": {"startLine": 117}}}]}, {"ruleId": "scanner-3b896f7335595212", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/links.html:236"}, "properties": {"repobilityId": "f3aec40f99f31494", "scanner": "scanner-primary", "fingerprint": "3b896f7335595212", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/links.html"}, "region": {"startLine": 236}}}]}, {"ruleId": "scanner-cac6225d3d7bf291", "level": "warning", "message": {"text": "var in href \u2014 website/src/links.html:295"}, "properties": {"repobilityId": "5d740635511f0f94", "scanner": "scanner-primary", "fingerprint": "cac6225d3d7bf291", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "html-templates"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/links.html"}, "region": {"startLine": 295}}}]}, {"ruleId": "scanner-2812bc3318bd1721", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/messaging.html:21"}, "properties": {"repobilityId": "c89b58d9d10dbed0", "scanner": "scanner-primary", "fingerprint": "2812bc3318bd1721", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/messaging.html"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-e8bdf265f92e6e28", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/old.html:14"}, "properties": {"repobilityId": "953fe3179b0c5b96", "scanner": "scanner-primary", "fingerprint": "e8bdf265f92e6e28", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/old.html"}, "region": {"startLine": 14}}}]}, {"ruleId": "scanner-d1cf6cfa52e23d69", "level": "warning", "message": {"text": "template unescaped with safe \u2014 website/src/why.html:15"}, "properties": {"repobilityId": "4c7be278f9a7eaa8", "scanner": "scanner-primary", "fingerprint": "d1cf6cfa52e23d69", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "flask"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/why.html"}, "region": {"startLine": 15}}}]}, {"ruleId": "scanner-3a3527e70129fb18", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 Dockerfile"}, "properties": {"repobilityId": "691787f6b20605df", "scanner": "scanner-primary", "fingerprint": "3a3527e70129fb18", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-3c4041c454cda88e", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 Dockerfile"}, "properties": {"repobilityId": "da995bb2cfa21f65", "scanner": "scanner-primary", "fingerprint": "3c4041c454cda88e", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-a4b9283354e8accd", "level": "error", "message": {"text": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 Dockerfile"}, "properties": {"repobilityId": "c484f9f5427be180", "scanner": "scanner-primary", "fingerprint": "a4b9283354e8accd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-9212dfb5585dffa6", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 Dockerfile.build"}, "properties": {"repobilityId": "1bb9a8955c27fadc", "scanner": "scanner-primary", "fingerprint": "9212dfb5585dffa6", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-36e3fde2a5facb6d", "level": "error", "message": {"text": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 Dockerfile.build"}, "properties": {"repobilityId": "f2548d43002f6cfe", "scanner": "scanner-primary", "fingerprint": "36e3fde2a5facb6d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-dc83e44bf55910b6", "level": "warning", "message": {"text": "Privileged port 256 in use"}, "properties": {"repobilityId": "0ec1f2d0c9e6da94", "scanner": "scanner-primary", "fingerprint": "dc83e44bf55910b6", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/simplex-chat-reproduce-builds.sh"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f01032220206384d", "level": "warning", "message": {"text": "Privileged port 98 in use"}, "properties": {"repobilityId": "6c2637adabd7c962", "scanner": "scanner-primary", "fingerprint": "f01032220206384d", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/simplex-chat-reproduce-builds.sh"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ae8cc70ffc7d7022", "level": "warning", "message": {"text": "Privileged port 70 in use"}, "properties": {"repobilityId": "353d31c086b0a24a", "scanner": "scanner-primary", "fingerprint": "ae8cc70ffc7d7022", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/simplex-chat-reproduce-builds-android.sh"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-05cb8b58b94b41f7", "level": "warning", "message": {"text": "Privileged port 14 in use"}, "properties": {"repobilityId": "2dbd4b719a1412ff", "scanner": "scanner-primary", "fingerprint": "05cb8b58b94b41f7", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/simplex-chat-reproduce-builds-android.sh"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6a0dd1c78bdd0436", "level": "warning", "message": {"text": "Privileged port 77 in use"}, "properties": {"repobilityId": "8973066c94ce1cf2", "scanner": "scanner-primary", "fingerprint": "6a0dd1c78bdd0436", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/simplex-chat-reproduce-builds-android.sh"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d63da3583b14afc0", "level": "warning", "message": {"text": "Dockerfile runs as root: Dockerfile"}, "properties": {"repobilityId": "a2ed1bd120e507db", "scanner": "scanner-primary", "fingerprint": "d63da3583b14afc0", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-b7396bc6b618acbd", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: ubuntu:${TAG}"}, "properties": {"repobilityId": "63877cd79cb44c89", "scanner": "scanner-primary", "fingerprint": "b7396bc6b618acbd", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-e2f1cddf8cbe14d3", "level": "error", "message": {"text": "Dockerfile pipes a remote installer into a shell"}, "properties": {"repobilityId": "589a52dcd3d98fa1", "scanner": "scanner-primary", "fingerprint": "e2f1cddf8cbe14d3", "layer": "hardware", "severity": "high", "confidence": 1.0, "tags": ["supply-chain", "docker", "remote-installer"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 15}}}]}, {"ruleId": "scanner-54fd559fd5a28a50", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in apps/multiplatform/common/src/commonMain/resources/assets/www/desktop/ui.js:89"}, "properties": {"repobilityId": "ea224a36d8f856f4", "scanner": "scanner-primary", "fingerprint": "54fd559fd5a28a50", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/multiplatform/common/src/commonMain/resources/assets/www/desktop/ui.js"}, "region": {"startLine": 89}}}]}, {"ruleId": "scanner-acb101d9b72dc9c5", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in website/.eleventy.js:136"}, "properties": {"repobilityId": "f7d28ba360e462f8", "scanner": "scanner-primary", "fingerprint": "acb101d9b72dc9c5", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/.eleventy.js"}, "region": {"startLine": 136}}}]}, {"ruleId": "scanner-ad7e4e7ef1bcea81", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in website/src/js/prism.min.js:3"}, "properties": {"repobilityId": "d043df0f06c7201e", "scanner": "scanner-primary", "fingerprint": "ad7e4e7ef1bcea81", "layer": "security", "severity": "medium", "confidence": 0.85, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/js/prism.min.js"}, "region": {"startLine": 3}}}]}, {"ruleId": "scanner-3d3d816fa27b2fac", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in website/src/js/swiper-bundle.min.js:13"}, "properties": {"repobilityId": "1f310f519710f895", "scanner": "scanner-primary", "fingerprint": "3d3d816fa27b2fac", "layer": "security", "severity": "medium", "confidence": 0.85, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/js/swiper-bundle.min.js"}, "region": {"startLine": 13}}}]}, {"ruleId": "scanner-b9272c04c5a18d5e", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in website/src/js/docs.js:6"}, "properties": {"repobilityId": "a8cb807ad8d0a357", "scanner": "scanner-primary", "fingerprint": "b9272c04c5a18d5e", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/js/docs.js"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-ad1a9928348d53cd", "level": "warning", "message": {"text": "Insecure pattern 'insert_adjacent_html' in website/src/js/demo.js:61"}, "properties": {"repobilityId": "be258ad213f2898c", "scanner": "scanner-primary", "fingerprint": "ad1a9928348d53cd", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "insert_adjacent_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/js/demo.js"}, "region": {"startLine": 61}}}]}, {"ruleId": "scanner-dac2c9a8e67947f8", "level": "warning", "message": {"text": "Insecure pattern 'insert_adjacent_html' in website/src/js/index.js:61"}, "properties": {"repobilityId": "2a661d6fbb258d43", "scanner": "scanner-primary", "fingerprint": "dac2c9a8e67947f8", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "insert_adjacent_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/js/index.js"}, "region": {"startLine": 61}}}]}, {"ruleId": "scanner-1853d72c598b2255", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in packages/simplex-chat-webrtc/src/desktop/ui.ts:108"}, "properties": {"repobilityId": "b9727dfd3f49f560", "scanner": "scanner-primary", "fingerprint": "1853d72c598b2255", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-webrtc/src/desktop/ui.ts"}, "region": {"startLine": 108}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-8ecdc3efdd4aa236", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ed932b39659201ea", "scanner": "scanner-primary", "fingerprint": "8ecdc3efdd4aa236", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/cla.yml"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-2fdcc3aac10df7e9", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "8790272a56f5e9ce", "scanner": "scanner-primary", "fingerprint": "2fdcc3aac10df7e9", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/cla.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-73b22d23d303a3a0", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "a7ecc871a5a39ede", "scanner": "scanner-primary", "fingerprint": "73b22d23d303a3a0", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/web.yml"}, "region": {"startLine": 27}}}]}, {"ruleId": "scanner-8200d745dafb1795", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "9c022d2e116e8e49", "scanner": "scanner-primary", "fingerprint": "8200d745dafb1795", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/reproduce-schedule.yml"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-6ba9bfab5f283202", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "43f61b861591d638", "scanner": "scanner-primary", "fingerprint": "6ba9bfab5f283202", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/build.yml"}, "region": {"startLine": 79}}}]}, {"ruleId": "scanner-361c9c3d725df6cc", "level": "note", "message": {"text": "package.json defines install-time lifecycle scripts"}, "properties": {"repobilityId": "0664f550ab3a335c", "scanner": "scanner-primary", "fingerprint": "361c9c3d725df6cc", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "npm", "install-scripts"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-nodejs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-349a56cdc52f291a", "level": "note", "message": {"text": "Very large file: apps/multiplatform/common/src/commonMain/resources/assets/www/call.js (1505 lines)"}, "properties": {"repobilityId": "2248409d588da3f1", "scanner": "scanner-primary", "fingerprint": "349a56cdc52f291a", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-72f2376383857ca3", "level": "note", "message": {"text": "Very large file: apps/simplex-support-bot/bot.test.ts (2706 lines)"}, "properties": {"repobilityId": "3bd398405d6ab5b5", "scanner": "scanner-primary", "fingerprint": "72f2376383857ca3", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-826d16b77e3bb3d0", "level": "note", "message": {"text": "Very large file: packages/simplex-chat-python/src/simplex_chat/types/_types.py (3562 lines)"}, "properties": {"repobilityId": "266637a0a9f8e571", "scanner": "scanner-primary", "fingerprint": "826d16b77e3bb3d0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-005811cee59e8bf5", "level": "note", "message": {"text": "Very large file: packages/simplex-chat-webrtc/src/call.ts (1872 lines)"}, "properties": {"repobilityId": "f9c5c0de0d43b5c6", "scanner": "scanner-primary", "fingerprint": "005811cee59e8bf5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-babf804452f97582", "level": "note", "message": {"text": "Very large file: packages/simplex-chat-client/types/typescript/src/types.ts (5070 lines)"}, "properties": {"repobilityId": "4ccd1fb717bc8bb9", "scanner": "scanner-primary", "fingerprint": "babf804452f97582", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ea3b5e389d8c9c0f", "level": "note", "message": {"text": "Low test-to-source ratio"}, "properties": {"repobilityId": "ef7b2552cc00a375", "scanner": "scanner-primary", "fingerprint": "ea3b5e389d8c9c0f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["tests"]}}, {"ruleId": "scanner-0075309a6605cbd9", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: website/package.json"}, "properties": {"repobilityId": "01f4e1ec5819a84a", "scanner": "scanner-primary", "fingerprint": "0075309a6605cbd9", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9d0ad3de1b0a95bd", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/simplex-chat-nodejs/package.json"}, "properties": {"repobilityId": "2f30fd3d42391df0", "scanner": "scanner-primary", "fingerprint": "9d0ad3de1b0a95bd", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-nodejs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-666a05be2dfb94bd", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/simplex-chat-webrtc/package.json"}, "properties": {"repobilityId": "e4d480dfbea5f8c4", "scanner": "scanner-primary", "fingerprint": "666a05be2dfb94bd", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-webrtc/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-405514940086b49f", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/simplex-chat-client/types/typescript/package.json"}, "properties": {"repobilityId": "4a9197af689c070c", "scanner": "scanner-primary", "fingerprint": "405514940086b49f", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-client/types/typescript/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9459e1bdf08e40de", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/simplex-chat-client/typescript/package.json"}, "properties": {"repobilityId": "7854589a3ddd9a6e", "scanner": "scanner-primary", "fingerprint": "9459e1bdf08e40de", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-client/typescript/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "25ee8738f1e668e3", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "ebbab21a10ffc5db", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-55be46ce63e4f882", "level": "none", "message": {"text": "Commented-code block (5 lines) in apps/multiplatform/common/src/commonMain/resources/assets/www/call.js:394"}, "properties": {"repobilityId": "4487520e8b8c96b8", "scanner": "scanner-primary", "fingerprint": "55be46ce63e4f882", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/multiplatform/common/src/commonMain/resources/assets/www/call.js"}, "region": {"startLine": 394}}}]}, {"ruleId": "scanner-fa3baf4c5a0300a4", "level": "note", "message": {"text": "Legacy-named symbol `simplex_v1` in apps/simplex-support-bot/src/config.ts:63"}, "properties": {"repobilityId": "1d2d4aa4e18299f5", "scanner": "scanner-primary", "fingerprint": "fa3baf4c5a0300a4", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-05cbfb7271f1d203", "level": "note", "message": {"text": "Legacy-named symbol `isOld` in website/customize_docs_frontmatter.js:78"}, "properties": {"repobilityId": "b80dac69e80e3537", "scanner": "scanner-primary", "fingerprint": "05cbfb7271f1d203", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-7c07ecd85796a5a0", "level": "note", "message": {"text": "Legacy-named symbol `content_copy` in website/src/js/contact.js:41"}, "properties": {"repobilityId": "6241346b11916081", "scanner": "scanner-primary", "fingerprint": "7c07ecd85796a5a0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-2bca68ea7ee5db3e", "level": "none", "message": {"text": "Commented-code block (6 lines) in website/src/js/directory.js:376"}, "properties": {"repobilityId": "98a6e107a7ae5d89", "scanner": "scanner-primary", "fingerprint": "2bca68ea7ee5db3e", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/js/directory.js"}, "region": {"startLine": 376}}}]}, {"ruleId": "scanner-2ab7256b01f63ddd", "level": "none", "message": {"text": "Commented-code block (10 lines) in website/src/js/animation2.js:4"}, "properties": {"repobilityId": "c34954409899d767", "scanner": "scanner-primary", "fingerprint": "2ab7256b01f63ddd", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/js/animation2.js"}, "region": {"startLine": 4}}}]}, {"ruleId": "scanner-6deb31ec89b62598", "level": "note", "message": {"text": "Legacy-named symbol `content_copy` in website/src/js/index.js:361"}, "properties": {"repobilityId": "5ade189f2e5204b9", "scanner": "scanner-primary", "fingerprint": "6deb31ec89b62598", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-f6b52c5f2fff9616", "level": "none", "message": {"text": "Commented-code block (10 lines) in website/src/js/animation.js:43"}, "properties": {"repobilityId": "e5572aacc9ca5280", "scanner": "scanner-primary", "fingerprint": "f6b52c5f2fff9616", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/js/animation.js"}, "region": {"startLine": 43}}}]}, {"ruleId": "scanner-add249c786702e9c", "level": "none", "message": {"text": "Commented-code block (5 lines) in website/src/call/call.js:479"}, "properties": {"repobilityId": "8762647f714fb2f9", "scanner": "scanner-primary", "fingerprint": "add249c786702e9c", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/call/call.js"}, "region": {"startLine": 479}}}]}, {"ruleId": "scanner-1fd1f68279cf930a", "level": "none", "message": {"text": "Commented-code block (6 lines) in website/src/call/ui.js:19"}, "properties": {"repobilityId": "8869246c4dce77b9", "scanner": "scanner-primary", "fingerprint": "1fd1f68279cf930a", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/src/call/ui.js"}, "region": {"startLine": 19}}}]}, {"ruleId": "scanner-9a63a91057d181f7", "level": "note", "message": {"text": "Legacy-named symbol `simplex_v1` in packages/simplex-chat-nodejs/src/api.ts:77"}, "properties": {"repobilityId": "1519085bb8f67ca1", "scanner": "scanner-primary", "fingerprint": "9a63a91057d181f7", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-525a0c763e747a5a", "level": "note", "message": {"text": "Legacy-named symbol `from_buffer_copy` in packages/simplex-chat-python/src/simplex_chat/_native.py:188"}, "properties": {"repobilityId": "4db2c427d6a5f97a", "scanner": "scanner-primary", "fingerprint": "525a0c763e747a5a", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-fff6cca32dffa01f", "level": "note", "message": {"text": "Legacy-named symbol `expiredOld` in packages/simplex-chat-python/src/simplex_chat/types/_types.py:152"}, "properties": {"repobilityId": "dd412f24b19f803c", "scanner": "scanner-primary", "fingerprint": "fff6cca32dffa01f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-7509df1178fc87ff", "level": "none", "message": {"text": "Commented-code block (6 lines) in packages/simplex-chat-webrtc/src/ui.js:19"}, "properties": {"repobilityId": "840d6fd64c3693a4", "scanner": "scanner-primary", "fingerprint": "7509df1178fc87ff", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-webrtc/src/ui.js"}, "region": {"startLine": 19}}}]}, {"ruleId": "scanner-73a37d69cb51830f", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/simplex-chat-webrtc/src/call.ts:686"}, "properties": {"repobilityId": "5979ca72c7541c79", "scanner": "scanner-primary", "fingerprint": "73a37d69cb51830f", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-webrtc/src/call.ts"}, "region": {"startLine": 686}}}]}, {"ruleId": "scanner-475dd4cdbb915027", "level": "note", "message": {"text": "Legacy-named symbol `ExpiredOld` in packages/simplex-chat-client/types/typescript/src/types.ts:205"}, "properties": {"repobilityId": "5bec86c02d75f213", "scanner": "scanner-primary", "fingerprint": "475dd4cdbb915027", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-165feafc550752d7", "level": "error", "message": {"text": "Vulnerable dependency vitest 1.6.1: GHSA-5xrq-8626-4rwp"}, "properties": {"repobilityId": "d0cf3aad4bf409cb", "scanner": "scanner-primary", "fingerprint": "165feafc550752d7", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-5xrq-8626-4rwp", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/simplex-support-bot/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6998a30cc67c4017", "level": "error", "message": {"text": "Vulnerable dependency rollup 2.72.1: GHSA-gcx4-mw62-g8wm"}, "properties": {"repobilityId": "65e14f3e8b31d61c", "scanner": "scanner-primary", "fingerprint": "6998a30cc67c4017", "layer": "dependencies", "severity": "high", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-gcx4-mw62-g8wm", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-client/typescript/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6a28d5abb3a21338", "level": "error", "message": {"text": "Vulnerable dependency rollup 2.72.1: GHSA-mw96-cpmx-2vgc"}, "properties": {"repobilityId": "33b8df6459218f25", "scanner": "scanner-primary", "fingerprint": "6a28d5abb3a21338", "layer": "dependencies", "severity": "high", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-mw96-cpmx-2vgc", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-client/typescript/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-23f84f0d08cf9228", "level": "warning", "message": {"text": "Vulnerable dependency fs 0.0.1-security: MAL-2025-21003"}, "properties": {"repobilityId": "19d92a1e82d38e3e", "scanner": "scanner-primary", "fingerprint": "23f84f0d08cf9228", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "MAL-2025-21003"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7d0af19f905d175c", "level": "warning", "message": {"text": "Vulnerable dependency markdown-it 13.0.1: GHSA-38c4-r59v-3vqw"}, "properties": {"repobilityId": "f407a196356661cc", "scanner": "scanner-primary", "fingerprint": "7d0af19f905d175c", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-38c4-r59v-3vqw"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5d534136b77c7084", "level": "warning", "message": {"text": "Vulnerable dependency markdown-it 13.0.1: GHSA-6v5v-wf23-fmfq"}, "properties": {"repobilityId": "b3ae943ff26d78d1", "scanner": "scanner-primary", "fingerprint": "5d534136b77c7084", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-6v5v-wf23-fmfq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bce14173c06b5350", "level": "error", "message": {"text": "Vulnerable dependency fast-uri 2.1.0: GHSA-q3j6-qgpj-74h6"}, "properties": {"repobilityId": "bbf8fa822742a5bb", "scanner": "scanner-primary", "fingerprint": "bce14173c06b5350", "layer": "dependencies", "severity": "high", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-q3j6-qgpj-74h6", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-09feb9c813cefdf4", "level": "error", "message": {"text": "Vulnerable dependency fast-uri 2.1.0: GHSA-v39h-62p7-jpjc"}, "properties": {"repobilityId": "06042a4aed32cf26", "scanner": "scanner-primary", "fingerprint": "09feb9c813cefdf4", "layer": "dependencies", "severity": "high", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-v39h-62p7-jpjc", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4bd54199af779af6", "level": "warning", "message": {"text": "Vulnerable dependency esbuild 0.21.5: GHSA-67mh-4wv8-2f99"}, "properties": {"repobilityId": "be00f073db852f14", "scanner": "scanner-primary", "fingerprint": "4bd54199af779af6", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-67mh-4wv8-2f99", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/simplex-support-bot/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c33ad296124c932f", "level": "error", "message": {"text": "Vulnerable dependency postcss 8.5.10: GHSA-6g55-p6wh-862q"}, "properties": {"repobilityId": "8a94917bf6cfa1fe", "scanner": "scanner-primary", "fingerprint": "c33ad296124c932f", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-6g55-p6wh-862q", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/simplex-support-bot/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0608f2d29b2565de", "level": "warning", "message": {"text": "Vulnerable dependency vite 5.4.21: GHSA-4w7w-66w2-5vf9"}, "properties": {"repobilityId": "90685dbb72b15019", "scanner": "scanner-primary", "fingerprint": "0608f2d29b2565de", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-4w7w-66w2-5vf9", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/simplex-support-bot/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f0b3454151599e5c", "level": "error", "message": {"text": "Vulnerable dependency vite 5.4.21: GHSA-fx2h-pf6j-xcff"}, "properties": {"repobilityId": "d9b9604813f5ec55", "scanner": "scanner-primary", "fingerprint": "f0b3454151599e5c", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-fx2h-pf6j-xcff", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/simplex-support-bot/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f9500129983dd770", "level": "warning", "message": {"text": "Vulnerable dependency vite 5.4.21: GHSA-v6wh-96g9-6wx3"}, "properties": {"repobilityId": "6d8cd9b06e1669ff", "scanner": "scanner-primary", "fingerprint": "f9500129983dd770", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-v6wh-96g9-6wx3", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/simplex-support-bot/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9faf81221a573ee8", "level": "note", "message": {"text": "Dependency commander is a major version behind"}, "properties": {"repobilityId": "52a9914cee6cd3a5", "scanner": "scanner-primary", "fingerprint": "9faf81221a573ee8", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/simplex-support-bot/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f6b4a27d30e54c85", "level": "note", "message": {"text": "Dependency isomorphic-ws is a major version behind"}, "properties": {"repobilityId": "52d06c354371c1cb", "scanner": "scanner-primary", "fingerprint": "f6b4a27d30e54c85", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-client/typescript/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4f8e0d7871001fc2", "level": "warning", "message": {"text": "Dependency jsdom is two or more major versions behind"}, "properties": {"repobilityId": "323663bd402305c5", "scanner": "scanner-primary", "fingerprint": "4f8e0d7871001fc2", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6767832726b8c642", "level": "note", "message": {"text": "Dependency markdown-it is a major version behind"}, "properties": {"repobilityId": "512c2207b6719129", "scanner": "scanner-primary", "fingerprint": "6767832726b8c642", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2dc73caad484864f", "level": "warning", "message": {"text": "Dependency typescript is two or more major versions behind"}, "properties": {"repobilityId": "bfa16e61139cf2f1", "scanner": "scanner-primary", "fingerprint": "2dc73caad484864f", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/simplex-chat-client/types/typescript/package.json"}, "region": {"startLine": 1}}}]}]}]}