{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "foundry_assumption_check", "name": "Foundry mined assumption checks: vishal8shah/au-jobs", "shortDescription": {"text": "Foundry mined assumption checks: vishal8shah/au-jobs"}, "fullDescription": {"text": "Comment chain pattern product: assumption_checks\nRepo: vishal8shah/au-jobs\nThread: vishal8shah/au-jobs#1\nOutcome: claimed_resolved_unverified\nThread label: thread_has_human_issue_and_fix_context\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, link_quality_weak_supervision, high_risk_human_feedback_label\nChain evidence:\nIssue/PR evidence chain: vishal8shah/au-jobs#1\nRepo: vishal8shah/au-jobs\nThread label: thread_has_human_issue_and_fix_context\nOutcome: claimed_resolved_unverified\nComment count: 1\nLinked commit count: 2\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 8\nLabels: {'security_auth_secret': 1}\nPolarities: {'bad': 1}\nChanged file labels: {'source_or_other': 6, 'docs_or_claims': 2}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-bc92ca3a74b0f03e\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"security_auth_secret\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.com/v"}, "properties": {"scanner": "foundry_dataset", "category": "practices", "severity": "medium", "confidence": 0.62, "cwe": "", "owasp": ""}}, {"id": "foundry_auth_guardrail_gap", "name": "Foundry mined security auth guardrail gaps: vishal8shah/au-jobs", "shortDescription": {"text": "Foundry mined security auth guardrail gaps: vishal8shah/au-jobs"}, "fullDescription": {"text": "Graph query export: Security/auth changes without enough guardrails\nQuery id: security_auth_guardrail_gaps\nQuery type: motif_query\nIntent: Assumption-check security/auth examples requiring stronger tests or CI.\nMotif: security_auth_without_guardrails\nTraining usage: assumption_check\nGraph gold label: weak_supervision_needs_review\nRepo: vishal8shah/au-jobs\nThread: vishal8shah/au-jobs#1\nEvidence:\nGraph motif: Security/auth change without enough guardrails\nMotif id: security_auth_without_guardrails\nPolarity: bad\nTraining usage: assumption_check\nSeverity: critical\nRepo: vishal8shah/au-jobs\nThread: vishal8shah/au-jobs#1\nGraph gold label: weak_supervision_needs_review\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: vishal8shah/au-jobs#1\nRepo: vishal8shah/au-jobs\nIssue/PR number: 1\nGraph consistency label: weak_supervision_needs_review\nNodes: 19\nEdges: 37\nNode types: {'pr_file': 8, 'link_quality': 3, 'commit': 2, 'thread': 1, 'repo': 1, 'comment': 1, 'comment_chain': 1, 'issu"}, "properties": {"scanner": "foundry_dataset", "category": "auth", "severity": "critical", "confidence": 0.78, "cwe": "", "owasp": ""}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-27d047e0434272f0", "name": "Insecure pattern 'direct_innerhtml_assignment' in docs/index.html:889", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/index.html:889"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 84 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-319e66a630e14977", "name": "2 env vars used in code but missing from .env.example", "shortDescription": {"text": "2 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `GEMINI_API_KEY_2`, `OPENROUTER_API_KEY`. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/22309"}, "properties": {"repository": "vishal8shah/au-jobs", "repoUrl": "https://github.com/vishal8shah/au-jobs", "branch": "main"}, "results": [{"ruleId": "foundry_assumption_check", "level": "warning", "message": {"text": "Foundry mined assumption checks: vishal8shah/au-jobs"}, "properties": {"repobilityId": 313632, "scanner": "foundry_dataset", "fingerprint": "51a348030b30b08b61e3f3378c4a6484699d37e648290e3bfea4b82aebd8df31", "category": "practices", "severity": "medium", "confidence": 0.62, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "comment_chain_pattern_product", "source": "comment_chain_pattern_miner", "product": "assumption_checks", "synthetic": false, "thread_key": "vishal8shah/au-jobs#1", "human_labels": ["docs_or_claims", "security_auth_secret", "source_or_other"], "issue_number": "1", "thread_label": "thread_has_human_issue_and_fix_context", "outcome_label": "claimed_resolved_unverified", "source_backed": true, "max_confidence": 0.65, "repo_full_name": "vishal8shah/au-jobs", "training_usage": "weak_supervision", "confidence_tier": "weak_supervision", "source_chain_id": "evidence-chain-issue_chain-f12f8ebce5cd7b45", "helicopter_views": {}, "artifact_families": {"docs": 1, "tests": 1}, "source_chain_kind": "issue_chain", "changed_file_count": 8, "source_graph_label": "source_backed_multi_signal_graph", "changed_file_labels": {"docs_or_claims": 2, "source_or_other": 6}, "linked_commit_count": 2, "helicopter_view_count": 0, "source_artifact_count": 2, "classification_reasons": ["source_graph_has_real_artifacts", "source_graph_has_verification_artifacts", "link_quality_weak_supervision", "high_risk_human_feedback_label"], "linked_ci_commit_count": 0, "verification_artifact_count": 1, "design_schema_api_artifact_count": 0}, "text": "Comment chain pattern product: assumption_checks\nRepo: vishal8shah/au-jobs\nThread: vishal8shah/au-jobs#1\nOutcome: claimed_resolved_unverified\nThread label: thread_has_human_issue_and_fix_context\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, link_quality_weak_supervision, high_risk_human_feedback_label\nChain evidence:\nIssue/PR evidence chain: vishal8shah/au-jobs#1\nRepo: vishal8shah/au-jobs\nThread label: thread_has_human_issue_and_fix_context\nOutcome: claimed_resolved_unverified\nComment count: 1\nLinked commit count: 2\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 8\nLabels: {'security_auth_secret': 1}\nPolarities: {'bad': 1}\nChanged file labels: {'source_or_other': 6, 'docs_or_claims': 2}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-bc92ca3a74b0f03e\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"security_auth_secret\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.com/vishal8shah/au-jobs/pull/1\",\n    \"text\": \"GitHub feedback: security_auth_secret\\nPolarity: bad\\nKind: pull_request_body\\nRepo: vishal8shah/au-jobs\\nAuthor: vishal8shah (User)\\nURL: https://github.com/vishal8shah/au-jobs/pull/1\\nTitle: Add comparison mode to visualize AI exposure changes between runs\\nBody:\\n## Summary\\nThis PR adds a \\\"compare to last refresh\\\" feature that allows users to visualize how AI exposure scores have changed between the current and previous scoring runs. The frontend now displays delta values with a new color scheme, and the backend archives previous scores and computes comparison metadata.\\n\\n## Key Changes\\n\\n**Frontend (docs/index.html)**\\n- Added `.compare-toggle` and `.compare-warning` UI components to switch between \\\"Current\\\" and \\\"vs. Last Refresh\\\" modes\\n- Implemented `deltaColor()` function with blue/purple for rising exposure and amber/orange for falling exposure\\n- Added `updateCompareStats()` to display comparison-specific statistics: rising/falling percentages, biggest movers, and delta distribution histogram\\n- Modified `tileColorCSS()`, `tileSubInfo()`, and `tooltipHighlight()` to handle delta visualization\\n- Updated gradient legend to reflect delta scale (-5 to +5) when in comparison mode\\n- Added `up\"\n  }\n]\nChanged files:\n[\n  {\n    \"id\": \"github-pr-file-file-00572cfbccd8d571\",\n    \"filename\": \".gitignore\",\n    \"label\": \"source_or_other\",\n    \"status\": \"modified\",\n    \"additions\": 1,\n    \"deletions\": 0,\n    \"changes\": 1,\n    \"blob_url\": \"https://github.com/vishal8shah/au-jobs/blob/67a8fe33819982caa50541d18a9bfe6027ba187a/.gitignore\"\n  },\n  {\n    \"id\": \"github-pr-file-file-c40f2f40a6c30195\",\n    \"filename\": \"README.md\",\n    \"label\": \"docs_or_claims\",\n    \"status\": \"modified\",\n    \"additions\": 16,\n    \"deletions\": 5,\n    \"changes\": 21,\n    \"blob_url\": \"https://github.com/vishal8shah/au-jobs/blob/67a8fe33819982caa50541d18a9bfe6027ba187a/README.md\"\n  },\n  {\n    \"id\": \"github-pr-file-file-9aaef\n[truncated by importer]", "source": "foundry_mined_dataset", "repo_url": "https://github.com/vishal8shah/au-jobs", "source_id": "comment-chain-pattern-assumption_checks-4ee708ebf728ef9d", "synthetic": false, "gold_label": "", "graph_label": "source_backed_multi_signal_graph", "source_path": "/data/distillate/foundry_data/comment_chain_patterns/assumption_checks/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "vishal8shah/au-jobs", "source_dataset": "comment_chain_patterns/assumption_checks", "training_usage": "weak_supervision"}}}, {"ruleId": "foundry_auth_guardrail_gap", "level": "error", "message": {"text": "Foundry mined security auth guardrail gaps: vishal8shah/au-jobs"}, "properties": {"repobilityId": 335247, "scanner": "foundry_dataset", "fingerprint": "f058a4aaad58c483feea752c3b6c8c9eef16e7cd88cb9a714b5013e0e4186fd1", "category": "auth", "severity": "critical", "confidence": 0.78, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Security/auth changes without enough guardrails", "intent": "Assumption-check security/auth examples requiring stronger tests or CI.", "labels": {"bug_fix": 1, "docs_or_claims": 2, "source_or_other": 6, "security_or_secrets": 1, "security_auth_secret": 1, "claimed_resolved_unverified": 3, "issue_or_pull_request_thread": 1, "human_reported_issue_then_fix_attempt": 1, "thread_has_human_issue_and_fix_context": 2}, "source": "graph_query_export", "motif_id": "security_auth_without_guardrails", "outcomes": {"claimed_resolved_unverified": 6}, "polarity": "bad", "query_id": "security_auth_guardrail_gaps", "severity": "critical", "ci_labels": {}, "synthetic": false, "edge_count": 37, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "thread_touches_file": 8, "chain_has_link_quality": 3, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 8, "thread_has_comment_chain": 1, "comment_chain_links_commit": 2, "comment_chain_touches_file": 8, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 19, "node_types": {"repo": 1, "commit": 2, "thread": 1, "comment": 1, "pr_file": 8, "fix_outcome": 1, "issue_chain": 1, "link_quality": 3, "comment_chain": 1}, "query_type": "motif_query", "thread_key": "vishal8shah/au-jobs#1", "issue_number": "1", "quality_tiers": {"weak_supervision": 3}, "repo_full_name": "vishal8shah/au-jobs", "training_usage": "assumption_check", "source_motif_id": "graph-pattern-motif-thread-ee6a257ef77a6a59", "graph_gold_label": "weak_supervision_needs_review", "changed_file_labels": {"docs_or_claims": 8, "source_or_other": 24}}, "text": "Graph query export: Security/auth changes without enough guardrails\nQuery id: security_auth_guardrail_gaps\nQuery type: motif_query\nIntent: Assumption-check security/auth examples requiring stronger tests or CI.\nMotif: security_auth_without_guardrails\nTraining usage: assumption_check\nGraph gold label: weak_supervision_needs_review\nRepo: vishal8shah/au-jobs\nThread: vishal8shah/au-jobs#1\nEvidence:\nGraph motif: Security/auth change without enough guardrails\nMotif id: security_auth_without_guardrails\nPolarity: bad\nTraining usage: assumption_check\nSeverity: critical\nRepo: vishal8shah/au-jobs\nThread: vishal8shah/au-jobs#1\nGraph gold label: weak_supervision_needs_review\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: vishal8shah/au-jobs#1\nRepo: vishal8shah/au-jobs\nIssue/PR number: 1\nGraph consistency label: weak_supervision_needs_review\nNodes: 19\nEdges: 37\nNode types: {'pr_file': 8, 'link_quality': 3, 'commit': 2, 'thread': 1, 'repo': 1, 'comment': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'thread_touches_file': 8, 'comment_chain_touches_file': 8, 'issue_chain_touches_file': 8, 'chain_has_link_quality': 3, 'comment_chain_links_commit': 2, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'source_or_other': 6, 'claimed_resolved_unverified': 3, 'docs_or_claims': 2, 'thread_has_human_issue_and_fix_context': 2, 'issue_or_pull_request_thread': 1, 'security_auth_secret': 1, 'human_reported_issue_then_fix_attempt': 1, 'security_or_secrets': 1, 'bug_fix': 1}\nOutcomes: {'claimed_resolved_unverified': 6}\nQuality tiers: {'weak_supervision': 3}\nCI labels: {}\nCurriculum targets:\n- Train auth boundary repair with tests, permission matrices, and secret-handling checks.\n- Keep risky auth changes separate from ordinary bug-fix examples.\nAssumption checks:\n- Are auth/permission paths covered by tests?\n- Are secrets, CORS, or access rules verified rather than summarized?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/vishal8shah/au-jobs", "source_id": "graph-query-motif_query-62a3a09b8875ef52", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/security_auth_guardrail_gaps/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "vishal8shah/au-jobs", "source_dataset": "graph_queries/security_auth_guardrail_gaps", "training_usage": "assumption_check"}}}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-27d047e0434272f0", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/index.html:889"}, "properties": {"repobilityId": "cba7363c134f7b1d", "scanner": "scanner-primary", "fingerprint": "27d047e0434272f0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/index.html"}, "region": {"startLine": 889}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "41798dd67a62c5b2", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "95c20a6df01c89f6", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "eef13d46c4a31089", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-319e66a630e14977", "level": "none", "message": {"text": "2 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "d838d1fc5d8231c9", "scanner": "scanner-primary", "fingerprint": "319e66a630e14977", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}]}]}